Practical DevSecOps Certification Exam Journey

Add Comment

"To go faster, slow down." - Scott Cherf

TL;DR:

If you've ever wondered why DevSecOps is suddenly everywhere - this blog is your answer. I break it down from scratch. This blog walks you through the why behind DevSecOps in the simplest way possible, and points you toward a certification that's 100% hands-on. No theory dumping, no multiple choice - just real skills. If you're serious about this space, this is your starting point. 😊 

The result of all the hard work in this course looks like this! :-) 


Once you earn it, it's yours - for life.

No renewals. No expiry dates. No paying again just to keep a badge active. You put in the work once, you prove your skills once, and that certification stays on your profile forever. In a world where most certifications come with a countdown timer, that's honestly refreshing.


Part 1: Why DevSecOps? What It Means & Why Everyone's Talking About It

Let me take you back a few years.

A developer writes code for weeks, maybe months. The product looks great, the team is excited, launch day is approaching. Then, right before release, the security team gets their hands on it - and finds a dozen vulnerabilities. Everything grinds to a halt. Deadlines slip. Fingers get pointed. The security team is now the villain, the developers are frustrated, and the business is losing money by the day.

Sound familiar? This was the reality for most software teams, and honestly, it was nobody's fault. Security was just always treated as someone else's problem - something you dealt with at the end. Like checking for spelling errors after you've already printed a million copies of a book.

That's exactly the problem DevSecOps was born to fix.

1.1 So What Actually Is DevSecOps?

Dev (Development) + Sec (Security) + Ops (Operations).

Imagine you're a developer at a banking app company. You write a login feature and push your code. In the old world, that code goes through development, gets tested, gets deployed and three months later a security audit finds that you accidentally stored passwords in plain text. Now you're scrambling to fix a live system with real users and real money at stake.

In the DevSecOps world, the moment you push that code, an automated security tool immediately flags it "hey, passwords aren't being hashed properly"  before it ever leaves your laptop, basically. You fix it in 10 minutes. No crisis. No news headline.

1.2 Why Is DevSecOps Booming Right Now?

  • Cyberattacks aren't what they used to be
  • Software ships faster than ever.

1.3 Why Do Organizations Really Need This?

It's cheaper to fix things early. Research consistently shows that fixing a vulnerability in production can cost up to 100x more than catching it during development. 

Speed without security is just fast failure. There's this pressure to ship features constantly and rightfully so, because the market moves fast. But shipping fast while ignoring security is like driving 120 mph on a highway with no brakes. DevSecOps gives you the brakes without making you slow down.

Trust is the most valuable thing a company has. Users give you their data, their payment information, their private conversations. The moment they stop trusting you, they're gone and so the business.

1.4 The Real Challenges (Because It's Not All Smooth)

Culture is the hardest part. Developers and security teams have historically had a tense relationship. Developers want to move fast; security wants to slow down and check everything. Bringing them together requires a genuine shift in mindset and mindset shifts in large organizations don't happen overnight. People resist change. Teams protect their turf. Managers are skeptical of new processes. This is probably the single biggest barrier.

There's a serious skills shortage. DevSecOps sits at the intersection of development, security, and operations - three disciplines that already individually have talent gaps. Finding someone who understands all three, or building teams that can collaborate across all three, is genuinely hard. 

1.5 The Bottom Line

Let's be real - DevSecOps sounds great on paper, but actually implementing it? That's where things get messy. And this course comes into the picture - this will teach very basic way how things works.


Part 2: How To Actually Learn It - Practical DevSecOps Certification Breakdown

If you've been reading through everything above and thinking "okay, this all makes sense - but where do I actually learn this properly?"  let me point you to something genuinely useful.

Practical DevSecOps is one of those rare platforms that doesn't just dump theory at you and call it a day. Everything is hands-on, practical, and built in a way that actually prepares you for real work - not just an exam.

Here's what the journey looks like:

2.1 The Course - Built From the Ground Up

What I really appreciate about this course is that it doesn't assume you already know everything. It starts from the absolute basics and walks you through the entire DevSecOps landscape step by step.

Here's what the course covers:

                                                          Image Source: Practical DevSecOps portal


2.2 Hands-On Lab Access -  This Is Where It Gets Real

Once you enroll, you get access to a live lab environment based on your plan. This is honestly what sets this course apart from most others out there.

You're not watching someone else do things on a screen and hoping it clicks. You're actually building pipelines, running security scans, configuring tools, and solving real problems - from scratch. Every concept you read about, you immediately get to apply in a real environment. That gap between "I understand this in theory" and "I can actually do this at work" closes really fast when you're doing it with your own hands.

2.3 Take Notes - Seriously, Don't Skip This

This might sound obvious but it's worth saying out loud - take notes on everything. Every lab, every concept, every tool configuration. The course covers a lot of ground and the exam will test you on practical scenarios drawn directly from what you've studied. Your notes become your single best resource when you're in the middle of an exam challenge and need to recall exactly how you set something up three weeks ago. Future you will be very grateful.

Bonus Point 

Course Material: Once you enroll, you'll get three years of access to all course videos - giving you plenty of time to learn and revisit the content at your own pace.

Lab Access: Hands-on lab access is available for 30 to 60 days depending on the course you choose, so it's best to plan your practical sessions early.

2.4 The Exam - This Is Not Your Typical Test

Here's where Practical DevSecOps really stands out from other certifications - there are no multiple choice questions. None.

  • The exam is entirely project and task-oriented
  • You get 5 real challenges, each with hands-on tasks - the kind of things you'd actually encounter on the job. 
  • You need to score at least 80% to pass and earn your certification
  • And once you complete the exam, you have 24 hours to submit your exam report through their internal portal - so documentation and clarity of your work matters too, just like in a real professional setting.
  • Note: The Certified DevSecOps is open book exam.

Part 3: My Exam Journey

  • Scheduling smartly was my first decision - I booked my exam slot in the afternoon, which gave me the entire morning to do some last-minute revision and get into the right headspace before sitting down.
  • The exam itself is 6 hours long, and trust me, the clock moves faster than you think once you're in it. Before you even start, make sure you've had a proper meal - not a quick snack, a real meal. You'll thank yourself later.
  • There are 5 questions, each carrying different weightage, so my biggest tip here is to eat the big frog first - tackle the higher-weightage questions early while your mind is fresh and your energy is at its peak.
  • Your notes will be your best friend during the exam. I can't stress this enough - keep them clean, organized, and easily searchable. Whatever you've been building throughout your prep, make sure it's in a shape you can navigate quickly under pressure.
  • One thing I genuinely appreciated was that the DevSecOps team creates a dedicated support channel just for you during the exam. If you hit any technical or troubleshooting issues, they're right there. For me personally, the exam went smoothly and I didn't need to use it - but knowing that support exists is reassuring.
  • I managed to wrap up my exam about an hour before the deadline, which gave me some breathing room. After the 6-hour exam window, you get an additional 24 hours to prepare and submit your report - use every bit of that time wisely. Go through your notes, organize your screenshots, and structure your findings clearly before hitting submit.

Best of luck - you've got this!

Conclusion:

DevSecOps isn't the future anymore - it's the present. The sooner you understand it, the sooner you become someone organizations are actively looking for. And the best way to get there isn't reading more blogs - it's getting your hands dirty. That's exactly what Practical DevSecOps helps you do. Now you know where to start. 🚀


If you've made it this far, you're already more serious about this than most people.

The link below is your starting point to enroll for this course. Take your time - but don't wait too long. The right moment is usually right now. 👇 Best of luck. 


Ready to get started? 👉 Click Here to Enroll

 

Certified AI/ML Pentester (C-AI/MLPen) Exam Journey

Add Comment

 “An AI that could design novel biological pathogens. An AI that could hack into computer systems. I think these are all scary.”  - Sam Altman , CEO - Open AI.

AI is the hot topic, no doubt… but beneath this boom lies a layer of underlying security risks waiting to be hacked. Like Naval says - before you can break the system, you gotta master it first.

As I delved deeper into AI security, I began exploring articles and hands-on playgrounds through good old Google ways. The more I learned, the more confident I felt - but I was still seeking a real challenge to truly test my skills. That’s when I came across the Certified AI/ML Pentester (C-AI/MLPen) by The SecOps Group. In this blog, I’d love to share my journey, learnings, and overall experience with you all.

TL;DR: This exam isn’t a walk in the park. It won’t teach you “How to?”  you’re expected to come prepared. Learn the concepts first, then challenge yourself with the exam. I’ve included some helpful resources you can use to practice beforehand. The exam experience itself is smooth, and you get + one attempt - so take a deep breath and go for it.  If you are prepared😊 Additionally, this blog is not intended to explain how to perform an AI/ML pentest.

The result of all the hard work in this course looks like this! :-)


🧠 Part 1: Preparation – What Should You Study?

