- Exam Snapshot: Format, Fees, and Logistics
- The 16 GPEN Domains at a Glance
- High-Yield Domains You Cannot Skip
- Understanding CyberLive Questions
- Open-Book Rules and Index Strategy
- Registration, Retakes, and Deadlines
- Certification Validity and Renewal Math
- Final-Week Review Sequencing
- Who Actually Hires GPEN Holders
- FAQ
- GPEN is 82 questions in three hours, with a 73% passing bar for July 12, 2025+ versions.
- The exam costs $999 ($899 to retake) and runs on CyberLive, a hands-on virtual-machine testing engine.
- Only printed books, notes, and indexes are allowed - no laptops, tablets, or internet access.
- You get 120 days from activation to schedule and sit the exam.
Exam Snapshot: Format, Fees, and Logistics
Before you build an index or crack open a lab, memorize the mechanics. GPEN is a single web-based, proctored exam delivered through either ProctorU (remote) or Pearson VUE (in-person testing center). There's no separate "practical" component to schedule - everything happens inside one CyberLive session.
The numbers that matter most:
- Cost: $999 for the initial attempt, $899 for a retake
- Length: 82 questions, 3 hours
- Passing score: 73% for exam versions released on or after July 12, 2025
- Attempt window: 120 days from activation date
- Validity: 4 years, renewable with 36 CPEs and a $499 fee
If you want the full breakdown of what each dollar buys - bundle pricing, training packages, and retake economics - the GPEN Certification Cost 2026: Complete Pricing Breakdown covers it in depth. For a plain-language answer on the score itself, see GPEN Passing Score 2026: Exactly What You Need to Pass.
The 16 GPEN Domains at a Glance
GIAC organizes the current GPEN objectives into 16 named domains. Knowing the exact domain names - not vague topic clusters - helps you map practice questions to real content areas and spot gaps before exam day.
| # | Domain |
|---|---|
| 1 | Advanced Password Attacks |
| 2 | Attacking Password Hashes |
| 3 | Azure Applications and Attack Strategies |
| 4 | Azure Overview, Attacks, and AD Integration |
| 5 | Command and Control (C2) |
| 6 | Domain Escalation and Persistence Attacks |
| 7 | Escalation and Exploitation |
| 8 | Exploitation Fundamentals |
| 9 | Kerberos Attacks |
| 10 | Metasploit |
| 11 | Password Attacks |
| 12 | Password Formats and Hashes |
| 13 | Penetration Test Planning |
| 14 | Reconnaissance |
| 15 | Scanning and Host Discovery |
| 16 | Vulnerability Scanning |
Notice the clustering: four domains revolve around passwords and hashes, two around Azure, two around domain/Kerberos escalation, and the rest span the classic pentest lifecycle from planning through exploitation and C2. That clustering is exactly why a domain-by-domain walkthrough matters more than generic advice - the GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas breaks down subtopics and typical question angles for each one individually.
High-Yield Domains You Cannot Skip
Not all 16 domains carry equal weight in practice. Based on how GPEN's blueprint clusters topics, four domain groups deserve disproportionate study time.
Password Attacks Cluster (Domains 1, 2, 11, 12)
Four separate domains touch passwords and hashes - that's a quarter of the entire blueprint. Candidates must distinguish hash formats (NTLM, NetNTLMv2, Kerberos AS-REP/TGS-REP), recognize which cracking tool fits which format, and understand rainbow tables versus GPU-accelerated brute force.
- Know how to identify a hash type from its structure alone
- Understand rule-based mutation attacks versus dictionary attacks
- Be comfortable with Hashcat mode numbers for common formats
Active Directory Escalation (Domains 6 and 9)
Domain Escalation and Persistence Attacks plus Kerberos Attacks form the AD backbone of GPEN. Expect scenario questions on Kerberoasting, AS-REP roasting, Golden/Silver Ticket concepts, and common persistence mechanisms after initial domain compromise.
- Map each attack to the Kerberos ticket-exchange step it abuses
- Know detection indicators as well as the attack mechanics
Azure Domains (Domains 3 and 4)
Cloud content is not an afterthought - two full domains are dedicated to Azure, covering AD integration, application attack surfaces, and how on-prem AD ties into Azure AD/Entra identities.
- Understand hybrid identity sync and where attackers pivot between environments
- Know common Azure app misconfiguration patterns testers exploit
Tooling Domains (Domain 5 and Domain 10)
Command and Control (C2) and Metasploit are named as standalone domains - meaning GIAC expects hands-on familiarity, not just theory. CyberLive questions in these areas often ask you to interact with a working framework.
- Practice actual Metasploit module usage, not just terminology
- Understand C2 beaconing, channel types, and evasion basics
If you're unsure how these clusters translate into real difficulty, How Hard Is the GPEN Exam? Complete Difficulty Guide 2026 discusses which domains trip up candidates most often and why the CyberLive format changes the calculus versus a purely multiple-choice test.
Understanding CyberLive Questions
CyberLive is GIAC's performance-based testing layer, and GPEN uses it to insert live virtual-machine challenges into the exam alongside standard multiple-choice items. Instead of just describing what a tool does, you may need to actually run it - issuing real commands against a live target inside a browser-based VM, using genuine tools and code rather than simulated screenshots.
