GIAC GPEN (Penetration Tester)

GIAC/SANS

Complete guide to passing the GIAC GPEN (Penetration Tester) exam on your first attempt.

HardMedium-High Search Volume
Key Information at a Glance
Cost

$949 (exam only), $8,500+ with SANS training

Pass Rate

~70%

Validity

4 years

Region

Global

Provider

GIAC/SANS

Salary Impact

$120k-$170k

Are you ready for GIAC GPEN (Penetration Tester)?

Loading quiz...

Complete Overview

GIAC Penetration Tester (GPEN) is the network penetration testing certification from GIAC, the certification body attached to the SANS Institute, and it is aimed at people who run authorised attacks against enterprise networks and Active Directory rather than at web application testers. A standalone GIAC certification attempt costs USD 999; the affiliated training course, SANS SEC560: Enterprise Penetration Testing, is listed at USD 8,780 for the self-paced format and carries 36 CPE credits across six sections.

The exam is one proctored sitting of 82 questions with a three-hour limit. GIAC has set the minimum passing score at 73 percent for candidates receiving the exam version released on or after 12 July 2025. That is roughly 2 minutes 12 seconds per question, and the exam includes CyberLive items that place you in a virtual machine with real tools, real code and real target systems and require you to produce the answer from the live environment.

GPEN is open book. GIAC permits hardcopy books, printed and handwritten notes, and an index you build yourself. Digital material is prohibited in every form, including PDF copies of the same books you are allowed to carry in print. Material that has the appearance of practice test questions with answers is also prohibited. Because the exam is command-heavy, the most useful index entries are not definitions but syntax: the exact Nmap flag combination, the Hashcat mode number for a given hash format, the Impacket script that performs a given action.

GIAC publishes 16 exam certification objectives for GPEN without percentage weights. They cover penetration test planning, reconnaissance, scanning and host discovery, vulnerability scanning, exploitation fundamentals, escalation and exploitation, Metasploit at an intermediate level, four separate password objectives covering formats and hashes, attacking hashes, password attacks generally and advanced password attacks, Kerberos attacks, domain escalation and persistence, command and control frameworks, and two Azure objectives covering Entra ID fundamentals and attacks plus federated and single sign-on application attacks.

The Azure and Entra ID content is what separates the current GPEN from older network penetration testing certifications. Two of the 16 objectives are cloud identity objectives, and the domain escalation content assumes Active Directory Certificate Services and Kerberos ticket attacks rather than stopping at local privilege escalation.

A certification attempt is active for 120 days from activation, with GIAC capping total access across attempts at 570 days. Candidates test either remotely through ProctorU or onsite at Pearson VUE. Submitted answers cannot be revisited, but GIAC lets you skip between 10 and 15 questions and come back to them, and the sitting carries 15 minutes of break time that can be taken in one or two blocks. GPEN is valid for four years and renews on 36 CPE credits plus a USD 499 certification maintenance fee.

Why Get GIAC GPEN (Penetration Tester) Certified?

GPEN is one of the GIAC certifications accredited to ANAB ISO/IEC 17024, which is the accreditation federal and defence hiring frameworks check for. GIAC publishes its current DoD 8140 mapping at giac.org/workforce-development/dodd-8140, where qualification runs by DCWF work role and proficiency level rather than by a flat certification list.

A certification attempt includes two practice tests that report performance objective by objective, so you get a calibrated score against GIAC's own item style before you sit the exam that counts.

Two of the 16 GIAC objectives cover Azure and Entra ID attacks specifically, including federated and single sign-on environments, which most network penetration testing certifications do not test at all.

CyberLive items place you in a live virtual machine with real tools, so the credential evidences that you can run the attack rather than describe it.

GPEN is valid for four years rather than the three that CompTIA and ISC2 use, and renews on 36 CPE credits plus a USD 499 maintenance fee.

The affiliated SEC560 course ends with a team-based capture the flag event across target networks, which is the closest rehearsal available for the CyberLive portion of the exam.

The exam is open book, so the index and annotated course books you build during preparation remain a working reference during engagements afterwards.

Exam Format & Structure

Duration

3 hours

Questions

82 questions

Passing Score

73 percent. GIAC states this applies to candidates receiving the exam version released on or after 12 July 2025.

