GPEN logo
Focused certification exam prep
Start practice

GPEN Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • GPEN is one 82-question, three-hour CyberLive exam requiring 73% on versions released July 12, 2025 or later.
  • The exam spans 16 domains, from Reconnaissance and Scanning to Kerberos Attacks and Azure exploitation.
  • CyberLive performance-based questions run inside real virtual machines, so command syntax practice matters as much as theory.
  • Only printed books, notes, and indexes are allowed open-book; no electronic devices or internet access.

What the GPEN Exam Actually Tests

The GIAC Penetration Tester (GPEN) certification measures whether you can plan, execute, and document a professional penetration test using the same methodology and tools employed inside real engagements. Unlike multiple-choice-only certifications, GPEN blends knowledge questions with CyberLive performance-based tasks that drop you into a virtual machine and ask you to actually run tools against a target. This matters for how you study: memorizing definitions will get you partway, but you also need muscle memory with command-line syntax, hash formats, and attack sequencing.

If you're still deciding whether this certification fits your career path, it helps to read a broader overview of what GPEN certification involves and how it compares to other offensive security credentials before committing study hours to it.

Exam Snapshot: 82 questions, three hours, delivered remotely through ProctorU or onsite through Pearson VUE. A passing score of 73% applies to versions released on or after July 12, 2025. The exam costs $999 for a first attempt and $899 for a retake.

How the CyberLive Format Changes Your Prep

CyberLive is the feature that separates GPEN from paper-only certifications. Instead of only answering "what would you do," a portion of the exam requires you to demonstrate it inside a live virtual environment using real tools and real code. That means your lab time needs to mirror exam conditions: you should be comfortable launching scans, cracking hashes, and pivoting through a network without hesitating over syntax.

Because the clock keeps running during these performance segments, efficiency matters. Candidates who've only read about a tool tend to lose minutes fumbling with flags they'd know instantly after hands-on repetition. Build lab exercises around each domain rather than passively reading slide decks, and time yourself completing tasks the way you would during the actual attempt.

Key Takeaway

Treat every practice session as if it were graded. If you can't complete a scan or hash-cracking task in a lab within a few minutes, you're not ready for that portion of CyberLive yet.

Breaking Down the 16 GPEN Domains

GPEN's blueprint covers 16 distinct domains, and candidates who treat them as a single blob of "pentesting knowledge" tend to underprepare for the more specialized areas like Azure and Kerberos. For a full breakdown of each domain's weight and subtopics, see our complete guide to all 16 content areas. Here's how to think about the major clusters.

Domain 13: Penetration Test Planning

Covers scoping, rules of engagement, legal considerations, and how a test is structured from kickoff to reporting.

  • Understand the difference between scope documents and rules of engagement
  • Know what belongs in a pre-engagement checklist

Domains 14-16: Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning

These early-phase domains test your ability to gather intelligence and map an environment before exploitation begins.

  • Practice interpreting scan output, not just running the scan
  • Know how host discovery differs from full port scanning

Domains 1, 2, 11, 12: Password Attacks and Hash Formats

Password-related domains are heavily represented and require you to identify hash types on sight and choose the correct attack method.

  • Memorize common hash format signatures
  • Practice both online and offline attack techniques against different hash types

Domain 9: Kerberos Attacks

Kerberos-based attacks are a modern staple of Active Directory penetration testing and are tested with technical depth.

  • Understand ticket-granting mechanics well enough to explain abuse paths
  • Practice these attacks in a lab against a domain controller, not just in theory

Domains 3 and 4: Azure Applications, Overview, Attacks, and AD Integration

Cloud-focused domains reflect how modern environments blend on-premises Active Directory with Azure. These trip up candidates who only trained in traditional network pentesting.

  • Learn how Azure AD integration changes the attack surface
  • Understand common misconfigurations attackers exploit in cloud identity

Domains 5, 6, 7, 8, 10: Post-Exploitation and Tooling

Command and Control, Domain Escalation and Persistence, Escalation and Exploitation, Exploitation Fundamentals, and Metasploit round out the back half of an engagement.

  • Know Metasploit workflow well enough to move quickly under time pressure
  • Understand persistence and escalation techniques at a conceptual and practical level

If you're unsure how difficult this mix of domains really is compared to other GIAC certifications, our GPEN difficulty guide walks through where most candidates struggle and why the cloud and Kerberos domains catch people off guard.

Registration, Costs, and Deadlines

Before you build a study plan, understand the logistics that will shape it. GIAC administers GPEN as a single web-based, proctored exam delivered remotely through ProctorU or in person through Pearson VUE. There is no separate practice exam bundled in - your registration fee covers the certification attempt itself.

ItemDetail
First attempt cost$999
Retake cost$899
Question count82 questions
Time limit3 hours
Passing score73% (versions released on or after July 12, 2025)
Activation window120 days to complete the attempt
Certification validity4 years
Renewal requirement36 CPE credits
Renewal fee$499

The 120-day activation window is easy to overlook when you're excited to register, but it's one of the most important planning constraints in the entire process. Once activated, the clock doesn't pause, so map your study calendar backward from your target test date before you pay. Our GPEN exam dates and scheduling guide covers how to avoid running out of runway, and our complete pricing breakdown details every fee you might encounter, including what happens if you need a retake.

Passing Score Reminder: The 73% threshold applies specifically to exam versions released on or after July 12, 2025. Always confirm which version you're assigned when you register, since blueprint and scoring details can shift between releases. See our passing score breakdown for more detail.

Building a Study Timeline That Matches the Domains

A generic week-by-week template won't help you much unless it's mapped to GPEN's actual content. The approach below groups domains by phase of a penetration test, which mirrors both how the exam is structured and how real engagements unfold.

Weeks 1-2

Planning and Reconnaissance

  • Study Domain 13 (Penetration Test Planning) and Domain 14 (Reconnaissance)
  • Review scoping documents and rules-of-engagement templates
Weeks 3-4

Scanning and Vulnerability Analysis

  • Work through Domain 15 (Scanning and Host Discovery) and Domain 16 (Vulnerability Scanning)
  • Run real scans in a home lab and interpret full output, not just summaries
Weeks 5-6

Password and Hash Attacks

  • Cover Domains 1, 2, 11, and 12 together since they're closely related
  • Drill hash identification until it becomes automatic
Weeks 7-8

Active Directory and Kerberos

  • Focus on Domain 6 (Domain Escalation and Persistence) and Domain 9 (Kerberos Attacks)
  • Build a small lab domain controller to practice attacks hands-on
Weeks 9-10

Exploitation, C2, and Metasploit

  • Study Domains 5, 7, 8, and 10 together
  • Practice full attack chains from initial access to post-exploitation
Weeks 11-12

Azure and Final Review

  • Study Domains 3 and 4 (Azure Applications and Azure AD Integration)
  • Take timed practice questions and review your index under exam conditions

Notice this timeline schedules the Azure domains near the end rather than the beginning. Cloud-identity attacks depend on understanding traditional Active Directory concepts first, so sequencing matters more than most study guides admit. For a more detailed domain-by-domain study sequence, our exam domains guide expands on prerequisite relationships between topics.

Open-Book Strategy: What You Can and Can't Bring

GPEN is open book, but the definition of "open book" is narrower than many first-time candidates expect. You may bring printed books, printed notes, and a printed index. Electronic materials and internet access are explicitly prohibited during the exam. That means your phone, tablet, laptop notes, and any cloud-based reference are off the table.

The practical implication is that your index-building process is part of your study plan, not an afterthought the night before. Build your index while you study each domain so the page references stay accurate, and organize it by task rather than alphabetically - for example, group "hash cracking commands" together rather than scattering them under individual tool names.

