GWAPT
The GWAPT is GIAC's specialist certification proving you can find and exploit real vulnerabilities in web applications — SQL injection, cross-site scripting, broken authentication, and session flaws — not just describe them. It maps to the SANS SEC542 curriculum and is a recognized credential for application security and offensive-security roles, frequently named in DoD 8140 and employer hiring lists. With an 82-question, open-book exam and a 71% cut score, a single weak attempt can cost a hefty retake fee and weeks of delay. This page lays out exactly what the exam covers, how it's delivered, and how to clear it on the first sitting.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the GIAC GWAPT exam is built — at a glance
82
82 questions in one sitting, mostly multiple-choice with some interactive items. There's no on-screen section breakdown — your final percentage is what counts.
71%
You must score 71% or higher. That means missing more than about 23 of the 82 questions fails you — a thinner margin than it looks under a 3-hour clock.
3h
Three hours for 82 questions — roughly 2 minutes each. Open-book candidates who index poorly burn that budget flipping pages instead of answering.
Like every GIAC certification, the GWAPT is open book — you may bring printed, indexed reference material into the exam. No laptop, phone, tablet, or electronic notes are permitted. Most candidates build a physical index of the SANS SEC542 course books so they can jump to the right page in seconds.
Scoring is a single overall percentage against a fixed 71% cut — no curve, no per-domain minimum. A practice test is bundled with your exam attempt so you can gauge readiness first. Once certified, the GWAPT stays valid for 4 years; you renew by submitting 36 CPE credits or by retaking the current exam.
GIAC publishes the GWAPT objectives but not exact weights — bars show relative emphasis, not official percentages
Profiling the target, fingerprinting the stack, spidering content, and mapping the full attack surface before any exploitation begins.
Detecting and exploiting SQL injection — error-based, union, and blind techniques — to extract data and pivot deeper into the application.
Cross-site scripting, cross-site request forgery, and other client-side injection attacks — crafting payloads and understanding their impact.
Bypassing and abusing web application authentication — credential attacks, logic flaws, and weak access controls.
Analyzing and attacking session handling — token prediction, fixation, hijacking, and weaknesses in cookie and session design.
Configuration testing plus practical use of the web-app testing toolkit — proxies, scanners, and fuzzers used across a methodology-driven assessment.
GIAC frames the GWAPT around a repeatable methodology: reconnaissance, mapping, discovery, and exploitation, finished with clear reporting. Because the cut is a single 71% figure, you can't lean on one strong area — a thin grasp of SQL injection or XSS will quietly drag your total below the line.
Two ways to sit the exam — and what to expect on test day
Take the exam from a private room at home or office, monitored live through ProctorU. You'll complete a system check, a webcam room scan, and a government ID verification beforehand. You may keep your printed, indexed reference books on the desk, but no electronic devices are allowed.
Sit the exam in a quiet, monitored room at a Pearson VUE test center. Staff verify your government-issued ID and supervise the session. You bring your printed reference materials; the center provides the workstation. A good fit if your home setup can't meet the online proctoring rules.
A valid, unexpired government photo ID whose name matches your GIAC account exactly. The proctor confirms your identity before the exam unlocks.
For online attempts: a clear desk, no second monitor, no phone within reach, and a webcam scan of the room. Printed reference books are allowed; electronic notes are not.
Stay in frame and on-camera throughout the 3-hour window. Leaving the seat, talking aloud, or a dropped connection can flag the session for review.
The GWAPT is built for hands-on web application security work
No formal requirements — but it's a genuinely technical exam
Difficulty: The GWAPT is open book, but "open book" misleads people — questions probe whether you actually understand how to exploit and chain web flaws, not whether you can find a definition. The pressure points are the 71% cut, the 3-hour clock, and the need for a tight, well-indexed reference set. That's exactly the kind of preparation our help is built to handle.
The GWAPT is a high-stakes, time-boxed exam with a real money cost on every attempt. Exam Assist pairs you with a vetted web-application security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your delivery method (ProctorU online or Pearson VUE center), your target test window, and whether this ties to a job or compliance deadline. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and the 71% bar and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a GWAPT specialist who maps the work around the objectives, the open-book index strategy, and the proctoring environment — discreetly and confidentially.
You only pay once your passing result is confirmed on your official GIAC report. No verified result, nothing owed.
Tell us about your exam and get a straight, no-pressure feasibility answer — you settle only after you pass.
Straight answers about the GIAC GWAPT exam
Get started, read a guide, and compare sibling exams
Pair with a vetted web-app security specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Book the GWAPT GuideBuilding toward a security career? This study playbook covers how to structure prep and exam strategy for technical security certifications.
Read the guide GPENGIAC's broader network and infrastructure pentest certification — a natural companion to the web-focused GWAPT.
View exam GXPNThe advanced, expert-level GIAC pentest credential — for those ready to go beyond GWAPT into deeper exploitation work.
View exam OSCPThe hands-on, 24-hour practical pentest exam from OffSec — a popular complement to GIAC's open-book format.
View exam CatalogExplore the full Exam Assist catalog of cybersecurity, cloud, and professional certifications we support.
See the catalogGet expert GWAPT help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.