GPEN logo
Focused certification exam prep
Start practice

GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas

TL;DR
  • GPEN covers 16 named domains spanning recon, exploitation, passwords, Kerberos, and Azure AD.
  • The exam is 82 questions in three hours, requiring 73% on versions released after July 12, 2025.
  • CyberLive adds hands-on challenges in real virtual machines - memorizing tool names isn't enough.
  • Password-related material spans four separate domains, making it the single heaviest topic cluster.

How GIAC Structures the GPEN Exam

Unlike certifications that publish a simple bullet list of topics, GIAC organizes the GPEN exam around 16 distinct content domains that map directly to the phases of a real penetration test - from planning and reconnaissance through exploitation, credential attacks, and post-exploitation persistence in Active Directory and Azure. If you're building a study plan, treating these 16 domains as your syllabus is far more productive than working through generic pentesting material and hoping it aligns.

This guide breaks down every domain, explains how GIAC tends to test it, and shows how the domains cluster into four practical study groups. For a broader walkthrough of preparation strategy, pair this with our GPEN Study Guide 2026, and if you're still deciding whether the certification is right for your career stage, read Is the GPEN Certification Worth It? first.

Why Domains Matter More Than Chapters: GIAC's exam blueprint isn't a marketing list - it's the actual skeleton the item-writers use to build questions and CyberLive lab scenarios. Studying domain-by-domain lets you self-assess gaps instead of assuming broad "pentesting knowledge" is sufficient.

The Complete List of 16 GPEN Domains

Here are all 16 domains exactly as GIAC defines them for the current GPEN blueprint:

  1. Advanced Password Attacks
  2. Attacking Password Hashes
  3. Azure Applications and Attack Strategies
  4. Azure Overview, Attacks, and AD Integration
  5. Command and Control (C2)
  6. Domain Escalation and Persistence Attacks
  7. Escalation and Exploitation
  8. Exploitation Fundamentals
  9. Kerberos Attacks
  10. Metasploit
  11. Password Attacks
  12. Password Formats and Hashes
  13. Penetration Test Planning
  14. Reconnaissance
  15. Scanning and Host Discovery
  16. Vulnerability Scanning

Notice that GIAC does not weight domains publicly with fixed percentages. That's intentional - GIAC rotates item pools, so instead of memorizing a percentage breakdown, focus on depth across every domain. Candidates who skip a domain because it "seems small" are often the ones surprised by CyberLive scenarios built specifically around it.

Planning, Reconnaissance & Scanning Domains

These four domains form the front half of a penetration test engagement and are foundational to everything that follows.

Penetration Test Planning

Covers scoping, rules of engagement, legal considerations, and methodology selection before any tool touches a target.

  • Know the difference between scoping documents, rules of engagement, and authorization letters
  • Understand how scope constraints shape which techniques are permissible

Reconnaissance

Passive and active information gathering techniques used before active scanning begins.

  • OSINT sources, DNS enumeration, and metadata harvesting
  • Distinguishing passive recon from techniques that risk detection

Scanning and Host Discovery

Network mapping techniques for identifying live hosts, open ports, and services.

  • Nmap scan types and timing/stealth options
  • Interpreting scan output to prioritize targets

Vulnerability Scanning

Automated identification of weaknesses and how findings feed into exploitation planning.

  • Reading and validating scanner output to avoid false positives
  • Prioritizing vulnerabilities by exploitability and business impact

Exploitation, Metasploit & C2 Domains

Once a target is scoped and mapped, GPEN shifts into the active attack phase. Four domains cover this middle stage of an engagement, and this is where CyberLive's hands-on lab challenges are most heavily concentrated.

Exploitation Fundamentals

Core exploitation concepts including payload delivery, shell types, and exploit reliability.

  • Bind vs. reverse shells and when each is appropriate
  • Understanding exploit stability across different target configurations

Escalation and Exploitation

Privilege escalation techniques on compromised hosts, both Windows and Linux.

  • Local privilege escalation vectors and misconfiguration hunting
  • Chaining an initial foothold into higher-privilege access

Metasploit

Framework-specific skills: modules, payloads, and the Meterpreter environment.

  • Module search, configuration, and payload staging
  • Post-exploitation modules and session management

Command and Control (C2)

How attackers maintain remote access and communicate with compromised hosts.

  • C2 channel concepts and detection evasion basics
  • Differences between commodity C2 frameworks and manual handling
CyberLive Reality Check: Because GIAC exams inject performance-based challenges into live virtual machines with real tools, memorizing Metasploit syntax from a cheat sheet won't help if you've never actually run the module against a target. Build a home lab and repeat each exploitation domain hands-on before exam day.

Password Attack & Hash Domains

Password-related material spans four separate domains - the single largest content cluster in the entire GPEN blueprint. This weighting reflects how often credential attacks determine the outcome of real-world penetration tests.

DomainCore Focus
Password AttacksOnline guessing, spraying, and lockout-aware attack techniques
Advanced Password AttacksRule-based cracking, mask attacks, and wordlist optimization
Password Formats and HashesIdentifying hash types and understanding storage formats across platforms
Attacking Password HashesOffline cracking methodology and tool-specific workflows

Candidates frequently underestimate how deep GIAC goes here. It's not enough to know that NTLM and bcrypt exist - you need to recognize hash formats on sight, choose the correct attack mode for the situation, and understand why a rule-based attack outperforms a brute-force attempt against a specific policy. This cluster alone justifies spending a full study week on password material, which we cover in the scheduling section below.

Key Takeaway

Build a personal reference of hash format identifiers (length, character set, prefix patterns) - GPEN questions and CyberLive labs both test rapid hash recognition under time pressure.

Active Directory, Kerberos & Azure Domains

The final four domains reflect GIAC's ongoing update of GPEN toward hybrid, cloud-integrated Active Directory environments - arguably the most consequential recent shift in the exam's content.

Domain Escalation and Persistence Attacks

Techniques for escalating privileges within a Windows domain and maintaining long-term access.

  • Lateral movement and domain trust abuse
  • Persistence mechanisms attackers use to survive reboots and credential rotation

Kerberos Attacks

Attacks against the Kerberos authentication protocol underlying most enterprise Active Directory environments.

  • Kerberoasting and AS-REP roasting mechanics
  • Ticket-based attack detection and mitigation awareness

Azure Overview, Attacks, and AD Integration

How on-premises Active Directory integrates with Azure AD (Entra ID) and where that integration introduces attack surface.

  • Hybrid identity sync mechanisms and their weaknesses
  • Common misconfigurations in AD Connect-style integrations

Azure Applications and Attack Strategies

Cloud-native application attack surface within Azure environments.

  • App registrations, service principals, and permission abuse
  • Enumeration techniques specific to Azure-hosted applications

These four domains are often the deciding factor for candidates who studied a strong general pentesting background but skipped Azure-specific material. If your background is heavier in traditional network pentesting, budget extra time here - it's the area most likely to catch experienced testers off guard. Our GPEN difficulty guide breaks down exactly why this cluster trips up otherwise well-prepared candidates.

Exam Format, Fees & CyberLive Mechanics

Understanding domain content only matters if you also understand how GIAC delivers the exam itself.

  • Format: One web-based, proctored exam delivered via ProctorU remotely or Pearson VUE onsite.
  • Length and scoring: 82 questions in three hours; versions released on or after July 12, 2025 require 73% to pass.
  • CyberLive: Performance-based challenges run inside realistic virtual machines using real tools and code - this is where domains like Metasploit, C2, and Attacking Password Hashes get tested practically, not just theoretically.
  • Reference materials: Open book, but only printed books, notes, and indexes - electronic materials and internet access are prohibited during the exam.
  • Attempt window: 120 days from activation to complete your attempt.
  • Cost: $999 for the certification attempt, $899 for a retake.
  • Validity and renewal: Valid four years; renewal requires 36 CPE credits and a $499 renewal fee.

Because the reference material rule bans electronic notes, your printed index needs to be organized by domain, not alphabetically by tool name. A well-tabbed printed index covering all 16 domains is often the single highest-leverage prep asset - see our GPEN Cheat Sheet for a starting structure. For a full cost breakdown including training and retake budgeting, check GPEN Certification Cost 2026, and confirm eligibility details in GPEN Requirements 2026 before you register.

Mapping Study Weeks to Domains

Rather than a generic study calendar, map your prep weeks directly onto the four domain clusters above. This keeps every study session tied to a specific, testable GPEN domain instead of vague "review pentesting" sessions.

Week 1-2

Planning, Recon & Scanning

  • Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
  • Build and drill your printed index for these four domains
Week 3-4

Exploitation & Metasploit

  • Exploitation Fundamentals, Escalation and Exploitation, Metasploit, Command and Control
  • Run every technique in a home lab, not just read about it
Week 5

Password Attack Cluster

  • Password Attacks, Advanced Password Attacks, Password Formats and Hashes, Attacking Password Hashes
  • Drill hash identification until it's automatic
Week 6

AD, Kerberos & Azure

  • Domain Escalation and Persistence Attacks, Kerberos Attacks, both Azure domains
  • Focus extra time here if your background is network-heavy, not cloud-heavy

This structure also makes practice testing far more useful - instead of taking a full-length mock exam blind, run domain-specific practice sets against gpenpracticetest.com after each cluster to confirm retention before moving on. If you want to understand exactly how the passing threshold applies across these clusters, see GPEN Passing Score 2026.

Who Actually Uses This Domain Knowledge: Penetration testers, red team analysts, and vulnerability assessment specialists are the primary hiring targets for GPEN holders, and job postings frequently reference specific domains like Kerberos attacks or Azure AD enumeration directly. Browse GPEN Jobs to see how domain language shows up in real listings, and review GPEN Salary Guide 2026 for how this maps to compensation.

Frequently Asked Questions

Does GIAC weight the 16 GPEN domains equally on the exam?

GIAC does not publish fixed percentage weightings per domain. Treat all 16 domains as fair game and avoid skipping any cluster based on assumed low weight.

Which domains are tested through CyberLive hands-on labs versus multiple-choice questions?

GIAC doesn't publicly map specific domains to CyberLive versus multiple-choice items, but practical clusters like Metasploit, Command and Control, and Attacking Password Hashes are the most likely candidates for performance-based virtual machine challenges given their tool-driven nature.

Are the Azure domains new additions to GPEN?

Azure Overview, Attacks, and AD Integration and Azure Applications and Attack Strategies reflect GIAC's ongoing update of the exam toward hybrid cloud-integrated Active Directory environments, so candidates who trained on older material should specifically shore up cloud identity content.

How many domains focus specifically on password attacks?

Four domains cover password material directly: Password Attacks, Advanced Password Attacks, Password Formats and Hashes, and Attacking Password Hashes, making it the largest single content cluster in the GPEN blueprint.

Can I use printed notes organized by these 16 domains during the exam?

Yes. GIAC exams are open book for printed books, notes, and indexes only - electronic materials and internet access are prohibited, so an index tabbed by domain is a practical and permitted study aid.

Ready to pass your GPEN exam?

Put this into practice with free GPEN questions across every exam domain.