- The Magic Number: 73%
- How GPEN Scoring Actually Works
- Exam Format and What 82 Questions in Three Hours Feels Like
- Domain Weight: Where the Points Actually Live
- CyberLive Performance Questions and the Passing Score
- Registration, Fees, and the 120-Day Clock
- A Domain-Aligned Study Plan for Hitting 73%
- Common Mistakes That Sink Candidates Under the Cut Score
- Frequently Asked Questions
- You need 73% to pass GPEN on versions released on or after July 12, 2025.
- The exam has 82 questions delivered in a three-hour CyberLive proctored session.
- CyberLive performance items in live virtual machines count toward your score, not just multiple choice.
- Only printed books, notes, and indexes are allowed - no electronic reference materials.
The Magic Number: 73%
If you're searching for a single number to plan your GPEN prep around, here it is: 73%. That's the passing score GIAC requires for exam versions released on or after July 12, 2025. Out of 82 questions delivered over a three-hour proctored session, you need to answer roughly 60 correctly to clear the bar. That's not a soft target or a curve - it's a fixed threshold set by GIAC's psychometric team, and it applies uniformly whether you take the exam remotely through ProctorU or onsite at a Pearson VUE center.
Unlike some certification exams that publish vague "70% or higher" language and then quietly adjust difficulty behind the scenes, GIAC is specific about the cut score tied to each exam version. That specificity matters for how you prepare. A 73% requirement across 82 questions means you have very little margin for guessing your way through entire domains you haven't studied. For a deeper look at how this compares to other technical certs, see our breakdown in How Hard Is the GPEN Exam? Complete Difficulty Guide 2026.
How GPEN Scoring Actually Works
GPEN doesn't publish a raw score-to-scaled-score conversion table the way some vendor exams do, but the practical takeaway is simple: every question theoretically carries similar weight toward your final percentage, and that percentage is measured against the 73% threshold. There's no partial credit for partially correct multi-select answers, and there's no indication that GIAC weights certain domains more heavily in scoring than others - though some domains appear far more frequently than others simply because they map to more real-world tasks.
This is different from raw pass/fail thresholds you might see referenced elsewhere. GIAC doesn't publish an official pass rate for GPEN, so resist the urge to treat forum anecdotes as statistical fact. If you want context on how candidates generally perform without relying on invented numbers, our article on the GPEN Pass Rate 2026: What the Data Shows walks through what's actually verifiable versus speculative.
Key Takeaway
Treat every question as equally important during practice. There's no evidence of domain-weighted scoring, so skipping "boring" domains like Reconnaissance to focus only on flashy topics like Metasploit is a risky strategy.
Exam Format and What 82 Questions in Three Hours Feels Like
Three hours for 82 questions works out to roughly 2.2 minutes per question - but that average is misleading because GPEN mixes traditional multiple-choice items with CyberLive performance-based challenges that take considerably longer to work through. You'll want to budget your time knowing that some questions are quick knowledge checks (identify a password hash format, recognize a Kerberos ticket type) while others require you to actually interact with a virtual machine, run a tool, and interpret output before selecting an answer.
The exam is delivered entirely web-based through GIAC's CyberLive platform, whether you're sitting at home with a ProctorU proctor watching remotely or at a physical Pearson VUE testing center. Either way, the interface and question format are identical - the delivery method is a logistics choice, not a difficulty variable.
One frequently misunderstood detail: GPEN is open book, but only for physical materials. You can bring printed books, printed notes, and printed indexes into the exam room or have them beside you during a remote session. Electronic PDFs, laptops with notes, phone access, and any form of internet lookup are strictly prohibited. This means your index and notes organization strategy matters almost as much as your actual knowledge - a well-tabbed printed reference can save you minutes on look-up-heavy questions.
Domain Weight: Where the Points Actually Live
GPEN's 16 domains span the full penetration testing lifecycle, from initial reconnaissance through domain-level persistence in Active Directory and Azure environments. Understanding what each domain actually tests - not just its title - is the difference between passing comfortably and squeaking by. Here's how the domains cluster conceptually:
Reconnaissance, Scanning, and Vulnerability Assessment
These domains cover the front end of any engagement: gathering intelligence, discovering live hosts, and identifying exploitable weaknesses before touching an exploit tool.
- Domain 14: Reconnaissance - passive and active information gathering techniques
- Domain 15: Scanning and Host Discovery - network mapping and service enumeration
- Domain 16: Vulnerability Scanning - interpreting scanner output and prioritizing findings
Password and Credential Attacks
A heavily represented cluster covering how credentials are stored, cracked, and abused across environments.
- Domain 1: Advanced Password Attacks
- Domain 2: Attacking Password Hashes
- Domain 11: Password Attacks - general methodology and tooling
- Domain 12: Password Formats and Hashes - recognizing hash types and encoding
Windows, Active Directory, and Kerberos
These domains test your ability to escalate privilege and persist inside a domain environment.
- Domain 6: Domain Escalation and Persistence Attacks
- Domain 9: Kerberos Attacks - ticket abuse and delegation issues
Exploitation and Tooling
Core exploitation mechanics and the frameworks used to execute them.
- Domain 7: Escalation and Exploitation
- Domain 8: Exploitation Fundamentals
- Domain 10: Metasploit - module usage and post-exploitation workflow
- Domain 5: Command and Control (C2) - maintaining access after initial compromise
Cloud and Planning
Azure content is a newer, growing emphasis area alongside the foundational planning domain.
- Domain 3: Azure Applications and Attack Strategies
- Domain 4: Azure Overview, Attacks, and AD Integration
- Domain 13: Penetration Test Planning - scoping, rules of engagement, and methodology
For a full breakdown of every domain with subtopics and study priorities, read GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas. Because scoring appears evenly distributed across questions rather than domain-weighted brackets, neglecting any single domain - especially the Azure-focused ones many candidates underestimate - directly threatens your 73% target.