Question Types

  • Multiple choice
  • CyberLive performance-based items answered inside a virtual machine using real penetration testing tools against real target systems

Delivery Method

One proctored exam, delivered remotely through ProctorU or onsite at a Pearson VUE test centre. Open book for hardcopy material only. Answers cannot be changed once submitted, though GIAC lets you skip between 10 and 15 questions and return to them, and the sitting includes 15 minutes of break time. The certification attempt is active for 120 days from activation.

Exam Domains & Topics

Planning, reconnaissance and scanning
not published

Covers the front half of an engagement: scoping and process discipline, open source intelligence gathering about a target organisation, network sweeps and host discovery, and port, operating system and service version scanning. GIAC's outcome statements ask for a process-oriented approach rather than tool familiarity alone, so scoping and rules of engagement appear as testable content.

Key Topics to Master:

  • Penetration test planning and process-oriented engagement methodology
  • Rules of engagement, scope definition and authorisation
  • Reconnaissance and open source intelligence about a target organisation
  • Scanning and host discovery technique selection
  • Port scanning, operating system fingerprinting and service version detection
  • Nmap options, timing templates and scripting engine usage
  • Masscan for large address space sweeps
Vulnerability scanning and analysis
not published

GIAC treats vulnerability scanning as its own objective, covering how to run scans and how to analyse the results rather than only how to launch a tool. Exam items test the interpretation step: separating a confirmed finding from a version-based guess, and deciding which reported issue is worth an exploitation attempt in a time-boxed engagement.

Key Topics to Master:

  • Configuring authenticated and unauthenticated vulnerability scans
  • Analysing scan results and validating findings
  • Distinguishing version-inferred findings from confirmed vulnerabilities
  • False positive identification and triage
  • Prioritising findings for exploitation within engagement scope
  • Mapping scan output to exploit availability
  • Reporting vulnerability findings with evidence
Exploitation and Metasploit
not published

Covers the exploitation phase end to end: the fundamental concepts, the Metasploit Framework at an intermediate configuration level, and the follow-on work of data exfiltration from a compromised host and pivoting deeper into the network. GIAC names intermediate Metasploit competence explicitly, which means module selection, option setting and payload choice rather than a canned exploit run.

Key Topics to Master:

  • Exploitation phase fundamentals and payload selection
  • Metasploit Framework at intermediate level: modules, options, payloads, handlers
  • Meterpreter usage and session management
  • Data exfiltration from compromised hosts
  • Pivoting and routing traffic through a compromised host
  • Client-side versus service-side exploitation decisions
  • Post-exploitation enumeration on Windows and Linux
Password attacks and hash cracking
not published

Four of GIAC's 16 objectives concern passwords, which makes this the heaviest concentration on the blueprint. It covers how credentials are stored and represented, how to obtain hashes and other representations, the categories of password attack and when each applies, and the additional methods used against hashes and authentication mechanisms.

Key Topics to Master:

  • Common password hash formats and password storage representations
  • Obtaining hashes from Windows, Linux and network captures
  • Credential harvesting with Mimikatz
  • Offline cracking with Hashcat, including mode selection per hash type
  • Password attack types: guessing, cracking, spraying and their defences
  • Pass-the-hash and other authentication-level attacks
  • Rule-based and mask-based cracking strategy
  • Password policy defences and how each attack works around them
Active Directory escalation, Kerberos and persistence
not published

Covers what happens after the first foothold in a Windows estate: Windows privilege escalation techniques, attacks against Active Directory and Kerberos specifically, lateral movement, and the persistence mechanisms an operator uses to keep access. GIAC splits Kerberos attacks and domain escalation into two separate objectives, which signals the depth expected.

Key Topics to Master:

  • Windows privilege escalation techniques
  • Kerberos protocol behaviour and attacks against it
  • Kerberoasting and AS-REP roasting
  • Golden ticket and silver ticket domain dominance attacks
  • Active Directory Certificate Services abuse
  • BloodHound attack path analysis
  • Lateral movement with Impacket tooling and SSH
  • Persistence mechanisms and their detection footprint
Command and control, and Azure attacks
not published

Covers the operator infrastructure side and the cloud identity plane. GIAC asks for an understanding of the design, application and use of command and control frameworks, then devotes two objectives to Azure: Entra ID implementation fundamentals with common attacks and authentication techniques, and Azure applications including federated and single sign-on environments.

