GPEN logo
Focused certification exam prep
Start practice

GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • GPEN is 82 questions in three hours, with a 73% passing bar for July 12, 2025+ versions.
  • The exam costs $999 ($899 to retake) and runs on CyberLive, a hands-on virtual-machine testing engine.
  • Only printed books, notes, and indexes are allowed - no laptops, tablets, or internet access.
  • You get 120 days from activation to schedule and sit the exam.

Exam Snapshot: Format, Fees, and Logistics

Before you build an index or crack open a lab, memorize the mechanics. GPEN is a single web-based, proctored exam delivered through either ProctorU (remote) or Pearson VUE (in-person testing center). There's no separate "practical" component to schedule - everything happens inside one CyberLive session.

The numbers that matter most:

  • Cost: $999 for the initial attempt, $899 for a retake
  • Length: 82 questions, 3 hours
  • Passing score: 73% for exam versions released on or after July 12, 2025
  • Attempt window: 120 days from activation date
  • Validity: 4 years, renewable with 36 CPEs and a $499 fee

If you want the full breakdown of what each dollar buys - bundle pricing, training packages, and retake economics - the GPEN Certification Cost 2026: Complete Pricing Breakdown covers it in depth. For a plain-language answer on the score itself, see GPEN Passing Score 2026: Exactly What You Need to Pass.

Fast Fact: There is no multiple-attempt grace period built into the fee - every retake after the first costs $899, so treat your first sitting as the one that counts.

The 16 GPEN Domains at a Glance

GIAC organizes the current GPEN objectives into 16 named domains. Knowing the exact domain names - not vague topic clusters - helps you map practice questions to real content areas and spot gaps before exam day.

#Domain
1Advanced Password Attacks
2Attacking Password Hashes
3Azure Applications and Attack Strategies
4Azure Overview, Attacks, and AD Integration
5Command and Control (C2)
6Domain Escalation and Persistence Attacks
7Escalation and Exploitation
8Exploitation Fundamentals
9Kerberos Attacks
10Metasploit
11Password Attacks
12Password Formats and Hashes
13Penetration Test Planning
14Reconnaissance
15Scanning and Host Discovery
16Vulnerability Scanning

Notice the clustering: four domains revolve around passwords and hashes, two around Azure, two around domain/Kerberos escalation, and the rest span the classic pentest lifecycle from planning through exploitation and C2. That clustering is exactly why a domain-by-domain walkthrough matters more than generic advice - the GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas breaks down subtopics and typical question angles for each one individually.

High-Yield Domains You Cannot Skip

Not all 16 domains carry equal weight in practice. Based on how GPEN's blueprint clusters topics, four domain groups deserve disproportionate study time.

Password Attacks Cluster (Domains 1, 2, 11, 12)

Four separate domains touch passwords and hashes - that's a quarter of the entire blueprint. Candidates must distinguish hash formats (NTLM, NetNTLMv2, Kerberos AS-REP/TGS-REP), recognize which cracking tool fits which format, and understand rainbow tables versus GPU-accelerated brute force.

  • Know how to identify a hash type from its structure alone
  • Understand rule-based mutation attacks versus dictionary attacks
  • Be comfortable with Hashcat mode numbers for common formats

Active Directory Escalation (Domains 6 and 9)

Domain Escalation and Persistence Attacks plus Kerberos Attacks form the AD backbone of GPEN. Expect scenario questions on Kerberoasting, AS-REP roasting, Golden/Silver Ticket concepts, and common persistence mechanisms after initial domain compromise.

  • Map each attack to the Kerberos ticket-exchange step it abuses
  • Know detection indicators as well as the attack mechanics

Azure Domains (Domains 3 and 4)

Cloud content is not an afterthought - two full domains are dedicated to Azure, covering AD integration, application attack surfaces, and how on-prem AD ties into Azure AD/Entra identities.

  • Understand hybrid identity sync and where attackers pivot between environments
  • Know common Azure app misconfiguration patterns testers exploit

Tooling Domains (Domain 5 and Domain 10)

Command and Control (C2) and Metasploit are named as standalone domains - meaning GIAC expects hands-on familiarity, not just theory. CyberLive questions in these areas often ask you to interact with a working framework.

  • Practice actual Metasploit module usage, not just terminology
  • Understand C2 beaconing, channel types, and evasion basics

If you're unsure how these clusters translate into real difficulty, How Hard Is the GPEN Exam? Complete Difficulty Guide 2026 discusses which domains trip up candidates most often and why the CyberLive format changes the calculus versus a purely multiple-choice test.

Understanding CyberLive Questions

CyberLive is GIAC's performance-based testing layer, and GPEN uses it to insert live virtual-machine challenges into the exam alongside standard multiple-choice items. Instead of just describing what a tool does, you may need to actually run it - issuing real commands against a live target inside a browser-based VM, using genuine tools and code rather than simulated screenshots.

This has direct implications for how you prepare:

  • Reading about Metasploit modules isn't enough - you need muscle memory for the actual syntax
  • Command and Control and password-cracking domains are prime candidates for CyberLive-style tasks
  • Time management matters more, since a hands-on challenge can eat minutes faster than a multiple-choice question

Key Takeaway

Spend part of your prep time inside a real lab environment (not just reading), since CyberLive rewards command familiarity over passive recognition of tool names.

Open-Book Rules and Index Strategy

GPEN is open book, but the rule is narrower than many candidates assume. You may bring printed books, printed notes, and a printed index. Electronic devices, PDFs on a tablet, and any form of internet access are explicitly prohibited during the exam.