This has direct implications for how you prepare:
- Reading about Metasploit modules isn't enough - you need muscle memory for the actual syntax
- Command and Control and password-cracking domains are prime candidates for CyberLive-style tasks
- Time management matters more, since a hands-on challenge can eat minutes faster than a multiple-choice question
Key Takeaway
Spend part of your prep time inside a real lab environment (not just reading), since CyberLive rewards command familiarity over passive recognition of tool names.
Open-Book Rules and Index Strategy
GPEN is open book, but the rule is narrower than many candidates assume. You may bring printed books, printed notes, and a printed index. Electronic devices, PDFs on a tablet, and any form of internet access are explicitly prohibited during the exam.
That single rule reshapes your entire prep strategy:
- Build a printed, tabbed index organized by domain name (matching the 16 domains above) so you can flip to the right section under time pressure
- Don't over-rely on the index for tool syntax you'll need to type live in a CyberLive challenge - index lookups won't help mid-VM
- Practice locating answers in your index during timed mock sessions, not just building it
A well-built index is one of the few controllable variables in GPEN's difficulty equation. For a step-by-step index-building process and full prep sequencing, see the GPEN Study Guide 2026: How to Pass on Your First Attempt.
Registration, Retakes, and Deadlines
Once you register, the clock starts immediately: you have 120 days from activation to sit the exam. That window covers scheduling, rescheduling if needed, and the sitting itself - it doesn't reset just because you haven't studied yet.
Key registration facts to plan around:
- Initial attempt: $999
- Retake attempt: $899
- Delivery: remote via ProctorU or in-person via Pearson VUE - pick based on your comfort with remote proctoring
- 120-day activation-to-completion window with no listed grace extension
Because the 120-day clock is unforgiving, treat registration as the trigger for a structured plan rather than a formality. The GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling article walks through how to reverse-engineer a study calendar from your activation date, and GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify covers what you need before you even register.
Certification Validity and Renewal Math
A passed GPEN stays valid for four years. Renewal isn't a re-exam - it's a continuing-education requirement: 36 CPE credits plus a $499 renewal fee. Spread across four years, that's roughly nine CPEs per year, which is manageable through conferences, training, writing, or teaching activities that GIAC accepts.
If you're weighing whether the ongoing renewal cost and effort pays off relative to the career upside, Is the GPEN Certification Worth It? Complete ROI Analysis 2026 lays out the tradeoffs, and GPEN Salary Guide 2026: Complete Earnings Analysis covers how the credential tends to factor into compensation conversations.
Final-Week Review Sequencing
Generic weekly planning templates rarely map cleanly onto a 16-domain, hands-on exam like GPEN. Instead of a one-size-fits-all calendar, sequence your last two weeks around domain clusters, prioritizing anything that requires live tool practice before anything that's pure recall.
Tooling and Hands-On Domains
- Metasploit (Domain 10) module practice in a live lab
- Command and Control (Domain 5) - set up a basic C2 channel and observe traffic
Password and Identity Domains
- Hash identification drills across Domains 2 and 12
- Kerberos Attacks (Domain 9) and Domain Escalation and Persistence Attacks (Domain 6) scenario review
Cloud and Recon Domains
- Azure Overview/AD Integration and Azure Applications (Domains 3-4)
- Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning (Domains 14-16)
Index Check and Rest
- Verify your printed index is tabbed by domain name
- Run one timed mock question set rather than cramming new material
This sequencing puts hands-on domains first, while your energy and lab access are freshest, and leaves passive-recall domains for the final days when you're mostly reinforcing rather than learning from scratch.
Who Actually Hires GPEN Holders
GPEN sits squarely in the offensive-security lane, and the domain list explains why employers value it: it signals hands-on competence in password attacks, AD/Kerberos exploitation, Azure attack paths, and core exploitation tooling - not just theoretical pentest methodology.
Roles that commonly list or reward GPEN include:
- Penetration testers and red team associates at consultancies
- Internal security teams running periodic internal network assessments
- Cloud security analysts working in hybrid Azure/AD environments
- Junior-to-mid offensive security roles where Metasploit and C2 familiarity is expected on day one
For a closer look at title trends and where GPEN shows up in job postings, check GPEN Jobs. If you're still mapping out what the certification actually signals to hiring managers, What Is GPEN Certification? and GPEN Certification give broader context, while GPEN Training covers formal course options that pair with self-study. You can also run a full practice attempt on the GPEN practice test platform to gauge readiness before spending on the real exam fee.
For a broader statistical view of how candidates perform against these numbers, GPEN Pass Rate 2026: What the Data Shows is a useful companion read, and repeated timed drills on our practice test site are the fastest way to convert this cheat sheet into exam-day speed.
Frequently Asked Questions
Both. GPEN uses GIAC's CyberLive engine, which mixes standard multiple-choice questions with performance-based challenges in real virtual machines using actual tools and commands.
No. The exam is open book only for printed books, printed notes, and a printed index. Electronic materials and internet access are not permitted.
A retake costs $899, compared to $999 for the initial attempt, so failing isn't free - plan your first sitting seriously rather than treating it as a practice run.
You have 120 days from the activation date to complete your attempt, which includes time to schedule with either ProctorU or Pearson VUE.
GPEN is valid for four years. To renew, you need 36 CPE credits and must pay a $499 renewal fee rather than retaking the full exam.