Credential type: certification examination · verified on the issuer's site September 25, 2026 issuer page
Exam Domains
1 Analyzing Volatile Malicious Event Artifacts
Weight not published
2 Analyzing Volatile Windows Event Artifacts
Weight not published
3 Enterprise Environment Incident Response
Weight not published
4 File System Timeline Artifact Analysis
Weight not published
5 Identification of Malicious System and User Activity
Weight not published
6 Identification of Normal System and User Activity
Weight not published
7 Introduction to File System Timeline Forensics
Weight not published
8 Introduction to Memory Forensics
Weight not published
9 NTFS Artifact Analysis
Weight not published
10 Windows Artifact Analysis
Weight not published
Exam Details
Question TypesPerformance-Based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesExperience in incident response, digital forensics, or related fields
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish