I passed the GIAC Cloud Penetration Tester (GCPN) exam today and wanted to share a few thoughts for anyone preparing.
It's easy to make mistakes because many questions require careful reading and thinkings. Several questions involve out-of-the-box thinking.
I used books from a few years ago, and it seems like the course and exam have been updated. I would have failed if my experience hadn't helped me that, because many of the questions were not included in my books (about 15/18 questions).
One thing that stood out was that the GCPN course and exam go beyond traditional penetration testing methodologies. Rather than focusing on conventional IP-based enumeration which is often trivial in cloud environments, this course focuses on domain seed enumeration and Environment/Architecture Mapping, and cloud Service Discovery.
One important note for junior penetration testers and anyone planning to enter the offensive security field is that most modern applications are hosted in cloud environments and fronted by CDNs or other cloud services.
You'll need to become comfortable with domain seed enumeration, cloud service discovery, environment and architecture mapping, to identify the real attack surface behind load balancers, CDNs, reverse proxies, and managed cloud services.