- GPEN is a single 82-question, three-hour CyberLive exam requiring 73% on versions from July 12, 2025 onward.
- The exam blends multiple-choice questions with hands-on CyberLive challenges in live virtual machines.
- 16 domains span password attacks, Kerberos, Azure AD, C2, Metasploit, and reconnaissance.
- Certification costs $999, retakes cost $899, and renewal every four years costs $499 plus 36 CPEs.
What Is GPEN?
GPEN - the GIAC Penetration Tester certification - is a vendor-neutral credential from GIAC that validates a candidate's ability to plan, execute, and report on network and system penetration tests. It's built around the practical, offensive-security skill set that shows up in real engagements: password attacks, exploitation, lateral movement, Active Directory abuse, and cloud attack paths in Azure. Unlike certifications that lean heavily on theory, GPEN is designed to confirm that you can actually run the attacks, not just describe them.
If you're weighing GPEN against other offensive security credentials, it helps to first understand exactly what the exam covers domain by domain - our GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas breaks each one down in depth. This article focuses on the bigger picture: what GPEN is, how GIAC structures the exam, and who ends up holding it.
How the GPEN Exam Is Actually Delivered
GPEN is administered as one web-based, proctored exam using GIAC's CyberLive platform. You can sit it remotely through ProctorU or in person at a Pearson VUE testing center - there's no separate "practical" exam bolted onto a written test. The current version has 82 questions delivered in a three-hour window, and candidates on versions released on or after July 12, 2025 need 73% to pass.
What makes CyberLive different from a standard multiple-choice cert exam is that a portion of the questions drop you into real virtual machines where you run actual tools against live targets. Instead of just answering "what would you type," you're expected to actually type it - interpreting output from tools like Metasploit, hash-cracking utilities, and Kerberos attack scripts inside the exam environment itself.
Open-Book Rules Are Narrower Than You'd Expect
GIAC exams, including GPEN, are open book - but only for printed books, printed notes, and printed indexes. Electronic materials and internet access are explicitly prohibited during the exam. That means your index needs to work as a paper artifact, not a searchable PDF.
- Build a printed index organized by domain and tool name
- Tab or color-code sections for Kerberos attacks, Metasploit syntax, and hash formats
- Practice locating answers in your printed materials under time pressure
Once you register, you have 120 days from activation to complete the attempt, which gives you a real scheduling runway rather than a rigid fixed date. For a full walkthrough of what "passing" actually requires on the current version, see GPEN Passing Score 2026: Exactly What You Need to Pass.
The 16 Domains GPEN Actually Tests
GPEN's content blueprint is unusually granular for a penetration testing certification - 16 named domains instead of a handful of broad categories. That granularity is useful for study planning because it tells you precisely where to spend hours instead of guessing at "general pentesting" topics.
Password and Credential Attacks (4 Domains)
A significant chunk of GPEN is dedicated to password and credential-based attacks, reflecting how often real engagements pivot on cracked or captured credentials.
- Advanced Password Attacks
- Attacking Password Hashes
- Password Attacks
- Password Formats and Hashes
Windows and Active Directory Escalation
Domain and identity attacks are core to modern internal penetration tests, and GPEN reflects that with dedicated domains on Kerberos and privilege escalation.
- Kerberos Attacks
- Domain Escalation and Persistence Attacks
- Escalation and Exploitation
Cloud: Azure-Specific Content
Two full domains are dedicated to Azure, which sets GPEN apart from older-style network pentest certs that ignore cloud identity entirely.
- Azure Applications and Attack Strategies
- Azure Overview, Attacks, and AD Integration
Exploitation, Tooling, and Recon
The remaining domains cover the engagement lifecycle from planning through active exploitation and command and control.
- Penetration Test Planning
- Reconnaissance
- Scanning and Host Discovery
- Vulnerability Scanning
- Exploitation Fundamentals
- Metasploit
- Command and Control (C2)
Notice how much of the blueprint is credential- and identity-focused: four domains touch passwords and hashes directly, and three more cover Kerberos and domain escalation. That's seven of sixteen domains built around Active Directory credential attacks alone. For a granular study checklist mapped to each of these areas, our GPEN Study Guide 2026: How to Pass on Your First Attempt is a good companion to this overview.
Who Hires GPEN Holders
GPEN is aimed squarely at people doing or supervising offensive security work, not generalist IT security staff. Roles that commonly list or reward GPEN include:
- Penetration testers at consultancies and MSSPs who run internal and external network assessments
- Red team operators who need credential attack and C2 fluency beyond entry-level scanning
- Internal security engineers tasked with validating Active Directory and Azure AD hardening
- Security consultants who need a recognized, vendor-neutral credential to bid on assessment contracts
- Blue-team and detection engineers who want to understand attacker tradecraft - Kerberos abuse, password spraying, C2 traffic - from the offensive side
Because GPEN is hands-on in its testing method, many hiring managers treat it as a stronger practical signal than certifications that are purely multiple-choice. If you're evaluating whether the credential is worth pursuing for your career stage, Is the GPEN Certification Worth It? Complete ROI Analysis 2026 looks at that question directly, and GPEN Jobs covers the specific roles and titles where the credential shows up in job postings.