That single rule reshapes your entire prep strategy:

  • Build a printed, tabbed index organized by domain name (matching the 16 domains above) so you can flip to the right section under time pressure
  • Don't over-rely on the index for tool syntax you'll need to type live in a CyberLive challenge - index lookups won't help mid-VM
  • Practice locating answers in your index during timed mock sessions, not just building it

A well-built index is one of the few controllable variables in GPEN's difficulty equation. For a step-by-step index-building process and full prep sequencing, see the GPEN Study Guide 2026: How to Pass on Your First Attempt.

Registration, Retakes, and Deadlines

Once you register, the clock starts immediately: you have 120 days from activation to sit the exam. That window covers scheduling, rescheduling if needed, and the sitting itself - it doesn't reset just because you haven't studied yet.

Key registration facts to plan around:

  • Initial attempt: $999
  • Retake attempt: $899
  • Delivery: remote via ProctorU or in-person via Pearson VUE - pick based on your comfort with remote proctoring
  • 120-day activation-to-completion window with no listed grace extension

Because the 120-day clock is unforgiving, treat registration as the trigger for a structured plan rather than a formality. The GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling article walks through how to reverse-engineer a study calendar from your activation date, and GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify covers what you need before you even register.

Certification Validity and Renewal Math

A passed GPEN stays valid for four years. Renewal isn't a re-exam - it's a continuing-education requirement: 36 CPE credits plus a $499 renewal fee. Spread across four years, that's roughly nine CPEs per year, which is manageable through conferences, training, writing, or teaching activities that GIAC accepts.

Plan Ahead: Start logging CPE-eligible activity as soon as you pass - waiting until year three to find 36 credits is avoidable stress, and the $499 fee is fixed regardless of how you accumulate the credits.

If you're weighing whether the ongoing renewal cost and effort pays off relative to the career upside, Is the GPEN Certification Worth It? Complete ROI Analysis 2026 lays out the tradeoffs, and GPEN Salary Guide 2026: Complete Earnings Analysis covers how the credential tends to factor into compensation conversations.

Final-Week Review Sequencing

Generic weekly planning templates rarely map cleanly onto a 16-domain, hands-on exam like GPEN. Instead of a one-size-fits-all calendar, sequence your last two weeks around domain clusters, prioritizing anything that requires live tool practice before anything that's pure recall.

Days 14-10

Tooling and Hands-On Domains

  • Metasploit (Domain 10) module practice in a live lab
  • Command and Control (Domain 5) - set up a basic C2 channel and observe traffic
Days 9-5

Password and Identity Domains

  • Hash identification drills across Domains 2 and 12
  • Kerberos Attacks (Domain 9) and Domain Escalation and Persistence Attacks (Domain 6) scenario review
Days 4-2

Cloud and Recon Domains

  • Azure Overview/AD Integration and Azure Applications (Domains 3-4)
  • Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning (Domains 14-16)
Final Day

Index Check and Rest

  • Verify your printed index is tabbed by domain name
  • Run one timed mock question set rather than cramming new material

This sequencing puts hands-on domains first, while your energy and lab access are freshest, and leaves passive-recall domains for the final days when you're mostly reinforcing rather than learning from scratch.

Who Actually Hires GPEN Holders

GPEN sits squarely in the offensive-security lane, and the domain list explains why employers value it: it signals hands-on competence in password attacks, AD/Kerberos exploitation, Azure attack paths, and core exploitation tooling - not just theoretical pentest methodology.

Roles that commonly list or reward GPEN include:

  • Penetration testers and red team associates at consultancies
  • Internal security teams running periodic internal network assessments
  • Cloud security analysts working in hybrid Azure/AD environments
  • Junior-to-mid offensive security roles where Metasploit and C2 familiarity is expected on day one

For a closer look at title trends and where GPEN shows up in job postings, check GPEN Jobs. If you're still mapping out what the certification actually signals to hiring managers, What Is GPEN Certification? and GPEN Certification give broader context, while GPEN Training covers formal course options that pair with self-study. You can also run a full practice attempt on the GPEN practice test platform to gauge readiness before spending on the real exam fee.

Quick Reference: If you only remember five numbers from this whole cheat sheet, make them these: 82 questions, 3 hours, 73% to pass, $999 to register, 120 days to test.

For a broader statistical view of how candidates perform against these numbers, GPEN Pass Rate 2026: What the Data Shows is a useful companion read, and repeated timed drills on our practice test site are the fastest way to convert this cheat sheet into exam-day speed.

Frequently Asked Questions

Is GPEN a hands-on exam or all multiple-choice?

Both. GPEN uses GIAC's CyberLive engine, which mixes standard multiple-choice questions with performance-based challenges in real virtual machines using actual tools and commands.

Can I use my laptop or PDFs during the GPEN exam?

No. The exam is open book only for printed books, printed notes, and a printed index. Electronic materials and internet access are not permitted.

How much does it cost if I fail and need to retake GPEN?

A retake costs $899, compared to $999 for the initial attempt, so failing isn't free - plan your first sitting seriously rather than treating it as a practice run.

How long do I have to schedule the exam after registering?

You have 120 days from the activation date to complete your attempt, which includes time to schedule with either ProctorU or Pearson VUE.

What happens when my GPEN certification expires?

GPEN is valid for four years. To renew, you need 36 CPE credits and must pay a $499 renewal fee rather than retaking the full exam.

Ready to pass your GPEN exam?

Put this into practice with free GPEN questions across every exam domain.