Certification guide

GWAPT

GIAC Web Application Penetration Tester (GWAPT): the honest guide

Everything GIAC publishes about GWAPT, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from GWAPT’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

See everything published on GWAPT

What the exam actually asks you to do

A CyberLive exam. Some of the questions put you into a live machine with the real tools and score what you do there. GIAC does not publish how many of the 82 are hands-on, so neither do we.

Item formats

  • Multiple choice
  • Hands-on lab

The highlighted formats are the ones you cannot answer from memory alone. GIAC, GWAPT certification details

Domain breakdown

Authentication and Session Management Attacks is the heaviest domain at 18 percent, followed by XSS, CSRF, and Client Injection at 18 percent.

GIAC publishes the GWAPT objectives as an unweighted list covering the web application overview, reconnaissance and mapping, authentication attacks, session management, SQL injection, cross-site scripting, cross-site request forgery and client injection, configuration testing, and testing tools. It attaches no percentages. The six groupings above and their percentages are ours, a study aid rather than an official GIAC weighting, and GIAC does not endorse them.

  • Web Application Overview and Reconnaissance16%
  • Authentication and Session Management Attacks18%
  • SQL Injection16%
  • XSS, CSRF, and Client Injection18%
  • Configuration Testing14%
  • Web Application Testing Tools18%

Where to focus: GWAPT is a web pen-test exam, so its CyberLive items expect you to find and exploit a flaw, not name it. Work through a deliberately vulnerable app with Burp or ZAP in front of you: knowing where SQL injection and stored XSS actually surface in a request is what the clock rewards.

GIAC: GIAC certification objectives

What comes after passing

GWAPT is valid for 4 years. GIAC certifications last four years. GIAC lists two renewal routes: collect 36 CPE credits over the four year cycle and pay the renewal fee, or retake the current exam. Additional renewals within two years of a full price renewal are charged at a reduced rate.

Costs across the full renewal cycle are on the GWAPT cost page.

Frequently asked questions

What does the GWAPT exam cost?

GIAC's pricing page lists a GIAC certification attempt at $999. The certification attempt can be bought on its own, without a training course.

Is the GWAPT exam hands-on?

GIAC tags GWAPT as a CyberLive certification. GIAC describes CyberLive as a hands-on format that replaces multiple choice with performance-based challenges in lab environments using virtual machines and real tools. The exam format section lists 1 proctored exam, 82 questions, 3 hours, and a minimum passing score of 71%.

Are there prerequisites for GWAPT?

GIAC's GWAPT page lists no prerequisite. Under How To Prepare it points to training in a variety of modalities, practical work experience, and self study.

Keep reading

Every guide and cost breakdown, by vendor