- GPEN is one 82-question CyberLive exam, three hours, requiring 73% on current versions.
- The attempt costs $999 ($899 to retake), with 120 days to schedule from activation.
- Sixteen domains span reconnaissance through Azure AD attacks and Kerberos abuse.
- Open-book means printed materials only - no electronic notes or internet access.
What the GPEN Certification Actually Verifies
The GIAC Penetration Tester (GPEN) certification is a hands-on validation that you can plan, execute, and report a network penetration test the way real engagement teams do it - not just recite terminology. Unlike broader security certifications that skim across many disciplines, GPEN drills into the mechanics of password attacks, Active Directory abuse, Kerberos exploitation, Azure attack paths, and the tooling (including Metasploit) that pentesters use daily. If you're still deciding whether this credential fits your career goals, the breakdown at What Is GPEN Certification? covers the fundamentals, and Is the GPEN Certification Worth It? Complete ROI Analysis 2026 digs into the return on investment question directly.
Because GIAC exams are built around applied skill rather than memorization, the GPEN certification tends to carry weight with hiring managers who need proof that a candidate can operate in a live environment, not just pass a multiple-choice quiz. That distinction matters when you're comparing GPEN against other pentesting credentials on a resume.
Exam Format, Delivery, and CyberLive
GPEN is delivered as a single web-based, proctored exam - either remotely through ProctorU or in person through Pearson VUE. The current version contains 82 questions administered in a three-hour window, and candidates receiving versions released on or after July 12, 2025 must score 73% to pass. For a deeper look at how that scoring threshold is calculated and what it means practically, see GPEN Passing Score 2026: Exactly What You Need to Pass.
What sets GPEN apart from a standard multiple-choice test is CyberLive. Instead of only answering questions about a scenario, you're placed into realistic virtual machines and asked to actually run tools, interpret output, and manipulate real code to solve performance-based challenges. This means memorizing flashcards alone won't get you through - you need muscle memory with the command syntax and workflows tied to the domains below.
If you're trying to gauge how tough this format really is compared to other infosec exams, How Hard Is the GPEN Exam? Complete Difficulty Guide 2026 walks through the specific friction points candidates run into with CyberLive's live-VM tasks.
Registration, Fees, and the 120-Day Window
A GPEN certification attempt costs $999, and a retake (if you don't pass the first time) is priced at $899. Once your access is activated, you have 120 days to schedule and complete the exam - plan your prep timeline around that clock rather than an open-ended "someday." For eligibility details and how the activation window interacts with training bundles, review GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify.
A full cost breakdown - including how the attempt fee compares to renewal costs and optional training - is available in GPEN Certification Cost 2026: Complete Pricing Breakdown. Before you register, it's worth checking GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling so you know how proctoring availability through ProctorU or Pearson VUE might affect your scheduling options.
Key Takeaway
Treat the 120-day activation period as your real study deadline. Build your domain review calendar backward from that date, not forward from "whenever I feel ready."
The 16 GPEN Exam Domains
GPEN's blueprint covers sixteen domains, and each one maps to a distinct phase or technique in a real penetration test. Understanding what each domain actually tests - rather than just its title - is the single biggest lever for exam readiness.
Domain 1: Advanced Password Attacks
Covers techniques beyond basic dictionary attacks, including rule-based mutation and targeted wordlist construction.
- Understand how attack complexity scales against modern password policies
Domain 2: Attacking Password Hashes
Focuses on cracking methodologies once hashes are captured, including hardware and software cracking approaches.
- Know which cracking method fits which hash type and constraint
Domain 3: Azure Applications and Attack Strategies
Tests knowledge of attacking cloud-hosted applications within Azure environments.
- Recognize misconfigurations that expose Azure app attack surfaces
Domain 4: Azure Overview, Attacks, and AD Integration
Covers how Azure AD integrates with on-prem Active Directory and where that hybrid trust breaks down.
- Map hybrid identity attack paths between cloud and on-prem
Domain 5: Command and Control (C2)
Examines how pentesters establish and maintain C2 channels during an engagement.
- Understand C2 traffic patterns and operational security tradeoffs
Domain 6: Domain Escalation and Persistence Attacks
Covers techniques for escalating privileges within a Windows domain and maintaining long-term access.
- Know common persistence mechanisms and their detection footprints
Domain 7: Escalation and Exploitation
Broader exploitation concepts tied to moving from initial access to elevated privileges.
- Practice chaining exploitation steps logically, not in isolation
Domain 8: Exploitation Fundamentals
Foundational exploitation theory that underpins later, more advanced domains.
- Solidify core exploit mechanics before tackling Metasploit-specific content
Domain 9: Kerberos Attacks
Covers Kerberoasting, AS-REP roasting, ticket forgery, and related Active Directory authentication abuse.
- Be fluent in ticket-granting mechanics and where trust can be forged
Domain 10: Metasploit
Tests practical fluency with the framework - modules, payloads, and session management.
- Practice live in a lab; CyberLive tasks reward muscle memory here
Domain 11: Password Attacks
General password attack methodology, separate from the "advanced" and "hash" domains.
