GIAC · Global Information Assurance Certification

GIAC Web Application Penetration Tester

GWAPT

The GWAPT is GIAC's specialist certification proving you can find and exploit real vulnerabilities in web applications — SQL injection, cross-site scripting, broken authentication, and session flaws — not just describe them. It maps to the SANS SEC542 curriculum and is a recognized credential for application security and offensive-security roles, frequently named in DoD 8140 and employer hiring lists. With an 82-question, open-book exam and a 71% cut score, a single weak attempt can cost a hefty retake fee and weeks of delay. This page lays out exactly what the exam covers, how it's delivered, and how to clear it on the first sitting.

3 hours
82 Questions
71% to Pass
Open Book

Pay Only After You Pass

No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider GIAC
Format Proctored · open-book MCQ
Duration 3 hours
Questions 82
Passing Score 71%
Fee ~$979 (exam-only attempt)
Proctoring ProctorU or Pearson VUE
Validity 4 years
Languages English
See GWAPT Help Options

EXAM FORMAT

How the GIAC GWAPT exam is built — at a glance

82

Proctored questions

82 questions in one sitting, mostly multiple-choice with some interactive items. There's no on-screen section breakdown — your final percentage is what counts.

71%

Cut score to pass

You must score 71% or higher. That means missing more than about 23 of the 82 questions fails you — a thinner margin than it looks under a 3-hour clock.

3h

Time limit

Three hours for 82 questions — roughly 2 minutes each. Open-book candidates who index poorly burn that budget flipping pages instead of answering.

Open-book, but not open-device

Like every GIAC certification, the GWAPT is open book — you may bring printed, indexed reference material into the exam. No laptop, phone, tablet, or electronic notes are permitted. Most candidates build a physical index of the SANS SEC542 course books so they can jump to the right page in seconds.

How scoring & renewal work

Scoring is a single overall percentage against a fixed 71% cut — no curve, no per-domain minimum. A practice test is bundled with your exam attempt so you can gauge readiness first. Once certified, the GWAPT stays valid for 4 years; you renew by submitting 36 CPE credits or by retaking the current exam.

WHAT'S TESTED

GIAC publishes the GWAPT objectives but not exact weights — bars show relative emphasis, not official percentages

1

Recon & Mapping

Profiling the target, fingerprinting the stack, spidering content, and mapping the full attack surface before any exploitation begins.

2

SQL Injection

Detecting and exploiting SQL injection — error-based, union, and blind techniques — to extract data and pivot deeper into the application.

3

XSS, CSRF & Client Injection

Cross-site scripting, cross-site request forgery, and other client-side injection attacks — crafting payloads and understanding their impact.

4

Authentication Attacks

Bypassing and abusing web application authentication — credential attacks, logic flaws, and weak access controls.

5

Session Management

Analyzing and attacking session handling — token prediction, fixation, hijacking, and weaknesses in cookie and session design.

6

Config Testing & Tooling

Configuration testing plus practical use of the web-app testing toolkit — proxies, scanners, and fuzzers used across a methodology-driven assessment.

GIAC frames the GWAPT around a repeatable methodology: reconnaissance, mapping, discovery, and exploitation, finished with clear reporting. Because the cut is a single 71% figure, you can't lean on one strong area — a thin grasp of SQL injection or XSS will quietly drag your total below the line.

DELIVERY & PROCTORING

Two ways to sit the exam — and what to expect on test day

Online, proctored via ProctorU

Take the exam from a private room at home or office, monitored live through ProctorU. You'll complete a system check, a webcam room scan, and a government ID verification beforehand. You may keep your printed, indexed reference books on the desk, but no electronic devices are allowed.

Onsite at a Pearson VUE center

Sit the exam in a quiet, monitored room at a Pearson VUE test center. Staff verify your government-issued ID and supervise the session. You bring your printed reference materials; the center provides the workstation. A good fit if your home setup can't meet the online proctoring rules.

ID & identity check

A valid, unexpired government photo ID whose name matches your GIAC account exactly. The proctor confirms your identity before the exam unlocks.

Environment scan

For online attempts: a clear desk, no second monitor, no phone within reach, and a webcam scan of the room. Printed reference books are allowed; electronic notes are not.

During the exam

Stay in frame and on-camera throughout the 3-hour window. Leaving the seat, talking aloud, or a dropped connection can flag the session for review.

WHO SHOULD TAKE THIS

The GWAPT is built for hands-on web application security work

  • Penetration testers focusing on web and API targets
  • Application security engineers and AppSec analysts
  • Red teamers and offensive security professionals
  • Developers hardening apps against OWASP-class flaws
  • Defenders in roles tied to DoD 8140 / 8570 requirements

PREREQUISITES & DIFFICULTY

No formal requirements — but it's a genuinely technical exam

  • No mandatory prerequisites or required training course
  • Working knowledge of HTTP, HTML, and how web apps work
  • Comfort with a proxy and basic SQL/JavaScript syntax
  • Aligns with the SANS SEC542 curriculum (not required)

Difficulty: The GWAPT is open book, but "open book" misleads people — questions probe whether you actually understand how to exploit and chain web flaws, not whether you can find a definition. The pressure points are the 71% cut, the 3-hour clock, and the need for a tight, well-indexed reference set. That's exactly the kind of preparation our help is built to handle.

HOW EXAM ASSIST HELPS YOU PASS THE GWAPT

The GWAPT is a high-stakes, time-boxed exam with a real money cost on every attempt. Exam Assist pairs you with a vetted web-application security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.

1

Share your exam details

Tell us your delivery method (ProctorU online or Pearson VUE center), your target test window, and whether this ties to a job or compliance deadline. Takes a couple of minutes over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and the 71% bar and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You're matched with a GWAPT specialist who maps the work around the objectives, the open-book index strategy, and the proctoring environment — discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing result is confirmed on your official GIAC report. No verified result, nothing owed.

Ready to lock in your GWAPT result?

Tell us about your exam and get a straight, no-pressure feasibility answer — you settle only after you pass.

Start with the GWAPT

FREQUENTLY ASKED

Straight answers about the GIAC GWAPT exam

What score do you need to pass the GIAC GWAPT exam? +
You need a minimum of 71% to pass the GWAPT exam. GIAC sets the cut score per certification, and the GWAPT passing threshold is 71% across its 82 questions. There is no curve and no section-by-section minimum — a single overall percentage determines pass or fail.
How many questions are on the GWAPT exam and how long is it? +
The GWAPT exam has 82 questions and a 3-hour time limit. The format is proctored multiple-choice with some interactive items, delivered in a single sitting with no scheduled breaks beyond what your proctor allows.
Is the GIAC GWAPT exam open book? +
Yes. Like other GIAC certifications, the GWAPT is open book — you may bring printed, indexed reference materials into the exam. You cannot use any electronic device, phone, tablet, or computer for notes. Most candidates build a physical index of their course books to navigate the 82 questions quickly.
How do I take the GWAPT, online or at a test center? +
GIAC offers two delivery methods: remote online proctoring through ProctorU from a private room, or onsite proctoring at a Pearson VUE test center. Both require a government ID check and a controlled environment. The online option needs a webcam, a clear desk, and a stable connection.
How long is the GWAPT certification valid? +
The GWAPT certification is valid for four years. To renew, you submit 36 Continuing Professional Education (CPE) credits along with a renewal fee, or you retake the current exam before your certification expires.
Do I pay Exam Assist before or after I see my GWAPT result? +
You settle only after your verified passing result is confirmed. There is no upfront fee — you share your exam details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.

KEEP EXPLORING

Get started, read a guide, and compare sibling exams

YOUR GWAPT RESULT, HANDLED

Get expert GWAPT help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US