GIAC Penetration Tester (GPEN) Practice Test

180 questions available

Build your confidence for GIAC Penetration Tester (GPEN). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
115 Exam questions
5 hours Time Limit
Your practice
180 Practice questions
3 hours Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 74 Published passing score for this certification.
Explore exam topics Official objectives from GIAC
GIAC180 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-06-11How we verify

Exam overview and details

The GIAC Penetration Tester (GPEN) certification is a globally recognized, performance-based credential that validates a professional's ability to conduct authorized penetration tests using a structured, ethical methodology. Administered by the Global Information Assurance Certification (GIAC) and aligned with the SANS SEC560: Network Penetration Testing and Ethical Hacking course, GPEN certifies that holders possess the practical skills to effectively identify, exploit, and document security vulnerabilities in enterprise networks. The exam rigorously tests knowledge across the entire penetration testing lifecycle, from initial reconnaissance and enumeration to exploitation, post-exploitation, and professional reporting. Earning the GPEN demonstrates not only technical proficiency with modern attack tools and techniques but also a deep understanding of the legal frameworks, scoping requirements, and ethical considerations that define professional security assessments. This certification is a cornerstone for cybersecurity professionals seeking to establish or advance their careers in offensive security, providing tangible proof of hands-on competency to employers, clients, and regulatory bodies.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Exploitation Fundamentals

A healthcare provider has approved a scoped internal assessment, but the rules of engagement prohibit disruption of clinical systems and require clear notes for every finding. The finding under review is cross-site scripting finding, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Domain Escalation and Persistence Attacks

A university permits limited active testing against named systems and asks the tester to explain findings in language the infrastructure team can act on. The finding under review is DCSync-capable privilege, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Kerberos Attacks

An energy cooperative asks for a focused validation of exposure found by its vulnerability team, while legal requires that all tests stay inside the signed target list. The notes show a service accepts Kerberos tickets without contacting the DC for every authorization decision. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A SaaS company gives the tester production and staging ranges, a change-freeze calendar, and read-only cloud review access for the engagement. The notes show the tester must select between staged and stageless payloads for a restrictive network path. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A manufacturer requests a GPEN-style assessment after a merger, with separate Active Directory forests, legacy services, and strict written authorization boundaries. The finding under review is session upgrade, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In the competitive field of cybersecurity, the GPEN certification serves as a critical differentiator, signaling to employers a validated, hands-on skill set that directly translates to enhanced organizational security. It is frequently listed as a preferred or required qualification for roles such as Penetration Tester, Ethical Hacker, Red Team Member, and Security Consultant. Beyond resume enhancement, GPEN provides a structured and comprehensive knowledge framework that ensures practitioners can conduct tests methodically, safely, and effectively, reducing risk for both the tester and the client organization. Its alignment with the SANS curriculum and GIAC's rigorous exam process confers immediate industry recognition and credibility, often leading to accelerated career advancement, increased earning potential, and opportunities to work on high-stakes security engagements.

Your Path Forward

You are here GIAC Penetration Tester (GPEN) Practice Test Step 4 of 4 – Expert
Penetration Testing Specialist

What this exam covers

01Advanced Password Attacks

Topics

  • Advanced Password Attacks
  • Attacking Password Hashes

Learning objectives

  • Advanced Password Attacks: The candidate will be able to use additional methods to attack password hashes and authenticate
  • Attacking Password Hashes: The candidate will be able to obtain and attack password hashes and other password representations

02Azure Overview, Integration, and Attacks, and In-Depth Password Attacks

Topics

  • Azure Overview, Attacks, and AD Integration
  • Azure Applications and Attack Strategies
  • Password Attacks

Learning objectives

  • Azure Overview, Attacks, and AD Integration: The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques
  • Azure Applications and Attack Strategies: The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols
  • Password Attacks: The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks

03Command and Control (C2)

Topics

  • Command and Control (C2)

Learning objectives

  • Command and Control (C2): The candidate will demonstrate an understanding of the design, application, and use of Command and Control (C2) and common C2 Frameworks

04Comprehensive Pen Test Planning, Scoping, and Recon

Topics

  • Penetration Test Planning

Learning objectives

  • Penetration Test Planning: The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting

05Domain Escalation and Persistence Attacks

Topics

  • Domain Escalation and Persistence Attacks

Learning objectives

  • Domain Escalation and Persistence Attacks: The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory

06In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting

Topics

  • Scanning and Host Discovery
  • Exploitation Fundamentals
  • Escalation and Exploitation

Learning objectives

  • Scanning and Host Discovery: The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results
  • Exploitation Fundamentals: The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest
  • Escalation and Exploitation: The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network

07Kerberos Attacks

Topics

  • Kerberos Attacks

Learning objectives

  • Kerberos Attacks: The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks

08Metasploit

Topics

  • Metasploit

Learning objectives

  • Metasploit: The candidate will be able to use and configure the Metasploit Framework at an intermediate level

09Password Formats and Hashes

Topics

  • Password Formats and Hashes

Learning objectives

  • Password Formats and Hashes: The candidate will demonstrate an understanding of common password hashes and formats for storing password data

10Reconnaissance

Topics

  • Reconnaissance

Learning objectives

  • Reconnaissance: The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems

11Vulnerability Scanning

Topics

  • Vulnerability Scanning

Learning objectives

  • Vulnerability Scanning: The candidate will be able to conduct vulnerability scans and analyze the results

Exam Details GPEN | $949 USD | 5 hours

Exam Code GPEN
Vendor GIAC
Exam Cost $949 USD
Passing Score 74
Time Limit 5 hours
Exam questions 115
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

What are the prerequisites for taking the GPEN exam?

What is the format of the GPEN exam, and how is it scored?

How does GPEN differ from other penetration testing certifications like OSCP or CEH?

How long is the GPEN certification valid, and what are the renewal requirements?

What is the best way to prepare for the GPEN exam?