Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Penetration Tester (GPEN)

The GIAC Penetration Tester (GPEN) certification validates your ability to conduct professional penetration tests using effective techniques and methodologies. It is designed for security professionals who assess networks and systems, including penetration testers, ethical hackers, and red team members. Earning GPEN proves you can perform detailed reconnaissance, execute exploits, and deliver rigorous, actionable reporting.

Exam formatCyberLive hands-on performance-based
Duration180 minutes
DeliveryGIAC
Passing score73%
Free questions642

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Penetration Tester (GPEN) proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
16objectives
145concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Penetration Tester (GPEN) certification validates a practitioner's ability to properly conduct a penetration test employing effective techniques and methodologies. GPEN certification holders have the knowledge and skills to conduct exploits, engage in detailed environmental reconnaissance, and apply a process-oriented approach to penetration testing projects.

The exam covers comprehensive penetration test planning, scoping, and reconnaissance; in-depth scanning and exploitation, post-exploitation, and pivoting; Azure overview, integration, and attacks; and in-depth password attacks. GPEN is a hands-on, performance-based certification delivered through GIAC's CyberLive format, which uses realistic lab environments to validate real-world capability.

Who it’s for

The GPEN certification is for security personnel responsible for assessing network and systems, including penetration testers, ethical hackers, red team members, and blue team members. It is also valuable for defenders, auditors, and forensic specialists who want to better understand offensive tactics. Candidates typically have hands-on experience with network scanning, exploitation tools, and penetration testing methodologies, and are comfortable working in Linux and Windows environments.

Recommended experience

Practical work experience in penetration testing or related security roles is recommended to ensure mastery of the skills necessary for certification. Hands-on experience with network scanning and exploitation tools; Understanding of penetration testing methodologies and reporting; Familiarity with password attacks and Azure security concepts; Experience with command-line interfaces and virtual machines

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Penetration Testing Foundations
  • Penetration Test Planning
  • Reconnaissance
  • Scanning and Host Discovery
  • Vulnerability Scanning
4 objectives · 157 free questions · 33 pages
Exploitation and Post-Exploitation
  • Exploitation Fundamentals
  • Escalation and Exploitation
  • Metasploit
  • Command and Control (C2)
4 objectives · 141 free questions · 29 pages
Password Attacks and Credential Attacks
  • Password Formats and Hashes
  • Password Attacks
  • Attacking Password Hashes
  • Advanced Password Attacks
4 objectives · 178 free questions · 38 pages
Active Directory Attacks
  • Kerberos Attacks
  • Domain Escalation and Persistence Attacks
2 objectives · 96 free questions · 20 pages
Cloud and Azure Attacks
  • Azure Overview, Attacks, and AD Integration
  • Azure Applications and Attack Strategies
2 objectives · 70 free questions · 15 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Penetration Tester (GPEN)
Exam formatCyberLive hands-on performance-based
Duration180 minutes
Questions82 questions
Passing score73%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Penetration Tester (GPEN)

GIAC Penetration Tester (GPEN) badgeCredential earnedGIAC Penetration Tester (GPEN) Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 Continuing Professional Education (CPE) credits or by retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does GPEN relate to the GIAC Experienced Penetration Tester (GX-PT) certification?

GX-PT is a higher-level, Applied Knowledge certification for seasoned penetration testers. GPEN is a Practitioner-level certification that validates core penetration testing skills. Earning GPEN can be a stepping stone toward GX-PT, but GX-PT is not a successor that automatically renews GPEN.

Is the GPEN exam hands-on?

Yes. The GPEN exam uses GIAC's CyberLive format, which replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. You work with virtual machines, real security tools, and authentic code to demonstrate your skills.

What is the retake policy if I fail the GPEN exam?

GIAC allows candidates to retake the exam after a waiting period. Specific retake policies, including waiting periods between attempts, are detailed in the GIAC terms and conditions. Check your GIAC account for the exact policy that applies to your attempt.

Can I schedule, reschedule, or cancel my GPEN exam appointment?

Yes. After your certification attempt is activated in your GIAC account, you can schedule your proctored exam through the GIAC portal. Rescheduling and cancellation policies are governed by GIAC's terms and the proctoring provider (ProctorU or PearsonVUE).

What job roles does the GPEN certification map to?

GPEN is designed for security personnel responsible for assessing networks and systems, including penetration testers, ethical hackers, red team members, blue team members, and defenders, auditors, and forensic specialists who want to better understand offensive tactics.

Can I earn CPE credits for other certifications toward GPEN renewal?

Yes. GIAC allows CPE credits for earning ISO-17024-accredited certifications (such as CISSP, CCNP, CEH, Security+) and other approved activities. You can submit these credits through your GIAC dashboard for renewal.

Are there regional differences in GPEN exam delivery?

GIAC exams are available worldwide through remote proctoring via ProctorU and onsite proctoring via PearsonVUE. Regional availability may vary, and candidates should check the GIAC website for the latest delivery options in their area.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 642 questions, free, no account needed.