GCIH (GIAC Certified Incident Handler) (GCIH) Exam Blueprint

GCIH

106Questions
240 minDuration
73/percentagePassing Score
$949Price
4 yearsValid For
1Languages
Practice GCIH (GIAC Certified Incident Handler) on QuizForge

Exam Domains

1.0 Attacking Passwords Weight not published
  • 1.1Demonstrate a detailed understanding of how to conduct password attacks
2.0 Detecting Evasive and Post-Exploitation Techniques Weight not published
  • 2.1Identify and defend against an attacker already in an environment, discover methods used to establish persistence, hide their presence, and achieve actions on objectives
3.0 Detecting Exploitation and Covert Communications Tools Weight not published
  • 3.1Demonstrate an understanding of how to identify and defend against the use of exploitation tools such as Metasploit and covert communications tools such as netcat
4.0 Endpoint Attack and Pivoting Weight not published
  • 4.1Demonstrate an understanding of how to identify and defend against endpoint specific attacks and pivoting in an environment
5.0 Exploiting Insecure Web Application References Weight not published
  • 5.1Demonstrate an understanding of common methods for exploiting insecure web application references
6.0 Incident Response and Cyber Investigation Weight not published
  • 6.1Demonstrate an understanding of the PICERL and DAIR incident handling processes and incident response challenges
7.0 Integrating LLMs with Offensive Operations Weight not published
  • 7.1Demonstrate an understanding of LLM prompt processing, risks, common attack methods, and defend against AI specific attacks in modern environments
8.0 Malware and AI Assisted Investigations Weight not published
  • 8.1Demonstrate an understanding of the steps necessary to perform basic malware analysis and understand how AI can be used to augment investigative efforts
9.0 Network and Log Investigations Weight not published
  • 9.1Demonstrate an understanding of the steps necessary to perform effective investigations of network and log data
10.0 Scanning and Mapping Weight not published
  • 10.1Demonstrate an understanding of how to discover and map networks and hosts, reveal services and vulnerabilities, and identify and defend against scanning
11.0 Securing Credentials and Data in the Cloud Weight not published
  • 11.1Demonstrate an understanding of how to identify, defend against, and mitigate password attacks and insecure storage in cloud-based environments
12.0 SMB Security Weight not published
  • 12.1Demonstrate an understanding of SMB features, vulnerabilities, how to discover and access shares, and how to secure the service
13.0 Understanding Passwords Weight not published
  • 13.1Identify password hashes, understand password weaknesses, and secure passwords
14.0 Web Application API Attacks Weight not published
  • 14.1Demonstrate the basics of interacting with and abusing access to web APIs
15.0 Web Application Injection Attacks Weight not published
  • 15.1Demonstrate an understanding of common web application injection attacks

Exam Details

Question Typesperformance-based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesPractical work experience in incident handling and computer security
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish

Official Study Resources