Group Purchasing
Group Purchasing

What Is the GCPN Certification?

The GIAC Cloud Penetration Tester (GCPN) certification validates a practitioner's fluency in cloud technologies and readiness to conduct cloud-focused penetration testing. GCPN certification holders are qualified to assess and test the security of systems, networks, architecture, and cloud technologies.

By the numbers

2 hrs

Exam duration

75

Questions

70%

Min. passing score

What GCPN Covers

GIAC publishes 12 exam objectives for GCPN, and they group into five practical domains.

Recon and Discovery

Covers Cloud Penetration Testing Fundamentals, Discovering Cloud Services and Data, and Cloud CLI and Application Mapping.

Identity and Password Attacks

Covers Password Attacks on Cloud Environments and Microsoft Azure Cloud Services and Attacks.

AWS and Azure Services

Covers AWS Authentication and Cloud Services and Azure Functions and Windows Containers.

Cloud Native Applications

Covers Cloud Native Applications and CI/CD Pipelines and Web Application Attacks.

Containers and Red Teaming

Covers Containers and Kubernetes Structure, Red Team Penetration Testing of Cloud Environments, and Redirection and Attack Obfuscation.

Prepare With This Course

SEC588: Cloud Penetration Testing

How SEC588 Prepares You for GCPN

SEC588 aligns with the exam objectives that make up the GCPN certification: 

  • Section 1, Architecture, Discovery, and Recon at Scale builds skills tested under Cloud Penetration Testing Fundamentals, Discovering Cloud Services and Data, and Cloud CLI and Application Mapping.
  • Section 2, Attacking Identity Systems aligns with Password Attacks on Cloud Environments and Microsoft Azure Cloud Services and Attacks.
  • Section 3, Attacking and Abusing Cloud Services builds skills tested under AWS Authentication and Cloud Services and Azure Functions and Windows Containers.
  • Section 4, Vulnerabilities in Cloud Native Applications aligns with Cloud Native Applications and CI/CD Pipelines and Web Application Attacks.
  • Section 5, Infrastructure Attacks and Red Teaming builds skills tested under Containers and Kubernetes Structure, Red Team Penetration Testing of Cloud Environments, and Redirection and Attack Obfuscation.
  • Section 6, Capstone Event brings the objectives together in a team-based, end-to-end assessment of a new cloud environment, ending in a written report.

Across all six sections, 24 hands-on labs and a team-based capstone event give you the chance to apply each skill in lab environments featuring AWS, Azure, Microsoft 365, and Kubernetes before you sit the exam. 

Read the full GCPN certification overview 

SEC588 Course Authors

Who Should Pursue GCPN

Attack-focused and Defense-focused Security Practitioners

Penetration Testers

Vulnerability Analysts

Risk Assessment Officers

DevOps Engineers and Site Reliability Engineers

Frequently Asked Questions

The GIAC Cloud Penetration Tester (GCPN) certification validates a practitioner's fluency in cloud technologies and readiness to conduct cloud-focused penetration testing. Holders are qualified to assess and test the security of systems, networks, architecture, and cloud technologies.

The GCPN is one proctored exam with 75 questions and a two-hour time limit. The minimum passing score is 70%. GIAC periodically reviews exam specifications, so confirm the details for your attempt in your GIAC account.

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GIAC lists attack-focused and defense-focused security practitioners, penetration testers, vulnerability analysts, risk assessment officers, DevOps engineers, and site reliability engineers as the audience for GCPN.

 SEC588: Cloud Penetration Testing maps to the GCPN exam objectives. The course includes 24 hands-on labs and a team-based capstone event in lab environments featuring AWS, Azure, Microsoft 365, and Kubernetes, and it provides great training if you're thinking of pursuing GCPN. Completing SANS training is not required for GIAC certification.

SANS Institute is a training organization. GIAC LLC is an independent certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012. Completion of SANS training is not required for GIAC certification, nor does it guarantee a passing exam result.

Ready to earn your GCPN certification?

Add the GCPN exam attempt when you register for SEC588.