- How GIAC Structures the GPEN Exam
- The Complete List of 16 GPEN Domains
- Planning, Reconnaissance & Scanning Domains
- Exploitation, Metasploit & C2 Domains
- Password Attack & Hash Domains
- Active Directory, Kerberos & Azure Domains
- Exam Format, Fees & CyberLive Mechanics
- Mapping Study Weeks to Domains
- FAQ
- GPEN covers 16 named domains spanning recon, exploitation, passwords, Kerberos, and Azure AD.
- The exam is 82 questions in three hours, requiring 73% on versions released after July 12, 2025.
- CyberLive adds hands-on challenges in real virtual machines - memorizing tool names isn't enough.
- Password-related material spans four separate domains, making it the single heaviest topic cluster.
How GIAC Structures the GPEN Exam
Unlike certifications that publish a simple bullet list of topics, GIAC organizes the GPEN exam around 16 distinct content domains that map directly to the phases of a real penetration test - from planning and reconnaissance through exploitation, credential attacks, and post-exploitation persistence in Active Directory and Azure. If you're building a study plan, treating these 16 domains as your syllabus is far more productive than working through generic pentesting material and hoping it aligns.
This guide breaks down every domain, explains how GIAC tends to test it, and shows how the domains cluster into four practical study groups. For a broader walkthrough of preparation strategy, pair this with our GPEN Study Guide 2026, and if you're still deciding whether the certification is right for your career stage, read Is the GPEN Certification Worth It? first.
The Complete List of 16 GPEN Domains
Here are all 16 domains exactly as GIAC defines them for the current GPEN blueprint:
- Advanced Password Attacks
- Attacking Password Hashes
- Azure Applications and Attack Strategies
- Azure Overview, Attacks, and AD Integration
- Command and Control (C2)
- Domain Escalation and Persistence Attacks
- Escalation and Exploitation
- Exploitation Fundamentals
- Kerberos Attacks
- Metasploit
- Password Attacks
- Password Formats and Hashes
- Penetration Test Planning
- Reconnaissance
- Scanning and Host Discovery
- Vulnerability Scanning
Notice that GIAC does not weight domains publicly with fixed percentages. That's intentional - GIAC rotates item pools, so instead of memorizing a percentage breakdown, focus on depth across every domain. Candidates who skip a domain because it "seems small" are often the ones surprised by CyberLive scenarios built specifically around it.
Planning, Reconnaissance & Scanning Domains
These four domains form the front half of a penetration test engagement and are foundational to everything that follows.
Penetration Test Planning
Covers scoping, rules of engagement, legal considerations, and methodology selection before any tool touches a target.
- Know the difference between scoping documents, rules of engagement, and authorization letters
- Understand how scope constraints shape which techniques are permissible
Reconnaissance
Passive and active information gathering techniques used before active scanning begins.
- OSINT sources, DNS enumeration, and metadata harvesting
- Distinguishing passive recon from techniques that risk detection
Scanning and Host Discovery
Network mapping techniques for identifying live hosts, open ports, and services.
- Nmap scan types and timing/stealth options
- Interpreting scan output to prioritize targets
Vulnerability Scanning
Automated identification of weaknesses and how findings feed into exploitation planning.
- Reading and validating scanner output to avoid false positives
- Prioritizing vulnerabilities by exploitability and business impact
Exploitation, Metasploit & C2 Domains
Once a target is scoped and mapped, GPEN shifts into the active attack phase. Four domains cover this middle stage of an engagement, and this is where CyberLive's hands-on lab challenges are most heavily concentrated.
Exploitation Fundamentals
Core exploitation concepts including payload delivery, shell types, and exploit reliability.
- Bind vs. reverse shells and when each is appropriate
- Understanding exploit stability across different target configurations
Escalation and Exploitation
Privilege escalation techniques on compromised hosts, both Windows and Linux.
- Local privilege escalation vectors and misconfiguration hunting
- Chaining an initial foothold into higher-privilege access
Metasploit
Framework-specific skills: modules, payloads, and the Meterpreter environment.
- Module search, configuration, and payload staging
- Post-exploitation modules and session management
Command and Control (C2)
How attackers maintain remote access and communicate with compromised hosts.
- C2 channel concepts and detection evasion basics
- Differences between commodity C2 frameworks and manual handling
Password Attack & Hash Domains
Password-related material spans four separate domains - the single largest content cluster in the entire GPEN blueprint. This weighting reflects how often credential attacks determine the outcome of real-world penetration tests.
| Domain | Core Focus |
|---|---|
| Password Attacks | Online guessing, spraying, and lockout-aware attack techniques |
| Advanced Password Attacks | Rule-based cracking, mask attacks, and wordlist optimization |
| Password Formats and Hashes | Identifying hash types and understanding storage formats across platforms |
| Attacking Password Hashes | Offline cracking methodology and tool-specific workflows |
Candidates frequently underestimate how deep GIAC goes here. It's not enough to know that NTLM and bcrypt exist - you need to recognize hash formats on sight, choose the correct attack mode for the situation, and understand why a rule-based attack outperforms a brute-force attempt against a specific policy. This cluster alone justifies spending a full study week on password material, which we cover in the scheduling section below.
