OSINT Study Guide 2026

Everything you need to pass the OSINT exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 OSINT Exam Format at a Glance

60
Questions
90 min
Time Limit
70%
Passing Score

📚 OSINT Topics to Study (71)

✍️ Sample OSINT Questions & Answers

1. Which tool is commonly used to aggregate leaked credential data from data breach dumps for OSINT investigations?
Have I Been Pwned (HIBP)

Have I Been Pwned aggregates credentials from publicly disclosed data breaches, allowing investigators to check whether an email or domain appears in known dumps.

2. What documentation practice is considered essential in Domain & Infrastructure Analysis within the Open Source Intelligence field?
Recording actions, observations, and outcomes in real-time or as close to the event as possible

Real-time or near-real-time documentation in Domain & Infrastructure Analysis ensures accuracy, provides a contemporaneous record, and is considered the gold standard for professional accountability and legal defensibility.

3. When assessing the threat environment for an OSINT operation, analysts should prioritize adversaries based on:
Both their intent to collect against the operation AND their capability to do so

Threat assessment combines adversary intent and capability; a capable adversary with no intent poses less risk than one with both intent and capability.

4. An analyst is examining a video that purports to show artillery fire at night. Which visual characteristic can help estimate the type of weapon based on the muzzle flash?
Flash duration, color, and dispersion pattern compared to known weapon signatures

Different weapons produce characteristic muzzle flash patterns in duration, color, and shape, which can be cross-referenced with reference databases for weapon identification.

5. What is the significance of 'onion service version 3' (.onion v3) compared to the older version 2 addresses?
V3 uses 56-character addresses with stronger cryptography (ED25519) resisting enumeration attacks

Onion v3 uses 256-bit ED25519 keys producing 56-character addresses, making enumeration and impersonation attacks computationally infeasible.

6. Which artifact in a digitally manipulated image is most commonly revealed by Error Level Analysis (ELA)?
Regions saved at different JPEG compression levels than the surrounding image

ELA detects regions re-saved or inserted at different JPEG quality levels, which appear as bright or anomalous areas compared to the uniform compression of an unaltered image.

🎯 Free OSINT Practice Tests

📖 OSINT Guides & Articles

Your OSINT Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?