
GIAC AI Security Automation Engineer
The GIAC AI Security Automation Engineer (GASAE) certification validates your ability to apply practical, real-world automation and artificial intelligence across offensive, defensive, and cloud security operations. It is designed for security professionals who build and operate AI-driven security workflows, from automated vulnerability discovery and adversary emulation to SOAR-driven incident response. Earning GASAE proves you can engineer scalable, resilient security automation that combines AI with hands-on technical skill.
438 practice questions · Updated 2026-07-30
GASAE Curriculum
Every domain, objective, and concept the GASAE exam measures.
- Define Security Automation
- Identify Automation Benefits
- Recognize Automation Challenges
- Understand Automation Use Cases
- Explain Automation vs. Orchestration
- Apply Automation Fundamentals
- Workflow Automation Fundamentals
- Workflow Design Principles
- Workflow Orchestration
- Workflow Integration
- Workflow Triggers and Conditions
- Workflow Error Handling
- Workflow Monitoring and Logging
- Workflow Security and Compliance
- SOAR Fundamentals
- SOAR Components
- SOAR Use Cases
- SOAR Integration
- SOAR Workflows
- SOAR Benefits and Challenges
- AWS Shared Responsibility Model
- AWS Identity and Access Management (IAM)
- AWS CloudTrail
- AWS Config
- AWS GuardDuty
- AWS Security Hub
- AWS Lambda for Security Automation
- AWS Step Functions for Incident Response
- AWS Systems Manager Incident Manager
- AWS EventBridge for Security Events
- AWS S3 Security and Access Control
- AWS VPC Security and Flow Logs
- AWS KMS and Encryption
- AWS CloudFormation for Security Baselines
- AWS Well-Architected Security Pillar
- Azure Security Center Automation
- Azure Sentinel Incident Response
- Azure Logic Apps for Security
- Azure Functions for Security Automation
- Azure Policy and Compliance Automation
- Azure Key Vault Automation
- Azure Monitor and Alerting Automation
- Azure Automation Runbooks
- Azure Security Graph and Threat Intelligence
- Azure DevOps Security Pipelines
- AI Fundamentals
- Adversary Emulation Basics
- AI in Security Automation
- Adversarial AI Threats
- AI System Evaluation
- Adversary Emulation Definition
- MITRE ATT&CK Framework
- Threat Intelligence Integration
- Emulation Planning and Scoping
- Emulation Execution
- Detection and Response Validation
- Reporting and Lessons Learned
- Automating Offensive Workflows
- Workflow Automation Tools
- Integration of Offensive Tools
- Automated Reconnaissance
- Automated Exploitation
- Automated Post-Exploitation
- Workflow Orchestration and Scheduling
- Safety and Ethical Considerations
- Defensive Automation Fundamentals
- Automated Threat Detection
- Automated Incident Response
- Automated Remediation
- Integration with Security Tools
- Continuous Monitoring and Alerting
- Automation Workflow Design
- Testing and Validation of Automation
- Maintaining and Updating Automation
- Automation in Detection Engineering
- AI for Detection Engineering
- Automated Incident Response Playbooks
- AI-Driven Incident Triage and Prioritization
- Integration of Automation and AI in IR Workflows
- Evaluation and Improvement of Automated Systems
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GASAE, so none is invented.