Key Topics to Master:

  • Command and control design, application and common C2 frameworks
  • Sliver and comparable C2 implant and listener configuration
  • Beacon traffic profiles and evasion considerations
  • Entra ID implementation fundamentals
  • Common Entra ID attacks and Azure authentication techniques
  • Azure applications and attacks against them
  • Federated identity and single sign-on attack paths
  • Azure AD authentication protocols and token abuse

Recommended Study Plan

Week 1: Objective mapping, lab build and index framework
10-12 hours
  • 1Download the 16 GPEN exam certification objectives from giac.org and turn them into a tracking spreadsheet
  • 2Build a lab with a Windows domain controller, two domain-joined workstations and a Linux host
  • 3Set up your index template with columns for term, book, page and command syntax
  • 4Activate the certification attempt only when your study block starts, since the 120-day clock runs from activation
  • 5Review penetration test planning: scoping, rules of engagement and the process-oriented approach GIAC asks for
Week 2: Reconnaissance, scanning and host discovery
10-12 hours
  • 1Practise open source intelligence collection against a domain you own and document what each source yields
  • 2Run Nmap across your lab with different timing templates, scan types and NSE scripts, and record the syntax in your index
  • 3Compare Masscan and Nmap output on the same range and note the trade-offs
  • 4Learn operating system fingerprinting and service version detection accuracy limits
  • 5Index every scan flag by what it does rather than alphabetically by letter
Week 3: Vulnerability scanning and result analysis
8-10 hours
  • 1Run authenticated and unauthenticated scans against lab hosts and diff the findings
  • 2Practise validating three findings manually to confirm or reject each
  • 3Build a triage rule set for deciding which findings justify an exploitation attempt
  • 4Study how scanners infer vulnerabilities from banners and where that fails
  • 5Write index entries for scanner configuration options you would need under time pressure
Week 4: Exploitation fundamentals and Metasploit
12-14 hours
  • 1Work through Metasploit module selection, options, payload choice and handler configuration until it is automatic
  • 2Exploit at least five lab targets end to end and record each command sequence in the index
  • 3Practise Meterpreter session management, migration and post modules
  • 4Set up pivoting through a compromised host and reach a second network segment
  • 5Practise data exfiltration from a compromised host and note the detection footprint
Week 5: Password formats, hashes and harvesting
12-14 hours
  • 1Learn the common hash formats by sight: NTLM, NetNTLMv2, Kerberos ticket hashes, Linux shadow formats
  • 2Dump credentials with Mimikatz in your lab and understand what each command retrieves
  • 3Capture NetNTLMv2 hashes from the network and confirm how the relay path differs from cracking
  • 4Index the Hashcat mode number for every hash type in the objectives, this is the single highest-value index page
  • 5Practise identifying a hash type from a raw string without a tool
Week 6: Password attacks and advanced hash attacks
12-14 hours
  • 1Run Hashcat with dictionary, rule-based and mask attacks and compare recovery rates
  • 2Practise password spraying against your lab domain and observe the lockout behaviour
  • 3Study pass-the-hash and other authentication attacks that skip cracking entirely
  • 4Learn which defences stop which attack class and be able to state the mapping
  • 5Complete a timed drill: given a hash file, identify the format and launch the correct attack in under three minutes
Week 7: Kerberos and Active Directory attacks
12-14 hours
  • 1Learn the Kerberos exchange step by step and where each attack inserts itself
  • 2Practise Kerberoasting and AS-REP roasting in the lab and crack the resulting tickets
  • 3Run BloodHound against your domain and read the attack paths it returns
  • 4Study Active Directory Certificate Services abuse paths
  • 5Index every Impacket script by the action it performs, not by filename alone
Week 8: Domain escalation, persistence and evasion
12-14 hours
  • 1Practise Windows privilege escalation from a low-privilege shell using at least three different paths
  • 2Execute golden ticket and silver ticket attacks in the lab and understand what each forges
  • 3Study persistence mechanisms and the artefacts each leaves behind
  • 4Review AMSI and EDR bypass concepts at the level the objectives require
  • 5Move laterally with Impacket and SSH and document the command sequences
Week 9: Command and control frameworks
10-12 hours
  • 1Deploy a C2 framework such as Sliver in the lab, generate an implant and establish a session
  • 2Study listener configuration, beacon intervals and traffic profiles
  • 3Compare at least two C2 frameworks on design and operator workflow
  • 4Practise tasking an implant through a full post-exploitation sequence
  • 5Index C2 concepts by the operational question they answer
Week 10: Azure and Entra ID attacks
12-14 hours
  • 1Create a free Azure tenant and study Entra ID implementation fundamentals hands-on
  • 2Practise common Entra ID attacks and understand the authentication techniques behind each
  • 3Study federated and single sign-on environments and where the trust relationship can be abused
  • 4Learn the Azure AD authentication protocols named in the objectives and how tokens are issued and consumed
  • 5Complete the two Azure objectives fully, since they are the newest content and the least covered by older study material
Week 11: First practice test and index repair
10-12 hours
  • 1Sit your first GIAC practice test under exam conditions with only your printed index and books
  • 2Log every question where you searched rather than looked up, then add the missing index entries
  • 3Review the objective-level breakdown and rank your weakest four objectives
  • 4Re-drill those four objectives in the lab rather than by reading
  • 5Time yourself against the real budget: 82 questions in 180 minutes is about 2 minutes 12 seconds each
Week 12: Second practice test, CyberLive drilling and exam logistics
10-12 hours
  • 1Sit your second GIAC practice test and compare the objective breakdown with the first
  • 2Drill CyberLive-style tasks against the clock: given a live shell and a question, produce the answer in under six minutes
  • 3Finalise the index: verify page numbers, merge duplicates, put the Hashcat mode table and Nmap flag table on the front page
  • 4Confirm proctoring logistics, and for ProctorU run the equipment check on the machine you will use
  • 5Pack physical books, printed index and two forms of unexpired original ID, and remove anything resembling practice questions with answers

