Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Red Team Professional

GIAC Red Team Professional (GRTP)

The GIAC Red Team Professional (GRTP) certification validates your ability to conduct end-to-end Red Team engagements, from building an adversary emulation plan to establishing command-and-control infrastructure and emulating adversary tactics, techniques, and procedures (TTPs). Designed for security professionals responsible for offensive operations, this hands-on, performance-based certification proves you can improve your organization's security by thinking and operating like a real adversary.

Exam formatCyberLive hands-on exam (performance-based)
Duration180 minutes
DeliveryGIAC (via ProctorU for remote, Pearson VUE for onsite)
Passing score76%
Free questions443

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Red Team Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

3domains
10objectives
97concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Red Team Professional (GRTP) certification validates an individual's ability to conduct end-to-end Red Team engagements. GRTP certification holders have the expertise to build an adversary emulation plan, establish command-and-control (C2) infrastructure, and emulate adversary tactics, techniques, and procedures (TTPs) to assist in improving overall security.

Delivered through GIAC's CyberLive hands-on exam format, GRTP replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. Candidates work with full-scale virtual machines, real security tools, and authentic code to prove they can apply offensive tradecraft in real-world scenarios. The certification covers the full Red Team lifecycle — from planning and reconnaissance to gaining access, moving laterally, exfiltrating data, and producing an engagement report.

Who it’s for

The GRTP certification is designed for security professionals responsible for Red Team engagements, including penetration testers, Red Team members, and Blue Team members who want to better understand offensive methodologies, tools, and TTPs. It is also valuable for auditors, defenders, and forensic specialists seeking deeper insight into offensive operations, as well as information security managers who participate in Red Team engagements.

Recommended experience

Practical work experience in offensive security, penetration testing, or Red Team operations is recommended. GIAC also suggests SANS-aligned training, such as SEC565: Red Team Operations and Adversary Emulation, to prepare for the exam. Hands-on experience with penetration testing tools and methodologies; Familiarity with Active Directory environments and common attack techniques; Understanding of network protocols, reconnaissance, and exploitation; Experience with command-and-control frameworks such as Empire or Cobalt Strike

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Red Team Operations and Infrastructure
  • Adversary Emulation Fundamentals
  • Red Team Engagement Planning and Reporting
  • Creating the Attack infrastructure
  • Command and Control infrastructure
4 objectives · 167 free questions · 35 pages
Initial Access and Discovery
  • Gaining Access
  • Discovery and Enumeration
  • Enumerating and Attacking Privileges
3 objectives · 132 free questions · 28 pages
Active Directory Attacks and Post-Exploitation
  • Attacking Active Directory
  • Leveraging the Domain
  • Persistence and Exfiltration
3 objectives · 144 free questions · 30 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Red Team Professional
Exam formatCyberLive hands-on exam (performance-based)
Duration180 minutes
Questions82 questions
Passing score76%
DeliveryGIAC (via ProctorU for remote, Pearson VUE for onsite)
LanguagesEnglish
Certification levelProfessional
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Red Team Professional

GIAC Red Team Professional badgeCredential earnedGIAC Red Team Professional Professional level certification
Renewal and maintenance

GIAC certifications must be renewed every four years. Renew by earning 36 Continuing Professional Education (CPE) credits or by retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC (via ProctorU for remote, Pearson VUE for onsite), GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GRTP exam relate to other GIAC offensive security certifications?

GRTP is a Practitioner-level certification focused specifically on Red Team operations. It complements other offensive certifications like GIAC Experienced Penetration Tester (GX-PT) and GIAC Penetration Tester (GPEN), but is distinct in its emphasis on full-scope adversary emulation and C2 infrastructure.

Is the GRTP exam hands-on?

Yes. GRTP uses GIAC's CyberLive format, which replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. You will work with virtual machines, real security tools, and authentic code to demonstrate your skills.

What is the retake policy if I fail the GRTP exam?

GIAC allows candidates to retake a failed exam after a waiting period. Specific retake policies, including waiting times and any limits on attempts, are detailed in your GIAC account and the GIAC retake policy.

Can I earn CPE credits for the GRTP certification?

Yes. You can earn CPE credits through various activities, including SANS training, conferences, and approved events. These CPEs can be used to renew your GRTP certification.

What job roles does the GRTP certification map to?

GRTP is designed for security professionals responsible for Red Team engagements, including penetration testers, Red Team members, Blue Team members, auditors, defenders, and forensic specialists who want to understand offensive methodologies.

Is there a lower-level certification required before taking GRTP?

No. GIAC does not require any prerequisite certifications for GRTP. However, practical experience and SANS training are recommended to ensure success.

How soon will I receive my exam results?

GIAC typically provides score reports immediately after the exam for CyberLive exams. Detailed score breakdowns may be available in your GIAC account.

Are there any regional restrictions for taking the GRTP exam?

GIAC exams are available globally through remote proctoring via ProctorU and onsite proctoring through Pearson VUE. Regional availability may vary, so check your GIAC account for options in your area.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 443 questions, free, no account needed.