1. Home
  2. GIAC
  3. GPEN Exam Syllabus

GIAC GPEN Exam Syllabus

Start Free GPEN Exam Practice After Reviewing the Topics

Before starting your GPEN exam preparation, it is recommended to review the complete GIAC Certified Penetration Tester exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free GPEN questions. We also provide premium GPEN practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

Vendor
GPEN
Exam Code
391
Total Questions
17
Total Exam Domains

START FREE GPEN EXAM PRACTICE

NO SIGNUP REQUIRED  •  100% FREE TO START

GPEN EXAM QUESTIONS

GIAC GPEN Exam Objectives

Section 1: Advanced Password Attacks
Weight:
-
The candidate will be able to use additional methods to attack password hashes and authenticate.
Section 2: Attacking Password Hashes
Weight:
-
The candidate will be able to obtain and attack password hashes and other password representations.
Section 3: Azure Applications and Attack Strategies
Weight:
-
The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols
Section 4: Azure Overview, Attacks, and AD Integration
Weight:
-
The candidate will demonstrate an understanding of Azure Active Directory implementation fundamentals, common Azure AD attacks, and Azure authentication techniques
Section 5: Domain Escalation and Persistence Attacks
Weight:
-
The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory.
Section 6: Escalation and Exploitation
Weight:
-
The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network.
Section 7: Exploitation Fundamentals
Weight:
-
The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest.
Section 8: Kerberos Attacks
Weight:
-
The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks.
Section 9: Metasploit
Weight:
-
The candidate will be able to use and configure the Metasploit Framework at an intermediate level.
Section 10: Moving Files with Exploits
Weight:
-
The candidate will be able to use exploits to move files between remote systems.
Section 11: Password Attacks
Weight:
-
The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks.
Section 12: Password Formats and Hashes
Weight:
-
The candidate will demonstrate an understanding of common password hashes and formats for storing password data.
Section 13: Penetration Test Planning
Weight:
-
The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting.
Section 14: Penetration Testing with PowerShell and the Windows Command Line
Weight:
-
The candidate will demonstrate an understanding of the use of advanced Windows command line skills during a penetration test, and demonstrate an understanding of the use of advanced Windows Power Shell skills during a penetration test.
Section 15: Reconnaissance
Weight:
-
The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems.
Section 16: Scanning and Host Discovery
Weight:
-
The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results.
Section 17: Vulnerability Scanning
Weight:
-
The candidate will be able to conduct vulnerability scans and analyze the results.
Info