Key Takeaway
Build a personal reference of hash format identifiers (length, character set, prefix patterns) - GPEN questions and CyberLive labs both test rapid hash recognition under time pressure.
Active Directory, Kerberos & Azure Domains
The final four domains reflect GIAC's ongoing update of GPEN toward hybrid, cloud-integrated Active Directory environments - arguably the most consequential recent shift in the exam's content.
Domain Escalation and Persistence Attacks
Techniques for escalating privileges within a Windows domain and maintaining long-term access.
- Lateral movement and domain trust abuse
- Persistence mechanisms attackers use to survive reboots and credential rotation
Kerberos Attacks
Attacks against the Kerberos authentication protocol underlying most enterprise Active Directory environments.
- Kerberoasting and AS-REP roasting mechanics
- Ticket-based attack detection and mitigation awareness
Azure Overview, Attacks, and AD Integration
How on-premises Active Directory integrates with Azure AD (Entra ID) and where that integration introduces attack surface.
- Hybrid identity sync mechanisms and their weaknesses
- Common misconfigurations in AD Connect-style integrations
Azure Applications and Attack Strategies
Cloud-native application attack surface within Azure environments.
- App registrations, service principals, and permission abuse
- Enumeration techniques specific to Azure-hosted applications
These four domains are often the deciding factor for candidates who studied a strong general pentesting background but skipped Azure-specific material. If your background is heavier in traditional network pentesting, budget extra time here - it's the area most likely to catch experienced testers off guard. Our GPEN difficulty guide breaks down exactly why this cluster trips up otherwise well-prepared candidates.
Exam Format, Fees & CyberLive Mechanics
Understanding domain content only matters if you also understand how GIAC delivers the exam itself.
- Format: One web-based, proctored exam delivered via ProctorU remotely or Pearson VUE onsite.
- Length and scoring: 82 questions in three hours; versions released on or after July 12, 2025 require 73% to pass.
- CyberLive: Performance-based challenges run inside realistic virtual machines using real tools and code - this is where domains like Metasploit, C2, and Attacking Password Hashes get tested practically, not just theoretically.
- Reference materials: Open book, but only printed books, notes, and indexes - electronic materials and internet access are prohibited during the exam.
- Attempt window: 120 days from activation to complete your attempt.
- Cost: $999 for the certification attempt, $899 for a retake.
- Validity and renewal: Valid four years; renewal requires 36 CPE credits and a $499 renewal fee.
Because the reference material rule bans electronic notes, your printed index needs to be organized by domain, not alphabetically by tool name. A well-tabbed printed index covering all 16 domains is often the single highest-leverage prep asset - see our GPEN Cheat Sheet for a starting structure. For a full cost breakdown including training and retake budgeting, check GPEN Certification Cost 2026, and confirm eligibility details in GPEN Requirements 2026 before you register.
Mapping Study Weeks to Domains
Rather than a generic study calendar, map your prep weeks directly onto the four domain clusters above. This keeps every study session tied to a specific, testable GPEN domain instead of vague "review pentesting" sessions.
Planning, Recon & Scanning
- Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
- Build and drill your printed index for these four domains
Exploitation & Metasploit
- Exploitation Fundamentals, Escalation and Exploitation, Metasploit, Command and Control
- Run every technique in a home lab, not just read about it
Password Attack Cluster
- Password Attacks, Advanced Password Attacks, Password Formats and Hashes, Attacking Password Hashes
- Drill hash identification until it's automatic
AD, Kerberos & Azure
- Domain Escalation and Persistence Attacks, Kerberos Attacks, both Azure domains
- Focus extra time here if your background is network-heavy, not cloud-heavy
This structure also makes practice testing far more useful - instead of taking a full-length mock exam blind, run domain-specific practice sets against gpenpracticetest.com after each cluster to confirm retention before moving on. If you want to understand exactly how the passing threshold applies across these clusters, see GPEN Passing Score 2026.
Frequently Asked Questions
GIAC does not publish fixed percentage weightings per domain. Treat all 16 domains as fair game and avoid skipping any cluster based on assumed low weight.
GIAC doesn't publicly map specific domains to CyberLive versus multiple-choice items, but practical clusters like Metasploit, Command and Control, and Attacking Password Hashes are the most likely candidates for performance-based virtual machine challenges given their tool-driven nature.
Azure Overview, Attacks, and AD Integration and Azure Applications and Attack Strategies reflect GIAC's ongoing update of the exam toward hybrid cloud-integrated Active Directory environments, so candidates who trained on older material should specifically shore up cloud identity content.
Four domains cover password material directly: Password Attacks, Advanced Password Attacks, Password Formats and Hashes, and Attacking Password Hashes, making it the largest single content cluster in the GPEN blueprint.
Yes. GIAC exams are open book for printed books, notes, and indexes only - electronic materials and internet access are prohibited, so an index tabbed by domain is a practical and permitted study aid.