CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA phased OSCP preparation roadmap — prerequisites to close, how to work the PEN-200 labs, outside practice machines, note-taking and a readiness checklist.

Preparing for the OSCP is not primarily about reading — it is about accumulating hours of hands-on practice until unfamiliar machines stop intimidating you. The exam is a 24-hour practical against targets you have never seen, so effective preparation replicates that: build the prerequisite skills, work the PEN-200 labs until the method is automatic, harden yourself against fresh machines outside the course, and rehearse the endurance and documentation the exam demands.
This roadmap gives you a phased plan for doing exactly that. It is a preparation guide, not a difficulty rating or a certification overview — if you still need the format, cost and scoring basics, start with the OSCP certification guide, and if you want an honest read on the exam's brutality, see how hard the OSCP exam is. Here, the focus is entirely on what to do, in what order.
The OSCP has no formal prerequisites, but the PEN-200 course assumes real technical fluency and will not teach it to you. Before you spend a single day of your paid lab clock, you want these foundations solid, because OffSec explicitly recommends them:
The reason this phase comes first is economic as much as technical. Lab access is time-boxed and paid for; learning what a subnet is on OffSec's clock is expensive. Spend free time on this groundwork now so that paid time later goes to penetration testing, not fundamentals.
Self-check to leave Phase 0: you can stand up a Linux and a Windows VM, move confidently around both, write a short Bash or Python script without a tutorial open, and explain what a port scan is doing. If any of those makes you hesitate, stay in this phase — it is the cheapest place to improve.
PEN-200, "Penetration Testing with Kali Linux", is the official course — 20-plus modules and roughly 321 hours of material spanning enumeration, exploitation, web attacks, privilege escalation and Active Directory attacks, with cloud (AWS) content included. How you consume it matters more than that you consume it.
A method that works:
The 90-day bundle gives a hard three-month lab clock; the Learn One subscription gives a year. Choose the runway that matches your available weekly hours honestly — the certification guide breaks down which purchase option suits which candidate.
Here is the uncomfortable truth about lab-only preparation: the exam's machines are not OffSec's lab machines. If your entire practice history is inside PEN-200, exam day is the first time you meet a genuinely unfamiliar target under pressure. The fix is to practise on machines you have never seen from other reputable sources.
Platforms such as Hack The Box provide large pools of vulnerable machines that stretch your method against variety the course cannot fully supply. How to use outside practice well:
Aim to reach the point where you can compromise unfamiliar intermediate machines end to end, unassisted, more often than not. That consistency — not any single impressive solve — is the real readiness signal.
The OSCP report is a graded, pass/fail component, and candidates routinely under-prepare it because it feels administrative next to the hacking. That is a mistake with a simple remedy: build your documentation habit during practice, so it is automatic under exam fatigue.
Set up a repeatable note structure and use it on every practice machine:
Practising this from Phase 1 pays off twice. It ingrains the discipline so that, exhausted at hour twenty of the exam, you are following a habit rather than inventing a process. And it converts note-taking from an exam-day tax into muscle memory. A compromise you cannot evidence cleanly is a compromise that may not score — the documentation is not optional polish.
Skills are necessary but not sufficient; the OSCP also tests stamina, time management and composure across a continuous 24-hour window. Rehearse those explicitly:
For lower-stakes reinforcement between big sessions, timed, self-tested practice questions on security fundamentals help keep core concepts sharp and reveal weak domains cheaply — used as a study aid to check understanding, never as a substitute for hands-on machine work. The practice test simulation overview explains how timed conditions surface the gaps that relaxed study hides.
Pulling the phases into a working order (compress or extend each block to your background and weekly hours — there is no official timeline, and anyone quoting a guaranteed one is guessing):
Book the exam when you can honestly tick every box:
Gaps in this list are not a verdict on your ability — they are simply your next study targets, telling you which phase to revisit.
Preparation for the OSCP is a progression, not a cram: foundations before you pay, the labs worked as rehearsals rather than reading, unfamiliar machines to break the comfort of the course, documentation drilled until it is reflexive, and full-length timed sessions to prove your stamina and judgement hold. When the checklist is genuinely true, you are ready to book — and if it is not yet, you know exactly where to spend your next block of hours.
If, while preparing, you find yourself questioning whether the whole grind pays off, that is a fair question to pause on — our is OSCP worth it? piece weighs the return by candidate profile. And to see where the credential can take you afterwards, the OSCP career path and salary guide maps the roles and progression it opens.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading