GWAPT logo
Focused certification exam prep
Start practice

GWAPT Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • GWAPT covers 8 published domains, from reconnaissance through SQLi to testing tools.
  • The exam is 82 questions in 3 hours, open-book, with a 71% passing score.
  • Hands-on CyberLive tasks test tool use inside the domains, not just theory recall.
  • Exam-only registration costs $999; retakes are $899 after a 30-day wait.

GWAPT Exam Format Overview

The GIAC Web Application Penetration Tester (GWAPT) exam is a single, web-based, proctored assessment: 82 questions, a 3-hour time limit, and a minimum passing score of 71%. Unlike purely multiple-choice certifications, GWAPT blends traditional question formats with CyberLive tasks - live virtual-machine environments where you actually run commands, inspect requests, and manipulate application behavior rather than just answer about it. That format matters directly for how you should study each of the eight domains below, because memorizing terminology alone will not get you through the practical sections.

You can sit the exam through ProctorU remote proctoring or at a Pearson VUE test center, depending on how your specific attempt is authorized. It's open-book - hardcopy books, printed notes, and an index are allowed - but internet access, personal electronic devices, and any pre-made practice-question collections are strictly prohibited. Once you submit an answer you can't revise it, though skipped questions can be revisited before time runs out. For a full breakdown of scoring mechanics, see our GWAPT Passing Score guide, and for scheduling logistics check GWAPT Exam Dates 2026.

Why the Domains Matter More Than a Syllabus: GIAC publishes these eight domain names as the actual certification objectives - they are the exam blueprint, not a loose course outline. Every CyberLive task and every multiple-choice item traces back to one of these eight areas.

Domain 1: Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

This domain focuses on client-side attack vectors that abuse trust between the browser, the user, and the application. You need to distinguish reflected, stored, and DOM-based XSS, understand how CSRF tokens are supposed to prevent forged requests, and recognize when input sanitization fails to stop injection into HTML, JavaScript, or attribute contexts.

  • Crafting and recognizing payloads that break out of different injection contexts
  • Understanding same-origin policy and why it does or doesn't block a given attack
  • Identifying missing or predictable anti-CSRF tokens in request flows

Candidates who treat this domain as "just XSS trivia" tend to struggle with the CyberLive component, where you're asked to actually construct a working payload against a live target rather than pick the right answer from a list.

Domain 2: Reconnaissance and Mapping

Reconnaissance and Mapping

Before you attack an application, you have to understand its footprint. This domain covers passive and active information gathering: identifying technology stacks, enumerating hidden endpoints, spidering application structure, and building an attack surface map that informs everything that follows.

  • Passive OSINT techniques versus active scanning and their tradeoffs
  • Directory and file enumeration to discover unlinked or forgotten resources
  • Fingerprinting frameworks, servers, and third-party components

Domain 3: Web Application Authentication Attacks

Web Application Authentication Attacks

Authentication mechanisms are a favorite pentest target because failures here often grant direct account takeover. This domain expects familiarity with credential-based attacks, weaknesses in password reset and account recovery flows, and multi-factor bypass techniques.

  • Brute force and credential stuffing considerations against login forms
  • Logic flaws in password reset, "remember me," and account recovery
  • Weaknesses in how applications implement or bypass multi-factor checks

Domain 4: Web Application Configuration Testing

Web Application Configuration Testing

Not every vulnerability comes from bad code - plenty come from bad configuration. This domain covers server and application hardening gaps: verbose error messages, exposed admin interfaces, misconfigured HTTP headers, and overly permissive access controls.

  • Identifying insecure HTTP security headers and their real-world impact
  • Spotting default credentials, exposed configuration files, and debug interfaces
  • Evaluating transport security and certificate/configuration weaknesses

Domain 5: Web Application Overview

Web Application Overview

This domain establishes the foundational knowledge everything else builds on: how HTTP requests and responses actually work, how web architectures are structured, and how a pentester should scope and plan an engagement. If you're weak here, the more technical domains will feel disconnected.

  • HTTP methods, status codes, headers, and request/response structure
  • Client-server architecture and where trust boundaries typically break down
  • Scoping and methodology considerations before testing begins

Key Takeaway

Treat Domain 5 as your foundation layer - review it first even if it feels basic, because the CyberLive tasks in later domains assume fluency with raw HTTP request/response mechanics.

Domain 6: Web Application Session Management

Web Application Session Management

Sessions are how applications maintain state after login, and broken session handling is one of the most common paths to account compromise. This domain covers cookie attributes, session fixation, token predictability, and improper session termination.

  • Secure, HttpOnly, and SameSite cookie attributes and what happens when they're missing
  • Session fixation and session hijacking scenarios
  • Weak or predictable session token generation

Domain 7: Web Application SQL Injection Attacks

Web Application SQL Injection Attacks

SQL injection remains a core penetration testing skill, and this domain tests both detection and exploitation depth: error-based, blind, and time-based injection techniques, along with the ability to extract data and understand database-specific syntax quirks.

  • Differentiating in-band, blind, and out-of-band SQL injection
  • Constructing payloads for data extraction and enumeration
  • Recognizing when parameterization or ORM usage actually mitigates risk

Domain 8: Web Application Testing Tools

Web Application Testing Tools

This is the domain most directly tied to CyberLive's hands-on nature. You're expected to know how to actually operate the tools of the trade - proxies, scanners, and manual testing utilities - not just name them.

