- 82 questions, 3 hours, 71% to pass - mix of multiple-choice and CyberLive hands-on tasks.
- Exam-only registration is $999; retake is $899 after a mandatory 30-day wait.
- You get 120 days from activation to sit the attempt - plan your date immediately.
- Open book is allowed, but only hardcopy books, notes, and an index - no internet, no digital references.
Exam Format at a Glance
GWAPT stands for GIAC Web Application Penetration Tester, a certification issued by the Global Information Assurance Certification (GIAC) body. If you've landed here from a search for a different "GWAPT," this page is specifically about the GIAC credential tied to SANS SEC542 training - keep that distinction in mind whenever you're comparing pricing or domain content across sites.
The exam itself is a single web-based, proctored assessment: 82 questions, a 3-hour time limit, and a minimum passing score of 71%. It's not purely multiple-choice - GIAC blends traditional questions with CyberLive virtual-machine tasks, meaning you'll actually interact with a live environment to demonstrate technique rather than just recall a definition. That hybrid format is the single biggest reason generic "read and memorize" study plans fail this exam.
For a deeper breakdown of how difficult candidates actually find this exam in practice, see How Hard Is the GWAPT Exam? Complete Difficulty Guide 2026. If you want the full data picture on outcomes, GWAPT Pass Rate 2026: What the Data Shows is worth reading before you commit to a date.
Fees and Registration Logistics
Budgeting for GWAPT means separating the exam cost from the training cost - they are purchased independently. Here's the current fee structure straight from GIAC's own pricing:
| Item | Cost |
|---|---|
| Exam-only certification attempt | $999 USD (before taxes) |
| Retake attempt | $899 |
| Standalone official practice test | $399 |
| Attempt extension | $479 |
A failed attempt requires a mandatory 30-day waiting period before you can retake. That waiting period should factor into how you plan a second attempt - it's not something you can shortcut by paying more. Once your attempt is activated, the clock starts: you have 120 days to complete it, so don't activate before you're genuinely ready to schedule a session.
For the complete cost breakdown, including how training factors into total spend, check GWAPT Certification Cost 2026: Complete Pricing Breakdown. And if you're still deciding whether the investment makes sense for your career stage, Is the GWAPT Certification Worth It? Complete ROI Analysis 2026 lays out the ROI considerations.
Key Takeaway
Activate your attempt only when you have a realistic 120-day study runway mapped out - extensions cost $479, and it's cheaper to simply activate later.
The 8 GWAPT Domains, Fast
GIAC publishes eight certification-objective domains for GWAPT. These aren't equally weighted trivia categories - they map directly to the workflow of an actual web app penetration test, from initial recon through exploitation and tooling. Memorize the sequence and you'll understand why the exam is structured the way it is.
Domain 1: Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Covers XSS variants (reflected, stored, DOM-based), CSRF token bypass logic, and other client-side injection vectors.
- Distinguish reflected vs. stored XSS payload delivery
- Understand CSRF token validation weaknesses
Domain 2: Reconnaissance and Mapping
Enumeration and application footprinting techniques that establish the attack surface before exploitation begins.
- Spidering and content discovery methodology
- Identifying technology stack fingerprints
Domain 3: Web Application Authentication Attacks
Attacks against login mechanisms, credential handling, and multi-factor implementation flaws.
- Brute force and credential stuffing considerations
- Password reset and account recovery flaws
Domain 4: Web Application Configuration Testing
Server and framework misconfiguration issues that expose sensitive data or functionality.
- Default credentials and exposed admin panels
- HTTP header and security control misconfigurations
Domain 5: Web Application Overview
Foundational concepts of how web applications, HTTP, and browser interactions work - the baseline everything else builds on.
- HTTP request/response mechanics
- Core application architecture concepts
Domain 6: Web Application Session Management
How sessions are created, maintained, and can be hijacked or fixed by an attacker.
- Session token entropy and predictability
- Session fixation and hijacking scenarios
Domain 7: Web Application SQL Injection Attacks
Classic and blind SQL injection technique identification and exploitation logic.
- Error-based vs. blind/time-based injection
- Database-specific syntax differences
Domain 8: Web Application Testing Tools
Practical fluency with the tooling used throughout an assessment - this is where CyberLive tasks concentrate.
- Proxy-based interception and manipulation workflows
- Automated scanning vs. manual verification tradeoffs
For a much more detailed walk-through of each domain with study emphasis guidance, see GWAPT Exam Domains 2026: Complete Guide to All 8 Content Areas.
