- GWAPT is one 82-question exam over 3 hours combining multiple-choice with hands-on CyberLive tasks.
- You need 71% to pass; the exam maps to 8 published domains from recon to SQL injection.
- Exam-only registration costs $999; a failed attempt requires a 30-day wait before a $899 retake.
- The exam is open book with hardcopy notes and an index - but no internet or pre-made answer banks.
What the GWAPT Actually Tests
The GIAC Web Application Penetration Tester (GWAPT) credential, administered by GIAC, exists to verify that a candidate can actually assess and attack web applications, not just recite security theory. If you've landed here after searching around, our companion pieces on what GWAPT is and GWAPT meaning cover the basics; this guide is the tactical, exam-day version aimed squarely at first-attempt passing.
GWAPT is built around the associated SANS SEC542: Web App Penetration Testing and Ethical Hacking course, though GIAC explicitly lists practical work experience, college coursework, and self-paced study as valid preparation routes too - you are not required to sit the SANS class to take the exam. For a fuller breakdown of who is eligible and how prerequisites work, see GWAPT Requirements 2026.
Exam Format, Timing, and CyberLive Tasks
The GWAPT exam is a single, web-based, proctored assessment: 82 questions, 3 hours, minimum passing score of 71%. It blends standard multiple-choice items with CyberLive tasks - hands-on exercises performed against live virtual machines inside the exam interface. This is a meaningful difference from a purely multiple-choice certification exam, and it's the single most important thing to understand before you build a study plan. For a deeper dive into exactly how demanding this format is relative to other options, read How Hard Is the GWAPT Exam?.
You can sit the exam via ProctorU remote proctoring or at a Pearson VUE test center, depending on what's authorized for your registered attempt - check your candidate account, which also lists the attempt-specific exam specifications you'll be held to.
Two mechanics matter for pacing strategy:
- Submitted answers are locked. Once you confirm an answer, you cannot go back and change it.
- Skipped questions can be revisited. If a question stalls you, skip it rather than guess-and-lock; return to it once you've banked easier points.
The exam engine also provides an on-screen calculator and a scratch notepad - useful for tracking encoding conversions, hash fragments, or multi-step logic during CyberLive tasks. For the precise scoring mechanics and what 71% means in practice across 82 items, see GWAPT Passing Score 2026.
Key Takeaway
Because CyberLive tasks take longer per question than multiple-choice items, budget your 3 hours unevenly: skim through knowledge questions quickly, then protect a larger reserve of time for hands-on tasks tied to Domains 1, 3, 6, and 7.
The 8 GWAPT Domains, Broken Down
GIAC publishes eight certification-objective domains for GWAPT. Treat these as your master syllabus - every study hour should map back to one of them. A full domain-by-domain walkthrough with subtopics lives at GWAPT Exam Domains 2026: Complete Guide to All 8 Content Areas; here's the condensed, exam-prep version.
Domain 1: Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Covers reflected, stored, and DOM-based XSS, CSRF token bypasses, and other client-side injection vectors.
- Know the difference between stored and reflected XSS payload delivery
- Understand how anti-CSRF tokens can be predicted or replayed
Domain 2: Reconnaissance and Mapping
Passive and active information gathering, application footprinting, and spidering techniques used before an attack begins.
- Practice mapping application structure with proxy-based crawling
- Understand what OSINT sources reveal about attack surface
Domain 3: Web Application Authentication Attacks
Login mechanism weaknesses, credential attacks, and multi-factor bypass patterns.
- Study brute-force and credential-stuffing detection evasion
- Know common password reset and account-recovery flaws
Domain 4: Web Application Configuration Testing
Server and framework misconfiguration, exposed admin interfaces, and default-credential risks.
- Review common HTTP header and TLS configuration mistakes
- Understand directory listing and verbose error disclosure risks
Domain 5: Web Application Overview
Foundational architecture concepts: HTTP mechanics, request/response structure, and application component relationships.
- Be fluent in HTTP methods, status codes, and header semantics
Domain 6: Web Application Session Management
Cookie handling, session fixation, token entropy, and session hijacking scenarios.
- Practice identifying weak session token generation
- Know how session fixation differs from session hijacking
Domain 7: Web Application SQL Injection Attacks
Classic, blind, and error-based SQL injection, plus exploitation and extraction techniques.
- Master manual injection syntax before relying on automated tools
- Understand time-based and boolean-based blind injection detection
Domain 8: Web Application Testing Tools
Practical use of interception proxies, scanners, and exploitation frameworks common in web app pentesting workflows.
- Get hands-on with proxy-based interception and manipulation
- Practice interpreting scanner output rather than trusting it blindly
Registration, Fees, and Retake Mechanics
Understanding the financial and scheduling mechanics matters as much as the content itself, since a wasted attempt is expensive. Here's the current structure:
| Item | Cost / Rule |
|---|---|
| Exam-only certification attempt | $999 USD before taxes |
| Retake attempt | $899 |
| Standalone official practice test | $399 |
| Attempt extension | $479 |
| Waiting period after a failed attempt | 30 days before retake |
| Attempt window | 120 days from activation |
Note that training (SANS SEC542) is purchased separately from the exam attempt - the $999 figure is exam-only. For the complete cost picture, including how extensions and retakes stack up depending on your scenario, see GWAPT Certification Cost 2026: Complete Pricing Breakdown. If you're trying to plan around specific windows or renewal cycles, GWAPT Exam Dates 2026 covers scheduling logistics in more depth.
A Domain-Driven Study Timeline
Rather than a generic weekly template, sequence your study around which domains carry the heaviest hands-on burden during CyberLive tasks. Domains involving live exploitation (1, 3, 6, 7) deserve more lab repetition than purely conceptual domains (2, 4, 5, 8).
Foundations and Recon
- Domain 5 (Web Application Overview): HTTP fundamentals, request/response anatomy
- Domain 2 (Reconnaissance and Mapping): spidering, footprinting practice
Injection Attacks
- Domain 7 (SQL Injection): manual injection drills, blind injection scenarios
- Domain 1 (XSS/CSRF/Client Injection): build and test payloads in a lab
Identity and State
- Domain 3 (Authentication Attacks): credential attack scenarios
- Domain 6 (Session Management): cookie and token analysis
Configuration and Tools + Full Review
- Domain 4 (Configuration Testing) and Domain 8 (Testing Tools)
- Build your index, take the standalone official practice test, review weak domains
If you want a compressed, one-page reference to sanity-check your index against before exam day, bookmark GWAPT Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Open-Book Strategy: What to Bring, What to Skip
GWAPT is open book, but the allowed materials are narrower than many candidates assume. You may bring hardcopy books, printed notes, and an index. You may not use internet access, personal electronic reference devices, or collections of practice questions and answers during the exam.
This means your index-building work during study is not optional - it's the actual exam strategy. As you move through each domain, build a page-referenced index organized by domain name (Reconnaissance and Mapping, SQL Injection Attacks, Session Management, etc.) rather than alphabetically by tool name. During CyberLive tasks especially, you want to flip to "Domain 7 - injection syntax cheatsheet" in seconds, not hunt page by page.
Key Takeaway
Build your index while you study, not the week before the exam - a rushed index built in one sitting is nearly useless under a 3-hour clock with 82 questions.
Who Hires GWAPT Holders
Because the domains map directly onto offensive web testing work - reconnaissance, authentication attacks, session manipulation, SQL injection, and tool-driven assessment - the credential signals readiness for roles centered on application-layer penetration testing rather than broad network security or GRC work. Organizations running internal red teams, consulting firms performing client web app assessments, and security teams responsible for pre-release application testing are the natural hiring pool.
If you're evaluating whether this specific specialization fits your career trajectory, GWAPT Jobs looks at how the credential is referenced in job postings, and GWAPT Salary Guide 2026 and Is the GWAPT Certification Worth It? weigh the credential against the cost of pursuing it. For context on how competitive the exam actually is, GWAPT Pass Rate 2026: What the Data Shows is worth reading before you commit to a registration date.
Staying Certified: Renewal and CPEs
GWAPT certification is valid for four years. To maintain it, you have two routes: accumulate 36 CPEs and pay the standard $499 renewal fee, or take a renewal examination instead. Plan which route suits you well before your four-year window closes - CPE tracking is far easier if you log activity continuously rather than scrambling in year four.
For readers still deciding whether to pursue the credential at all, our overview articles - GWAPT Certification, What Is GWAPT Certification?, and What Does GWAPT Stand For? - cover the basics before you dive into exam mechanics. And if SANS SEC542 training is on your radar as a preparation route, GWAPT Training breaks down what the course covers relative to the exam domains.
Once you're ready to test your recall against realistic scenario-based questions, practicing under timed conditions on our practice test platform is one of the most direct ways to simulate the pressure of the 3-hour window. Many candidates also use structured practice sets specifically to rehearse domain-switching speed, since the real exam jumps between conceptual and hands-on question types without warning.
FAQ
The GWAPT exam has 82 questions to complete in 3 hours, mixing multiple-choice questions with hands-on CyberLive virtual-machine tasks.
The minimum passing score is 71%. See GWAPT Passing Score 2026 for a deeper breakdown of what that means across 82 questions.
Yes. You may bring hardcopy books, notes, and an index. Internet access, personal electronic reference devices, and pre-made practice question/answer collections are not permitted.
You must wait 30 days before retaking the exam, and the retake fee is $899, separate from the original $999 exam-only registration.
No. SEC542 is the associated training course, but GIAC also recognizes practical work experience, college coursework, and self-paced study as valid preparation routes.