GPEN logo
Focused certification exam prep
Start practice

What Is A GPEN?

TL;DR
  • GPEN is GIAC's Penetration Tester certification, tested via one CyberLive exam with 82 questions in three hours.
  • Passing requires 73% for versions released on or after July 12, 2025.
  • The exam spans 16 domains, from reconnaissance and scanning to Kerberos, Azure, and password attacks.
  • Attempts cost $999 (retake $899), and candidates have 120 days from activation to sit the exam.

What Is A GPEN, Exactly?

A GPEN - the GIAC Penetration Tester certification - is a credential issued by GIAC that validates a professional's ability to plan, execute, and report on real penetration tests using industry-standard tools and methodology. If you've searched "What Is GPEN?" or "GPEN Meaning," the short answer is the same: it's a hands-on, technically rigorous certification aimed at people who actually break into networks for a living, not just people who can define terms on a multiple-choice quiz.

Unlike many entry-level security certifications, GPEN doesn't stop at theory. The exam includes CyberLive components - performance-based challenges run inside realistic virtual machines using real tools and real code. That means a GPEN holder has demonstrated, under proctored conditions, that they can actually use the tools they claim to know. For a deeper breakdown of terminology and scope, see What Does GPEN Stand For? and What Does GPEN Mean?.

Why This Distinction Matters: Many certifications test whether you can recognize the right answer among four choices. GPEN's CyberLive format tests whether you can operate the tool, interpret the output, and make the next decision - a much closer simulation of actual pentest work.

How the GPEN Exam Works

The GPEN exam is delivered as a single web-based, proctored CyberLive exam. You can take it remotely through ProctorU or in person through a Pearson VUE testing center - your choice depends on scheduling flexibility and comfort with remote proctoring software.

  • Format: 82 questions, three-hour time limit
  • Passing score: 73% for exam versions released on or after July 12, 2025
  • Question style: Mix of knowledge-based multiple choice and CyberLive performance-based tasks in live virtual machines
  • Reference materials: Open book - but only printed books, printed notes, and printed indexes. Electronic materials and internet access are strictly prohibited during the exam
  • Attempt window: 120 days from activation to complete the exam

That open-book policy is one of the most misunderstood parts of GPEN. Because you can bring printed references, many candidates assume the exam is memorization-light. In practice, the three-hour window and 82-question volume mean you can't afford to look up basic concepts - your printed index needs to function as a quick-reference tool for edge cases, not a crutch for fundamentals. For a full breakdown of exactly how tough this balance is in practice, read How Hard Is the GPEN Exam? Complete Difficulty Guide 2026.

If you want the passing threshold explained in more depth - including how it interacts with different exam versions - check out GPEN Passing Score 2026: Exactly What You Need to Pass.

Key Takeaway

Build your printed index around CyberLive command syntax and less-common flags - things you'd forget under time pressure - rather than concepts you already understand cold.

The 16 GPEN Domains

GPEN's content is organized into 16 domains that span reconnaissance through post-exploitation, plus dedicated coverage of Azure and Active Directory attack paths. Understanding what each domain actually demands - not just its title - is the difference between generic prep and targeted prep.

Domain 13: Penetration Test Planning

Covers scoping, rules of engagement, legal considerations, and how a professional test differs from unauthorized hacking.

  • Know the components of a proper scope document and why rules of engagement protect both parties

Domain 14: Reconnaissance & Domain 15: Scanning and Host Discovery

Passive and active information gathering, host enumeration, and service fingerprinting form the foundation every later domain builds on.

  • Be fluent in the logic behind common scanning techniques, not just tool syntax

Domain 16: Vulnerability Scanning

Tests your ability to interpret scanner output, prioritize findings, and distinguish false positives from exploitable weaknesses.

  • Understand how scan results feed into the exploitation phase

Domain 8: Exploitation Fundamentals & Domain 7: Escalation and Exploitation

Covers the mechanics of turning a vulnerability into access, and then turning access into elevated privileges.

  • Practice mapping a discovered vulnerability to a realistic exploitation path

Domain 10: Metasploit

A dedicated domain on one of the most widely used exploitation frameworks - modules, payloads, and post-exploitation workflow.

  • Practice building full attack chains inside Metasploit, not just isolated module usage

Domains 1, 2, 11, 12: Password Attacks & Hashes

Advanced Password Attacks, Attacking Password Hashes, Password Attacks, and Password Formats and Hashes collectively make up a heavily weighted cluster.

  • Know hash formats cold, and understand cracking strategy selection based on hash type and constraints

Domain 9: Kerberos Attacks & Domain 6: Domain Escalation and Persistence Attacks

Active Directory attack paths - ticket abuse, delegation issues, and persistence mechanisms attackers use after initial compromise.

  • Understand how Kerberos ticket attacks connect to broader domain escalation strategy

Domains 3 & 4: Azure Applications and Azure Overview/AD Integration

Cloud-focused domains covering Azure attack surfaces and how Azure AD integrates with - and extends - traditional on-prem attack paths.

  • Don't treat cloud domains as an afterthought; they represent real exam weight

Domain 5: Command and Control (C2)

Covers how testers maintain access and communicate with compromised hosts after initial exploitation.

  • Understand C2 architecture concepts, not just tool names

For a complete, domain-by-domain study breakdown with more granular subtopics, see GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas.

Who Earns and Hires GPEN Holders

GPEN sits squarely in the offensive security / penetration testing career track. Typical roles pursuing or holding this credential include penetration testers, red team operators, security consultants, and internal security analysts moving into offensive roles. Employers value GPEN because the CyberLive format proves hands-on capability rather than just theoretical knowledge - a meaningful signal when hiring for roles where mistakes on a live client network have real consequences.

Because the domains cover both classic infrastructure attacks (password cracking, Metasploit, scanning) and modern cloud attack paths (Azure, Azure AD), GPEN holders are relevant to organizations running hybrid environments - which describes most mid-size and enterprise networks today. If you're evaluating whether this fits your career trajectory, GPEN Salary Guide 2026: Complete Earnings Analysis and Is the GPEN Certification Worth It? Complete ROI Analysis 2026 both dig into the return on the investment. For open roles that specifically list GPEN as a requirement or preference, browse GPEN Jobs.

Eligibility Note: GIAC doesn't require a specific prerequisite course to sit the GPEN exam, but the content assumes real familiarity with networking, Windows/AD internals, and basic scripting. Review GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify before you register so there are no surprises.

Registration, Fees, and Timelines

Understanding the mechanics of registering for GPEN matters as much as understanding the content, because the fee structure and deadlines are unforgiving once you commit.

ItemDetail
Initial attempt cost$999
Retake cost$899
Question count82 questions
Time limit3 hours
Passing score73% (versions released on/after July 12, 2025)
Attempt window120 days from activation
Delivery optionsProctorU (remote) or Pearson VUE (onsite)
Reference materialsPrinted books, notes, and indexes only - no electronic materials or internet access

The 120-day activation window is worth planning around carefully. It's generous compared to some certifications, but it's also easy to let slip by if you don't map out a study schedule the moment you register. For a full cost breakdown including retake economics and what's actually included in the $999 fee, read GPEN Certification Cost 2026: Complete Pricing Breakdown. And if timing your attempt around specific windows or personal deadlines matters to you, GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling walks through scheduling logistics in more detail.

Keeping the Credential Current

A GPEN certification is valid for four years from the date it's earned. To renew, you need 36 CPE credits accumulated over that period, plus a $499 renewal fee. This is materially different from a one-time certification - GIAC expects continued engagement with the field, whether through additional training, conference attendance, teaching, or other qualifying activities that generate CPE credit.

Practically, this means the moment you pass, it's worth starting a habit of logging CPE-eligible activity rather than scrambling in year three. It also means the value of the certification is tied to staying current with attack techniques - which, given how fast Azure and AD attack surfaces evolve, is arguably a feature rather than a burden.

A GPEN-Specific Prep Approach

Generic study advice - spaced repetition, timed practice, active recall - works for any certification. What makes prep effective for GPEN specifically is sequencing your study around how the domains build on each other, and weighting time toward the domains with the most exam presence.

Weeks 1-2

Foundations

  • Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
  • Build comfort with the logic of enumeration before moving to exploitation
Weeks 3-4

Exploitation Core

  • Exploitation Fundamentals, Escalation and Exploitation, Metasploit
  • Run full attack chains in a lab, not isolated commands
Weeks 5-6

Password & Identity Attacks

  • Password Formats and Hashes, Attacking Password Hashes, Advanced Password Attacks, Password Attacks, Kerberos Attacks
  • Drill hash identification and cracking-strategy selection until it's automatic
Weeks 7-8

Cloud & Persistence

  • Azure Overview and AD Integration, Azure Applications and Attack Strategies, Domain Escalation and Persistence Attacks, Command and Control
  • Practice timed CyberLive-style scenarios under the three-hour constraint

This sequencing matters because several later domains - Kerberos Attacks, Domain Escalation and Persistence Attacks, and the Azure domains - assume you're already fluent with the fundamentals from earlier domains. Trying to study them out of order tends to create gaps that resurface on exam day. For a complete week-by-week plan with more resource recommendations, see GPEN Study Guide 2026: How to Pass on Your First Attempt, and for a condensed one-page reference to keep nearby during final review, use GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts.

Key Takeaway

Weight your prep time toward the password-attack cluster and Metasploit - these domains recur across multiple exam questions in different forms, so mastery here pays off repeatedly.

Once your content review is solid, timed practice under exam-like conditions is what actually builds exam-day confidence. Running full-length practice sessions on GPEN Exam Prep lets you rehearse the pacing needed to move through 82 questions in three hours without leaving CyberLive tasks rushed. It's worth revisiting practice questions regularly in the final two weeks specifically to catch weak spots before they cost you on the real attempt.

If you're still deciding whether GPEN is the right next step versus other GIAC or offensive security credentials, the broader overview articles - GPEN Certification, What Is GPEN Certification?, and What Is A GPEN? - are good companion reads alongside formal GPEN Training options if you want structured instruction rather than self-study alone.

Frequently Asked Questions

What does GPEN actually stand for?

GPEN stands for GIAC Penetration Tester. It's a certification issued by GIAC that validates hands-on penetration testing skills across 16 domains, from reconnaissance to Azure attack paths.

Is the GPEN exam multiple choice or hands-on?

Both. GPEN is delivered as a CyberLive exam, combining traditional questions with performance-based tasks in live virtual machines using real tools, across 82 questions in a three-hour window.

Can I use notes during the GPEN exam?

Yes, but only printed books, printed notes, and printed indexes. Electronic materials and internet access are not permitted during the proctored exam.

How long is the GPEN certification valid?

Four years from the date earned. Renewal requires 36 CPE credits and a $499 renewal fee to keep the credential active.

How much does it cost to register for GPEN?

The initial attempt costs $999, and a retake costs $899. Candidates have 120 days from activation to complete the exam once registered.

Ready to pass your GPEN exam?

Put this into practice with free GPEN questions across every exam domain.