- GPEN is GIAC's Penetration Tester certification, tested via one CyberLive exam with 82 questions in three hours.
- Passing requires 73% for versions released on or after July 12, 2025.
- The exam spans 16 domains, from reconnaissance and scanning to Kerberos, Azure, and password attacks.
- Attempts cost $999 (retake $899), and candidates have 120 days from activation to sit the exam.
What Is A GPEN, Exactly?
A GPEN - the GIAC Penetration Tester certification - is a credential issued by GIAC that validates a professional's ability to plan, execute, and report on real penetration tests using industry-standard tools and methodology. If you've searched "What Is GPEN?" or "GPEN Meaning," the short answer is the same: it's a hands-on, technically rigorous certification aimed at people who actually break into networks for a living, not just people who can define terms on a multiple-choice quiz.
Unlike many entry-level security certifications, GPEN doesn't stop at theory. The exam includes CyberLive components - performance-based challenges run inside realistic virtual machines using real tools and real code. That means a GPEN holder has demonstrated, under proctored conditions, that they can actually use the tools they claim to know. For a deeper breakdown of terminology and scope, see What Does GPEN Stand For? and What Does GPEN Mean?.
How the GPEN Exam Works
The GPEN exam is delivered as a single web-based, proctored CyberLive exam. You can take it remotely through ProctorU or in person through a Pearson VUE testing center - your choice depends on scheduling flexibility and comfort with remote proctoring software.
- Format: 82 questions, three-hour time limit
- Passing score: 73% for exam versions released on or after July 12, 2025
- Question style: Mix of knowledge-based multiple choice and CyberLive performance-based tasks in live virtual machines
- Reference materials: Open book - but only printed books, printed notes, and printed indexes. Electronic materials and internet access are strictly prohibited during the exam
- Attempt window: 120 days from activation to complete the exam
That open-book policy is one of the most misunderstood parts of GPEN. Because you can bring printed references, many candidates assume the exam is memorization-light. In practice, the three-hour window and 82-question volume mean you can't afford to look up basic concepts - your printed index needs to function as a quick-reference tool for edge cases, not a crutch for fundamentals. For a full breakdown of exactly how tough this balance is in practice, read How Hard Is the GPEN Exam? Complete Difficulty Guide 2026.
If you want the passing threshold explained in more depth - including how it interacts with different exam versions - check out GPEN Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Build your printed index around CyberLive command syntax and less-common flags - things you'd forget under time pressure - rather than concepts you already understand cold.
The 16 GPEN Domains
GPEN's content is organized into 16 domains that span reconnaissance through post-exploitation, plus dedicated coverage of Azure and Active Directory attack paths. Understanding what each domain actually demands - not just its title - is the difference between generic prep and targeted prep.
Domain 13: Penetration Test Planning
Covers scoping, rules of engagement, legal considerations, and how a professional test differs from unauthorized hacking.
- Know the components of a proper scope document and why rules of engagement protect both parties
Domain 14: Reconnaissance & Domain 15: Scanning and Host Discovery
Passive and active information gathering, host enumeration, and service fingerprinting form the foundation every later domain builds on.
- Be fluent in the logic behind common scanning techniques, not just tool syntax
Domain 16: Vulnerability Scanning
Tests your ability to interpret scanner output, prioritize findings, and distinguish false positives from exploitable weaknesses.
- Understand how scan results feed into the exploitation phase
Domain 8: Exploitation Fundamentals & Domain 7: Escalation and Exploitation
Covers the mechanics of turning a vulnerability into access, and then turning access into elevated privileges.
- Practice mapping a discovered vulnerability to a realistic exploitation path
Domain 10: Metasploit
A dedicated domain on one of the most widely used exploitation frameworks - modules, payloads, and post-exploitation workflow.
- Practice building full attack chains inside Metasploit, not just isolated module usage
Domains 1, 2, 11, 12: Password Attacks & Hashes
Advanced Password Attacks, Attacking Password Hashes, Password Attacks, and Password Formats and Hashes collectively make up a heavily weighted cluster.
- Know hash formats cold, and understand cracking strategy selection based on hash type and constraints
Domain 9: Kerberos Attacks & Domain 6: Domain Escalation and Persistence Attacks
Active Directory attack paths - ticket abuse, delegation issues, and persistence mechanisms attackers use after initial compromise.
- Understand how Kerberos ticket attacks connect to broader domain escalation strategy
Domains 3 & 4: Azure Applications and Azure Overview/AD Integration
Cloud-focused domains covering Azure attack surfaces and how Azure AD integrates with - and extends - traditional on-prem attack paths.
- Don't treat cloud domains as an afterthought; they represent real exam weight
Domain 5: Command and Control (C2)
Covers how testers maintain access and communicate with compromised hosts after initial exploitation.
- Understand C2 architecture concepts, not just tool names
For a complete, domain-by-domain study breakdown with more granular subtopics, see GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas.
Who Earns and Hires GPEN Holders
GPEN sits squarely in the offensive security / penetration testing career track. Typical roles pursuing or holding this credential include penetration testers, red team operators, security consultants, and internal security analysts moving into offensive roles. Employers value GPEN because the CyberLive format proves hands-on capability rather than just theoretical knowledge - a meaningful signal when hiring for roles where mistakes on a live client network have real consequences.
