GCIA (GIAC Certified Intrusion Analyst) (GCIA) Exam Blueprint

GCIA

106Questions
240 minDuration
67/percentagePassing Score
$949Price
4 yearsValid For
1Languages
Practice GCIA (GIAC Certified Intrusion Analyst) on QuizForge

Exam Domains

1.0 Fundamentals of Traffic Analysis and Application Protocols Weight not published
  • 1.1Application Protocols
    Demonstrate knowledge and skill relating to application layer protocol dissection and analysis.
2.0 Open-Source Intrusion Detection Systems (IDS): Snort and Zeek Weight not published
  • 2.1IDS Fundamentals and Network Architecture
    Demonstrate knowledge of fundamental IDS concepts, such as network architecture options and benefits/weaknesses of common IDS systems.
  • 2.2Intrusion Detection System Rules
    Create effective IDS rules to detect varied types of malicious activity.
3.0 Network Traffic Forensics and Monitoring Weight not published
  • 3.1Network Forensics and Traffic Analysis
    Demonstrate competence in analyzing data from multiple sources (e.g., full packet capture, netflow, log files) to identify normal and malicious behaviors.
4.0 Concepts of TCP/IP and the Link Layer Weight not published
  • 4.1Concepts of TCP/IP and the Link Layer
    Demonstrate understanding of the TCP/IP communications model and link layer operations.
5.0 Fragmentation Weight not published
  • 5.1Fragmentation
    Demonstrate understanding of how fragmentation works, and how to identify fragmentation and fragmentation-based attacks in packet captures.
6.0 IP Headers Weight not published
  • 6.1IP Headers
    Demonstrate the ability to dissect IP packet headers and analyze them for normal and anomalous values that may point to security issues.
7.0 IPv6 Weight not published
  • 7.1IPv6
    Demonstrate knowledge of IPv6 and how it differs from IPv4.
8.0 Packet Engineering Weight not published
  • 8.1Packet Engineering
    Demonstrate knowledge relating to packet crafting and manipulation.
9.0 SiLK and Other Traffic Analysis Tools Weight not published
  • 9.1SiLK and Other Traffic Analysis Tools
    Demonstrate an understanding of SiLK and other tools to perform network traffic and flow analysis.
10.0 TCP Weight not published
  • 10.1TCP
    Demonstrate understanding of the TCP protocol and the ability to discern between typical and anomalous behavior.
11.0 Tcpdump Filters Weight not published
  • 11.1Tcpdump Filters
    Demonstrate ability to craft tcpdump filters that match on given criteria.
12.0 UDP and ICMP Weight not published
  • 12.1UDP and ICMP
    Demonstrate understanding of the UDP and ICMP protocols and the ability to discern between typical and anomalous behavior.
13.0 Wireshark Fundamentals Weight not published
  • 13.1Wireshark Fundamentals
    Demonstrate ability to use Wireshark to analyze typical and malicious network traffic.

Exam Details

Question Typesperformance-based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesHands-on experience in intrusion detection, network monitoring, traffic analysis, and intrusion detection systems.
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish

Official Study Resources