- What the GPEN Exam Actually Tests
- How the CyberLive Format Changes Your Prep
- Breaking Down the 16 GPEN Domains
- Registration, Costs, and Deadlines
- Building a Study Timeline That Matches the Domains
- Open-Book Strategy: What You Can and Can't Bring
- Common First-Attempt Mistakes
- Who Hires GPEN Holders and Why It Matters
- After the Exam: Renewal and Maintenance
- Frequently Asked Questions
- GPEN is one 82-question, three-hour CyberLive exam requiring 73% on versions released July 12, 2025 or later.
- The exam spans 16 domains, from Reconnaissance and Scanning to Kerberos Attacks and Azure exploitation.
- CyberLive performance-based questions run inside real virtual machines, so command syntax practice matters as much as theory.
- Only printed books, notes, and indexes are allowed open-book; no electronic devices or internet access.
What the GPEN Exam Actually Tests
The GIAC Penetration Tester (GPEN) certification measures whether you can plan, execute, and document a professional penetration test using the same methodology and tools employed inside real engagements. Unlike multiple-choice-only certifications, GPEN blends knowledge questions with CyberLive performance-based tasks that drop you into a virtual machine and ask you to actually run tools against a target. This matters for how you study: memorizing definitions will get you partway, but you also need muscle memory with command-line syntax, hash formats, and attack sequencing.
If you're still deciding whether this certification fits your career path, it helps to read a broader overview of what GPEN certification involves and how it compares to other offensive security credentials before committing study hours to it.
How the CyberLive Format Changes Your Prep
CyberLive is the feature that separates GPEN from paper-only certifications. Instead of only answering "what would you do," a portion of the exam requires you to demonstrate it inside a live virtual environment using real tools and real code. That means your lab time needs to mirror exam conditions: you should be comfortable launching scans, cracking hashes, and pivoting through a network without hesitating over syntax.
Because the clock keeps running during these performance segments, efficiency matters. Candidates who've only read about a tool tend to lose minutes fumbling with flags they'd know instantly after hands-on repetition. Build lab exercises around each domain rather than passively reading slide decks, and time yourself completing tasks the way you would during the actual attempt.
Key Takeaway
Treat every practice session as if it were graded. If you can't complete a scan or hash-cracking task in a lab within a few minutes, you're not ready for that portion of CyberLive yet.
Breaking Down the 16 GPEN Domains
GPEN's blueprint covers 16 distinct domains, and candidates who treat them as a single blob of "pentesting knowledge" tend to underprepare for the more specialized areas like Azure and Kerberos. For a full breakdown of each domain's weight and subtopics, see our complete guide to all 16 content areas. Here's how to think about the major clusters.
Domain 13: Penetration Test Planning
Covers scoping, rules of engagement, legal considerations, and how a test is structured from kickoff to reporting.
- Understand the difference between scope documents and rules of engagement
- Know what belongs in a pre-engagement checklist
Domains 14-16: Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
These early-phase domains test your ability to gather intelligence and map an environment before exploitation begins.
- Practice interpreting scan output, not just running the scan
- Know how host discovery differs from full port scanning
Domains 1, 2, 11, 12: Password Attacks and Hash Formats
Password-related domains are heavily represented and require you to identify hash types on sight and choose the correct attack method.
- Memorize common hash format signatures
- Practice both online and offline attack techniques against different hash types
Domain 9: Kerberos Attacks
Kerberos-based attacks are a modern staple of Active Directory penetration testing and are tested with technical depth.
- Understand ticket-granting mechanics well enough to explain abuse paths
- Practice these attacks in a lab against a domain controller, not just in theory
Domains 3 and 4: Azure Applications, Overview, Attacks, and AD Integration
Cloud-focused domains reflect how modern environments blend on-premises Active Directory with Azure. These trip up candidates who only trained in traditional network pentesting.
- Learn how Azure AD integration changes the attack surface
- Understand common misconfigurations attackers exploit in cloud identity
Domains 5, 6, 7, 8, 10: Post-Exploitation and Tooling
Command and Control, Domain Escalation and Persistence, Escalation and Exploitation, Exploitation Fundamentals, and Metasploit round out the back half of an engagement.
- Know Metasploit workflow well enough to move quickly under time pressure
- Understand persistence and escalation techniques at a conceptual and practical level
If you're unsure how difficult this mix of domains really is compared to other GIAC certifications, our GPEN difficulty guide walks through where most candidates struggle and why the cloud and Kerberos domains catch people off guard.
Registration, Costs, and Deadlines
Before you build a study plan, understand the logistics that will shape it. GIAC administers GPEN as a single web-based, proctored exam delivered remotely through ProctorU or in person through Pearson VUE. There is no separate practice exam bundled in - your registration fee covers the certification attempt itself.
| Item | Detail |
|---|---|
| First attempt cost | $999 |
| Retake cost | $899 |
| Question count | 82 questions |
| Time limit | 3 hours |
| Passing score | 73% (versions released on or after July 12, 2025) |
| Activation window | 120 days to complete the attempt |
| Certification validity | 4 years |
| Renewal requirement | 36 CPE credits |
| Renewal fee | $499 |
The 120-day activation window is easy to overlook when you're excited to register, but it's one of the most important planning constraints in the entire process. Once activated, the clock doesn't pause, so map your study calendar backward from your target test date before you pay. Our GPEN exam dates and scheduling guide covers how to avoid running out of runway, and our complete pricing breakdown details every fee you might encounter, including what happens if you need a retake.
