GIAC Penetration Tester (GPEN) Practice Test
Build your confidence for GIAC Penetration Tester (GPEN). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
The GIAC Penetration Tester (GPEN) certification is a globally recognized, performance-based credential that validates a professional's ability to conduct authorized penetration tests using a structured, ethical methodology. Administered by the Global Information Assurance Certification (GIAC) and aligned with the SANS SEC560: Network Penetration Testing and Ethical Hacking course, GPEN certifies that holders possess the practical skills to effectively identify, exploit, and document security vulnerabilities in enterprise networks. The exam rigorously tests knowledge across the entire penetration testing lifecycle, from initial reconnaissance and enumeration to exploitation, post-exploitation, and professional reporting. Earning the GPEN demonstrates not only technical proficiency with modern attack tools and techniques but also a deep understanding of the legal frameworks, scoping requirements, and ethical considerations that define professional security assessments. This certification is a cornerstone for cybersecurity professionals seeking to establish or advance their careers in offensive security, providing tangible proof of hands-on competency to employers, clients, and regulatory bodies.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
A healthcare provider has approved a scoped internal assessment, but the rules of engagement prohibit disruption of clinical systems and require clear notes for every finding. The finding under review is cross-site scripting finding, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?
A university permits limited active testing against named systems and asks the tester to explain findings in language the infrastructure team can act on. The finding under review is DCSync-capable privilege, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?
An energy cooperative asks for a focused validation of exposure found by its vulnerability team, while legal requires that all tests stay inside the signed target list. The notes show a service accepts Kerberos tickets without contacting the DC for every authorization decision. Which interpretation best matches the evidence for a GPEN-style report?
A SaaS company gives the tester production and staging ranges, a change-freeze calendar, and read-only cloud review access for the engagement. The notes show the tester must select between staged and stageless payloads for a restrictive network path. Which interpretation best matches the evidence for a GPEN-style report?
A manufacturer requests a GPEN-style assessment after a merger, with separate Active Directory forests, legacy services, and strict written authorization boundaries. The finding under review is session upgrade, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?
Career Opportunities & Salary
Exam insights and study advice
In the competitive field of cybersecurity, the GPEN certification serves as a critical differentiator, signaling to employers a validated, hands-on skill set that directly translates to enhanced organizational security. It is frequently listed as a preferred or required qualification for roles such as Penetration Tester, Ethical Hacker, Red Team Member, and Security Consultant. Beyond resume enhancement, GPEN provides a structured and comprehensive knowledge framework that ensures practitioners can conduct tests methodically, safely, and effectively, reducing risk for both the tester and the client organization. Its alignment with the SANS curriculum and GIAC's rigorous exam process confers immediate industry recognition and credibility, often leading to accelerated career advancement, increased earning potential, and opportunities to work on high-stakes security engagements.
Your Path Forward
What this exam covers
01Advanced Password Attacks
Topics
- Advanced Password Attacks
- Attacking Password Hashes
Learning objectives
- Advanced Password Attacks: The candidate will be able to use additional methods to attack password hashes and authenticate
- Attacking Password Hashes: The candidate will be able to obtain and attack password hashes and other password representations
02Azure Overview, Integration, and Attacks, and In-Depth Password Attacks
Topics
- Azure Overview, Attacks, and AD Integration
- Azure Applications and Attack Strategies
- Password Attacks
Learning objectives
- Azure Overview, Attacks, and AD Integration: The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques
- Azure Applications and Attack Strategies: The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols
- Password Attacks: The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks
03Command and Control (C2)
Topics
- Command and Control (C2)
Learning objectives
- Command and Control (C2): The candidate will demonstrate an understanding of the design, application, and use of Command and Control (C2) and common C2 Frameworks
04Comprehensive Pen Test Planning, Scoping, and Recon
Topics
- Penetration Test Planning
Learning objectives
- Penetration Test Planning: The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting
05Domain Escalation and Persistence Attacks
Topics
- Domain Escalation and Persistence Attacks
Learning objectives
- Domain Escalation and Persistence Attacks: The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory
06In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting
Topics
- Scanning and Host Discovery
- Exploitation Fundamentals
- Escalation and Exploitation
Learning objectives
- Scanning and Host Discovery: The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results
- Exploitation Fundamentals: The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest
- Escalation and Exploitation: The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network
07Kerberos Attacks
Topics
- Kerberos Attacks
Learning objectives
- Kerberos Attacks: The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks
08Metasploit
Topics
- Metasploit
Learning objectives
- Metasploit: The candidate will be able to use and configure the Metasploit Framework at an intermediate level
09Password Formats and Hashes
Topics
- Password Formats and Hashes
Learning objectives
- Password Formats and Hashes: The candidate will demonstrate an understanding of common password hashes and formats for storing password data
10Reconnaissance
Topics
- Reconnaissance
Learning objectives
- Reconnaissance: The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems
11Vulnerability Scanning
Topics
- Vulnerability Scanning
Learning objectives
- Vulnerability Scanning: The candidate will be able to conduct vulnerability scans and analyze the results