SEC536: Adversarial AI - Penetration Testing AI Systems


GWAPT proves that a practitioner can find and exploit vulnerabilities in web applications using a structured penetration testing methodology. GWAPT validates the ability to advance organization security through penetration testing and a deep understanding of web application security issues, spanning authentication attacks, session management, SQL injection, cross site scripting, and configuration testing.
The GWAPT exam is a single proctored exam with 82 questions to complete in 3 hours, with a minimum passing score of 71%. Specifications can change, so candidates should confirm the current format in the Certification Information section of their GIAC account before sitting the exam.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GIAC lists security practitioners, penetration testers, ethical hackers, web application developers, and website designers and architects as the audience for GWAPT. The certification fits both people running penetration tests and the developers who build the applications being tested.
SEC542: Web App Penetration Testing and Ethical Hacking is the SANS course built to prepare candidates for GWAPT. It runs 6 days instructor-led (or 36 hours self-paced) and includes 35 hands-on labs covering the OWASP Web Security Testing Guide methodology, from reconnaissance and authentication attacks through SQL injection, XSS, CSRF, and a closing Capture the Flag exercise.