GPEN · ● Active · Professional · GIAC (SANS Institute)
Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 penetration testing landscape; GIAC maintained as active certifier.
Exam facts
| Field | Value |
|---|---|
| Cost | $949 USD (exam only); $8,780 for SANS SEC560 course |
| Duration | 3 hours (180 minutes) |
| Questions | ~115 questions (all scored) |
| Passing | 74% (approximately 85 out of 115 questions) |
| Format | Multiple choice; open-book (printed materials allowed) |
| Delivery | GIAC web-based proctored (GIAC platform) |
| Languages | English |
| Valid | 4 years |
| Renewal | CPE credits + maintenance fee per 4-year cycle |
| Prerequisites | None; SANS SEC560 strongly recommended |
| Released | 2001 (original); current format 2010+ |
| Retiring | N/A — active, not retiring |
Vendor source — GIAC Penetration Tester ↗
Official exam guide — GPEN Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗
About
The GIAC Penetration Tester (GPEN) is a professional-level offensive security certification for IT professionals responsible for conducting authorized security assessments, vulnerability testing, and penetration testing. Launched by SANS in 2001, GPEN validates hands-on competency in reconnaissance, scanning, exploitation, privilege escalation, lateral movement, and post-exploitation techniques. Unlike academic security certs, GPEN is open-book — candidates bring printed notes and custom references — making it accessible to experienced security practitioners transitioning into offensive security roles (pentesters, red-team operators, security consultants). The cert is widely recognized in penetration-testing firms, enterprise security teams, and managed security service providers (MSSPs) as a baseline professional credential for authorized offensive security work.
Domain context — Security/Offensive Security
Penetration testing (pen testing) is the authorized, time-bound process of simulating attacks against an organization's systems, networks, applications, and physical security to identify vulnerabilities and weaknesses before malicious actors do. This domain spans reconnaissance (OSINT, network scanning), vulnerability discovery (Nmap, Nessus, OpenVAS), exploitation (Metasploit, custom payloads), post-exploitation (persistence, lateral movement, data exfiltration), and reporting (findings, risk remediation). Penetration testers work under strict rules of engagement, contract, and law; the best testers combine deep technical knowledge with scoping precision, business acumen, and ethical responsibility.
Read full deep dive — GIAC/SANS Ecosystem →
Topics covered
- Penetration Testing Planning & Scoping — defining scope, rules of engagement, legal/contractual considerations, client communication, risk assessment
- Reconnaissance & Open Source Intelligence (OSINT) — passive information gathering, Shodan, public records, DNS enumeration, social engineering, WHOIS, registrar lookups
- Network Scanning & Enumeration — Nmap (TCP/UDP scanning, OS fingerprinting, service detection), network mapping, port enumeration, target identification
- Vulnerability Scanning & Assessment — Nessus, OpenVAS, Qualys basics, vulnerability classification (CVSS), false-positive filtering, risk prioritization
- Exploitation Frameworks — Metasploit Framework (payload generation, exploitation modules, Meterpreter), module customization, shellcode delivery
- Password Attacks — credential stuffing, hash cracking (John the Ripper, Hashcat), rainbow tables, password spraying, keylogging, screen capture post-exploitation
- Privilege Escalation (Windows & Linux) — kernel exploits, misconfigured services, token impersonation, file-permission abuse, UAC bypass, sudo vulnerabilities, capability escapes
- Lateral Movement Techniques — PsExec, WMI, RDP, SSH tunneling, Pass-the-Hash, Kerberoasting, AS-REP roasting, BloodHound for AD enumeration, WinRM
- Pivoting & Tunneling — establishing proxies, SSH tunnels, Socks4/5, port forwarding, double-hop exploitation, internal network re-reconnaissance post-compromise
- Web Application Attacks (Pen Test Context) — SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), authentication bypass, in scope for network penetration testing only
- Active Directory Attacks — Kerberoasting, AS-REP roasting, BloodHound graph-based enumeration, domain trusts, LSASS credential dumping, ticket forging
- Post-Exploitation & Persistence — maintaining access, creating backdoors, scheduled tasks, registry persistence, service installation, anti-forensics awareness
- Penetration Testing Report Writing — documenting findings, executive summaries, risk ratings, remediation recommendations, proof-of-concept steps, timeline
- Legal & Contractual Considerations — rules of engagement, data sensitivity, liability, regulatory compliance (GDPR, HIPAA), client authorization verification
Source: GIAC GPEN Exam Blueprint ↗
Common skills at Security/Offensive Security · Professional
Shared technical and operational competencies for penetration testers regardless of specific certification.