  • Intercepting proxy workflows for request manipulation and replay
  • Automated scanning tools and interpreting their output critically
  • Manual testing techniques that complement automated findings
CyberLive Reality Check: Domains involving active exploitation - CSRF/XSS, authentication attacks, SQL injection, and testing tools - are the ones most likely to appear as live VM tasks. Reading about a payload is different from typing it correctly under time pressure.

How the Domains Map to Study Time

GIAC does not publish a fixed percentage weighting per domain for GWAPT, so resist any study plan that promises precise domain percentages - that number is not something GIAC has released. What you can do instead is sequence your study by dependency and hands-on complexity. Domain 5 (Web Application Overview) and Domain 2 (Reconnaissance and Mapping) form the conceptual base; Domains 1, 3, 6, and 7 are the attack-technique core; Domain 4 and Domain 8 round out configuration awareness and tool fluency.

Domain GroupFocusStudy Approach
Foundational (5, 2)HTTP mechanics, architecture, reconRead first; build vocabulary and mental model
Attack Techniques (1, 3, 6, 7)XSS/CSRF, auth attacks, sessions, SQLiHands-on labs, repeated payload practice
Operational (4, 8)Config testing, tool usagePractice with proxy tools and scanners directly

If you want a condensed version of the concepts across all eight domains for last-minute review, our GWAPT Cheat Sheet 2026 distills the must-know facts into one page. For a broader study framework that sequences these domains across weeks, see the GWAPT Study Guide 2026.

Weeks 1-2

Foundation and Recon

  • Master Domain 5 (Web Application Overview) HTTP fundamentals
  • Practice Domain 2 (Reconnaissance and Mapping) enumeration techniques
Weeks 3-5

Core Attack Domains

  • Drill Domain 1 (CSRF/XSS/injection) payload construction
  • Work through Domain 3 (authentication attacks) and Domain 6 (session management) scenarios
  • Practice Domain 7 (SQL injection) extraction techniques
Week 6

Configuration and Tools

  • Review Domain 4 (configuration testing) checklists
  • Get comfortable in Domain 8 (testing tools) proxy and scanner workflows

Registration, Fees, and Retake Mechanics

The exam-only certification attempt costs $999 USD before taxes, and training through SANS SEC542: Web App Penetration Testing and Ethical Hacking is purchased separately. Once your attempt is activated, you have 120 days to complete it - plan your domain review schedule around that window rather than an open-ended timeline. If you don't pass, a retake costs $899, and GIAC requires a 30-day waiting period before you can attempt again.

Additional options worth budgeting for: a standalone official practice test for $399, and an attempt extension for $479 if you need more time within your activation window. None of these fees include training costs, so plan your full budget before registering. A detailed breakdown of every fee combination lives in our GWAPT Certification Cost 2026 guide, and eligibility specifics are covered in GWAPT Requirements 2026.

Key Takeaway

Because submitted answers can't be changed, use the built-in scratch notepad to flag uncertain domain-1 or domain-7 questions and revisit them before your 3-hour window closes.

Who Actually Hires for GWAPT

Organizations hiring for application security testing, penetration testing, and offensive security roles look for GWAPT because it validates hands-on ability across exactly the eight domains above - not just theoretical security knowledge. It signals that a candidate can move from reconnaissance through exploitation to reporting on real web applications. If you're weighing whether the credential is worth pursuing relative to your career goals, our ROI analysis and salary guide go deeper into market positioning, and GWAPT Jobs surveys the kinds of roles where this credential is commonly listed as preferred or required.

GIAC also recognizes multiple preparation routes beyond formal training - practical work experience, college coursework, and self-paced study are all acceptable ways to prepare, which is part of why the domain list matters so much: it's your objective checklist regardless of how you got there.

Certification Validity: GWAPT is valid for 4 years. Renewal requires either 36 CPEs plus the standard $499 renewal fee, or a renewal examination route - so the domain knowledge you build now has a maintenance path, not just a one-time payoff.

If you're still confirming exactly what this credential entails before diving into domain-level prep, start with What Is GWAPT Certification? or the broader GWAPT Certification overview. For a difficulty-focused perspective that weighs the CyberLive format against these eight domains, see How Hard Is the GWAPT Exam?, and for context on outcomes, our GWAPT Pass Rate 2026 article uses only officially reported figures rather than guesses. You can also sharpen your domain-specific instincts using realistic practice questions on our practice test platform before exam day.

FAQ

How many domains are on the GWAPT exam?

GIAC publishes eight certification-objective domains for GWAPT, ranging from Reconnaissance and Mapping through Web Application Testing Tools, as detailed throughout this guide.

Does GIAC publish exact percentage weights for each domain?

No official per-domain percentage breakdown is published for GWAPT. Study by dependency and hands-on complexity instead of chasing an unpublished weighting figure.

Are the CyberLive tasks tied to specific domains?

Yes. Hands-on virtual-machine tasks most commonly relate to exploitation-heavy domains like CSRF/XSS/injection, authentication attacks, SQL injection, and testing tools, since those skills require doing rather than describing.

What training aligns to these eight domains?

SANS SEC542: Web App Penetration Testing and Ethical Hacking is the associated training course, though GIAC also accepts practical experience, college coursework, and self-study as preparation.

How much time do I have to complete the exam once registered?

You must complete your attempt within 120 days of activation. Your candidate account shows the attempt-specific exam specifications, including the 82-question, 3-hour format and 71% passing score.

Ready to pass your GWAPT exam?

Put this into practice with free GWAPT questions across every exam domain.