- GWAPT Exam Format Overview
- Domain 1: CSRF, XSS, and Client Injection Attacks
- Domain 2: Reconnaissance and Mapping
- Domain 3: Web Application Authentication Attacks
- Domain 4: Web Application Configuration Testing
- Domain 5: Web Application Overview
- Domain 6: Web Application Session Management
- Domain 7: Web Application SQL Injection Attacks
- Domain 8: Web Application Testing Tools
- How the Domains Map to Study Time
- Registration, Fees, and Retake Mechanics
- Who Actually Hires for GWAPT
- FAQ
- GWAPT covers 8 published domains, from reconnaissance through SQLi to testing tools.
- The exam is 82 questions in 3 hours, open-book, with a 71% passing score.
- Hands-on CyberLive tasks test tool use inside the domains, not just theory recall.
- Exam-only registration costs $999; retakes are $899 after a 30-day wait.
GWAPT Exam Format Overview
The GIAC Web Application Penetration Tester (GWAPT) exam is a single, web-based, proctored assessment: 82 questions, a 3-hour time limit, and a minimum passing score of 71%. Unlike purely multiple-choice certifications, GWAPT blends traditional question formats with CyberLive tasks - live virtual-machine environments where you actually run commands, inspect requests, and manipulate application behavior rather than just answer about it. That format matters directly for how you should study each of the eight domains below, because memorizing terminology alone will not get you through the practical sections.
You can sit the exam through ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. It's open-book - hardcopy books, printed notes, and an index are allowed - but internet access, personal electronic devices, and any pre-made practice-question collections are strictly prohibited. Once you submit an answer you can't revise it, though skipped questions can be revisited before time runs out. For a full breakdown of scoring mechanics, see our GWAPT Passing Score guide, and for scheduling logistics check GWAPT Exam Dates 2026.
Domain 1: Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
This domain focuses on client-side attack vectors that abuse trust between the browser, the user, and the application. You need to distinguish reflected, stored, and DOM-based XSS, understand how CSRF tokens are supposed to prevent forged requests, and recognize when input sanitization fails to stop injection into HTML, JavaScript, or attribute contexts.
- Crafting and recognizing payloads that break out of different injection contexts
- Understanding same-origin policy and why it does or doesn't block a given attack
- Identifying missing or predictable anti-CSRF tokens in request flows
Candidates who treat this domain as "just XSS trivia" tend to struggle with the CyberLive component, where you're asked to actually construct a working payload against a live target rather than pick the right answer from a list.
Domain 2: Reconnaissance and Mapping
Reconnaissance and Mapping
Before you attack an application, you have to understand its footprint. This domain covers passive and active information gathering: identifying technology stacks, enumerating hidden endpoints, spidering application structure, and building an attack surface map that informs everything that follows.
- Passive OSINT techniques versus active scanning and their tradeoffs
- Directory and file enumeration to discover unlinked or forgotten resources
- Fingerprinting frameworks, servers, and third-party components
Domain 3: Web Application Authentication Attacks
Web Application Authentication Attacks
Authentication mechanisms are a favorite pentest target because failures here often grant direct account takeover. This domain expects familiarity with credential-based attacks, weaknesses in password reset and account recovery flows, and multi-factor bypass techniques.
- Brute force and credential stuffing considerations against login forms
- Logic flaws in password reset, "remember me," and account recovery
- Weaknesses in how applications implement or bypass multi-factor checks
Domain 4: Web Application Configuration Testing
Web Application Configuration Testing
Not every vulnerability comes from bad code - plenty come from bad configuration. This domain covers server and application hardening gaps: verbose error messages, exposed admin interfaces, misconfigured HTTP headers, and overly permissive access controls.
- Identifying insecure HTTP security headers and their real-world impact
- Spotting default credentials, exposed configuration files, and debug interfaces
- Evaluating transport security and certificate/configuration weaknesses
Domain 5: Web Application Overview
Web Application Overview
This domain establishes the foundational knowledge everything else builds on: how HTTP requests and responses actually work, how web architectures are structured, and how a pentester should scope and plan an engagement. If you're weak here, the more technical domains will feel disconnected.
- HTTP methods, status codes, headers, and request/response structure
- Client-server architecture and where trust boundaries typically break down
- Scoping and methodology considerations before testing begins
Key Takeaway
Treat Domain 5 as your foundation layer - review it first even if it feels basic, because the CyberLive tasks in later domains assume fluency with raw HTTP request/response mechanics.
Domain 6: Web Application Session Management
Web Application Session Management
Sessions are how applications maintain state after login, and broken session handling is one of the most common paths to account compromise. This domain covers cookie attributes, session fixation, token predictability, and improper session termination.
- Secure, HttpOnly, and SameSite cookie attributes and what happens when they're missing
- Session fixation and session hijacking scenarios
- Weak or predictable session token generation
Domain 7: Web Application SQL Injection Attacks
Web Application SQL Injection Attacks
SQL injection remains a core penetration testing skill, and this domain tests both detection and exploitation depth: error-based, blind, and time-based injection techniques, along with the ability to extract data and understand database-specific syntax quirks.