Ready to pass GIAC GPEN (Penetration Tester)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$475$237

Best Study Resources

GIAC GPEN certification page and exam objectives

Official blueprint

The authoritative list of the 16 exam certification objectives with outcome statements, plus the current question count, time limit and passing score with its effective date.

Free

SANS SEC560: Enterprise Penetration Testing

Training course

The affiliated SANS course: six sections, 30 hands-on labs, 36 CPE credits, six days instructor-led or 36 hours self-paced with four months of access, covering reconnaissance and scanning, initial access, post-exploitation, domain escalation and lateral movement, persistence and evasion, and a team-based capture the flag across target networks.

$8,780 listed for self-paced, varies by location and format

GIAC practice tests

Practice exam

The only questions written in GIAC's own item style, returning a breakdown by exam objective. Take the first mid-preparation and the second under full exam conditions with your index.

Two included with a certification attempt, additional tests $399

GIAC standalone certification attempt

Exam registration

Registers a 120-day attempt window with two practice tests included. A retake after a failure costs $899 and an attempt extension costs $479.

$999

Hack The Box and TryHackMe

Practice platform

Active Directory and Windows escalation paths on both platforms map closely to the Kerberos, domain escalation and lateral movement objectives. Use them for repetition rather than for content coverage.

Free tiers, paid subscriptions available

Metasploit Framework

Tool

GIAC names intermediate Metasploit competence as its own objective. Install it locally and work through module selection, payload choice and handler configuration rather than relying on course walkthroughs.

Free

BloodHound

Tool

Used for the Active Directory attack path content in the domain escalation objective. Run it against your own lab domain and read the paths it returns rather than reading about the tool.

Free community edition

Impacket

Tool collection

The lateral movement and Kerberos attack scripts referenced throughout the SEC560 material. Index each script by the action it performs, since that is how exam scenarios are phrased.

Free

Microsoft Azure free tier and Entra ID

Lab environment

Two GPEN objectives cover Entra ID and Azure application attacks. A free tenant lets you study authentication flows, federation and single sign-on trust relationships hands-on.

Free tier available

GIAC certification attempt delivery and retake policies

Official policy

Defines the 120-day attempt window, the 570-day maximum access period, the three-attempts-per-year limit and the retake waiting periods.

Free

Common Mistakes to Avoid

Indexing definitions instead of syntax. GPEN questions frequently need a specific command, flag or mode number, and a definition-only index cannot supply one.

Build command tables. One page for Nmap flags by purpose, one for Hashcat mode numbers by hash type, one for Impacket scripts by action, one for Metasploit module paths you use repeatedly. These pages will be the most consulted part of your index.

