GIAC Penetration Tester

GIAC (SANS Institute) · GPEN · Professional

GIAC (SANS Institute) · GIAC/SANS

GIAC Penetration Tester

GPENactiveProfessional
Official GIAC (SANS Institute) source · giac.org

GPEN · ● Active · Professional · GIAC (SANS Institute)

Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 penetration testing landscape; GIAC maintained as active certifier.


Exam facts

FieldValue
Cost$949 USD (exam only); $8,780 for SANS SEC560 course
Duration3 hours (180 minutes)
Questions~115 questions (all scored)
Passing74% (approximately 85 out of 115 questions)
FormatMultiple choice; open-book (printed materials allowed)
DeliveryGIAC web-based proctored (GIAC platform)
LanguagesEnglish
Valid4 years
RenewalCPE credits + maintenance fee per 4-year cycle
PrerequisitesNone; SANS SEC560 strongly recommended
Released2001 (original); current format 2010+
RetiringN/A — active, not retiring

Vendor source — GIAC Penetration Tester ↗
Official exam guide — GPEN Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗


About

The GIAC Penetration Tester (GPEN) is a professional-level offensive security certification for IT professionals responsible for conducting authorized security assessments, vulnerability testing, and penetration testing. Launched by SANS in 2001, GPEN validates hands-on competency in reconnaissance, scanning, exploitation, privilege escalation, lateral movement, and post-exploitation techniques. Unlike academic security certs, GPEN is open-book — candidates bring printed notes and custom references — making it accessible to experienced security practitioners transitioning into offensive security roles (pentesters, red-team operators, security consultants). The cert is widely recognized in penetration-testing firms, enterprise security teams, and managed security service providers (MSSPs) as a baseline professional credential for authorized offensive security work.


Domain context — Security/Offensive Security

Penetration testing (pen testing) is the authorized, time-bound process of simulating attacks against an organization's systems, networks, applications, and physical security to identify vulnerabilities and weaknesses before malicious actors do. This domain spans reconnaissance (OSINT, network scanning), vulnerability discovery (Nmap, Nessus, OpenVAS), exploitation (Metasploit, custom payloads), post-exploitation (persistence, lateral movement, data exfiltration), and reporting (findings, risk remediation). Penetration testers work under strict rules of engagement, contract, and law; the best testers combine deep technical knowledge with scoping precision, business acumen, and ethical responsibility.

Read full deep dive — GIAC/SANS Ecosystem →


Topics covered

  • Penetration Testing Planning & Scoping — defining scope, rules of engagement, legal/contractual considerations, client communication, risk assessment
  • Reconnaissance & Open Source Intelligence (OSINT) — passive information gathering, Shodan, public records, DNS enumeration, social engineering, WHOIS, registrar lookups
  • Network Scanning & Enumeration — Nmap (TCP/UDP scanning, OS fingerprinting, service detection), network mapping, port enumeration, target identification
  • Vulnerability Scanning & Assessment — Nessus, OpenVAS, Qualys basics, vulnerability classification (CVSS), false-positive filtering, risk prioritization
  • Exploitation Frameworks — Metasploit Framework (payload generation, exploitation modules, Meterpreter), module customization, shellcode delivery
  • Password Attacks — credential stuffing, hash cracking (John the Ripper, Hashcat), rainbow tables, password spraying, keylogging, screen capture post-exploitation
  • Privilege Escalation (Windows & Linux) — kernel exploits, misconfigured services, token impersonation, file-permission abuse, UAC bypass, sudo vulnerabilities, capability escapes
  • Lateral Movement Techniques — PsExec, WMI, RDP, SSH tunneling, Pass-the-Hash, Kerberoasting, AS-REP roasting, BloodHound for AD enumeration, WinRM
  • Pivoting & Tunneling — establishing proxies, SSH tunnels, Socks4/5, port forwarding, double-hop exploitation, internal network re-reconnaissance post-compromise
  • Web Application Attacks (Pen Test Context) — SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), authentication bypass, in scope for network penetration testing only
  • Active Directory Attacks — Kerberoasting, AS-REP roasting, BloodHound graph-based enumeration, domain trusts, LSASS credential dumping, ticket forging
  • Post-Exploitation & Persistence — maintaining access, creating backdoors, scheduled tasks, registry persistence, service installation, anti-forensics awareness
  • Penetration Testing Report Writing — documenting findings, executive summaries, risk ratings, remediation recommendations, proof-of-concept steps, timeline
  • Legal & Contractual Considerations — rules of engagement, data sensitivity, liability, regulatory compliance (GDPR, HIPAA), client authorization verification

Source: GIAC GPEN Exam Blueprint ↗


Common skills at Security/Offensive Security · Professional

Shared technical and operational competencies for penetration testers regardless of specific certification.