Key Takeaway

Build your printed index domain-by-domain as you study, and rehearse looking things up in it under a timer. An index you can't navigate quickly during CyberLive tasks won't save you any time.

Common First-Attempt Mistakes

Most candidates who don't pass GPEN on the first attempt fall into a few predictable patterns rather than being unprepared across the board.

  • Skipping hands-on practice for "easy" domains. Reconnaissance and scanning look simple on paper but the CyberLive components test actual tool fluency.
  • Underestimating Azure content. Candidates coming from traditional network pentesting backgrounds often haven't touched Azure AD integration attacks before studying for GPEN.
  • Building a messy or untested index. An index that isn't organized for speed becomes useless once the clock is running.
  • Registering before confirming study time. With a 120-day activation window, waiting to register until your study plan is realistic avoids wasted fees.
  • Treating all 16 domains as equal weight in study time. Some domains, like password attacks and Kerberos, warrant more lab repetition than others.

Our GPEN pass rate analysis looks at what the available data suggests about where candidates struggle most, which can help you allocate review time more realistically.

Who Hires GPEN Holders and Why It Matters

GPEN is aimed at penetration testers, ethical hackers, red teamers, and security consultants who need to demonstrate hands-on offensive skill rather than just theoretical knowledge. Organizations hiring for these roles - from consulting firms to internal security teams at larger enterprises - often list GPEN specifically because the CyberLive component gives them confidence that a candidate can perform real tasks, not just recognize terminology.

Understanding who values this credential helps you prioritize your study time toward the domains most relevant to the roles you're targeting. If you're weighing whether the investment makes sense for your career stage, our ROI analysis of GPEN certification and salary guide break down how the credential tends to factor into compensation and hiring decisions. You can also browse GPEN-related job listings to see how employers phrase requirements, which often maps directly back to specific domains like Kerberos attacks or Azure AD integration.

Before registering, it's also worth reviewing GPEN eligibility and prerequisites to confirm you meet any background expectations GIAC or your employer may have, even though GIAC itself doesn't mandate formal prerequisites for sitting the exam.

After the Exam: Renewal and Maintenance

Passing GPEN is not the end of the obligation - the certification is valid for four years, after which renewal requires 36 continuing professional education (CPE) credits and a $499 renewal fee. Building CPE accumulation into your ongoing professional development, rather than scrambling in year three, keeps the credential active without last-minute stress.

Many candidates use hands-on lab work, security conferences, or additional coursework to accumulate CPEs naturally while working in the field. Keeping a simple log of qualifying activities as you complete them saves significant time when renewal approaches.

Plan Ahead: Four years feels distant right after you pass, but CPE credits are easier to earn gradually through normal work and training than to backfill in a rush before expiration.

For a condensed, single-page reference you can return to throughout your prep - covering the passing score, domain names, fees, and format details in one place - see our GPEN cheat sheet. And if you want to test your readiness under realistic timed conditions before exam day, our practice test platform is built specifically around GPEN's domain structure and CyberLive-style question formats.

Frequently Asked Questions

How many questions are on the GPEN exam and how much time do I get?

The current GPEN exam has 82 questions and a three-hour time limit, delivered as a single web-based, proctored CyberLive exam.

What score do I need to pass GPEN?

Candidates receiving exam versions released on or after July 12, 2025 need 73% to pass. Confirm your specific version at registration since requirements can vary by release.

Can I use my laptop or phone during the exam since it's open book?

No. GPEN is open book only for printed books, printed notes, and a printed index. Electronic materials and internet access are prohibited during the exam.

How long do I have to schedule and take the exam after registering?

You have 120 days from activation to complete your attempt, so it's important to plan your study schedule before you activate rather than after.

What happens if I don't pass on my first try?

You can retake the exam for $899, which is less than the original $999 attempt fee. Use the gap between attempts to focus specifically on the domains that gave you the most trouble.

Ready to pass your GPEN exam?

Put this into practice with free GPEN questions across every exam domain.