- Understand online vs. offline attack tradeoffs
Domain 12: Password Formats and Hashes
Covers hash types, storage formats, and how format affects crackability.
- Memorize which hash formats correspond to which platforms
Domain 13: Penetration Test Planning
Covers scoping, rules of engagement, and legal/contractual groundwork before testing begins.
- Know what belongs in a scope document versus a report
Domain 14: Reconnaissance
Passive and active information gathering techniques used before engagement.
- Distinguish OSINT sources from active recon tooling
Domain 15: Scanning and Host Discovery
Covers network scanning methodology and identifying live hosts and services.
- Understand scan types and their noise/accuracy tradeoffs
Domain 16: Vulnerability Scanning
Tests how vulnerability scanners are configured, run, and interpreted for engagement value.
- Know how to prioritize findings, not just generate them
For a domain-by-domain study plan with more granular sub-topics than fit here, GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas is the deeper companion resource.
How the Domains Cluster Together
Rather than studying all sixteen domains as isolated topics, it helps to see how they group into phases of an actual engagement:
| Engagement Phase | Related Domains |
|---|---|
| Pre-engagement & setup | Penetration Test Planning |
| Information gathering | Reconnaissance; Scanning and Host Discovery; Vulnerability Scanning |
| Exploitation | Exploitation Fundamentals; Escalation and Exploitation; Metasploit |
| Credential attacks | Password Attacks; Advanced Password Attacks; Password Formats and Hashes; Attacking Password Hashes |
| Active Directory abuse | Kerberos Attacks; Domain Escalation and Persistence Attacks |
| Cloud attack paths | Azure Overview, Attacks, and AD Integration; Azure Applications and Attack Strategies |
| Post-exploitation | Command and Control (C2) |
This grouping is useful for building a mental model of the exam and for structuring practice sessions - a topic covered thoroughly in GPEN Study Guide 2026: How to Pass on Your First Attempt.
A Domain-Aware Study Schedule
Generic study techniques only help if they're anchored to the actual GPEN blueprint. Here's one way to sequence an eight-week plan that respects how the domains build on each other:
Foundations
- Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
Exploitation Core
- Exploitation Fundamentals, Escalation and Exploitation, Metasploit hands-on lab time
Credentials and AD
- Password Attacks, Advanced Password Attacks, Password Formats and Hashes, Attacking Password Hashes, Kerberos Attacks, Domain Escalation and Persistence Attacks
Cloud and Integration Review
- Azure Overview, Attacks, and AD Integration; Azure Applications and Attack Strategies; Command and Control (C2); full CyberLive practice runs
Use short, timed practice blocks against realistic CyberLive-style scenarios rather than passive reading during the final two weeks - this is where a resource like the practice environment on gpenpracticetest.com earns its place in your rotation, since it mirrors the performance-based question style you'll face on exam day.
Who Hires GPEN Holders
GPEN is most commonly sought for roles centered on offensive security engagements: penetration testers, red team operators, security consultants who run internal or client-facing network assessments, and analysts transitioning from defensive roles into offensive testing. Because the domains include Azure-specific attack paths and Active Directory exploitation, the certification also resonates with organizations running hybrid cloud environments who need testers fluent in both on-prem and cloud attack surfaces.
If you're mapping this credential to specific job titles and compensation expectations, GPEN Jobs and GPEN Salary Guide 2026: Complete Earnings Analysis go into more detail than fits in this overview. And if you're comparing GPEN against pass-rate expectations for other GIAC-adjacent credentials, GPEN Pass Rate 2026: What the Data Shows is worth reviewing before you commit to a registration date.
Maintaining the Credential
Once earned, GPEN is valid for four years. To renew, you'll need 36 CPE credits accumulated over that period, along with a $499 renewal fee. Because the domains evolve with the threat landscape - Azure content, for instance, reflects how much cloud identity attacks have grown in relevance - staying current on CPE activity tends to naturally keep your practical skills aligned with what the exam tests.
For readers who are still deciding whether the initial investment and ongoing renewal cost make sense relative to career impact, the ROI analysis in Is the GPEN Certification Worth It? Complete ROI Analysis 2026 lays out the tradeoffs without inflating the numbers.
Frequently Asked Questions
The current GPEN exam has 82 questions administered in a three-hour testing window, delivered via CyberLive through ProctorU or Pearson VUE.
Candidates receiving exam versions released on or after July 12, 2025 need a score of 73% to pass.
Yes, GIAC exams are open book for printed books, printed notes, and a printed index. Electronic materials and internet access are not permitted during the exam.
You can retake the exam for $899, compared to the $999 initial attempt fee. Make sure you still have time remaining in your 120-day activation window.
GPEN is valid for four years. Renewal requires 36 CPE credits and a $499 renewal fee to maintain active certification status.
For a condensed, single-page reference you can review the night before your exam, the GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts distills the domains and mechanics covered here into a quick-scan format. And if you haven't already, spend time running through realistic performance-based scenarios on gpenpracticetest.com before exam day - CyberLive rewards familiarity with the tools, not just the terminology.