
GIAC Certified Detection Analyst
The GIAC Certified Detection Analyst (GCDA) certification validates your ability to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity. Built for security analysts, SOC professionals, and threat investigators, GCDA proves you can wield SIEM tools and techniques to turn attacker strengths into weaknesses and strengthen your organization's continuous security monitoring.
400 practice questions · Updated 2026-07-30
4Domains
9Objectives
63Concepts
400Questions
GCDA Curriculum
Every domain, objective, and concept the GCDA exam measures.
- SIEM Definition and Purpose
- Core SIEM Functions
- SIEM Architecture Components
- Data Sources and Log Collection
- Event Normalization and Parsing
- Correlation Rules and Use Cases
- Alerting and Incident Response Integration
- SIEM Reporting and Compliance
- Log Sources and Types
- Log Collection Methods
- Normalization and Parsing
- Enrichment Data Sources
- Enrichment Techniques
- Data Quality and Integrity
- Log Sources and Types
- Log Collection and Normalization
- Correlation Rules and Logic
- Alerting and Notification
- Alert Triage and Investigation
- Alert Tuning and Optimization
- Azure Logging Overview
- AWS Logging Overview
- Comparison of Azure and AWS Logging
- Microsoft Defender Overview
- Microsoft Sentinel Overview
- Defender and Sentinel Integration
- Asset Discovery
- Asset Inventory Management
- Network Topology Mapping
- Traffic Flow Analysis
- Protocol Analysis
- Network Baseline Establishment
- Anomaly Detection
- Asset Vulnerability Assessment
- Asset Criticality Classification
- Network Segmentation Analysis
- Log and Event Correlation
- Threat Intelligence Integration
- Application Protocol Identification
- Protocol Behavior Analysis
- Application Layer Traffic Inspection
- Protocol Decoding and Parsing
- Encrypted Traffic Analysis
- Application Protocol Anomaly Detection
- Correlating Application Activity with Assets
- Endpoint Data Sources
- Endpoint Data Collection
- Endpoint Detection Use Cases
- Endpoint Analytics Techniques
- Endpoint Detection Tuning
- Application Monitoring Fundamentals
- User Monitoring Fundamentals
- Application Behavior Baselining
- User Behavior Baselining
- Anomaly Detection in Application Logs
- Anomaly Detection in User Activity
- Correlating Application and User Events
- Indicators of Compromise in Application Usage
- Indicators of Compromise in User Behavior
- Response Actions for Application Anomalies
- Response Actions for User Anomalies
- Integrating Application and User Monitoring with SIEM
- Leveraging Analytics for Threat Hunting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCDA, so none is invented.