Infosys Certified Offensive Security Professional
Practice with real exam-pattern questions for Infosys Certified Offensive Security Professional. Each question includes a detailed explanation to help you understand the concept, not just memorise the answer. Try 10 questions free — no login required.
Full question bank for this exam + 1,357+ others. Cancel anytime.
Join Premium10 Infosys Certified Offensive Security Professional practice questions with answers
Real Lex exam-pattern multiple-choice questions for the Infosys Certified Offensive Security Professional certification. Each question includes the correct answer. The full question bank is available to Premium members.
- Question 1
What is the acceptable input for the "employee_id" and "pin" parameters to perform the login in the AES_Tool.exe?
- ✓employee_id: 15 digits; pin: 10 digitsCorrect
- Bemployee_id: 5 digits; pin: 15 digits
- Cemployee_id: 5 digits; pin: 5 digits
- Demployee_id: 15 digits; pin: 15 digits
- Question 2
What is the correct Employee ID of the John Smith user's bank account in the Encrypted Data Intercept scenario?
- ✓23847.0Correct
- Buser
- C23840.0
- D13847.0
- Question 3
Which of the following steps should be taken to mitigate the SQL injection vulnerability in the customer data exfiltration scenario?
- ✓Validate all input from users before sending it to the database.Correct
- BUse prepared statements to execute SQL queries.
- CWhitelist all allowed characters in the form.
- DAll the above
- Question 4
What is the password for the DMZ machine (Jump Server - WIN7-001) in the C.I Flaw scenario?
- ✓Qwert123Correct
- B123456.0
- Cp@55w04d
- DCheesecake
- Question 5
In the C.I Flaw scenario, what interesting information did you find during the initial reconnaissance?
- ✓Some machine IPs end with 254.Correct
- BAll machines run Win7.
- CSome machines have an open 3389 port.
- DSome machines have an open 443 port.
- Question 6
In the C.I Flaw scenario, how can the attacker propagate into the domain network from the Jump Server in the DMZ network?
- ✓We can try to get the hash of the compromised machine and using it to login to one of the domain machines.Correct
- BWe can use the same credentials to connect to a domain machine.
- CWe can't propagate into the domain network.
- DWe can use the RDP shortcut found on the compromised machine.
- Question 7
In the C.I. Flaw scenario, what is the purpose of the CI hook?
- ✓To automatically execute the reverse shell when the domain controller executes the plink.exe file.Correct
- BTo access the jump server (WIN7-001) in the DMZ network.
- CTo gain access to the leonh user's host.
- DAll the above
- Question 8
Which of the following files is used to execute the C.I. jobs in the C.I Flaw scenario?
- ✓plink.exeCorrect
- Bhydra
- Cncrack
- DMetasploit/meterpreter
- Question 9
Which of the following is the IP address of the Domain controller in the C.I Flaw scenario?
- ✓199.203.100.30Correct
- B172.16.100.7
- C192.168.200.71
- D192.168.200.12
- Question 10
In the C.I. Flaw scenario, what is the purpose of the payload created with msfvenom?
- ✓To provide a reverse shell to the attacker.Correct
- BTo escalate privileges on the target machine.
- CTo gain access to the domain controller.
- DAll the above
More in Security
Infosys Certified CyberArk Defender
Infosys Certified Associate in Cyber Defense Center
Infosys Certified Associate in OT Security
Pay once. Clear every cert this year.
One subscription, full Telegram channel access, every PDF posted during your membership.
- Full access to all 1,357+ certifications
- Monthly updated question banks
- Telegram private channel access
- Cancel anytime
- Everything in Monthly
- Save ₹2,100 vs monthly billing
- Priority answer key requests
- Best for increasing DQ score fast
- Everything in Quarterly
- Lifetime channel access — no renewals
- All future certifications included
- Priority response from admin team
Common questions, straight answers.
A monthly-updated Telegram channel where we post real exam-pattern question banks and detailed answer keys for 1,357+ Infosys Lex certifications. You join once, you get every PDF posted during your membership.
Right after payment on our Graphy page, you'll receive a private invite link to the Telegram channel. Access is instant — usually under 30 seconds.
We compile question banks from the actual Lex test pattern, sourced and verified by 180K+ community members who've recently cleared these exams. Match rate is consistently 85–95%.
Every single month. When Infosys rolls out new versions of certifications, we post updated dumps within 7–10 days. You'll see channel activity weekly.
Clearing certifications is one of the highest-weighted DQ factors. Members typically clear 3–5 certifications in their first 3 months, which moves DQ scores up by a full band.