Back to blog
Study Tips9 min read

GPEN Certification in 2026: Cost, 73% Pass Mark and an 8-Week Study Plan

The GIAC GPEN certification costs $999, runs 82 questions in 3 hours, and needs 73% to pass. Here is what CyberLive questions actually involve, the 16 topic areas, and an 8-week study plan with an index strategy that works.

Tom Ashford

Tom Ashford · Security Certifications Lead

5 September 2026

The GPEN certification is GIAC's penetration testing credential, and in 2026 it costs $999 for a certification attempt, runs 82 questions in 3 hours, and requires 73% to pass. It is open book, so you can bring printed notes, and part of it is performance based, so you will be dropped into a virtual machine with real tools and asked to produce an answer rather than pick one.

That combination catches people out. Candidates who prepare for GPEN the way they prepared for Security+ tend to fail, because a multiple-choice revision routine does not build the muscle memory a CyberLive question demands. This guide covers the format, the real costs, the 16 topic areas, and an 8-week study plan built around the two things that actually decide the result: hands-on repetition and a usable index.

What the GPEN Certification Actually Is

GPEN stands for GIAC Penetration Tester. It validates that you can plan and run a penetration test against a network, escalate privileges once you have a foothold, and move through an Active Directory or Entra ID environment the way an attacker would.

It maps to SANS SEC560: Enterprise Penetration Testing, a six-section course with more than 30 hands-on labs that runs from initial reconnaissance through to domain dominance. You do not have to take SEC560 to sit GPEN. GIAC sells a certification attempt on its own, and plenty of people self-study using their own lab.

The certification is valid for four years, after which renewal costs $499 and requires CPE credits submitted before your expiry date.

Exam Tip: GIAC lets you buy a certification attempt without training, but the attempt includes fewer practice tests than a bundled course purchase. Check what your purchase includes before you plan your revision, because the practice tests are the only realistic gauge of whether you are ready.

GPEN Exam Format, Pass Mark and Cost in 2026

Here are the numbers, taken from GIAC's own certification and pricing pages.

ItemDetail
Questions82
Time limit3 hours
Minimum passing score73% (for exam versions released on or after 12 July 2025)
FormatProctored, open book, with CyberLive performance-based questions
Certification attempt$999
Retake$899
Additional practice exam$399
Validity4 years
Renewal$499

Three hours for 82 questions works out at roughly 2 minutes 12 seconds each, but that average is misleading. Knowledge questions take 30 to 60 seconds. A CyberLive question where you have to run a tool, read the output and interpret it can take 5 minutes or more. Your time budget has to account for that split, which is the single most common reason prepared candidates run out of clock.

The 73% pass mark means you can afford to lose about 22 questions. That is a workable margin, but not a generous one once a handful of CyberLive items eat your time.

What CyberLive Questions Mean for Your Prep

CyberLive is GIAC's performance-based question format. Instead of describing a scenario and offering four options, the exam gives you a virtual machine loaded with real security tools and asks you to do something in it.

The practical consequence is simple. You cannot index your way through a CyberLive question. If you have never run the tool, you will not produce the answer in the time available, no matter how good your notes are.

Build a lab and use it weekly. A domain controller, a member server and a couple of Windows and Linux clients on a laptop with 16GB of RAM is enough. Practise until the following are automatic:

  • Nmap scanning and reading the output without thinking about the flags
  • Responder and password capture on a local network
  • Hashcat against captured hashes, including choosing the right mode
  • Metasploit module selection, configuration and post-exploitation
  • BloodHound collection and reading an attack path
  • Kerberoasting end to end, from request to cracked service account

The 16 GPEN Topic Areas, Grouped Into Five Study Blocks

GIAC publishes 16 topic areas for GPEN. Studying them in the published order is inefficient because several overlap heavily. Grouping them into five blocks maps better to how an actual test runs.

BlockGIAC topic areas it covers
Planning and reconnaissancePenetration Test Planning, Reconnaissance, Scanning and Host Discovery, Vulnerability Scanning
Passwords and hashesPassword Attacks, Advanced Password Attacks, Password Formats and Hashes, Attacking Password Hashes
ExploitationExploitation Fundamentals, Metasploit, Escalation and Exploitation
Active DirectoryKerberos Attacks, Domain Escalation and Persistence Attacks, Command and Control (C2)
Cloud and identityAzure Overview, Attacks and AD Integration, Azure Applications and Attack Strategies

The Azure and Entra ID material is the block candidates most often underestimate. It is two of the 16 topic areas, and it is the newest content on the exam, so older study notes and second-hand indexes tend to be thin there.

An 8-Week GPEN Study Plan

This assumes 8 to 10 hours a week. If you have taken SEC560, you can compress it to six weeks by halving the first two blocks.

Week 1: Planning and reconnaissance. Cover scoping, rules of engagement and the legal and contractual side. Learn OSINT sources properly. Start your index this week, not later.

Week 2: Scanning. Nmap in depth, including timing, scripts and output formats. Masscan for scale. Vulnerability scanning and, more importantly, how to tell a real finding from scanner noise.

Week 3: Passwords and hashes. Hash formats first, then attacks. Know which mode Hashcat needs for NTLM, NetNTLMv2 and Kerberos tickets without looking it up. Run Responder in your lab and capture something real.

Week 4: Exploitation fundamentals and Metasploit. Work through module selection, payload choice and the difference between a shell and a Meterpreter session. Practise pivoting.

Week 5: Active Directory attacks. Kerberoasting, AS-REP roasting, ADCS abuse and BloodHound. This block carries the most exam weight relative to how long it takes to learn, so give it the full week.

Week 6: Persistence, C2 and Azure. Golden and Silver tickets, domain dominance techniques, then Entra ID attack paths and how they connect back to on-premises AD.

Week 7: First practice exam and index repair. Sit a full timed practice test. Every question you had to hunt for is an index failure, not a knowledge failure. Fix those entries the same day.

Week 8: Second practice exam and lab drills. Sit the second practice test. Spend the rest of the week repeating CyberLive-style tasks in your lab under a timer. Book the real exam for the end of this week while the material is fresh.

Exam Tip: Treat a practice test score below 80% as a signal to delay, not to cram. GIAC practice tests are a reasonable predictor, and a 73% pass mark leaves too little room to gamble on a bad day.

Building the Index That Passes the Exam

GIAC allows printed books, printed notes and a printed index. No electronic devices, and no hardcopy material that looks like practice questions with answers.

A good GPEN index is not a summary of the course. It is a lookup table that gets you to a page number in under 15 seconds.

  • One row per term, with the book, section and page number
  • Sorted alphabetically, not by topic
  • Colour coded by block, so your hand goes to the right section before your eyes do
  • Built as you study, week by week, because an index written in week 8 teaches you nothing

Include command syntax you know you will forget, particularly Hashcat modes, Nmap script names and Metasploit module paths. Leave out anything you can already recall instantly, because every unnecessary row slows down the rows that matter.

GPEN vs OSCP: Which One Should You Take?

Both are respected. They test different things and suit different people.

GPENOSCP
Format3-hour proctored exam, open book, CyberLive tasks24-hour hands-on lab exam plus report
Pass mark73%Points based across lab machines
EmphasisMethodology, Active Directory, Azure and Entra IDExploitation and lab persistence
Cost$999 certification attemptBundled with course access

GPEN suits people who want structured methodology coverage, work in enterprise environments with Active Directory and Azure, or need a credential recognised on government and defence frameworks. OSCP suits people who want to prove endurance and raw exploitation skill over a long practical exam.

If you are choosing a first pen-testing certification and the price is a barrier, CompTIA PenTest+ covers similar methodology ground at a fraction of the cost. Our PenTest+ vs CEH comparison covers that decision, and if you already hold OSCP, what to take after OSCP covers where GPEN sits against OSEP, CRTO and CRTP.

Frequently Asked Questions

How much does it cost to get the GIAC GPEN certification?

A GPEN certification attempt costs $999 if you buy it without training. A retake is $899 and an additional practice exam is $399. Renewal is $499 every four years. Buying the attempt bundled with SANS SEC560 costs considerably more but includes the course and its labs.

How hard is the GPEN exam?

Harder than the 73% pass mark suggests, because of the format rather than the content. The knowledge questions are fair for anyone who has worked through the material, but the CyberLive tasks require you to have actually used the tools. Candidates who study from notes alone and never build a lab are the group that most often fails.

What is a GPEN certification?

GPEN is the GIAC Penetration Tester certification. It validates network penetration testing skills across reconnaissance, exploitation, password attacks, Active Directory escalation and Azure or Entra ID attacks. It maps to the SANS SEC560 course and is valid for four years.

Is GPEN better than OSCP?

Neither is better in general. GPEN tests methodology and enterprise Active Directory and cloud attack paths in a 3-hour open book exam. OSCP tests hands-on exploitation over a 24-hour lab exam with a written report. Employers hiring for enterprise internal testing tend to recognise GPEN; employers hiring for offensive consultancy work often ask for OSCP.

Do I need to take SANS SEC560 to sit GPEN?

No. GIAC sells certification attempts separately from training, and there are no formal prerequisites. Self-study is realistic if you build a lab, but you will need to source your own reference material, which also means building your index from scratch.

Ready to Start Practising?

The gap between reading about Kerberoasting and doing it under a 3-hour clock is where GPEN candidates lose marks. Timed practice questions close that gap, because they train recall speed and show you which index entries are missing before the real exam does.

CertCrush has practice exams, study guides and performance-based questions across the penetration testing and security certification paths, including CompTIA PenTest+ for candidates building up to GPEN. If you are working through the wider GIAC catalogue, our GCIH 8-week study plan uses the same index-first approach.

Create a free CertCrush account and start practising today.

GPENGIACpenetration testingstudy planexam prepCyberLiveSANS SEC560
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a GPEN practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.