← All Certifications
GIAC

GIAC GCIH Certification

GCIH · 6 domains

Last updated: March 31, 2026

Exam Syllabus & Domains

The GIAC GCIH certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 20%

Incident Handling Process

  • 1.1 Apply the six-step incident handling process (PICERL)
  • 1.2 Establish and manage incident response teams and communication
  • 1.3 Perform initial triage and incident classification
  • 1.4 Execute containment, eradication, and recovery procedures
PICERL MethodologyIncident ClassificationTriage ProceduresCommunication PlansEvidence PreservationContainment StrategiesEradication TechniquesRecovery ValidationLessons LearnedIR Playbooks
Domain 2 15%

Reconnaissance & Scanning

  • 2.1 Detect and analyze reconnaissance activities against networks
  • 2.2 Identify scanning techniques and their network signatures
  • 2.3 Understand OSINT techniques used by attackers
  • 2.4 Implement countermeasures against reconnaissance
OSINT DetectionPort Scanning SignaturesNetwork MappingDNS ReconnaissanceSocial Engineering ReconGoogle DorkingBanner Grabbing DetectionHoneypotsDeception TechnologyScan Detection Tools
Domain 3 20%

Exploitation Tools & Techniques

  • 3.1 Understand common exploitation frameworks and tools
  • 3.2 Analyze exploit delivery mechanisms and payloads
  • 3.3 Detect and respond to exploitation attempts
  • 3.4 Understand malware types and their behaviors
Metasploit FrameworkExploit Delivery MethodsShellcode AnalysisMalware CategoriesTrojan DetectionRootkit IdentificationRansomware ResponseFileless MalwareLiving off the LandEndpoint Detection
Domain 4 20%

Network Protocol Attacks

  • 4.1 Identify and respond to network-layer attacks
  • 4.2 Detect session hijacking and man-in-the-middle attacks
  • 4.3 Analyze DoS/DDoS attack patterns and mitigation
  • 4.4 Respond to DNS and routing protocol attacks
ARP SpoofingDNS PoisoningSession HijackingMITM AttacksDoS/DDoS PatternsSYN FloodAmplification AttacksBGP HijackingVLAN HoppingProtocol Anomalies
Domain 5 10%

Password Attacks

  • 5.1 Understand password attack methodologies and tools
  • 5.2 Detect credential-based attacks in logs and traffic
  • 5.3 Implement password security controls and policies
  • 5.4 Respond to credential compromise incidents
Brute Force AttacksDictionary AttacksPassword SprayingCredential StuffingHash CrackingRainbow TablesPass-the-HashKerberoastingPassword PoliciesMFA Implementation
Domain 6 15%

Web Application Attacks

  • 6.1 Identify and respond to web application attack patterns
  • 6.2 Detect SQL injection and XSS attacks in logs and traffic
  • 6.3 Analyze web shell activity and command injection
  • 6.4 Implement web application security monitoring
SQL Injection DetectionXSS Attack PatternsCSRF DetectionWeb Shell IndicatorsCommand InjectionFile Inclusion AttacksWAF Log AnalysisHTTP Log AnalysisOWASP Top 10Web App Monitoring

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Incident Handling Process
20%
D2 Reconnaissance & Scanning
15%
D3 Exploitation Tools & Techniques
20%
D4 Network Protocol Attacks
20%
D5 Password Attacks
10%
D6 Web Application Attacks
15%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the GIAC GCIH Practice Quiz

Get the GIAC GCIH Study Planner

Fillable PDF with 12-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your GIAC GCIH certification training:

Frequently Asked Questions

What is the GIAC GCIH certification?

The GIAC GCIH (GCIH) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the GIAC GCIH certification syllabus cover?

The GIAC GCIH exam syllabus covers 6 domains. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for GIAC GCIH?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for GIAC GCIH?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.