Group Purchasing
Group Purchasing

What Is the GWAPT Certification?

GWAPT validates a practitioner's ability to advance organization security through penetration testing and a deep understanding of web application security issues, covering exploits and testing methodology across authentication, session management, injection, and configuration.

By the numbers

3 hrs

Exam duration

82

Questions

71%

Min. passing score

What GWAPT Covers

The exam's 8 published objectives group into 5 practical domains that map to SEC542's course sections.

Web App Fundamentals and Recon

Covers Web Application Overview, Reconnaissance and Mapping, and Configuration Testing.

Testing Tools and Authentication

Covers Web Application Testing Tools and Web Application Authentication Attacks.

Session and Client-Side Attacks

Covers Web Application Session Management and Cross Site Scripting/client injection.

SQL Injection Attacks

Covers Web Application SQL Injection Attacks.

Cross Site Request Forgery

Covers the CSRF portion of the client injection objective.

Prepare With This Course

SEC542: Web App Penetration Testing and Ethical Hacking

How SEC542 Prepares You for GWAPT

SEC542 is built around the exam objectives that make up the GWAPT certification: 

  • Section 1, Introduction and Information Gathering builds skills tested under Web Application Overview, Reconnaissance and Mapping, and Web Application Configuration Testing.
  • Section 2, Fuzzing, Scanning, APIs, and Authentication builds skills tested under Web Application Testing Tools and Web Application Authentication Attacks.
  • Section 3, Identity, AuthN/AuthZ Bypass, and Client-Side Attacks builds skills tested under Web Application Session Management and the Cross Site Scripting portion of the Client Injection Attack objective.
  • Section 4, Prototype Pollution, Database and Command Injection, SSRF, and XXE builds skills tested under Web Application SQL Injection Attacks.
  • Section 5, CSRF, Serialization, SSTI, and Advanced Tools builds skills tested under the Cross Site Request Forgery portion of the Client Injection Attack objective.

Across five technical sections and a closing Capture the Flag day, 35 hands-on labs give you the chance to apply each objective against live web application and API targets before you sit the exam. 

Read the full GWAPT certification overview 

SEC542 Authors

Who Should Pursue GWAPT

Security Practitioners

Penetration Testers

Ethical Hackers

Web Application Developers

Website Designers and Architects

Frequently Asked Questions

GWAPT proves that a practitioner can find and exploit vulnerabilities in web applications using a structured penetration testing methodology. GWAPT validates the ability to advance organization security through penetration testing and a deep understanding of web application security issues, spanning authentication attacks, session management, SQL injection, cross site scripting, and configuration testing. 

The GWAPT exam is a single proctored exam with 82 questions to complete in 3 hours, with a minimum passing score of 71%. Specifications can change, so candidates should confirm the current format in the Certification Information section of their GIAC account before sitting the exam. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page

GIAC lists security practitioners, penetration testers, ethical hackers, web application developers, and website designers and architects as the audience for GWAPT. The certification fits both people running penetration tests and the developers who build the applications being tested. 

SEC542: Web App Penetration Testing and Ethical Hacking is the SANS course built to prepare candidates for GWAPT. It runs 6 days instructor-led (or 36 hours self-paced) and includes 35 hands-on labs covering the OWASP Web Security Testing Guide methodology, from reconnaissance and authentication attacks through SQL injection, XSS, CSRF, and a closing Capture the Flag exercise. 

Ready to earn your GWAPT certification?

Add the GWAPT exam attempt when you register for SEC542.

Already trained? Register for the exam directly through GIAC here.