Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Detection Analyst

GCDA

The GIAC Certified Detection Analyst (GCDA) certification validates your ability to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity. Built for security analysts, SOC professionals, and threat investigators, GCDA proves you can wield SIEM tools and techniques to turn attacker strengths into weaknesses and strengthen your organization's continuous security monitoring.

400 practice questions · Updated 2026-07-30

4Domains
9Objectives
63Concepts
400Questions

GCDA Curriculum

Every domain, objective, and concept the GCDA exam measures.

SIEM Overview

8 concepts · 47 questions
  1. SIEM Definition and Purpose
  2. Core SIEM Functions
  3. SIEM Architecture Components
  4. Data Sources and Log Collection
  5. Event Normalization and Parsing
  6. Correlation Rules and Use Cases
  7. Alerting and Incident Response Integration
  8. SIEM Reporting and Compliance

Log Collection and Enrichment

6 concepts · 44 questions
  1. Log Sources and Types
  2. Log Collection Methods
  3. Normalization and Parsing
  4. Enrichment Data Sources
  5. Enrichment Techniques
  6. Data Quality and Integrity

Log Analysis and Alerting

6 concepts · 44 questions
  1. Log Sources and Types
  2. Log Collection and Normalization
  3. Correlation Rules and Logic
  4. Alerting and Notification
  5. Alert Triage and Investigation
  6. Alert Tuning and Optimization

Azure and AWS Logging Overview

3 concepts · 31 questions
  1. Azure Logging Overview
  2. AWS Logging Overview
  3. Comparison of Azure and AWS Logging

Defender and Sentinel Overview

3 concepts · 36 questions
  1. Microsoft Defender Overview
  2. Microsoft Sentinel Overview
  3. Defender and Sentinel Integration

Asset and Network Analytics

12 concepts · 52 questions
  1. Asset Discovery
  2. Asset Inventory Management
  3. Network Topology Mapping
  4. Traffic Flow Analysis
  5. Protocol Analysis
  6. Network Baseline Establishment
  7. Anomaly Detection
  8. Asset Vulnerability Assessment
  9. Asset Criticality Classification
  10. Network Segmentation Analysis
  11. Log and Event Correlation
  12. Threat Intelligence Integration

Application Protocol Analytics

7 concepts · 45 questions
  1. Application Protocol Identification
  2. Protocol Behavior Analysis
  3. Application Layer Traffic Inspection
  4. Protocol Decoding and Parsing
  5. Encrypted Traffic Analysis
  6. Application Protocol Anomaly Detection
  7. Correlating Application Activity with Assets

Endpoint Analytics

5 concepts · 43 questions
  1. Endpoint Data Sources
  2. Endpoint Data Collection
  3. Endpoint Detection Use Cases
  4. Endpoint Analytics Techniques
  5. Endpoint Detection Tuning
  1. Application Monitoring Fundamentals
  2. User Monitoring Fundamentals
  3. Application Behavior Baselining
  4. User Behavior Baselining
  5. Anomaly Detection in Application Logs
  6. Anomaly Detection in User Activity
  7. Correlating Application and User Events
  8. Indicators of Compromise in Application Usage
  9. Indicators of Compromise in User Behavior
  10. Response Actions for Application Anomalies
  11. Response Actions for User Anomalies
  12. Integrating Application and User Monitoring with SIEM
  13. Leveraging Analytics for Threat Hunting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCDA, so none is invented.