GCFA (GIAC Certified Forensic Analyst) (GCFA) Exam Blueprint

GCFA

115Questions
180 minDuration
71/percentagePassing Score
$949Price
4 yearsValid For
1Languages
Practice GCFA (GIAC Certified Forensic Analyst) on QuizForge

Exam Domains

1.0 Advanced incident response and digital forensics Weight not published
  • 1.1Analyzing Volatile Malicious Event Artifacts
    Understanding abnormal activity within the structure of Windows memory; Identifying artifacts such as malicious processes, suspicious drivers, and malware techniques such as code injection and rootkits
  • 1.2Analyzing Volatile Windows Event Artifacts
    Understanding normal activity within the structure of Windows memory; Identifying artifacts such as network connections, memory resident command line artifacts and processes, handles and threads
  • 1.3Enterprise Environment Incident Response
    Understanding the steps of the incident response process; Understanding attack progression and adversary fundamentals; Rapidly assessing and analyzing systems in an enterprise environment; Scaling tools to meet the demands of large investigations
  • 1.4File System Timeline Artifact Analysis
    Understanding the Windows filesystem time structure; Understanding how these artifacts are modified by system and user activity
  • 1.5Identification of Malicious System and User Activity
    Identifying and documenting indicators of compromise on a system; Detecting malware and attacker tools; Attributing activity to events and accounts; Identifying and compensating for anti-forensic actions using memory and disk resident artifacts
  • 1.6Identification of Normal System and User Activity
    Identifying, documenting, and differentiating normal and abnormal system and user activity using memory and disk resident artifacts
  • 1.7Introduction to File System Timeline Forensics
    Understanding the methodology required to collect and process timeline data from a Windows system
  • 1.8Introduction to Memory Forensics
    Understanding how and when to collect volatile data from a system; Understanding how to document and preserve the integrity of volatile evidence
  • 1.9NTFS Artifact Analysis
    Understanding core structures of the Windows filesystems; Identifying, recovering, and analyzing evidence from any file system layer, including the data storage layer, metadata layer, and filename layer
  • 1.10Windows Artifact Analysis
    Understanding Windows system artifacts; Collecting and analyzing data such as system backup and restore data and evidence of application execution

Exam Details

Question TypesPerformance-Based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesExperience in incident response, digital forensics, or related fields
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish

Official Study Resources