Open-Book Index Strategy
GWAPT is an open-book exam, but the rules are specific: you may bring hardcopy books, printed notes, and a self-built index. Internet access, personal electronic references, and any practice-question or answer collections are explicitly prohibited. This means your prep should include building a physical, tabbed index while you study - not scrambling to create one the night before.
Because you can't search digitally during the exam, your index needs to be organized by domain and cross-referenced by tool/technique name. Many candidates build this index directly from SEC542 material and their own hands-on lab notes, which is one reason the official training track pairs so closely with exam performance. Full guidance on structuring this kind of prep lives in GWAPT Study Guide 2026: How to Pass on Your First Attempt.
A Domain-Weighted Prep Sequence
Rather than a generic study calendar, sequence your prep around the natural flow of a penetration test - this mirrors how the domains build on each other and reduces redundant review later.
Domain 5 & Domain 2
- Solidify HTTP fundamentals and application architecture (Domain 5)
- Practice enumeration and mapping workflows (Domain 2)
Domain 3 & Domain 6
- Drill authentication attack scenarios
- Study session token weaknesses and hijacking patterns
Domain 1 & Domain 7
- Build XSS/CSRF payload recognition
- Practice SQL injection variants including blind techniques
Domain 4 & Domain 8
- Review configuration testing checklists
- Get hands-on with proxy tools ahead of CyberLive tasks
- Finalize your index and schedule your attempt
Adjust this pacing to your existing experience - someone coming from a hands-on pentesting role may compress the first weeks, while someone newer to the field should slow down on Domains 5 and 2 before moving forward. If you're unsure whether your background even qualifies you to sit for the exam, review GWAPT Requirements 2026: Eligibility, Prerequisites & How to Qualify - GIAC accepts practical work experience, college coursework, and self-paced study as valid preparation routes, not just formal training.
Who Hires GWAPT Holders
The domain list itself tells you the target roles: penetration testers, application security analysts, and security consultants who need to assess web apps rather than networks or infrastructure. Because the exam explicitly tests SQL injection, XSS/CSRF, authentication attacks, and tooling fluency together, it signals hands-on offensive capability specific to the web layer - distinct from broader security generalist certifications.
Organizations running bug bounty programs, application security teams inside SaaS companies, and consulting firms that perform web app assessments are common environments where this credential is referenced. For a broader look at how this translates into job titles and compensation ranges, see GWAPT Salary Guide 2026: Complete Earnings Analysis and browse current openings via GWAPT Jobs.
Key Takeaway
Domains 1, 3, 6, and 7 map almost directly onto the OWASP-style vulnerability classes employers expect a web app pentester to demonstrate in an interview.
Renewal and Retake Math
Once earned, GWAPT is valid for 4 years. Renewal happens through one of two routes: accumulate 36 CPEs and pay the standard $499 renewal fee, or sit a renewal examination instead. Plan your CPE accumulation early in the 4-year window rather than scrambling near expiration - conference attendance, relevant training, and other GIAC-recognized activities all count toward the total.
If your first attempt doesn't succeed, remember the mechanics: a 30-day waiting period applies before you can register for the $899 retake. Use that mandatory gap productively - it's built-in time to revisit weak domains rather than dead time. Before you even sit the first attempt, it helps to know exactly what score you're aiming for; GWAPT Passing Score 2026: Exactly What You Need to Pass breaks down the 71% threshold in more depth, and GWAPT Exam Dates 2026: Testing Windows, Deadlines & Scheduling covers how the 120-day activation window interacts with scheduling ProctorU or Pearson VUE sessions.
If you're still early in your research and want the broader picture of what this certification actually covers before diving into domain-level prep, start with What Is GWAPT Certification? or the general overview at GWAPT Certification. For quick terminology clarification, GWAPT Meaning and What Does GWAPT Stand For? cover the basics, while GWAPT Training outlines the SEC542 course pairing in more detail.
Use this page as your recurring reference sheet - bookmark it alongside our GWAPT practice test platform so you can cross-check facts against real exam-style questions as you study. Rotating between this cheat sheet and timed practice sessions is one of the most efficient ways to confirm you've actually retained the domain material rather than just recognized it on a page.
Frequently Asked Questions
82 questions within a 3-hour time limit, combining multiple-choice items with CyberLive hands-on tasks.
A minimum of 71% is required to pass the GWAPT exam.
No. The exam is open book for hardcopy books, notes, and an index only - internet access, personal electronic references, and practice-question collections are prohibited.
An exam-only attempt is $999 USD before taxes. A retake after a failed attempt costs $899, and there's a mandatory 30-day wait before retaking.
GWAPT is valid for 4 years. Renew through 36 CPEs plus a $499 fee, or via a renewal examination route.