Before diving into the exam, it's essential to know what you're signing up for. The exam portal provides a well-structured syllabus that outlines the key areas you’ll be tested on. This helps set your direction and gives clarity on what to expect.


                                                                  Image Source

The topics are spread across AI/ML attack surfaces, prompt injection, output handling vulnerabilities, chaining attacks, and more — so make sure to read the syllabus thoroughly. Understanding the core concepts will go a long way in helping you connect the dots during practical challenges.

🧪 Part 2: Is There a Playground to Practice On?

Yes! And honestly, practice is the game-changer here. You don't want to go into this exam cold.

🔹 1. Web LLM Attacks byPortSwigger

This one’s a goldmine. I spent a good amount of time going through it thoroughly and practicing the hands-on labs. It covers a variety of real-world LLM vulnerabilities like:

  • Exploiting LLM APIs with excessive agency
  • Chaining vulnerabilities in LLM APIs
  • Indirect prompt injection
  • Insecure output handling

You’ll learn not just the what, but the how behind these vulnerabilities -  and trust me, that’s key.

🔹 2. Gandalf Lab – Your AI Boss Fight

This one's just fun. Gandalf challenges you with increasingly clever prompt injection puzzles - like trying to trick an LLM that's actively resisting you.

⚔️ Try to solve all exercises - they sharpen your creative thinking and simulate what you'll face in a real-world AI pentest.




Trust me this is super fun challenge's xD 






🔹 3. More Study Materials (Credit to the Awesome Creators)

Don’t stop at just one or two labs. Here are some handpicked resources that helped me strengthen my understanding:

You can also explore this awesome GitHub repo with hands-on vulnerable LLM apps:

📌 Vulnerable LLM Applications (OWASP) 

🔹 4. Payloads & Playbooks – Your Offensive AI Toolkit (Credit to the Awesome Creators)

These are must-haves if you’re serious about this domain:

🔗 Payloads for Attacking LLMs (PALLMs) 

🔗 Offensive ML Playbook – Wiki

They’re regularly updated and full of practical examples, payloads, and red-teaming mindsets for attacking LLMs.


Part 4: Exam Time!

⏱️ Duration: 4 hours and 15 minutes

🌍 Mode: 100% Online & On-Demand - take it from anywhere

Format: A mix of practical scenarios where you’ll need to spot, exploit, and capture flags from various AI/ML-based vulnerabilities


🎯 Part 5: What’s the Pass Criteria?

To pass:

You need to score 60% or more / Capture 6 out of 8 total flags.

Solve multiple challenges and identify vulnerabilities

The exam is not beginner-friendly, but if you’re prepared and you’ve gone through the practice labs, it becomes a rewarding and achievable milestone.


Conclusion 

If you’ve made it this far, I truly appreciate you taking the time to read my journey! There are likely many other insightful blog posts out there that I might have missed, so if you stumble upon any, please don’t hesitate to DM me. I’d love to include them here to create a more valuable resource for those preparing for this certification and looking to gain practical expertise in AI/ML pentesting. 

I’d also like to commend the incredible work by The SecOps Group team for designing such an outstanding exam; it’s definitely a must-try! Best of luck :-) 

Breaking Android SSL Pinning: A Guide with Frida and Objection

Add Comment


Learn how to bypass Android SSL pinning using Frida and Objection runtime in this comprehensive blog. Explore the powerful combination of Frida's dynamic instrumentation and Objection's runtime manipulation to effectively bypass SSL pinning mechanisms in Android applications.

Identify if an Android application has SSL pinning enabled or not. 

To verify if SSL pinning is enabled in an Android application, first, install the .apk file in the emulator by dragging and dropping it. Next, configure the Android emulator and Burp Suite for traffic interception. 

Launch the application on the emulator and navigate through its features. While testing, closely monitor Burp Suite's "Event log." If SSL pinning is active, the log will indicate its presence. Keep in mind that bypassing or disabling SSL pinning should only be done for legitimate testing purposes, as it may have security implications. Proceed with caution and follow ethical guidelines when attempting to bypass SSL pinning.



To circumvent SSL pinning or deactivate it, follow the steps below.

Start your emulator and make sure you are connected with adb devices 


Step 1: Go to https://github.com/frida/frida/releases 

Step 2: Current dated latest release is - https://github.com/frida/frida/releases/tag/15.2.2 -  from this search frida-server-15.2.2-android-x86.xz as per your environment. (to find your environment run below command) 

The purpose of the command getprop | grep abi is to retrieve the Android Application Binary Interface (ABI) information on an Android device or emulator.