  • Network reconnaissance & passive information gathering (OSINT, Shodan, DNS)
  • Active network scanning & enumeration (Nmap, port mapping, OS detection)
  • Vulnerability identification & prioritization (CVSS, business impact)
  • Exploitation tool proficiency (Metasploit, custom payloads, encoding/obfuscation)
  • Post-exploitation techniques (privilege escalation, lateral movement, persistence)
  • Rules of engagement compliance & ethical responsibility (authorization, data handling)
  • Evidence documentation & proof-of-concept reporting (screenshots, timelines)
  • Communication with non-technical stakeholders (risk explanations, remediation steps)

Recommended courses at Security/Offensive Security · Professional

ProviderTitleCostURL
SANS InstituteSEC560: Network Penetration Testing and Ethical Hacking$8,780
SANS Institute (Self-Paced)SEC560 OnDemand$1,600–$2,000
Udemy (Chad Causey)Practical Ethical Hacking & GPEN Prep$15–$50
CybraryPenetration Testing & GPEN Certification PrepFree–$99
INE (Infosec Institute)GPEN On-Demand Training$499–$999

Course-selection rule: SEC560 is the canonical gold-standard course; OnDemand offers flexibility. Udemy and Cybrary serve self-paced learners with tight budgets. Choose based on learning style and available time.


Practice exams

ProviderTitleCostURL
GIAC OfficialGPEN Practice Test (included in SEC560 course)Included
GIAC OfficialStandalone Practice Exam Bundle$399
WhizlabsGPEN Practice Test$49–$99
MeasureUpGIAC Penetration Tester Practice Test$129–$199

Books

TitleAuthorPublisherYearISBNURL
GPEN GIAC Penetration Tester All-in-One Exam GuideDaniel D. "Skip" EasterMcGraw-Hill Education2021978-1260461688
SANS SEC560 Course Materials (Official)SANS InstructorsSANS Institute2024–2026N/A
The Penetration Tester's PlaybookDavid J. Kennedy, Sharon L. WeinbergerCreateSpace2015978-1512214130
Metasploit: A Penetration Tester's GuideDavid Kennedy, Jim O'Gorman, Devon Kearns, Mati AharoniNo Starch Press2011978-1593271595

Book rule: The Easter All-in-One guide is the dedicated GPEN study resource. SANS course materials are the authoritative reference; SEC560 OnDemand includes them digitally. Kennedy's Penetration Tester's Playbook and Metasploit Guide provide practical hands-on methodology beyond any single cert.


Typical job titles at Security/Offensive Security · Professional

Penetration Tester · Red Team Operator · Ethical Hacker · Security Consultant · Offensive Security Engineer · Vulnerability Researcher · Security Assessment Specialist

(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GPEN as required or strongly preferred.)


Salary

RegionRangeSource
USD$115,000 – $170,000 annuallyGlassdoor ↗ · PayScale ↗ · ZipRecruiter ↗
ZARR1,900,000 – R2,830,000 annually (estimated at 1 USD = 18.5 ZAR, May 2026)Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction)
GBP£68,000 – £102,000 annuallyIT Jobs Watch ↗ (penetration testing roles)
EUR€78,000 – €115,000 annually (DE/FR/NL average)IT Job Trends ↗
AUDA$148,000 – A$208,000 annuallySeek ↗ (security assessment specialist roles)

Salary rule: USD data cited from Glassdoor, PayScale, ZipRecruiter (Feb–May 2026 surveys). ZAR converted from USD at prevailing exchange rate; no region-specific ZA penetration-testing salary data available. GBP, EUR, and AUD derived from general pen testing and offensive security role postings; certs in demand typically place at upper ranges. Salaries vary by location, firm size, employer type (consulting, enterprise, government), certifications held, and years of experience.


Skills validated

Concrete technologies, protocols, and tools this exam actually tests.

  • Reconnaissance & enumeration tools — Shodan, DNS recon, WHOIS, Nmap, theHarvester, Recon-ng
  • Vulnerability scanning — Nessus, OpenVAS, Qualys, Rapid7 Nexpose
  • Exploitation frameworks — Metasploit Framework, Shellcode generation, payload encoding
  • Password attack tools — John the Ripper, Hashcat, Hydra, Medusa, credential stuffing
  • Lateral movement & privilege escalation — PsExec, WMI, Pass-the-Hash, Kerberoasting, BloodHound, UAC bypass techniques
  • Post-exploitation — Meterpreter, Empire, registry persistence, scheduled tasks, service installation
  • Active Directory tools — Kerberoasting (Impacket), AS-REP roasting, BloodHound, LSASS dumping (Mimikatz context)
  • Web application testing frameworks — Burp Suite basics (in pen testing context), SQL injection detection
  • Network protocols — TCP/IP, DNS, DHCP, LDAP, Kerberos, NTLM, RDP, SSH, WinRM
  • Reporting & documentation — executive summary writing, risk prioritization, remediation recommendations

Related certifications

  • Stacks with: GIAC Certified Incident Handler (GCIH) ↗ — defensive complement to offensive testing
  • Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — adds forensic analysis of compromised systems post-test
  • Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth after offensive perspective
  • Equivalent (different vendor): Offensive Security Certified Professional (OSCP) ↗ — hands-on practical exam alternative
  • Vendor overview: GIAC/SANS Vendor Overview ↗

Sources


Last verified: 2026-05-02
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Offensive Security Domain
Related certifications: GIAC_GCIH_Incident_Handler.md · GIAC_GSEC_Security_Essentials.md

Rate this cert
Was this helpful?
Comments ()
0/2000