The GPEN certification is GIAC's penetration testing credential, and in 2026 it costs $999 for a certification attempt, runs 82 questions in 3 hours, and requires 73% to pass. It is open book, so you can bring printed notes, and part of it is performance based, so you will be dropped into a virtual machine with real tools and asked to produce an answer rather than pick one.
That combination catches people out. Candidates who prepare for GPEN the way they prepared for Security+ tend to fail, because a multiple-choice revision routine does not build the muscle memory a CyberLive question demands. This guide covers the format, the real costs, the 16 topic areas, and an 8-week study plan built around the two things that actually decide the result: hands-on repetition and a usable index.
What the GPEN Certification Actually Is
GPEN stands for GIAC Penetration Tester. It validates that you can plan and run a penetration test against a network, escalate privileges once you have a foothold, and move through an Active Directory or Entra ID environment the way an attacker would.
It maps to SANS SEC560: Enterprise Penetration Testing, a six-section course with more than 30 hands-on labs that runs from initial reconnaissance through to domain dominance. You do not have to take SEC560 to sit GPEN. GIAC sells a certification attempt on its own, and plenty of people self-study using their own lab.
The certification is valid for four years, after which renewal costs $499 and requires CPE credits submitted before your expiry date.
Exam Tip: GIAC lets you buy a certification attempt without training, but the attempt includes fewer practice tests than a bundled course purchase. Check what your purchase includes before you plan your revision, because the practice tests are the only realistic gauge of whether you are ready.
GPEN Exam Format, Pass Mark and Cost in 2026
Here are the numbers, taken from GIAC's own certification and pricing pages.
| Item | Detail |
|---|---|
| Questions | 82 |
| Time limit | 3 hours |
| Minimum passing score | 73% (for exam versions released on or after 12 July 2025) |
| Format | Proctored, open book, with CyberLive performance-based questions |
| Certification attempt | $999 |
| Retake | $899 |
| Additional practice exam | $399 |
| Validity | 4 years |
| Renewal | $499 |
Three hours for 82 questions works out at roughly 2 minutes 12 seconds each, but that average is misleading. Knowledge questions take 30 to 60 seconds. A CyberLive question where you have to run a tool, read the output and interpret it can take 5 minutes or more. Your time budget has to account for that split, which is the single most common reason prepared candidates run out of clock.
The 73% pass mark means you can afford to lose about 22 questions. That is a workable margin, but not a generous one once a handful of CyberLive items eat your time.
What CyberLive Questions Mean for Your Prep
CyberLive is GIAC's performance-based question format. Instead of describing a scenario and offering four options, the exam gives you a virtual machine loaded with real security tools and asks you to do something in it.
The practical consequence is simple. You cannot index your way through a CyberLive question. If you have never run the tool, you will not produce the answer in the time available, no matter how good your notes are.
Build a lab and use it weekly. A domain controller, a member server and a couple of Windows and Linux clients on a laptop with 16GB of RAM is enough. Practise until the following are automatic:
- Nmap scanning and reading the output without thinking about the flags
- Responder and password capture on a local network
- Hashcat against captured hashes, including choosing the right mode
- Metasploit module selection, configuration and post-exploitation
- BloodHound collection and reading an attack path
- Kerberoasting end to end, from request to cracked service account
The 16 GPEN Topic Areas, Grouped Into Five Study Blocks
GIAC publishes 16 topic areas for GPEN. Studying them in the published order is inefficient because several overlap heavily. Grouping them into five blocks maps better to how an actual test runs.
| Block | GIAC topic areas it covers |
|---|---|
| Planning and reconnaissance | Penetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning |
| Passwords and hashes | Password Attacks, Advanced Password Attacks, Password Formats and Hashes, Attacking Password Hashes |
| Exploitation | Exploitation Fundamentals, Metasploit, Escalation and Exploitation |
| Active Directory | Kerberos Attacks, Domain Escalation and Persistence Attacks, Command and Control (C2) |
| Cloud and identity | Azure Overview, Attacks and AD Integration, Azure Applications and Attack Strategies |
The Azure and Entra ID material is the block candidates most often underestimate. It is two of the 16 topic areas, and it is the newest content on the exam, so older study notes and second-hand indexes tend to be thin there.
An 8-Week GPEN Study Plan
This assumes 8 to 10 hours a week. If you have taken SEC560, you can compress it to six weeks by halving the first two blocks.
Week 1: Planning and reconnaissance. Cover scoping, rules of engagement and the legal and contractual side. Learn OSINT sources properly. Start your index this week, not later.
Week 2: Scanning. Nmap in depth, including timing, scripts and output formats. Masscan for scale. Vulnerability scanning and, more importantly, how to tell a real finding from scanner noise.
Week 3: Passwords and hashes. Hash formats first, then attacks. Know which mode Hashcat needs for NTLM, NetNTLMv2 and Kerberos tickets without looking it up. Run Responder in your lab and capture something real.
Week 4: Exploitation fundamentals and Metasploit. Work through module selection, payload choice and the difference between a shell and a Meterpreter session. Practise pivoting.
Week 5: Active Directory attacks. Kerberoasting, AS-REP roasting, ADCS abuse and BloodHound. This block carries the most exam weight relative to how long it takes to learn, so give it the full week.
Week 6: Persistence, C2 and Azure. Golden and Silver tickets, domain dominance techniques, then Entra ID attack paths and how they connect back to on-premises AD.
Week 7: First practice exam and index repair. Sit a full timed practice test. Every question you had to hunt for is an index failure, not a knowledge failure. Fix those entries the same day.
Week 8: Second practice exam and lab drills. Sit the second practice test. Spend the rest of the week repeating CyberLive-style tasks in your lab under a timer. Book the real exam for the end of this week while the material is fresh.
Exam Tip: Treat a practice test score below 80% as a signal to delay, not to cram. GIAC practice tests are a reasonable predictor, and a 73% pass mark leaves too little room to gamble on a bad day.
Building the Index That Passes the Exam
GIAC allows printed books, printed notes and a printed index. No electronic devices, and no hardcopy material that looks like practice questions with answers.
A good GPEN index is not a summary of the course. It is a lookup table that gets you to a page number in under 15 seconds.
- One row per term, with the book, section and page number
- Sorted alphabetically, not by topic
- Colour coded by block, so your hand goes to the right section before your eyes do
- Built as you study, week by week, because an index written in week 8 teaches you nothing
Include command syntax you know you will forget, particularly Hashcat modes, Nmap script names and Metasploit module paths. Leave out anything you can already recall instantly, because every unnecessary row slows down the rows that matter.
GPEN vs OSCP: Which One Should You Take?
Both are respected. They test different things and suit different people.
| GPEN | OSCP | |
|---|---|---|
| Format | 3-hour proctored exam, open book, CyberLive tasks | 24-hour hands-on lab exam plus report |
| Pass mark | 73% | Points based across lab machines |
| Emphasis | Methodology, Active Directory, Azure and Entra ID | Exploitation and lab persistence |
| Cost | $999 certification attempt | Bundled with course access |
GPEN suits people who want structured methodology coverage, work in enterprise environments with Active Directory and Azure, or need a credential recognised on government and defence frameworks. OSCP suits people who want to prove endurance and raw exploitation skill over a long practical exam.
If you are choosing a first pen-testing certification and the price is a barrier, CompTIA PenTest+ covers similar methodology ground at a fraction of the cost. Our PenTest+ vs CEH comparison covers that decision, and if you already hold OSCP, what to take after OSCP covers where GPEN sits against OSEP, CRTO and CRTP.
Frequently Asked Questions
How much does it cost to get the GIAC GPEN certification?
A GPEN certification attempt costs $999 if you buy it without training. A retake is $899 and an additional practice exam is $399. Renewal is $499 every four years. Buying the attempt bundled with SANS SEC560 costs considerably more but includes the course and its labs.
How hard is the GPEN exam?
Harder than the 73% pass mark suggests, because of the format rather than the content. The knowledge questions are fair for anyone who has worked through the material, but the CyberLive tasks require you to have actually used the tools. Candidates who study from notes alone and never build a lab are the group that most often fails.
What is a GPEN certification?
GPEN is the GIAC Penetration Tester certification. It validates network penetration testing skills across reconnaissance, exploitation, password attacks, Active Directory escalation and Azure or Entra ID attacks. It maps to the SANS SEC560 course and is valid for four years.
Is GPEN better than OSCP?
Neither is better in general. GPEN tests methodology and enterprise Active Directory and cloud attack paths in a 3-hour open book exam. OSCP tests hands-on exploitation over a 24-hour lab exam with a written report. Employers hiring for enterprise internal testing tend to recognise GPEN; employers hiring for offensive consultancy work often ask for OSCP.
Do I need to take SANS SEC560 to sit GPEN?
No. GIAC sells certification attempts separately from training, and there are no formal prerequisites. Self-study is realistic if you build a lab, but you will need to source your own reference material, which also means building your index from scratch.
Ready to Start Practising?
The gap between reading about Kerberoasting and doing it under a 3-hour clock is where GPEN candidates lose marks. Timed practice questions close that gap, because they train recall speed and show you which index entries are missing before the real exam does.
CertCrush has practice exams, study guides and performance-based questions across the penetration testing and security certification paths, including CompTIA PenTest+ for candidates building up to GPEN. If you are working through the wider GIAC catalogue, our GCIH 8-week study plan uses the same index-first approach.
Create a free CertCrush account and start practising today.
