GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
Credential: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
Credentialing Agency: Global Information Assurance Certification (GIAC)
Renewal Period: 4 years
Global Information Assurance Certification (GIAC), Exploit Researcher and Advanced Penetration Tester (GXPN) is an advanced level certification for security personnel whose job duties involve assessing target networks, systems, and applications to find vulnerabilities. GXPN recognizes candidates who have the knowledge, skills, and ability to conduct advanced penetration tests, to model the abilities of an advanced attacker to find significant security flaws in systems, and to demonstrate the business risk associated with these flaws. GXPN does not require any prerequisites or specific training. GXPN candidates are required to pass a written exam.
More information can be found on the certifying agency's website.
GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
MINIMUM REQUIREMENTS
Attainability:
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
RECERTIFICATION SUMMARY
Renewal Period: 4 years
AGENCY CONTACT INFORMATION
Global Information Assurance Certification (GIAC)
11200 Rockville Pike
Suite 200
North Bethesda, MD 20852
Phone: (301) 654-7267
Fax: (301) 951-0140
Email: info@giac.org
Other REQUIREMENTS
The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) credential has the following other requirements:
- GXPN candidates must abide by the GIAC Code of Ethics.
Written Exam
- Accessing the Network
- Advanced Fuzzing Techniques
- Advanced Stack Smashing
- Client Exploitation and Escape
- Crypto for Pen Testers
- Exploiting the Network
- Fuzzing Introduction and Operation
- Hands-on Advanced Network Attacks and Lateral Movement
- Hands-on Linux System and Memory Exploitation
- Hands-on Network Attacks for Penetration Testers
- Hands-on Python Scripting and Fuzzing
- Hands-on Windows System and Memory Exploitation
- Introduction to Memory and Dynamic Linux Memory
- Introduction to Windows Exploitation
- Manipulating the Network
- Python and Scapy for Pen Testers
- Shellcode
- Smashing the Stack
- Windows Overflows
Exam Preparation Resources
There are a number of resources available to help you prepare for the GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) examination:
- Best Sources
- General References
- Related Courses
- Related Training
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the Related Sites page here on COOL to learn how to get free access.
Testing Information
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
For more information on the Global Information Assurance Certification (GIAC) testing process, visit the agency website.
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Pearson VUE
The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
- Search for Testing Program
- Learn About Testing for Military Communities
- Agency/Certification Specific Testing Information
- Contact Pearson VUE
RECERTIFICATION
GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
Renewal Period: 4 years
Additional considerations for the GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) include:
- GXPN certification does not require any prerequisites or specific training. Practical experience, self-study, college level courses, and courses from training providers, including SANS Institute, are options for acquiring the knowledge and skills necessary for certification.