faq

The questions I see asked in r/oscp and the OffSec Discord every single week. Full answers coming — short versions below.

is the PWK course enough?

No. It’s necessary but not sufficient. You need lab time on PG, HTB, or similar.

how long should I prep?

Most people: 3-6 months of consistent daily practice. Depends entirely on your starting level.

should I learn Metasploit?

Yes, but also learn to do things without it. The exam limits Metasploit usage.