Building a Study Timeline That Matches the Domains
A generic week-by-week template won't help you much unless it's mapped to GPEN's actual content. The approach below groups domains by phase of a penetration test, which mirrors both how the exam is structured and how real engagements unfold.
Planning and Reconnaissance
- Study Domain 13 (Penetration Test Planning) and Domain 14 (Reconnaissance)
- Review scoping documents and rules-of-engagement templates
Scanning and Vulnerability Analysis
- Work through Domain 15 (Scanning and Host Discovery) and Domain 16 (Vulnerability Scanning)
- Run real scans in a home lab and interpret full output, not just summaries
Password and Hash Attacks
- Cover Domains 1, 2, 11, and 12 together since they're closely related
- Drill hash identification until it becomes automatic
Active Directory and Kerberos
- Focus on Domain 6 (Domain Escalation and Persistence) and Domain 9 (Kerberos Attacks)
- Build a small lab domain controller to practice attacks hands-on
Exploitation, C2, and Metasploit
- Study Domains 5, 7, 8, and 10 together
- Practice full attack chains from initial access to post-exploitation
Azure and Final Review
- Study Domains 3 and 4 (Azure Applications and Azure AD Integration)
- Take timed practice questions and review your index under exam conditions
Notice this timeline schedules the Azure domains near the end rather than the beginning. Cloud-identity attacks depend on understanding traditional Active Directory concepts first, so sequencing matters more than most study guides admit. For a more detailed domain-by-domain study sequence, our exam domains guide expands on prerequisite relationships between topics.
Open-Book Strategy: What You Can and Can't Bring
GPEN is open book, but the definition of "open book" is narrower than many first-time candidates expect. You may bring printed books, printed notes, and a printed index. Electronic materials and internet access are explicitly prohibited during the exam. That means your phone, tablet, laptop notes, and any cloud-based reference are off the table.
The practical implication is that your index-building process is part of your study plan, not an afterthought the night before. Build your index while you study each domain so the page references stay accurate, and organize it by task rather than alphabetically - for example, group "hash cracking commands" together rather than scattering them under individual tool names.
Key Takeaway
Build your printed index domain-by-domain as you study, and rehearse looking things up in it under a timer. An index you can't navigate quickly during CyberLive tasks won't save you any time.
Common First-Attempt Mistakes
Most candidates who don't pass GPEN on the first attempt fall into a few predictable patterns rather than being unprepared across the board.
- Skipping hands-on practice for "easy" domains. Reconnaissance and scanning look simple on paper but the CyberLive components test actual tool fluency.
- Underestimating Azure content. Candidates coming from traditional network pentesting backgrounds often haven't touched Azure AD integration attacks before studying for GPEN.
- Building a messy or untested index. An index that isn't organized for speed becomes useless once the clock is running.
- Registering before confirming study time. With a 120-day activation window, waiting to register until your study plan is realistic avoids wasted fees.
- Treating all 16 domains as equal weight in study time. Some domains, like password attacks and Kerberos, warrant more lab repetition than others.
Our GPEN pass rate analysis looks at what the available data suggests about where candidates struggle most, which can help you allocate review time more realistically.
Who Hires GPEN Holders and Why It Matters
GPEN is aimed at penetration testers, ethical hackers, red teamers, and security consultants who need to demonstrate hands-on offensive skill rather than just theoretical knowledge. Organizations hiring for these roles - from consulting firms to internal security teams at larger enterprises - often list GPEN specifically because the CyberLive component gives them confidence that a candidate can perform real tasks, not just recognize terminology.
Understanding who values this credential helps you prioritize your study time toward the domains most relevant to the roles you're targeting. If you're weighing whether the investment makes sense for your career stage, our ROI analysis of GPEN certification and salary guide break down how the credential tends to factor into compensation and hiring decisions. You can also browse GPEN-related job listings to see how employers phrase requirements, which often maps directly back to specific domains like Kerberos attacks or Azure AD integration.
Before registering, it's also worth reviewing GPEN eligibility and prerequisites to confirm you meet any background expectations GIAC or your employer may have, even though GIAC itself doesn't mandate formal prerequisites for sitting the exam.
After the Exam: Renewal and Maintenance
Passing GPEN is not the end of the obligation - the certification is valid for four years, after which renewal requires 36 continuing professional education (CPE) credits and a $499 renewal fee. Building CPE accumulation into your ongoing professional development, rather than scrambling in year three, keeps the credential active without last-minute stress.
Many candidates use hands-on lab work, security conferences, or additional coursework to accumulate CPEs naturally while working in the field. Keeping a simple log of qualifying activities as you complete them saves significant time when renewal approaches.
For a condensed, single-page reference you can return to throughout your prep - covering the passing score, domain names, fees, and format details in one place - see our GPEN cheat sheet. And if you want to test your readiness under realistic timed conditions before exam day, our practice test platform is built specifically around GPEN's domain structure and CyberLive-style question formats.
Frequently Asked Questions
The current GPEN exam has 82 questions and a three-hour time limit, delivered as a single web-based, proctored CyberLive exam.
Candidates receiving exam versions released on or after July 12, 2025 need 73% to pass. Confirm your specific version at registration since requirements can vary by release.
No. GPEN is open book only for printed books, printed notes, and a printed index. Electronic materials and internet access are prohibited during the exam.
You have 120 days from activation to complete your attempt, so it's important to plan your study schedule before you activate rather than after.
You can retake the exam for $899, which is less than the original $999 attempt fee. Use the gap between attempts to focus specifically on the domains that gave you the most trouble.