The GIAC GCIH certification validates your expertise and opens doors to higher-paying roles in IT and cybersecurity. Whether you are just starting your study journey or doing a final review, this guide breaks down everything you need to know to pass the GCIH exam.
Exam Overview
- Certification: GIAC GCIH
- Exam Code: GCIH
- Vendor: GIAC
- Cost: $979 USD (certification attempt)
- Duration: 240 minutes
- Questions: 106 questions
- Passing Score: 70%
- Format: Multiple choice, open book
- Prerequisites: SANS SEC504 recommended
Domain Breakdown
Understanding the exam domains and their weights is critical for efficient study planning. Focus more time on heavily-weighted domains while ensuring you cover all areas.
Domain 1: Incident Handling Process (20%)
- 1.1 Apply the six-step incident handling process (PICERL)
- 1.2 Establish and manage incident response teams and communication
- 1.3 Perform initial triage and incident classification
- 1.4 Execute containment, eradication, and recovery procedures
Key concepts: PICERL Methodology, Incident Classification, Triage Procedures, Communication Plans, Evidence Preservation, Containment Strategies, Eradication Techniques, Recovery Validation
Domain 2: Reconnaissance & Scanning (15%)
- 2.1 Detect and analyze reconnaissance activities against networks
- 2.2 Identify scanning techniques and their network signatures
- 2.3 Understand OSINT techniques used by attackers
- 2.4 Implement countermeasures against reconnaissance
Key concepts: OSINT Detection, Port Scanning Signatures, Network Mapping, DNS Reconnaissance, Social Engineering Recon, Google Dorking, Banner Grabbing Detection, Honeypots
Domain 3: Exploitation Tools & Techniques (20%)
- 3.1 Understand common exploitation frameworks and tools
- 3.2 Analyze exploit delivery mechanisms and payloads
- 3.3 Detect and respond to exploitation attempts
- 3.4 Understand malware types and their behaviors
Key concepts: Metasploit Framework, Exploit Delivery Methods, Shellcode Analysis, Malware Categories, Trojan Detection, Rootkit Identification, Ransomware Response, Fileless Malware
Domain 4: Network Protocol Attacks (20%)
- 4.1 Identify and respond to network-layer attacks
- 4.2 Detect session hijacking and man-in-the-middle attacks
- 4.3 Analyze DoS/DDoS attack patterns and mitigation
- 4.4 Respond to DNS and routing protocol attacks
Key concepts: ARP Spoofing, DNS Poisoning, Session Hijacking, MITM Attacks, DoS/DDoS Patterns, SYN Flood, Amplification Attacks, BGP Hijacking
Domain 5: Password Attacks (10%)
- 5.1 Understand password attack methodologies and tools
- 5.2 Detect credential-based attacks in logs and traffic
- 5.3 Implement password security controls and policies
- 5.4 Respond to credential compromise incidents
Key concepts: Brute Force Attacks, Dictionary Attacks, Password Spraying, Credential Stuffing, Hash Cracking, Rainbow Tables, Pass-the-Hash, Kerberoasting
Domain 6: Web Application Attacks (15%)
- 6.1 Identify and respond to web application attack patterns
- 6.2 Detect SQL injection and XSS attacks in logs and traffic
- 6.3 Analyze web shell activity and command injection
- 6.4 Implement web application security monitoring
Key concepts: SQL Injection Detection, XSS Attack Patterns, CSRF Detection, Web Shell Indicators, Command Injection, File Inclusion Attacks, WAF Log Analysis, HTTP Log Analysis
Recommended Study Timeline
Plan for approximately 10-16 weeks of dedicated study. Here is a suggested weekly breakdown:
- Week 1: Domain 1: Incident handling process — PICERL, IR teams, communication, triage
- Week 2: Domain 1: Containment & recovery — Evidence preservation, eradication, validation, lessons learned
- Week 3: Domain 2: Reconnaissance — OSINT detection, scanning signatures, countermeasures
- Week 4: Domain 3: Exploitation tools — Metasploit, exploit analysis, payload detection
- Week 5: Domain 3: Malware — Trojans, rootkits, ransomware, fileless malware, LOTL techniques
- Week 6: Domain 4: Network attacks — ARP spoofing, DNS poisoning, session hijacking, MITM
- Week 7: Domain 4: DoS/DDoS — SYN floods, amplification attacks, mitigation strategies
- Week 8: Domain 5: Password attacks — Brute force, spraying, hash cracking, Kerberoasting
- Week 9: Domain 6: Web attacks — SQLi, XSS, command injection, web shell detection
- Week 10: Index Building: Create open-book index for exam day, organize notes by topic
- Week 11: Full Review: Practice exams, Weak areas, Index refinement
- Week 12: Final Review: Timed practice exams, Exam logistics, Last-minute review
Top Study Tips
- Start with the official exam objectives. Download them from the GIAC website and use them as your study checklist. Every exam question maps to a specific objective.
- Use active recall over passive reading. Instead of re-reading notes, test yourself with practice questions after each study session. This dramatically improves retention.
- Focus on heavily-weighted domains first. Domains with higher percentages appear more on the exam. Master these before moving to lower-weighted areas.
- Build hands-on experience. Set up a lab environment and practice the skills you are studying. Hands-on experience is especially valuable for performance-based questions.
- Take practice exams under real conditions. Time yourself, eliminate distractions, and simulate the exam environment. Review every wrong answer and understand why it was wrong.
Practice Resources
Test your knowledge with our free tools:
Take our free GIAC GCIH practice quiz
- CVSS Calculator — Practice scoring vulnerabilities
- Password Strength Checker — Test password security
Career Impact
The GIAC GCIH certification demonstrates validated expertise to employers. Certified professionals typically see:
- Higher starting salaries compared to non-certified peers
- More interview callbacks as the certification signals commitment and competence
- Faster career progression with a recognized credential on your resume
- Access to roles that specifically require or prefer GIAC GCIH certification
What to Study Next
After earning your GIAC GCIH certification, consider these natural next steps:
- Deepen your specialization with an advanced certification in the same vendor track
- Broaden your skills with a certification from a complementary domain
- Visit our Career Paths page for detailed certification roadmaps
Get Organized with a Study Planner
A structured study plan makes the difference between passing and failing. Our fillable PDF study planners include domain trackers, weekly schedules, and progress tracking designed specifically for GIAC GCIH exam prep.
This guide is independently created for educational purposes. GIAC trademarks belong to their respective owners. FixTheVuln is not affiliated with or endorsed by GIAC.
Explore More
Exam Syllabus & Domain Breakdown
Review the complete certification syllabus, domain weights, and free training resources.
View Full Certification Guide →FixTheVuln Store
GIAC/SANS Certification? Get the Study Planner
Structured planner for GIAC certifications. SANS course trackers, domain study guides, and index preparation tools.
Shop GSEC PlannerAlso available: GSEC, GCIH, GPEN, GCIA
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →