GPEN (GIAC Penetration Tester) (GPEN) Exam Blueprint

GPEN

115Questions
300 minDuration
74/percentagePassing Score
$949Price
4 yearsValid For
1Languages
Practice GPEN (GIAC Penetration Tester) on QuizForge

Exam Domains

1 Comprehensive Pen Test Planning, Scoping, and Recon Weight not published
  • 1.1Penetration Test Planning
    The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting.
2 In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting Weight not published
  • 2.1Scanning and Host Discovery
    The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results.
  • 2.2Exploitation Fundamentals
    The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest.
  • 2.3Escalation and Exploitation
    The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network.
3 Azure Overview, Integration, and Attacks, and In-Depth Password Attacks Weight not published
  • 3.1Azure Overview, Attacks, and AD Integration
    The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques.
  • 3.2Azure Applications and Attack Strategies
    The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols.
  • 3.3Password Attacks
    The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks.
4 Reconnaissance Weight not published
  • 4.1Reconnaissance
    The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems.
5 Vulnerability Scanning Weight not published
  • 5.1Vulnerability Scanning
    The candidate will be able to conduct vulnerability scans and analyze the results.
6 Password Formats and Hashes Weight not published
  • 6.1Password Formats and Hashes
    The candidate will demonstrate an understanding of common password hashes and formats for storing password data.
7 Advanced Password Attacks Weight not published
  • 7.1Advanced Password Attacks
    The candidate will be able to use additional methods to attack password hashes and authenticate.
  • 7.2Attacking Password Hashes
    The candidate will be able to obtain and attack password hashes and other password representations.
8 Command and Control (C2) Weight not published
  • 8.1Command and Control (C2)
    The candidate will demonstrate an understanding of the design, application, and use of Command and Control (C2) and common C2 Frameworks.
9 Domain Escalation and Persistence Attacks Weight not published
  • 9.1Domain Escalation and Persistence Attacks
    The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory.
10 Kerberos Attacks Weight not published
  • 10.1Kerberos Attacks
    The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks.
11 Metasploit Weight not published
  • 11.1Metasploit
    The candidate will be able to use and configure the Metasploit Framework at an intermediate level.

Exam Details

Question TypesPerformance-Based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesSecurity personnel responsible for assessing network and systems, Penetration testers, Ethical hackers, Red Team members, Blue Team members, Defenders, auditors, and forensic specialists who want to better understand offensive tactics
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish

Official Study Resources