CyberLive Performance Questions and the Passing Score
The single biggest factor separating GPEN's passing score requirement from a typical multiple-choice cert exam is CyberLive. These performance-based questions place you inside realistic virtual machines where you run actual tools - think Mimikatz-style credential dumping, Metasploit modules, or password cracking utilities - against live targets, then answer based on genuine output rather than a described scenario.
This matters for your passing score strategy in two ways. First, these questions typically take longer, so poor time management can cost you attempts at easier multiple-choice questions later in the exam. Second, you cannot bluff your way through them with test-taking tricks; you either know the correct syntax and workflow, or you don't. Command and Control, Metasploit, and Attacking Password Hashes are domains where CyberLive-style practice is non-negotiable - reading about a tool is not the same as having executed it under time pressure.
Key Takeaway
Practice hands-on labs for Domains 5, 10, 11, and 2 specifically - these map most directly to CyberLive's live-tool performance questions.
Registration, Fees, and the 120-Day Clock
Understanding the mechanics around your exam attempt helps you plan a realistic timeline toward that 73% score. A first attempt costs $999, and if you need to retake, the fee drops to $899. Once your attempt is activated, you have 120 days to schedule and complete it - plan your study calendar backward from that deadline rather than treating it as an afterthought.
The certification itself is valid for four years, after which renewal requires 36 CPE credits and a $499 renewal fee. For a complete cost breakdown including bundled training options, see GPEN Certification Cost 2026: Complete Pricing Breakdown. If you're still confirming you're eligible to sit the exam in the first place, check GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify before locking in a registration date.
| Item | Detail |
|---|---|
| Passing Score | 73% (versions released on/after July 12, 2025) |
| Question Count | 82 questions |
| Time Limit | Three hours |
| First Attempt Fee | $999 |
| Retake Fee | $899 |
| Attempt Window | 120 days from activation |
| Delivery | ProctorU (remote) or Pearson VUE (onsite), CyberLive platform |
| Certification Validity | 4 years |
| Renewal | 36 CPE credits, $499 fee |
A Domain-Aligned Study Plan for Hitting 73%
Generic study advice rarely accounts for the fact that GPEN's domains are not equally difficult to internalize. Reconnaissance and Scanning are largely conceptual and memorization-friendly; Kerberos Attacks and Azure AD Integration require you to actually understand attack chains, not just terms. Structure your weeks around that reality.
Foundations
- Penetration Test Planning (Domain 13) - methodology, scoping, and rules of engagement
- Reconnaissance and Scanning (Domains 14-15) - build your printed index for tool syntax
Credential Attacks
- Password Formats and Hashes (Domain 12) and Attacking Password Hashes (Domain 2)
- Advanced Password Attacks and Password Attacks (Domains 1 and 11) with hands-on cracking labs
Exploitation and Windows Domain Attacks
- Exploitation Fundamentals and Escalation and Exploitation (Domains 8 and 7)
- Metasploit (Domain 10) hands-on practice, Kerberos Attacks (Domain 9), and Domain Escalation and Persistence (Domain 6)
Cloud, C2, and Full Review
- Azure Overview and Attacks (Domains 3-4), Command and Control (Domain 5)
- Full-length practice exams and CyberLive-style lab drills targeting weak domains
This sequencing works because it builds from conceptual foundations toward hands-on complexity, mirroring how the actual exam blends recall questions with CyberLive lab tasks. For a more detailed week-by-week plan with resource recommendations, see GPEN Study Guide 2026: How to Pass on Your First Attempt, and use our GPEN practice tests throughout each phase to gauge whether you're tracking toward 73% or falling short in specific domains.
Common Mistakes That Sink Candidates Under the Cut Score
Most candidates who fall short of 73% don't fail because they lack general security knowledge - they fail because of predictable, fixable gaps:
- Treating Azure domains as optional. Domains 3 and 4 are relatively new additions and often under-studied, but they still count toward your score just like every other domain.
- Skipping hands-on practice for CyberLive-heavy domains. Reading about Metasploit modules or Command and Control frameworks isn't the same as executing them against a live VM under a countdown clock.
- Poor index organization. Since only printed materials are allowed, an unorganized binder costs you minutes per question you can't afford across a three-hour exam.
- Misjudging pacing. Spending too long on early performance-based questions leaves insufficient time for the remaining 82-question set.
- Ignoring lower-profile domains. Domain 12 (Password Formats and Hashes) and Domain 16 (Vulnerability Scanning) feel "basic" but are frequently tested.
If you're trying to gauge whether your current knowledge level is exam-ready, our GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful gut-check before you schedule. And if you're weighing whether the investment is worthwhile given the $999 fee and study time required, Is the GPEN Certification Worth It? Complete ROI Analysis 2026 covers the career-value side of that decision, while GPEN Salary Guide 2026: Complete Earnings Analysis looks at what roles typically seek this credential.
Frequently Asked Questions
You need 73% for exam versions released on or after July 12, 2025. Out of 82 total questions, that works out to roughly 60 correct answers.
GIAC has not published domain-specific weighting for scoring. Treat all 16 domains as equally important to your final percentage, even though question frequency may vary by domain.
You have 120 days from activation to schedule and sit your exam attempt, whether through ProctorU remotely or Pearson VUE onsite.
Yes, but only printed books, printed notes, and printed indexes. Electronic materials and any internet access, including on a second device, are prohibited during the proctored session.
You can retake the exam for $899, compared to the $999 initial attempt fee. Review your weakest domains before rescheduling, and use practice testing at gpenpracticetest.com to confirm improvement before you pay for another attempt.