Skipping the two Azure objectives because your engagement work is on-premises. Entra ID fundamentals and attacks, plus Azure applications with federated and single sign-on environments, are two of GIAC's 16 objectives.

Spin up a free Azure tenant and spend a full week there. Older GPEN study material predates this content, so a book from a previous exam version leaves a measurable gap.

Preparing for the exam by reading rather than by running the tools. CyberLive items give you a live virtual machine and expect an answer from the system, with no options to eliminate.

Build a lab with a domain controller and workstations and run every attack in the objectives at least twice. Drill under a clock, since a CyberLive item that takes fifteen minutes destroys the pace budget for the multiple-choice items.

Assuming the passing score you read somewhere still applies. GIAC sets passing scores per exam version and publishes them with an effective date.

Check the GPEN page before you sit. The current standard is 73 percent for candidates receiving the exam version released on or after 12 July 2025.

Treating all four password objectives as one topic. GIAC splits password formats and hashes, attacking password hashes, password attacks, and advanced password attacks into separate objectives.

Study them as four distinct areas. Format recognition is a separate skill from cracking strategy, and pass-the-hash style authentication attacks are distinct from both. Practise identifying a hash type from a raw string with no tool.

Bringing digital copies of the course books. GIAC permits hardcopy only, so a tablet holding the same material you are allowed in print is prohibited.

Print or bring the physical books. Confirm before the day that everything you plan to use exists on paper, including your index, and remove anything that looks like practice test questions with answers.

Activating the certification attempt on purchase and losing weeks of the 120-day window.

Activation starts the clock, purchase does not. Activate at the start of your study block. An attempt extension costs $479 and adds 45 days; up to 10 can be bought per attempt, but never past the 570-day total access ceiling.

Losing track of the clock during CyberLive items. At 82 questions in 180 minutes the average budget is about 2 minutes 12 seconds, and a lab task can run five times that.

Check your position against the clock at question 20 and question 45. Set a hard personal cap on any single lab item and move on if you hit it, since one unanswered item costs less than twenty rushed ones.

Learning Metasploit only through canned course walkthroughs, then failing to configure a module under exam conditions. GIAC asks for intermediate-level use and configuration.

Practise from a blank prompt: find the module, set the options, choose the payload, configure the handler and get the session, against several different targets. Record the sequence in your index in the order you would actually type it.

Exam Day Tips

  • 1

    Bring two forms of original, unexpired identification for a Pearson VUE sitting. The primary needs your name, photo and signature; the secondary needs your name and either a photo or a signature. First and last names must match your registration, and a mismatch or an arrival more than 15 minutes late forfeits the appointment and costs a USD 175 seating fee.

  • 2

    Bring the printed books as well as the index. GIAC permits an armful of hardcopy course material and notes, and the SEC560 books contain command syntax you will not have memorised.

  • 3

    Leave every digital device and file outside, including tablets or laptops holding the same course material you are allowed to carry in print.

  • 4

    Strip anything that resembles printed practice test questions with answers out of your materials, which GIAC prohibits in the testing area.

  • 5

    Put the command tables on the front page of your index: Hashcat modes by hash type, Nmap flags by purpose, Impacket scripts by action. These are the lookups you will make under time pressure.

  • 6

    Expect CyberLive items in a live virtual machine with real tools and real targets. Decide in advance how long you will give any single lab item before moving on.

  • 7

    Use the skip allowance on lab items you cannot finish quickly. GIAC lets you defer between 10 and 15 questions and return to them, but a submitted answer cannot be changed and an unanswered question at time-up scores zero.

  • 8

    Budget the 15 minutes of break time built into the sitting, in one block or two. The clock resumes automatically at the 15-minute mark whether you are back or not.

  • 9

    Pace against 82 questions in 180 minutes, about 2 minutes 12 seconds per item. Check your position at question 20 and question 45 rather than at the end.

  • 10

    If you test through ProctorU, run the equipment check on the exact machine and network beforehand and be ready to show the proctor your stack of hardcopy books on camera.

  • 11

    You receive your score at the end of the session along with a breakdown by exam objective, which tells you precisely which of the 16 objectives to rebuild if you did not pass.

Career Paths & Salary Ranges

Penetration tester

Runs authorised network and Active Directory assessments against client or internal estates. The GPEN objectives follow the engagement lifecycle from planning and reconnaissance through domain escalation and reporting, which maps directly to consulting delivery.