Because the domains cover both classic infrastructure attacks (password cracking, Metasploit, scanning) and modern cloud attack paths (Azure, Azure AD), GPEN holders are relevant to organizations running hybrid environments - which describes most mid-size and enterprise networks today. If you're evaluating whether this fits your career trajectory, GPEN Salary Guide 2026: Complete Earnings Analysis and Is the GPEN Certification Worth It? Complete ROI Analysis 2026 both dig into the return on the investment. For open roles that specifically list GPEN as a requirement or preference, browse GPEN Jobs.
Registration, Fees, and Timelines
Understanding the mechanics of registering for GPEN matters as much as understanding the content, because the fee structure and deadlines are unforgiving once you commit.
| Item | Detail |
|---|---|
| Initial attempt cost | $999 |
| Retake cost | $899 |
| Question count | 82 questions |
| Time limit | 3 hours |
| Passing score | 73% (versions released on/after July 12, 2025) |
| Attempt window | 120 days from activation |
| Delivery options | ProctorU (remote) or Pearson VUE (onsite) |
| Reference materials | Printed books, notes, and indexes only - no electronic materials or internet access |
The 120-day activation window is worth planning around carefully. It's generous compared to some certifications, but it's also easy to let slip by if you don't map out a study schedule the moment you register. For a full cost breakdown including retake economics and what's actually included in the $999 fee, read GPEN Certification Cost 2026: Complete Pricing Breakdown. And if timing your attempt around specific windows or personal deadlines matters to you, GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling walks through scheduling logistics in more detail.
Keeping the Credential Current
A GPEN certification is valid for four years from the date it's earned. To renew, you need 36 CPE credits accumulated over that period, plus a $499 renewal fee. This is materially different from a one-time certification - GIAC expects continued engagement with the field, whether through additional training, conference attendance, teaching, or other qualifying activities that generate CPE credit.
Practically, this means the moment you pass, it's worth starting a habit of logging CPE-eligible activity rather than scrambling in year three. It also means the value of the certification is tied to staying current with attack techniques - which, given how fast Azure and AD attack surfaces evolve, is arguably a feature rather than a burden.
A GPEN-Specific Prep Approach
Generic study advice - spaced repetition, timed practice, active recall - works for any certification. What makes prep effective for GPEN specifically is sequencing your study around how the domains build on each other, and weighting time toward the domains with the most exam presence.
Foundations
- Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
- Build comfort with the logic of enumeration before moving to exploitation
Exploitation Core
- Exploitation Fundamentals, Escalation and Exploitation, Metasploit
- Run full attack chains in a lab, not isolated commands
Password & Identity Attacks
- Password Formats and Hashes, Attacking Password Hashes, Advanced Password Attacks, Password Attacks, Kerberos Attacks
- Drill hash identification and cracking-strategy selection until it's automatic
Cloud & Persistence
- Azure Overview and AD Integration, Azure Applications and Attack Strategies, Domain Escalation and Persistence Attacks, Command and Control
- Practice timed CyberLive-style scenarios under the three-hour constraint
This sequencing matters because several later domains - Kerberos Attacks, Domain Escalation and Persistence Attacks, and the Azure domains - assume you're already fluent with the fundamentals from earlier domains. Trying to study them out of order tends to create gaps that resurface on exam day. For a complete week-by-week plan with more resource recommendations, see GPEN Study Guide 2026: How to Pass on Your First Attempt, and for a condensed one-page reference to keep nearby during final review, use GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Key Takeaway
Weight your prep time toward the password-attack cluster and Metasploit - these domains recur across multiple exam questions in different forms, so mastery here pays off repeatedly.
Once your content review is solid, timed practice under exam-like conditions is what actually builds exam-day confidence. Running full-length practice sessions on GPEN Exam Prep lets you rehearse the pacing needed to move through 82 questions in three hours without leaving CyberLive tasks rushed. It's worth revisiting practice questions regularly in the final two weeks specifically to catch weak spots before they cost you on the real attempt.
If you're still deciding whether GPEN is the right next step versus other GIAC or offensive security credentials, the broader overview articles - GPEN Certification, What Is GPEN Certification?, and What Is A GPEN? - are good companion reads alongside formal GPEN Training options if you want structured instruction rather than self-study alone.
Frequently Asked Questions
GPEN stands for GIAC Penetration Tester. It's a certification issued by GIAC that validates hands-on penetration testing skills across 16 domains, from reconnaissance to Azure attack paths.
Both. GPEN is delivered as a CyberLive exam, combining traditional questions with performance-based tasks in live virtual machines using real tools, across 82 questions in a three-hour window.
Yes, but only printed books, printed notes, and printed indexes. Electronic materials and internet access are not permitted during the proctored exam.
Four years from the date earned. Renewal requires 36 CPE credits and a $499 renewal fee to keep the credential active.
The initial attempt costs $999, and a retake costs $899. Candidates have 120 days from activation to complete the exam once registered.