GIAC GPEN Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Domain 1: Planning & scoping — Rules of engagement, legal considerations, methodologies
Domain 2: Reconnaissance — OSINT, DNS recon, Google dorking, Shodan, attack surface mapping
Domain 3: Scanning — Nmap advanced techniques, host discovery, service enumeration
Domain 3: Enumeration — SMB, SNMP, web apps, vulnerability scanning, network mapping
Domain 4: Exploitation — Metasploit, buffer overflows, service exploitation
Domain 4: Web exploitation — SQL injection, XSS, authentication bypass, web shells
Domain 4: Password & wireless — Brute force, hash cracking, WPA attacks, client-side
Domain 5: Post-exploitation — Windows/Linux privilege escalation techniques
Domain 5: Pivoting — Lateral movement, port forwarding, tunneling, AD attacks
Domain 6: Reporting — Report writing, risk ratings, remediation recommendations
Index Building: Create open-book index for exam day, organize notes by topic
Full Review: Practice exams, Index refinement, Weak areas, Exam logistics
Free Resources
Related Tools
GIAC GPEN Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the GIAC GPEN Study Planner
Fillable PDF with 12-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99