Exam Domains
1 Comprehensive Pen Test Planning, Scoping, and Recon
Weight not published
2 In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting
Weight not published
- 2.1Scanning and Host Discovery
The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results.
- 2.2Exploitation Fundamentals
The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest.
- 2.3Escalation and Exploitation
The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network.
3 Azure Overview, Integration, and Attacks, and In-Depth Password Attacks
Weight not published
- 3.1Azure Overview, Attacks, and AD Integration
The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques.
- 3.2Azure Applications and Attack Strategies
The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols.
- 3.3Password Attacks
The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks.
4 Reconnaissance
Weight not published
- 4.1Reconnaissance
The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems.
5 Vulnerability Scanning
Weight not published
6 Password Formats and Hashes
Weight not published
7 Advanced Password Attacks
Weight not published
8 Command and Control (C2)
Weight not published
9 Domain Escalation and Persistence Attacks
Weight not published
10 Kerberos Attacks
Weight not published
11 Metasploit
Weight not published
Exam Details
Question TypesPerformance-Based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesSecurity personnel responsible for assessing network and systems, Penetration testers, Ethical hackers, Red Team members, Blue Team members, Defenders, auditors, and forensic specialists who want to better understand offensive tactics
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish