PEN-210: Foundational Wireless Network Attacks - on the way to OSWP.
PEN-210 covers attacks against wireless networks: reconnaissance, authentication mechanisms, WPA variants, enterprise WLAN with RADIUS, and the usual misconfigurations. It leads to the OSWP certification.

- Certification
- OSWP - OffSec Wireless Professional
- Level
- Foundational
- Discipline
- Attack
- Audience
- Teams and individuals
Who this course is for
Testers and network owners who have to assess wireless infrastructure - typical in manufacturing, logistics and branch networks.
Not the right course yet if
- -Your scope contains no wireless
- -You want a broad pentest certification - that is PEN-200
- →Systematically survey and document wireless environments
- →Practically demonstrate weak authentication and misconfiguration
- →Assess enterprise WLAN with RADIUS instead of guessing
- ·Networking fundamentals
- ·Comfort on the Linux command line
- ·A compatible wireless adapter for the labs
Not sure whether you meet them? We run a short placement conversation before you buy.
What PEN-210 covers.
- Wireless recon and monitoring
- WPA/WPA2 and WPA3 transitions
- Enterprise WLAN with RADIUS
Course content, labs and the OSWP exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Course modules with exercises against your own hardware; a compatible wireless adapter is required.
Exam and credential
Practical exam against a wireless lab, with a report. Passing awards the OSWP certification.
The packages that include PEN-210.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Mapping the content onto your own site and branch topology
- +Combination with a physical access or onsite assessment
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
Yes, a wireless adapter with monitor mode support. We name specific models during onboarding.
If branches, plants or campus WLAN are in your scope, yes. Otherwise PEN-200 comes first.
Not sure whether PEN-210 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more