 



OR 

Use the following command to get information about the CPU architecture:

adb shell getprop ro.product.cpu.abi

This command will return the architecture of the emulator, such as x86, x86_64, armeabi-v7a, or arm64-v8a.


Step 3: Download the file and paste it in your emulator directory as below



Commands:

  • C:\Users\nileshs\Desktop\Android
  • $ adb push frida-server /data/local/tmp/


Step 4:- Give the file permission to execute by command `chmod +x`


Commands for your reference:-

  • C:\Users\nileshs\Desktop\Android
  • $ adb shell
  • vbox86p:/ # cd /data/local/tmp
  • cd /data/local/tmp
  • vbox86p:/data/local/tmp # ls
  • ls
  • frida-server
  • vbox86p:/data/local/tmp # ls -ls
  • ls -ls
  • total 45308
  • 45308 -rw-rw-rw- 1 root root 46387888 2022-09-18 02:56 frida-server
  • vbox86p:/data/local/tmp # chmod +x frida-server
  • chmod +x frida-server
  • vbox86p:/data/local/tmp # ls -ls
  • ls -ls
  • total 45308
  • 45308 -rwxrwxrwx 1 root root 46387888 2022-09-18 02:56 frida-server


Step 5:-  Start frida server by command `./frida-server &` 





Step 6:-  Run Objection on the target application by below command


To install objection run below command 
  • C:\Users\nileshs>pip3 install objection


Note: Highlighted red box is the path from where you need to run the objection command 

6.1 - Command to run objection : 
  • objection -g com.appname.mobile explore -q
Where com.appname.mobile = your app 

6.2 -  Now run the command in order to disable SSL Pinning in the Android app

  • android sslpinning disable

Console showing that the method for certificate pinning is bypassed.

Now browse the application you will able to capture the pinned application traffic runtime. 

Important Note Before running objection command: 

  1. In your Genymotion emulator or mobile device, please ensure that all applications are closed. After running the command "objection -g com.appname.mobile explore -q," your targeted application should automatically open. This confirms that the objection is functioning correctly.
  2. If you encounter any errors related to the Frida server while running the objection command, please make sure to verify that your Frida server is running. Typically, such errors occur when the Frida server is stopped.
  3. Please execute the following command in the command prompt with administrator privileges.






Happy testing! Remember, it is highly recommended to stop the Frida-Server after completing your tasks. To do so, you can terminate the Frida server process using the following commands: 

  • adb shell
  • ps -e | grep frida-server
  • kill -9 pid <pid of the frida-server>


Note:-  In case you encounter any errors try to restart the Frida-Server

Certified Red Team Professional (CRTP) Exam Journey

Add Comment
"The more that you read, the more things you will know. The more that you learn, the more places you’ll go." – Dr.Seus

I recently obtained a Certified Red Team Professional certification from Pentester Academy by taking over 5 box + Gaining Enterprise admin access + Report and would like to share my this entire experience with you all.


TL;DR: I always feel myself a learner considering that before we jump into CRTP I thought to make the ground level post as well in this so that the beginners who want to go for CRTP will understand all the basics. (Section 1) 
Those who are already into pentesting may skip this and start from "About the course" section. (Section 2)

Outcome of all the Hard work in this Course looks like this :-)




Section 1: Basics for Beginners 

1x1 Why organizations opt for Red Team Engagement?

This answer I will explain via giving simple difference between Pentesting vs RedTeaming 

Penetration Testing is a must have for any organization. A pentester is designated to ethically hack and evaluate your environment. In this role, they will be the point of contact and operate as the brains behind your organization’s security. An organization may hire someone specifically for pentesting, or may have pentester as part of their duties.

A Red teaming exercise is basically a penetration testing test, but from a military perspective. The red team expert is an attacker, who assumes there is also a defender in your organization’s IT security group. The primary difference is that a pentesting is scope-based, and that scope may not involve strengthening the organization’s defense. It may also be conducted by a single individual.
Red team, on the other hand, comprises of multiple participants, conduct testing without the knowledge of your staff, and may also operate continuously or routinely.

1x2 But You said Red teaming, is there any other color in it ? What Are the Different Types of Teams?

Yes the answer is Blue Team, Purple Team and wait… read till end to know more about it.
In Simple terms:
Red Teaming Goal is: 
  • Red team member is someone who is playing a role of an attacker/adversary, trying to achieve a single or multiple goal/objective and the ultimate goal is to not to get detected while achieving that particular goal/objective.
  • Red team  focuses on bypassing the existing controls. 

Blue Team:
  • The Blue Team is tasked with detecting adversaries and preventing them from breaking into the organization’s infrastructure.
  • Blue teams can begin to prepare themselves before an attack is taken place by evaluating the environment and hardening the infrastructure wherever needed. 
  • During the attack simulation, their goal is to identify breaches swiftly, limit the spread of infection by confining to the system it entered through, and successfully stop the attack.  
  • In simple term Blue team focuses on detecting the red team activity.
Purple team: 
  • It is called purple as its mixture of Red + Blue.  
  • Purple team is more of collaboration between red and blue team. 
  • Where the idea is to help each other i.e. say red team completes its goal/objective so that they will help blue team to improve or say blue team detects the red team so that they will help red team to know why they  got detected. 
  • So this way both red and blue team works together and helps to improve the organization’s security posture. (This is based on the organization scope)
Note: There is Yellow, Orange, and Green Teams as well. I am not including  their description here as our topic is to give you brief summary of CRTP. But below summary is for your reference
Security Function Colors and their tasks: 
 -  Yellow:Builder   
 -  Red:       Attacker
 -  Blue:      Defender
 -  Green:   Builder learns from defender
 -  Purple:  Defender learns from attacker
 -  Orange: Builder learns from attacker

1x3 Who Needs It?
If you’re a small to midsize businesses, you might think red teaming isn’t for you. “I’m too small to be a target,” you might theorize.
But in fact, this is exactly the line of thinking that puts an organization at a risk. If you were a bad actor, wouldn’t you want to go after the guy who’d never expect it? Hence it is needed by all the organization.

Below are some top reasons why a red team exercise should be conducted:

  • Simulate real attacks from a threat actor’s position
  • Focus on your critical assets
  • Remove internal bias from your scope 
  • Test your detection and response Capability 
  • Be a cost effective way to stress/test your wider organization’s capabilities
  • Combine real world offensive and defensive teams – Red Teamers understand both the attack (red team) and protective (blue team) sides of the coin.

Well now you know what Red Teaming is and why its very important for any organization. So now you know the importance of CRTP Cert :)

Let’s jump into the CRTP

Section 2: Certified Red Team Professional (CRTP) COURSE

About the course

Certified Red Team Professional (CRTP) is the introductory level Active Directory Certification offered by Pentester Academy. The instructor is Nikhil Mittal, who is the author of Nishang and has spoken at both DEFCON and Black Hat conferences.

According to me this course is really well made and covers the basics of both Active Directory and Powershell. So if you ask me then it’s a really good start for the beginners who want to know more about AD Pentesting/ Powershell / Red Teaming.

In this course we are focusing first on Assume breach scenario. Assume Breach is a mindset which limits the trust placed for application, services, identities and networks by treating them all (both internal & external) as not secure and probably already compromised. 

In very simple term, organization accepts the fact that an attacker will succeed at any cost and they build the defenses accordingly. This is the only course which is in affordable price that can teach you how to fully and successfully attack an AD on a realistic scenario.

LAB:
Lab Access Period is 30, 60 and 90 Days. You can select as per your time lines.

Is there any Pre-Requisites ?
To be honest NONE. Because if you are starting  from ground 0 in Powershell or Active Directory knowledge; The course instructor Nikhil will build you up to be competent enough to do what is required for the course.


Course Material:

  1. Entire course PDF
  2. Course videos which are from the same PDF
  3. Learning objectives videos
  4. One certification attempt to obtain Certified Red Team Professional (CRTP)
  5. VPN Connection to connect to the lab.

The course covers number of topics including but not limited to:

  • Powershell basics
  • Bypassing defenses in AD
  • Domain enumeration
  • Local privilege escalation
  • Admin recon
  • Lateral movements
  • Domain privilege escalation
  • Across trust attacks
  • Domain persistence and data exfiltration
  • Detecting attack techniques
  • Defending an Active Directory environment
Let’s jump into the Lab Set-Up


This Source Image may look very frightening for the beginners yes but let me tell you its not once you finish the course. This statement may not be applicable for those who are already into pentesting they know what i mean ;) 

In the lab,  you are provided with a multiple tools such as Mimikatz, PowerView, Bloodhound etc. to help you along with the video and reading material. Initially machine access has a low-privileged account which you must then escalate your privileges and laterally move throughout the domain.

So in this environment if you get NT AUTHORITY\SYSTEM then you still have to move ahead ;)



While learning focus on Recon. Recon with Bloodhound is a GAME changer ;)

Try to spend more time on bloodhound understand how it works etc. This will be really helpful ahead.


EXAM TIME


So if you are done with all the course material, learning objective then let’s jump to the Exam:

During the exam you will receive one email for testing the VPN before the exam takes place say half and hour early which includes the exam start time, but you will not receive another email when the exam actually starts, and this can cause confusion. So be aware of the exam start time or you  tend to lose your time if you expect an email authorizing you to go ahead with the activity.

I feel may be this half hour early details is because you will be provided with access to a machine with no tools on it, so be prepared with your arsenal/tools which you think  you will need so that you don’t have to lose time downloading the tools . So prepare your tool army in the machine so when actually time starts you are good to go.

The exam contains 5 machines that the user must pivot between in order to obtain command execution on each of them. Last but not the least your own machine too :P 

This must be accomplished in 24 hours and another 24 hours to write a professional findings report.

Again, I strongly recommend getting familiar with BloodHound and learning what each node/ edge represents.

Conclusion:

After gaining Enterprise admin access and successfully completing the exam I have wrote in depth detailed report and Submitted. Post that you will obtain your Certified Red Team Professional certification.

This title sounds pretty cool, but I don’t feel like a professional yet because I know there’s still a ton of work and study I have to go through, but this course surely helped me a lot and it was an amazing experience.

I highly recommend CRTP for those like me who have OSCP but feel as though they lack active directory experience OR any beginner in infosec can also take this course.


Hope this helps in your CRTP Journey.

Happy Hunting :-)

Important Update About CRTP Course : Certified Red Team Professional (CRTP) course and lab are offered by Altered Security who are creators of the course and lab. You can get the course from here - https://www.alteredsecurity.com/adlab 

OSCP Proctored Exam Journey

Add Comment

“Nothing Worth Having Comes Easy”

TL;DR: This is not a technical post but a story of my journey which I am sharing, so you can take something out of it. There are many OSCP blog post which will help you to give details about 
  • What to study 
  • How to prepare 
  • Where to start 
  • Researcher showing their ways to prepare for the OSCP. 
  • Different cheat-sheet for privilege escalation and many more...So you can refer that. 
The purpose of writing this blog post is to tell you: 
“It always seems impossible until it is done.” and my journey. 

Long time back when I was beginner in info sec, I always thought about should I give time to bug bounty or prepare for certification. Choices and situations makes people take decision in life. 

After few years finally I decided to give the OSCP certification. This decision I took when i was away from my home. Those who are on the same page can correlate as being home is always a blessing :-) 

Manage Time => Family => On time food and everything => Time management DONE :P 

It took a long time for me to prepare due to my on going situations at that time. Failure is part of the process of success. I did not make it on the first try.

Many times what we perceive as an error or failure is actually a gift. Learn from the mistakes and try not to repeat at-least. So I learnt from my all the mistake and made it to OSCP (y) 

   
This is proctored exam and many things you need to be prepared before jumping into it. Take your time to be ready with all the situation before you give your attempt. 

Some of my take-away before exam (its deep):  
  1. Study: Revise/Practice/Make your own notes before you attempt for the exam. Make a note which covers all windows and Linux privilege escalation 
  2. Plan:  Before you go for war try to be ready with your Plan A and Plan B what if this doesn't work what's next ? 
  3. Environment: Make sure your environment/surrounding is good before you give exam. 
  4. Your Weapons: Check twice/thrice or four time to see your Machine is all ready for challenge. (Hardware level - Your laptop/Camera etc)
  5. Quantum Realm:  Make sure your Internet connection is good. ("Rain fire!" on me) 
  6. Fresh Mind: Take proper break in between to fresh up. ("Rain fire!" on me)
  7. Move on: If you stuck move on and come back after sometime 
  8. Food: Have food your body needs so your brain too during exam.  ("Rain fire!" on me)
  9. Time: If you manage your exam time, your end result will be fruitful. 
  10. Points: Last but not least plan your targets to get require points to win the GAME :) 

During this journey you may feel broken, tense and many more negative things but always remember one thing in your exam and in your life #NeverGiveUp no matter what (y)

Offensive Security Certified Professional (OSCP) Certification journey will take you to the Roller coaster ride where you will see failure, demotivation, sleepless nights and all the negative elements on the road but the outcome at the end of the GAME will make's you "AVENGER" 





Best of Luck :-)