Exam Domains
1.0 Attacking Passwords
Weight not published
- 1.1Demonstrate a detailed understanding of how to conduct password attacks
2.0 Detecting Evasive and Post-Exploitation Techniques
Weight not published
- 2.1Identify and defend against an attacker already in an environment, discover methods used to establish persistence, hide their presence, and achieve actions on objectives
3.0 Detecting Exploitation and Covert Communications Tools
Weight not published
- 3.1Demonstrate an understanding of how to identify and defend against the use of exploitation tools such as Metasploit and covert communications tools such as netcat
4.0 Endpoint Attack and Pivoting
Weight not published
- 4.1Demonstrate an understanding of how to identify and defend against endpoint specific attacks and pivoting in an environment
5.0 Exploiting Insecure Web Application References
Weight not published
- 5.1Demonstrate an understanding of common methods for exploiting insecure web application references
6.0 Incident Response and Cyber Investigation
Weight not published
- 6.1Demonstrate an understanding of the PICERL and DAIR incident handling processes and incident response challenges
7.0 Integrating LLMs with Offensive Operations
Weight not published
- 7.1Demonstrate an understanding of LLM prompt processing, risks, common attack methods, and defend against AI specific attacks in modern environments
8.0 Malware and AI Assisted Investigations
Weight not published
- 8.1Demonstrate an understanding of the steps necessary to perform basic malware analysis and understand how AI can be used to augment investigative efforts
9.0 Network and Log Investigations
Weight not published
- 9.1Demonstrate an understanding of the steps necessary to perform effective investigations of network and log data
10.0 Scanning and Mapping
Weight not published
- 10.1Demonstrate an understanding of how to discover and map networks and hosts, reveal services and vulnerabilities, and identify and defend against scanning
11.0 Securing Credentials and Data in the Cloud
Weight not published
- 11.1Demonstrate an understanding of how to identify, defend against, and mitigate password attacks and insecure storage in cloud-based environments
12.0 SMB Security
Weight not published
- 12.1Demonstrate an understanding of SMB features, vulnerabilities, how to discover and access shares, and how to secure the service
13.0 Understanding Passwords
Weight not published
- 13.1Identify password hashes, understand password weaknesses, and secure passwords
14.0 Web Application API Attacks
Weight not published
- 14.1Demonstrate the basics of interacting with and abusing access to web APIs
15.0 Web Application Injection Attacks
Weight not published
- 15.1Demonstrate an understanding of common web application injection attacks
Exam Details
Question Typesperformance-based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesPractical work experience in incident handling and computer security
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish