Group Purchasing
Group Purchasing

What Is the GPEN Certification?

The GIAC Penetration Tester (GPEN) certification validates a practitioner's ability to properly conduct a penetration test using effective techniques and methodologies. GPEN holders can conduct exploits, perform detailed environmental reconnaissance, and apply a process-oriented approach to penetration testing projects.

By the numbers

3 hrs

Exam duration

82

Questions

73%

Min. passing score

What GPEN Covers

GPEN groups its exam objectives into 5 domains, which SEC560's 6 course sections map to as shown below.

Planning, Recon, and Scanning

Penetration Test Planning, Reconnaissance, and Scanning and Host Discovery, the groundwork of every engagement.

Password and Cloud Access

Password Attacks, Password Formats and Hashes, Vulnerability Scanning, Azure Overview, Attacks, and AD Integration, and Azure Applications and Attack Strategies.

Exploitation and Post-Exploitation

Exploitation Fundamentals, Escalation and Exploitation, Metasploit, Attacking Password Hashes, Advanced Password Attacks, and Command and Control (C2).

Kerberos and Active Directory Attacks

Kerberos Attacks against Active Directory authentication.

Domain Escalation and Persistence

Domain Escalation and Persistence Attacks used to consolidate and maintain administrative access.

Prepare With This Course

SEC560: Enterprise Penetration Testing

How SEC560 Prepares You for GPEN

SEC560 is built around the exam objectives that make up the GPEN certification:

  • Section 1, Miniature Engagement, Recon, and Scanning builds skills tested under Penetration Test Planning, Reconnaissance, and Scanning and Host Discovery. 
  • Section 2, Scanning and Initial Access aligns with Vulnerability Scanning, Password Attacks, Password Formats and Hashes, and Azure Overview, Attacks, and AD Integration and Azure Applications and Attack Strategies. 
  • Section 3, Post-Exploitation builds skills tested under Exploitation Fundamentals, Escalation and Exploitation, Metasploit, Attacking Password Hashes, Advanced Password Attacks, and Command and Control (C2). 
  • Section 4, Domain Privilege Escalation and Lateral Movement aligns with Kerberos Attacks. 
  • Section 5, Persistence and Evading Controls builds skills tested under Domain Escalation and Persistence Attacks.

Across all 6 sections, 30 hands-on labs and a capstone Capture the Flag competition give you the chance to apply each skill against realistic enterprise networks before you sit the exam. 

Read the full GPEN certification overview here.

SEC560 Authors

Who It's For

Penetration testers and ethical hackers

Red team operators

Security analysts and engineers

System administrators hardening enterprise environments

Incident responders and defenders seeking to understand attacker techniques

Compliance auditors requiring technical security validation

Frequently Asked Questions

GPEN proves you can properly conduct a penetration test using effective techniques and methodologies. Certification holders can conduct exploits, perform detailed environmental reconnaissance, and apply a process-oriented approach to penetration testing projects.

One proctored exam of 82 questions over 3 hours, with a minimum passing score of 73%. GIAC periodically reviews exam specifications, so confirm the format and passing score that apply to your specific attempt in the Certification Information section of your GIAC account.

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC's renewal page

GPEN is built for penetration testers, ethical hackers, red team operators, security analysts and engineers, system administrators hardening enterprise environments, incident responders, and compliance auditors who need to validate offensive security skills.

SEC560: Enterprise Penetration Testing prepares you for the exam through 30 hands-on labs across 6 sections and a capstone Capture the Flag competition covering reconnaissance, password attacks, Active Directory and Kerberos exploitation, and Azure and Entra ID

Ready to earn your GPEN certification?

Add the GPEN exam attempt when you register for SEC560

Already trained? Register for the exam directly through GIAC here.

GIAC Penetration Tester Certification (GPEN) | SANS Institute