GIAC · 2026 Edition
A complete preparation guide, edited by Johnson Ajibi, a network and security engineer with 12+ years' experience. Covers the exam format,all 15 blueprint domains, a week-by-week study plan, and proven tips for passing first time.
2–4 months
Prep time
Intermediate
Difficulty
60–90
Exam questions
700/1000
Pass mark
Exam code
GPEN
Full name
GIAC Penetration Tester
Vendor
GIAC
Duration
90 minutes
Questions
~0 items
Passing score
700/1000 (scaled)
Domains covered
15 blueprint domains
Recommended experience
Foundational IT knowledge recommended
Typical prep time
2–4 months
Domain percentage weights are not currently available for this exam. The checklist below is still useful for planning your study.
Phase 1
Attacking Password Hashes
Tip: Start with the official Attacking Password Hashes objectives, then practise questions on it.
Phase 2
Password Attacks and Formats
Tip: Cover the Password Attacks and Formats objectives, then answer practice questions to confirm you can apply them.
Phase 3
Scanning and Host Discovery
Tip: Cover the Scanning and Host Discovery objectives, then answer practice questions to confirm you can apply them.
Phase 4
Metasploit
Tip: Cover the Metasploit objectives, then answer practice questions to confirm you can apply them.
Phase 5
Vulnerability Scanning
Tip: Cover the Vulnerability Scanning objectives, then answer practice questions to confirm you can apply them.
Phase 6
Kerberos Attacks
Tip: Cover the Kerberos Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 7
Reconnaissance
Tip: Cover the Reconnaissance objectives, then answer practice questions to confirm you can apply them.
Phase 8
Command and Control
Tip: Cover the Command and Control objectives, then answer practice questions to confirm you can apply them.
Phase 9
Exploitation Fundamentals
Tip: Cover the Exploitation Fundamentals objectives, then answer practice questions to confirm you can apply them.
Phase 10
Azure AD Integration
Tip: Cover the Azure AD Integration objectives, then answer practice questions to confirm you can apply them.
Phase 11
Domain Escalation and Persistence
Tip: Cover the Domain Escalation and Persistence objectives, then answer practice questions to confirm you can apply them.
Phase 12
Azure Apps and Attacks
Tip: Cover the Azure Apps and Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 13
Escalation and Exploitation
Tip: Cover the Escalation and Exploitation objectives, then answer practice questions to confirm you can apply them.
Phase 14
Advanced Password Attacks
Tip: Cover the Advanced Password Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 15
Pen Test Planning
Tip: Finish with Pen Test Planning, then re-test your weakest earlier domain before a mock exam.
Study the official exam blueprint — weight percentages tell you exactly where to invest prep time.
Practise scenario-based questions regularly — every modern cert exam is scenario-heavy.
Use spaced repetition to retain what you've learned (Courseiva does this automatically).
Book your exam date once you're scoring 80%+ consistently on practice tests.
Review explanations for every wrong answer, not just the question — the 'why' is what makes it stick.
Apply everything in this guide with adaptive practice questions, detailed answer explanations, and domain analytics.