$120k-$170k

Red team operator

Executes longer-running adversary emulation with persistence and evasion requirements. The command and control objective, plus the persistence, AMSI and EDR content in the affiliated SEC560 material, is the direct preparation.

$120k-$170k

Security consultant

Combines assessment delivery with advisory work for clients. GPEN's ANAB ISO/IEC 17024 accreditation is what federal and defence consulting contracts check for when they require an accredited credential.

$120k-$170k

Cloud penetration tester

Assesses identity and application layers in Azure and hybrid environments. Two GPEN objectives cover Entra ID attacks and Azure applications including federated and single sign-on environments.

$120k-$170k

Purple team or detection engineer

Builds detections against the techniques attackers actually use. Working through Kerberoasting, ticket forging, Certificate Services abuse and C2 beaconing from the attacker side produces the telemetry knowledge the defensive role needs.

$120k-$170k

Prerequisites & Requirements

  • There are no formal prerequisites for GPEN. GIAC does not require prior certifications, a degree, or documented work experience.
  • SANS SEC560 is the affiliated training but is not mandatory. Standalone certification attempts are sold without any training requirement.
  • Working familiarity with Windows, Active Directory and Linux command lines is effectively assumed by the objectives, since CyberLive items are answered from a live system.
  • Access to a practice lab with a Windows domain is close to essential given the weight of Kerberos, domain escalation and lateral movement content.
  • A certification attempt must be activated before use and is then valid for 120 days, with GIAC capping total access across attempts at 570 days.

Frequently Asked Questions

How much does the GPEN exam cost?

A standalone GIAC certification attempt costs USD 999, which includes two practice tests and a 120-day attempt window. Taking it with the affiliated SANS SEC560: Enterprise Penetration Testing course costs substantially more, since the course alone is listed at USD 8,780 for the self-paced format. A retake after a failure costs USD 899, an attempt extension costs USD 479, and an extra practice test costs USD 399.

What is the GPEN passing score?

73 percent. GIAC states this minimum applies to candidates who receive the exam version released on or after 12 July 2025. GIAC sets passing scores per exam version rather than permanently, so confirm the figure on the GPEN certification page before you sit rather than relying on a study guide or forum post.

How many questions are on the GPEN exam and how long is it?

82 questions in a three-hour limit, delivered as one proctored exam. That works out to roughly 2 minutes 12 seconds per question. Some items are CyberLive performance-based tasks answered inside a virtual machine using real penetration testing tools, and those take far longer than the average, so the pacing plan matters more here than on a purely multiple-choice exam.

Is the GPEN exam open book?

Yes, for hardcopy material only. GIAC permits an armful of printed books and notes including original course material, handwritten or printed notes, and an index you built. All digital material is prohibited, including PDF versions of books you are allowed to carry in print. Hardcopy that has the appearance of practice test questions with answers is also prohibited.

What are CyberLive questions on the GPEN?

CyberLive is GIAC's performance-based format, which places you in a virtual machine loaded with real security tools, real code and real target systems and requires you to produce the answer from the live environment. There are no answer options to eliminate. Preparation means running the attacks yourself in a lab: scanning, cracking, escalating and moving laterally under a clock.

What happens if I fail the GPEN?

You may buy a retake for USD 899, and GIAC imposes a 30-day waiting period after any failure. Buying the retake extends your final exam deadline by 60 days, the 30-day wait included. If a waiver of that period is approved, a mandatory 14-day waiting period still applies and cannot be waived. Retakes must be purchased within 30 days of the attempt deadline or you must buy a new certification attempt. Candidates may attempt an exam up to three times per year, and after three failed attempts the attempt closes and you wait a year unless GIAC approves a waiver supported by documentation of at least 30 hours of additional training.

How long do GPEN results take?

You receive your score at the end of the exam session, along with a breakdown of performance by exam objective. There is no waiting period for official results as there is with ISC2 exams. The objective breakdown uses the same format as GIAC practice test reports, so if you did not pass it tells you exactly which of the 16 objectives to rebuild.

Can I take the GPEN exam online at home?

Yes. GIAC offers remote proctoring through ProctorU as well as onsite delivery at Pearson VUE test centres. Remote candidates still bring physical books and a printed index, and the proctor inspects them on camera before the exam starts. GIAC cannot deliver exams into countries and regions covered by US export sanctions, so check its policy pages before booking if you are testing outside your home country.

What ID do I need for the GPEN exam?

Two forms of original, unexpired personal identification for a Pearson VUE sitting, issued by the country you are testing in, or a passport from your country of citizenship as the primary document plus a second ID. The primary must carry your first and last name, your photo and your signature; the secondary must carry your name and either a photo or a signature. Photocopies and digital images are not accepted, and the first and last names must match the names on your exam appointment. A mismatch at the centre means no exam and a USD 175 seating fee to rebook.

How long is GPEN valid and how do I renew it?

Four years. Renewal requires 36 CPE credits earned during the active four-year period plus a certification maintenance fee of USD 499, and renewal registration opens two years before the expiration date. If you renew more than one GIAC certification within a two-year window, the first costs USD 499 and each additional renewal in that window costs USD 249. Retaking the current version of the exam is an accepted alternative to submitting CPEs, and the maintenance fee still applies.

How does GPEN compare to OSCP?

OSCP from OffSec gives you 23 hours 45 minutes on live machines and a further 24 hours to submit the report, with no multiple-choice component and no open book index. GPEN is a 3-hour, 82-question proctored exam that combines multiple choice with CyberLive lab items and permits hardcopy reference material. GPEN covers Azure and Entra ID attacks and command and control frameworks as named objectives. Employers often treat OSCP as evidence of exploitation stamina and GPEN as evidence of methodology breadth, and many testers hold both.

How does GPEN compare to CompTIA PenTest+?

PenTest+ is an early-career certification with a 165-minute exam, closed book, and a scaled score. GPEN is open book, includes live lab items, and reaches into Kerberos ticket attacks, Active Directory Certificate Services abuse, C2 framework operation and Entra ID attacks. PenTest+ costs a few hundred dollars against USD 999 for a standalone GIAC attempt. Candidates entering penetration testing often take PenTest+ first and GPEN once they have engagement experience.

Do I need to take SANS SEC560 before the GPEN?

No. GIAC sells standalone certification attempts with no training requirement. The practical consideration is the open-book format: the SEC560 course books are what most candidates index and consult during the exam, so self-study candidates need to assemble and index an equivalent printed reference of their own. GIAC reports that the average certified individual spends 55 hours of study beyond any classroom training, and that someone meeting the material for the first time can need three times that. The 120-day attempt window is the four months you have to fit it into.

How long is a GPEN certification attempt valid before I have to sit it?

120 days from the date of activation, which is a separate step from purchase. GIAC caps total access across all attempts for a certification at 570 days. If you run out of time an attempt extension costs USD 479 and adds 45 days. You cannot hold two active attempts for the same certification simultaneously, and GIAC removes duplicates without refund.

Are accommodations available for the GPEN exam?

Yes. GIAC operates an accommodations process, listed as its own category in the GIAC FAQ, for candidates who need adjustments such as additional time. Requests go to GIAC before you schedule rather than to the proctor on the day, so submit documentation well ahead of your intended exam date.

What is the GPEN pass rate?

GIAC does not publish pass rates for its certifications. Figures near 70 percent circulate in study communities but they are self-reported rather than vendor data. The two practice tests bundled with a certification attempt are the reliable calibration: take the second under real conditions with only the index and books you intend to carry, and treat the objective breakdown as your gap list.

Does GPEN count toward the DoD 8140 workforce framework?

GPEN is listed among GIAC's ANAB ISO/IEC 17024 accredited certifications, which is the baseline 8140 requires. DoD 8140 qualification itself is granted per DCWF work role and proficiency level rather than to a certification outright, so check the role you are hiring into against GIAC's current mapping at giac.org/workforce-development/dodd-8140 before treating it as settled.

How much lab time do I need to prepare for GPEN?

Enough to run every attack in the 16 objectives at least twice from a blank prompt. A minimum practical lab is a Windows domain controller, two domain-joined workstations, a Linux host and a free Azure tenant for the Entra ID objectives. The study plan on this page allocates roughly half its 130 hours to hands-on work, because CyberLive items are graded on what you can produce from a live system rather than what you can recognise.

50% OFF

Pass GIAC GPEN (Penetration Tester), Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $238
$237
$47550% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund