- GWAPT is issued by GIAC and validates hands-on web application penetration testing skill.
- The exam has 82 questions, a 3-hour time limit, and a 71% minimum passing score.
- It covers 8 domains, from reconnaissance to SQL injection to session management.
- The exam-only attempt costs $999 USD; retakes are $899 after a 30-day wait.
What Is GWAPT Certification?
GWAPT stands for GIAC Web Application Penetration Tester, a credential issued by the Global Information Assurance Certification (GIAC) organization. It's built to confirm that a security professional can actually find and exploit vulnerabilities in web applications - not just describe them in theory. Unlike broad security certifications that touch on web testing as one of many topics, GWAPT is laser-focused on the practical mechanics of attacking and assessing web apps.
The certification is closely associated with the SANS SEC542: Web App Penetration Testing and Ethical Hacking course, though GIAC does not require candidates to take that specific training. GIAC explicitly lists practical work experience, college coursework, and self-paced study as valid preparation routes alongside formal training. If you're weighing whether this credential fits your career goals, it helps to first understand what GWAPT is at a conceptual level before diving into exam mechanics.
Exam Format and How the Test Works
The GWAPT exam is a single web-based, proctored assessment consisting of 82 questions delivered over a 3-hour window. It blends traditional multiple-choice questions with hands-on tasks performed inside GIAC's CyberLive virtual-machine environment, meaning some questions require you to actually interact with a simulated target rather than just select an answer from a list.
You need a minimum score of 71% to pass. The exam is open book - you're allowed hardcopy books, personal notes, and an index during the attempt. However, internet access, personal electronic references, and any collection of practice questions or answers are strictly prohibited. Once you submit an answer, it cannot be changed, though you can skip a question and return to it later before time runs out. The exam interface also includes a built-in calculator and scratch notepad for working through technical calculations or notes during the test.
Candidates can sit for the exam through either ProctorU remote proctoring or an in-person Pearson VUE test center, depending on which option is authorized for their registered attempt. For a full breakdown of what to expect minute-by-minute, see the GWAPT difficulty guide, and for the exact scoring threshold and how it's calculated, check the GWAPT passing score breakdown.
Key Takeaway
Because CyberLive tasks require live interaction with a virtual machine, practicing actual exploitation techniques matters more than memorizing flashcards alone.
The 8 GWAPT Exam Domains
GIAC organizes the GWAPT body of knowledge into eight published domains. Each one represents a distinct cluster of skills you'll be tested on, and together they cover the full lifecycle of a web application penetration test - from initial reconnaissance through exploitation and reporting-relevant technical detail.
Domain 1: Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Covers how attackers manipulate client-side trust relationships and inject malicious scripts or requests.
- Identifying reflected, stored, and DOM-based XSS
- Constructing CSRF proof-of-concept attacks
- Recognizing client-side injection vectors
Domain 2: Reconnaissance and Mapping
Focuses on the discovery phase of assessing a target application before active testing begins.
- Enumerating application structure and endpoints
- Identifying technology stacks and hidden content
Domain 3: Web Application Authentication Attacks
Tests understanding of how login mechanisms fail and how attackers exploit weak authentication.
- Password attack techniques against login forms
- Bypassing or weakening multi-step authentication flows
Domain 4: Web Application Configuration Testing
Examines server and application misconfigurations that create exploitable weaknesses.
- Reviewing HTTP headers and security settings
- Identifying default or insecure configuration states
Domain 5: Web Application Overview
Establishes the foundational knowledge of how web applications are architected and how HTTP-based communication works.
- Understanding request/response cycles
- Recognizing common architectural patterns
Domain 6: Web Application Session Management
Covers how sessions are created, maintained, and how attackers hijack or manipulate them.
- Session token analysis
- Session fixation and hijacking techniques
Domain 7: Web Application SQL Injection Attacks
Tests deep familiarity with injecting malicious SQL through application inputs.
- Manual and tool-assisted SQL injection detection
- Extracting and manipulating data through injection flaws
Domain 8: Web Application Testing Tools
Covers the practical tooling used throughout a penetration test engagement.
- Using proxy-based interception tools
- Applying automated scanners appropriately alongside manual testing
For a deeper walkthrough of how these domains interrelate and where to allocate study time, the complete guide to all 8 GWAPT content areas breaks down each domain further.
Registration, Fees, and Timelines
Understanding the financial and administrative mechanics of GWAPT matters just as much as knowing the technical content. Here's how the numbers break down:
| Item | Cost / Detail |
|---|---|
| Exam-only certification attempt | $999 USD before taxes |
| Retake attempt | $899 |
| Standalone official practice test | $399 |
| Attempt extension | $479 |
| Waiting period after a failed attempt | 30 days before retake |
| Attempt window | 120 days from activation |
| Renewal fee (CPE route) | $499 plus 36 CPEs |
Training through SANS SEC542 is a separate purchase from the certification attempt itself - the $999 fee covers only the exam. Once your attempt is activated, you have 120 days to complete it, and your candidate account will display the exact exam specifications tied to your specific attempt. For a full cost breakdown including how these fees stack up in different scenarios, see the GWAPT certification cost breakdown. If you're unsure whether you meet the prerequisites or want to confirm eligibility before paying, review the GWAPT requirements and eligibility guide.
Who Earns GWAPT and Why
GWAPT tends to attract professionals who are directly involved in offensive security work against web applications - penetration testers, application security analysts, bug bounty hunters formalizing their skills, and security consultants who need a vendor-neutral way to prove hands-on capability to clients or employers. Because the exam leans heavily on practical exploitation across authentication, session management, and injection attacks, it signals something different than a generalist security credential.
Organizations that run internal red teams or offer penetration testing services often look for GWAPT specifically because the domain coverage maps closely to real engagement work: mapping an application, probing authentication, testing session handling, and executing SQL injection or XSS attacks are all standard phases of a professional web app pentest. If you're evaluating how this shows up in job postings and career trajectories, the GWAPT jobs overview and the GWAPT salary guide go into more detail on how employers position the credential.
Some candidates also weigh GWAPT against the time and cost investment before committing. If that's where you are, the ROI analysis on whether GWAPT is worth it walks through the tradeoffs without relying on invented statistics.
Preparing for the Exam Domains
Because GWAPT questions include hands-on CyberLive tasks, preparation needs to combine conceptual review with actual practice against vulnerable applications. A study approach that works well for this specific exam involves sequencing your review around the domains that carry the most hands-on weight - SQL Injection, Session Management, and Authentication Attacks - before layering in reconnaissance and configuration testing, which rely more on recognition and methodology.
Foundation and Reconnaissance
- Review Web Application Overview concepts and HTTP fundamentals
- Practice mapping and enumeration techniques from Domain 2
Core Attack Techniques
- Drill SQL Injection payloads and detection methods
- Practice CSRF, XSS, and client injection scenarios hands-on
- Work through authentication and session management attack labs
Tooling and Configuration Review
- Get comfortable with proxy and scanning tools from Domain 8
- Review configuration testing checklists
- Take the official practice test and review index organization
Since the exam is open book with an index but no internet access, building a well-organized personal index during your study period is a practical, GWAPT-specific technique - not a generic study hack. For a more detailed week-by-week plan and index-building strategy, see the GWAPT study guide for passing on your first attempt. A condensed reference of must-know facts across all domains is also available in the GWAPT cheat sheet, and practicing with realistic questions on our GWAPT practice test platform can help you get comfortable with the CyberLive-style question format before exam day.
Key Takeaway
Prioritize hands-on practice with SQL injection, session hijacking, and authentication bypass - these domains are most likely to appear as CyberLive tasks rather than pure multiple-choice.
Renewal and Long-Term Value
GWAPT certification is valid for 4 years from the date it's earned. To maintain it, GIAC offers two renewal paths: accumulating 36 CPEs and paying the standard $499 renewal fee, or completing a renewal examination instead. Neither path requires starting the certification process from scratch, but candidates should plan CPE activities well before the 4-year mark to avoid a lapse.
Because the certification field moves quickly - new attack techniques, frameworks, and tooling emerge constantly - the CPE requirement ensures certified professionals stay current on web application security practices rather than relying solely on knowledge from their original exam date. If you're planning your certification timeline around specific testing windows or deadlines, the GWAPT exam dates and scheduling guide covers how to plan attempt activation around your availability.
For those still deciding on overall exam strategy, comparing your expected performance against publicly available data can be useful - the GWAPT pass rate analysis reviews what's actually known versus commonly assumed. And if you want a single reference page that ties naming, meaning, and certification scope together, see GWAPT meaning, what GWAPT stands for, or the dedicated GWAPT certification overview.
Frequently Asked Questions
GWAPT tests practical web application penetration testing skills across 8 domains, including SQL injection, XSS/CSRF, authentication attacks, session management, reconnaissance, configuration testing, and tool usage - combining multiple-choice questions with hands-on CyberLive virtual-machine tasks.
The exam is 3 hours long with 82 questions, and you need a minimum score of 71% to pass.
Yes. You may bring hardcopy books, personal notes, and an index. Internet access, personal electronic references, and practice-question collections are not allowed during the attempt.
The exam-only attempt is $999 USD before taxes. Additional costs may include a $399 official practice test, a $479 attempt extension, or an $899 retake fee if a first attempt is unsuccessful.
GWAPT is valid for 4 years. Renewal requires either 36 CPEs plus a $499 fee, or passing a renewal examination.
Ready to pass your GWAPT exam?
Put this into practice with free GWAPT questions across every exam domain.