Concrete Skills You Need on Exam Day
Because GPEN's CyberLive component drops you into live tools, memorizing definitions isn't enough - you need muscle memory with specific commands and workflows. Concrete, testable skills include:
- Cracking captured hashes and interpreting hash formats correctly for the algorithm in use
- Executing Kerberoasting and related Kerberos attacks and reading the resulting output
- Navigating Metasploit modules, setting options, and chaining exploitation with post-exploitation modules
- Enumerating Azure AD and identifying attack paths tied to app registrations and integrations
- Running host discovery and vulnerability scans, then triaging results into an exploitation plan
- Establishing and recognizing command and control channels and their traffic patterns
Key Takeaway
Spend hands-on lab time with Metasploit, Kerberos attack tooling, and Azure AD enumeration before exam day - CyberLive questions expect you to operate tools, not just recognize their names.
Registration, Cost, and Renewal Mechanics
GIAC's pricing and scheduling structure for GPEN is straightforward but worth knowing precisely before you commit:
| Item | Detail |
|---|---|
| Initial certification attempt | $999 |
| Retake attempt | $899 |
| Exam format | 82 questions, 3 hours, CyberLive |
| Passing score | 73% (versions released on/after July 12, 2025) |
| Time to complete after activation | 120 days |
| Certification validity | 4 years |
| Renewal requirement | 36 CPE credits |
| Renewal fee | $499 |
Delivery is remote via ProctorU or onsite at Pearson VUE - there's no separate lab-exam location to book, since CyberLive's hands-on component runs inside the same proctored session as the multiple-choice portion. For a complete breakdown of every fee, bundle option, and what drives the total cost of earning and maintaining GPEN, see GPEN Certification Cost 2026: Complete Pricing Breakdown.
Building a Domain-Aware Study Plan
Generic study techniques only help if they're mapped to GPEN's actual domain list. A reasonable way to sequence preparation is to front-load the domains that carry the most exam weight in practice - password and credential attacks, plus Kerberos and Active Directory escalation - before moving to Azure and tooling-heavy domains.
Password and Hash Foundations
- Password Formats and Hashes, Attacking Password Hashes, Password Attacks, Advanced Password Attacks
- Practice cracking workflows and format identification until they're automatic
Identity and Domain Escalation
- Kerberos Attacks, Domain Escalation and Persistence Attacks, Escalation and Exploitation
- Run Kerberoasting labs and review real command output, not just theory
Cloud and Tooling
- Azure Overview, Attacks, and AD Integration; Azure Applications and Attack Strategies; Metasploit
- Practice enumerating Azure AD attack paths and chaining Metasploit modules
Recon, Scanning, and C2 Review
- Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning, Exploitation Fundamentals, Command and Control (C2), Penetration Test Planning
- Build and rehearse your printed index, then run full-length practice sessions
Before finalizing your timeline, confirm you meet GIAC's expectations and understand any prerequisites in GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify, and check upcoming testing windows in GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling so your study schedule lines up with your actual registration window. Running timed practice questions on GPEN Exam Prep throughout each phase is one of the most direct ways to confirm whether a domain is actually exam-ready or still needs more lab time.
Key Takeaway
Sequence study by exam weight, not alphabetical order - password and Active Directory domains dominate the blueprint, so master those before spending equal time on lighter tooling domains.
Frequently Asked Questions
Both. GPEN uses GIAC's CyberLive platform, which mixes standard multiple-choice questions with performance-based challenges in live virtual machines using real tools.
The current version has 82 questions to complete in three hours, with a required score of 73% for versions released on or after July 12, 2025.
Yes, but only printed books, printed notes, and printed indexes. Electronic devices and internet access are not permitted during the exam.
GPEN is valid for four years. Renewing requires earning 36 CPE credits and paying a $499 renewal fee.
You can retake it for $899, and you still have 120 days from your original activation date to complete attempts within that window, subject to GIAC's retake policy.
For a deeper look at how difficult candidates actually find this exam and how it compares to other offensive security certifications, read How Hard Is the GPEN Exam? Complete Difficulty Guide 2026, and check GPEN Pass Rate 2026: What the Data Shows before you lock in your exam date. When you're ready to test your readiness against real exam conditions, GPEN Exam Prep has practice questions built around every one of the 16 domains covered here.