GSEC (GIAC Security Essentials) (GSEC) Exam Blueprint

GSEC

180Questions
360 minDuration
73/percentagePassing Score
$949Price
4 yearsValid For
1Languages
Practice GSEC (GIAC Security Essentials) on QuizForge

Exam Domains

1.0 Access Control & Password Management Weight not published
  • 1.1Understand the fundamental theory of access control and the role of passwords in access control management.
2.0 Container and MacOS Security Weight not published
  • 2.1Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.
3.0 Cryptography Weight not published
  • 3.1Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.
4.0 Cryptography Application Weight not published
  • 4.1Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.
5.0 Data Loss Prevention and Mobile Device Security Weight not published
  • 5.1Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.
6.0 Defense in Depth Weight not published
  • 6.1Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.
7.0 Defensible Network Architecture Weight not published
  • 7.1Demonstrate how to architect a network to be monitored and controlled to resist intrusion.
8.0 Endpoint Security Weight not published
  • 8.1Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.
9.0 Enforcing Windows Security Policy Weight not published
  • 9.1Have a high-level understanding of the features of Group Policy and working with INF security templates.
10.0 Incident Handling & Response Weight not published
  • 10.1Understand the concepts and processes associated with incident handling.
11.0 Linux Fundamentals Weight not published
  • 11.1Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.
12.0 Linux Security and Hardening Weight not published
  • 12.1Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.
13.0 Log Management & SIEM Weight not published
  • 13.1Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.
14.0 Malicious Code & Exploit Mitigation Weight not published
  • 14.1Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.
15.0 Network Security Devices Weight not published
  • 15.1Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.
16.0 Networking & Protocols Weight not published
  • 16.1Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.
17.0 Security Frameworks and CIS Controls Weight not published
  • 17.1Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.
18.0 Virtualization, Cloud Security, and AI Essentials Weight not published
  • 18.1Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.
19.0 Vulnerability Scanning and Penetration Testing Weight not published
  • 19.1Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.
20.0 Web Communication Security Weight not published
  • 20.1Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.
21.0 Windows Access Controls Weight not published
  • 21.1Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.
22.0 Windows as a Service Weight not published
  • 22.1Understand how to manage updates for a network of Windows hosts.
23.0 Windows Automation, Auditing, and Forensics Weight not published
  • 23.1Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.
24.0 Windows Security Infrastructure Weight not published
  • 24.1Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.
25.0 Windows Services and Microsoft Cloud Weight not published
  • 25.1Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.
26.0 Wireless Network Security Weight not published
  • 26.1Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

Exam Details

Question Typesperformance-based
FormatMultiple Choice
Online ProctoringAvailable
ID RequirementsGovernment-issued photo ID required. ID must match the name on the exam registration. Acceptable forms include passport, driver's license, or national ID card.
RenewalRequired -- Certifications are valid for 4 years. Renewal requires 36 CPE (Continuing Professional Education) credits earned over the 4-year period, plus a $429 renewal fee. Alternatively, candidates may retake the current exam to renew.
PrerequisitesHands-on experience in information security tasks in IT systems
Retake PolicyTwo free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
LanguagesEnglish

Official Study Resources