- GPEN is a single 82-question, three-hour CyberLive exam requiring 73% to pass on newer versions.
- It covers 16 domains spanning password attacks, Kerberos, Azure, C2, Metasploit, and reconnaissance.
- Registration costs $999; a retake is $899; renewal every four years costs $499 plus 36 CPEs.
- CyberLive injects hands-on, tool-based challenges into a proctored exam, not just multiple choice.
What Is GPEN Certification?
GPEN stands for GIAC Penetration Tester, a credential issued by the Global Information Assurance Certification (GIAC) body to validate that a professional can plan, execute, and report on network and application penetration tests using industry-standard methodology and tooling. Unlike broad security-awareness certifications, GPEN is built around the actual mechanics of an engagement: reconnaissance, scanning, exploitation, password attacks, privilege escalation, and lateral movement inside Windows and Azure environments.
If you're still comparing entry-level titles or trying to figure out where GPEN fits among GIAC's offensive-security lineup, the companion piece on What Is GPEN? and the shorter GPEN Meaning breakdown cover the acronym and positioning in more depth. This article focuses specifically on what the certification tests, how it's delivered, and what it costs to earn and keep.
Exam Format and Delivery
GPEN is administered as a single web-based, proctored exam using GIAC's CyberLive technology. You can take it remotely through ProctorU or in person at a Pearson VUE test center - there is no separate lab exam or multi-part structure like some other penetration testing credentials.
The current version of the exam contains 82 questions delivered over three hours. Candidates who receive exam versions released on or after July 12, 2025 need a score of 73% to pass. Because GIAC periodically retires and refreshes question pools, it's worth confirming the exact passing threshold that applies to your scheduled attempt - the detailed breakdown in GPEN Passing Score 2026: Exactly What You Need to Pass tracks this closely.
What makes GPEN distinct from a standard multiple-choice test is CyberLive. Instead of only answering questions about what a tool does, a portion of the exam drops you into a real virtual machine where you run actual commands, parse real output, and interact with genuine attack tools to answer scenario-based questions. This mirrors the practical nature of the job far more than a purely theoretical exam would.
Key Takeaway
Treat GPEN prep as a mix of conceptual review and actual keyboard time in a lab - CyberLive questions reward candidates who have physically run the commands, not just read about them.
GIAC exams follow an open-book policy, but it's narrower than many candidates expect: you may bring printed books, printed notes, and printed indexes into the testing session. Electronic devices, PDFs, and any form of internet access are prohibited. This means your index needs to be built and organized before exam day - a well-tabbed printed reference is often the difference between finding an answer in seconds versus burning minutes you don't have. Once you register, you have 120 days from activation to schedule and complete your attempt, so plan your study timeline around that window rather than an open-ended calendar.
The 16 GPEN Exam Domains
GPEN's syllabus is organized into 16 domains that collectively map to the lifecycle of a penetration test, from initial planning through post-exploitation and reporting. Each domain expects working familiarity with specific tools, protocols, and attack techniques rather than surface-level definitions.
Penetration Test Planning
Covers scoping, rules of engagement, legal considerations, and how a professional test is structured before any technical work begins.
- Understand contract elements and engagement boundaries
Reconnaissance
Focuses on passive and active information gathering techniques used to build a target profile before touching production systems.
- OSINT sourcing and footprinting methodology
Scanning and Host Discovery
Tests knowledge of identifying live hosts, open ports, and services using scanning utilities and interpreting their output correctly.
- Port scanning logic and evasion considerations
Vulnerability Scanning
Covers automated vulnerability identification, false-positive triage, and how scan results feed into the exploitation phase.
- Interpreting scanner output and prioritizing findings
Exploitation Fundamentals
Establishes the core logic of turning a discovered vulnerability into actual access, including payload delivery basics.
- Exploit selection and execution logic
Metasploit
Requires hands-on comfort with the framework's modules, workflow, and integration with other tools during an engagement - a prime CyberLive target.
- Module selection, payload staging, session handling
Escalation and Exploitation
Bridges initial access to deeper compromise, covering pivoting and chaining multiple weaknesses together.
- Post-exploitation access expansion techniques
Command and Control (C2)
Tests understanding of maintaining and managing access to compromised systems throughout an engagement.
- C2 channel concepts and detection considerations
Password Attacks / Advanced Password Attacks
Two related domains covering credential-guessing strategy, attack automation, and more sophisticated bypass and cracking approaches.
- Online vs. offline attack methodology
Password Formats and Hashes / Attacking Password Hashes
Requires knowledge of how credentials are stored across platforms and the techniques used to crack or relay captured hashes.
- Hash type identification and cracking strategy
Kerberos Attacks
Covers ticket-based authentication weaknesses in Active Directory environments, including common ticket abuse techniques.
- Ticket request and abuse workflows
Domain Escalation and Persistence Attacks
Focuses on gaining and maintaining elevated control within an Active Directory domain after initial compromise.
- Privilege escalation paths inside AD
Azure Overview, Attacks, and AD Integration / Azure Applications and Attack Strategies
Two cloud-focused domains reflecting how modern penetration tests now regularly extend into Azure AD and cloud-hosted applications.
- Azure AD identity attack surfaces and hybrid integration risks
Sixteen domains is a lot of ground to cover, and the depth expected varies by topic. For a full walkthrough of each domain with study weighting suggestions, the dedicated guide at GPEN Exam Domains 2026: Complete Guide to All 16 Content Areas goes deeper than this overview allows.
Registration, Fees, and Renewal
A GPEN attempt costs $999, and if you don't pass on the first try, a retake is priced at $899. There is no bundled training requirement - you can register for the exam attempt directly and study independently, through a bootcamp, or through GIAC-affiliated coursework.
Once registered, your 120-day activation window starts, so it's worth registering only when you're genuinely close to exam-ready rather than banking time you won't use. If you're trying to line up a specific testing period around a work schedule or training cohort, GPEN Exam Dates 2026: Testing Windows, Deadlines & Scheduling walks through how the scheduling windows work with ProctorU and Pearson VUE.
The certification itself is valid for four years. To maintain it, you'll need to earn 36 continuing professional education (CPE) credits within that period and pay a $499 renewal fee - considerably less than a fresh attempt, which makes staying current more economical than letting the credential lapse and recertifying from scratch.
Who Earns GPEN and Why
GPEN is aimed at professionals who actually perform or oversee penetration testing engagements rather than those working purely in policy or compliance. Typical roles pursuing it include penetration testers, red team operators, security consultants, network and systems administrators moving into offensive security, and internal security analysts tasked with validating their organization's own defenses.
Employers hiring for these roles - consulting firms, managed security service providers, government contractors, and internal security teams at mid-to-large enterprises - often list GIAC certifications alongside or instead of other offensive-security credentials because GPEN's domain coverage maps directly onto real engagement tasks: scoping a test, running recon, exploiting a foothold, and escalating through Active Directory and Azure. If you're evaluating how the credential translates into job opportunities and compensation, GPEN Jobs and GPEN Salary Guide 2026: Complete Earnings Analysis cover market positioning in more detail, and GPEN Requirements 2026: Eligibility, Prerequisites & How to Qualify clarifies that there's no mandatory prerequisite course - motivated candidates can self-study and sit the exam directly.
Building a GPEN Study Plan by Domain
Generic study techniques only help if you apply them to GPEN's actual weak spots. A practical approach is to group the 16 domains into three study blocks and rotate weekly focus rather than reading linearly.
Foundations and Recon
- Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
Exploitation and Credentials
- Exploitation Fundamentals, Metasploit, Escalation and Exploitation, Password Attacks, Password Formats and Hashes, Attacking Password Hashes, Advanced Password Attacks
Active Directory, Cloud, and C2
- Kerberos Attacks, Domain Escalation and Persistence Attacks, Azure Overview and Attacks, Azure Applications, Command and Control
Within each block, spend the first pass building your printed index (remember: no electronic notes allowed in the exam room), then use timed practice sessions to simulate the CyberLive portion by actually running the commands rather than only reading about them. A structured week-by-week plan with more granularity, including how to weight review time against your strongest and weakest domains, is laid out in the GPEN Study Guide 2026: How to Pass on Your First Attempt.
Also worth checking honestly is your baseline comfort with the material before committing to a date - the difficulty analysis in How Hard Is the GPEN Exam? Complete Difficulty Guide 2026 and the exam performance context in GPEN Pass Rate 2026: What the Data Shows can help you calibrate how much runway to give yourself before the 120-day window closes.
GPEN At a Glance
| Attribute | Detail |
|---|---|
| Issuing body | GIAC |
| Delivery | Web-based, proctored, CyberLive (ProctorU remote or Pearson VUE onsite) |
| Questions | 82 |
| Time limit | 3 hours |
| Passing score | 73% (versions released on or after July 12, 2025) |
| Attempt cost | $999 |
| Retake cost | $899 |
| Activation window | 120 days from activation |
| Reference materials | Printed books, notes, and indexes only; no electronic or internet access |
| Validity period | 4 years |
| Renewal | 36 CPE credits, $499 fee |
For a condensed version of this table you can print and keep near your study desk, see the GPEN Cheat Sheet 2026: One-Page Review of Must-Know Facts. And if you'd rather test your readiness against realistic questions before committing to an exam date, you can start practicing directly on the main GPEN practice test platform.
Is GPEN the Right Certification for You?
Because GPEN blends knowledge-based questions with hands-on CyberLive challenges across 16 distinct domains, it tends to suit candidates who already have some exposure to networking, Windows/Active Directory administration, or basic scripting - not because there's a formal prerequisite, but because the exam moves quickly through technical material in three hours. If you're weighing GPEN against other paths or trying to determine whether the investment makes sense for your career stage, the ROI analysis in Is the GPEN Certification Worth It? Complete ROI Analysis 2026 looks at this from a cost-versus-outcome angle rather than a technical one.
Whichever path you choose, familiarity with GIAC's specific exam mechanics - the printed-materials-only policy, the CyberLive VM interactions, and the 120-day clock - matters as much as raw technical knowledge. Running through realistic practice questions on gpenpracticetest.com before exam day is one of the more direct ways to get comfortable with both the content and the format simultaneously, and pairing that with structured coursework via GPEN Training can round out gaps in domains you haven't touched hands-on before.
Frequently Asked Questions
It's both. The exam includes traditional knowledge-based questions plus CyberLive performance challenges where you interact with real virtual machines and tools to answer scenario-driven questions.
Yes. GPEN can be taken remotely through ProctorU or in person at a Pearson VUE testing center, both using the same CyberLive delivery format.
Printed books, printed notes, and printed indexes are allowed. Electronic devices and any internet access are strictly prohibited during the exam.
GPEN is valid for four years. Renewing requires earning 36 CPE credits and paying a $499 renewal fee before the certification expires.
You have 120 days from the date your exam attempt is activated to schedule and complete the test.
GPEN's value comes from how closely its 16 domains mirror the actual steps of a penetration test - planning, reconnaissance, scanning, exploitation, credential attacks, Active Directory and Kerberos abuse, Azure attack paths, and command and control. Understanding the exam's mechanics, from CyberLive's live VM challenges to the printed-only reference policy and the four-year renewal cycle, is just as important as mastering the technical content itself.