- Differentiating in-band, blind, and out-of-band SQL injection
- Constructing payloads for data extraction and enumeration
- Recognizing when parameterization or ORM usage actually mitigates risk
Domain 8: Web Application Testing Tools
Web Application Testing Tools
This is the domain most directly tied to CyberLive's hands-on nature. You're expected to know how to actually operate the tools of the trade - proxies, scanners, and manual testing utilities - not just name them.
- Intercepting proxy workflows for request manipulation and replay
- Automated scanning tools and interpreting their output critically
- Manual testing techniques that complement automated findings
How the Domains Map to Study Time
GIAC does not publish a fixed percentage weighting per domain for GWAPT, so resist any study plan that promises precise domain percentages - that number is not something GIAC has released. What you can do instead is sequence your study by dependency and hands-on complexity. Domain 5 (Web Application Overview) and Domain 2 (Reconnaissance and Mapping) form the conceptual base; Domains 1, 3, 6, and 7 are the attack-technique core; Domain 4 and Domain 8 round out configuration awareness and tool fluency.
| Domain Group | Focus | Study Approach |
|---|---|---|
| Foundational (5, 2) | HTTP mechanics, architecture, recon | Read first; build vocabulary and mental model |
| Attack Techniques (1, 3, 6, 7) | XSS/CSRF, auth attacks, sessions, SQLi | Hands-on labs, repeated payload practice |
| Operational (4, 8) | Config testing, tool usage | Practice with proxy tools and scanners directly |
If you want a condensed version of the concepts across all eight domains for last-minute review, our GWAPT Cheat Sheet 2026 distills the must-know facts into one page. For a broader study framework that sequences these domains across weeks, see the GWAPT Study Guide 2026.
Foundation and Recon
- Master Domain 5 (Web Application Overview) HTTP fundamentals
- Practice Domain 2 (Reconnaissance and Mapping) enumeration techniques
Core Attack Domains
- Drill Domain 1 (CSRF/XSS/injection) payload construction
- Work through Domain 3 (authentication attacks) and Domain 6 (session management) scenarios
- Practice Domain 7 (SQL injection) extraction techniques
Configuration and Tools
- Review Domain 4 (configuration testing) checklists
- Get comfortable in Domain 8 (testing tools) proxy and scanner workflows
Registration, Fees, and Retake Mechanics
The exam-only certification attempt costs $999 USD before taxes, and training through SANS SEC542: Web App Penetration Testing and Ethical Hacking is purchased separately. Once your attempt is activated, you have 120 days to complete it - plan your domain review schedule around that window rather than an open-ended timeline. If you don't pass, a retake costs $899, and GIAC requires a 30-day waiting period before you can attempt again.
Additional options worth budgeting for: a standalone official practice test for $399, and an attempt extension for $479 if you need more time within your activation window. None of these fees include training costs, so plan your full budget before registering. A detailed breakdown of every fee combination lives in our GWAPT Certification Cost 2026 guide, and eligibility specifics are covered in GWAPT Requirements 2026.
Key Takeaway
Because submitted answers can't be changed, use the built-in scratch notepad to flag uncertain domain-1 or domain-7 questions and revisit them before your 3-hour window closes.
Who Actually Hires for GWAPT
Organizations hiring for application security testing, penetration testing, and offensive security roles look for GWAPT because it validates hands-on ability across exactly the eight domains above - not just theoretical security knowledge. It signals that a candidate can move from reconnaissance through exploitation to reporting on real web applications. If you're weighing whether the credential is worth pursuing relative to your career goals, our ROI analysis and salary guide go deeper into market positioning, and GWAPT Jobs surveys the kinds of roles where this credential is commonly listed as preferred or required.
GIAC also recognizes multiple preparation routes beyond formal training - practical work experience, college coursework, and self-paced study are all acceptable ways to prepare, which is part of why the domain list matters so much: it's your objective checklist regardless of how you got there.
If you're still confirming exactly what this credential entails before diving into domain-level prep, start with What Is GWAPT Certification? or the broader GWAPT Certification overview. For a difficulty-focused perspective that weighs the CyberLive format against these eight domains, see How Hard Is the GWAPT Exam?, and for context on outcomes, our GWAPT Pass Rate 2026 article uses only officially reported figures rather than guesses. You can also sharpen your domain-specific instincts using realistic practice questions on our practice test platform before exam day.
FAQ
GIAC publishes eight certification-objective domains for GWAPT, ranging from Reconnaissance and Mapping through Web Application Testing Tools, as detailed throughout this guide.
No official per-domain percentage breakdown is published for GWAPT. Study by dependency and hands-on complexity instead of chasing an unpublished weighting figure.
Yes. Hands-on virtual-machine tasks most commonly relate to exploitation-heavy domains like CSRF/XSS/injection, authentication attacks, SQL injection, and testing tools, since those skills require doing rather than describing.
SANS SEC542: Web App Penetration Testing and Ethical Hacking is the associated training course, though GIAC also accepts practical experience, college coursework, and self-study as preparation.
You must complete your attempt within 120 days of activation. Your candidate account shows the attempt-specific exam specifications, including the 82-question, 3-hour format and 71% passing score.