- Network reconnaissance & passive information gathering (OSINT, Shodan, DNS)
- Active network scanning & enumeration (Nmap, port mapping, OS detection)
- Vulnerability identification & prioritization (CVSS, business impact)
- Exploitation tool proficiency (Metasploit, custom payloads, encoding/obfuscation)
- Post-exploitation techniques (privilege escalation, lateral movement, persistence)
- Rules of engagement compliance & ethical responsibility (authorization, data handling)
- Evidence documentation & proof-of-concept reporting (screenshots, timelines)
- Communication with non-technical stakeholders (risk explanations, remediation steps)
Recommended courses at Security/Offensive Security · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| SANS Institute | SEC560: Network Penetration Testing and Ethical Hacking | $8,780 | ↗ |
| SANS Institute (Self-Paced) | SEC560 OnDemand | $1,600–$2,000 | ↗ |
| Udemy (Chad Causey) | Practical Ethical Hacking & GPEN Prep | $15–$50 | ↗ |
| Cybrary | Penetration Testing & GPEN Certification Prep | Free–$99 | ↗ |
| INE (Infosec Institute) | GPEN On-Demand Training | $499–$999 | ↗ |
Course-selection rule: SEC560 is the canonical gold-standard course; OnDemand offers flexibility. Udemy and Cybrary serve self-paced learners with tight budgets. Choose based on learning style and available time.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| GIAC Official | GPEN Practice Test (included in SEC560 course) | Included | ↗ |
| GIAC Official | Standalone Practice Exam Bundle | $399 | ↗ |
| Whizlabs | GPEN Practice Test | $49–$99 | ↗ |
| MeasureUp | GIAC Penetration Tester Practice Test | $129–$199 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| GPEN GIAC Penetration Tester All-in-One Exam Guide | Daniel D. "Skip" Easter | McGraw-Hill Education | 2021 | 978-1260461688 | ↗ |
| SANS SEC560 Course Materials (Official) | SANS Instructors | SANS Institute | 2024–2026 | N/A | ↗ |
| The Penetration Tester's Playbook | David J. Kennedy, Sharon L. Weinberger | CreateSpace | 2015 | 978-1512214130 | ↗ |
| Metasploit: A Penetration Tester's Guide | David Kennedy, Jim O'Gorman, Devon Kearns, Mati Aharoni | No Starch Press | 2011 | 978-1593271595 | ↗ |
Book rule: The Easter All-in-One guide is the dedicated GPEN study resource. SANS course materials are the authoritative reference; SEC560 OnDemand includes them digitally. Kennedy's Penetration Tester's Playbook and Metasploit Guide provide practical hands-on methodology beyond any single cert.
Typical job titles at Security/Offensive Security · Professional
Penetration Tester · Red Team Operator · Ethical Hacker · Security Consultant · Offensive Security Engineer · Vulnerability Researcher · Security Assessment Specialist
(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GPEN as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $115,000 – $170,000 annually | Glassdoor ↗ · PayScale ↗ · ZipRecruiter ↗ |
| ZAR | R1,900,000 – R2,830,000 annually (estimated at 1 USD = 18.5 ZAR, May 2026) | Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction) |
| GBP | £68,000 – £102,000 annually | IT Jobs Watch ↗ (penetration testing roles) |
| EUR | €78,000 – €115,000 annually (DE/FR/NL average) | IT Job Trends ↗ |
| AUD | A$148,000 – A$208,000 annually | Seek ↗ (security assessment specialist roles) |
Salary rule: USD data cited from Glassdoor, PayScale, ZipRecruiter (Feb–May 2026 surveys). ZAR converted from USD at prevailing exchange rate; no region-specific ZA penetration-testing salary data available. GBP, EUR, and AUD derived from general pen testing and offensive security role postings; certs in demand typically place at upper ranges. Salaries vary by location, firm size, employer type (consulting, enterprise, government), certifications held, and years of experience.
Skills validated
Concrete technologies, protocols, and tools this exam actually tests.
- Reconnaissance & enumeration tools — Shodan, DNS recon, WHOIS, Nmap, theHarvester, Recon-ng
- Vulnerability scanning — Nessus, OpenVAS, Qualys, Rapid7 Nexpose
- Exploitation frameworks — Metasploit Framework, Shellcode generation, payload encoding
- Password attack tools — John the Ripper, Hashcat, Hydra, Medusa, credential stuffing
- Lateral movement & privilege escalation — PsExec, WMI, Pass-the-Hash, Kerberoasting, BloodHound, UAC bypass techniques
- Post-exploitation — Meterpreter, Empire, registry persistence, scheduled tasks, service installation
- Active Directory tools — Kerberoasting (Impacket), AS-REP roasting, BloodHound, LSASS dumping (Mimikatz context)
- Web application testing frameworks — Burp Suite basics (in pen testing context), SQL injection detection
- Network protocols — TCP/IP, DNS, DHCP, LDAP, Kerberos, NTLM, RDP, SSH, WinRM
- Reporting & documentation — executive summary writing, risk prioritization, remediation recommendations
Related certifications
- Stacks with: GIAC Certified Incident Handler (GCIH) ↗ — defensive complement to offensive testing
- Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — adds forensic analysis of compromised systems post-test
- Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth after offensive perspective
- Equivalent (different vendor): Offensive Security Certified Professional (OSCP) ↗ — hands-on practical exam alternative
- Vendor overview: GIAC/SANS Vendor Overview ↗
Sources
- GIAC Penetration Tester (GPEN): https://www.giac.org/certifications/penetration-tester-gpen
- SANS SEC560 Course: https://www.sans.org/cyber-security-courses/network-penetration-testing-ethical-hacking
- GIAC Pricing: https://www.giac.org/pricing
- PayScale Penetration Tester Salary Data: https://www.payscale.com/research/US/Job=Penetration_Tester/Salary
- ZipRecruiter Penetration Tester Salary: https://www.ziprecruiter.com/Salaries/Penetration-Tester-Salary
- Glassdoor Penetration Tester Salary: https://www.glassdoor.com/Salaries/penetration-tester-salary-SRCH_KO0,21.htm
- CompTIA Security+ vs GPEN Comparison: https://www.comptia.org/certifications/security
Last verified: 2026-05-02
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Offensive Security Domain
Related certifications: GIAC_GCIH_Incident_Handler.md · GIAC_GSEC_Security_Essentials.md