Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Enterprise Defender

The GIAC Certified Enterprise Defender (GCED) certification validates advanced defensive skills across network infrastructure, packet analysis, penetration testing, incident handling, and malware removal. Designed for incident responders, SOC engineers, and network security professionals, it proves you can implement comprehensive security solutions that protect the enterprise as a whole. Earning GCED signals readiness to defend complex environments with hands-on, practical expertise.

Exam formatProctored exam
Duration180 minutes
DeliveryGIAC
Passing score69%
Free questions493

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Certified Enterprise Defender proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
11objectives
86concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Certified Enterprise Defender (GCED) certification validates a practitioner's knowledge and abilities in defensive network infrastructure, packet analysis, penetration testing, incident handling, and malware removal. It builds on the security skills measured by the GIAC Security Essentials certification, equipping holders with the advanced technical skills needed to defend the enterprise environment and protect an organization as a whole.

GCED certification holders demonstrate proficiency in network and cloud-based defensive infrastructure, penetration testing, digital forensics, incident response, network monitoring, logging, packet analysis, intrusion analysis, and malware analysis. The certification is a rigorous, standardized assessment that objectively measures each candidate's knowledge and hands-on cybersecurity skills against a validated, industry-recognized standard.

Who it’s for

The GCED certification is designed for incident responders, penetration testers, Security Operations Center (SOC) engineers and analysts, and network security professionals. It is also ideal for anyone seeking technical, in-depth knowledge about implementing comprehensive security solutions. Candidates typically have practical experience in defensive security and are looking to validate their advanced skills in protecting enterprise environments.

Recommended experience

Practical work experience in defensive security, such as incident response, network security, or SOC operations, is recommended to ensure mastery of the skills necessary for certification. Hands-on experience with network and cloud-based defensive infrastructure; Familiarity with packet analysis, intrusion detection, and malware analysis; Understanding of penetration testing concepts and incident response processes

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Network Defense and Monitoring
  • Defending Network Protocols
  • Defensive Infrastructure and Tactics
  • Intrusion Detection and Packet Analysis
  • Network Security Monitoring Concepts and Application
4 objectives · 168 free questions · 35 pages
Incident Response and Forensics
  • Incident Response Concepts and Application
  • Digital Forensics Concepts and Application
  • Network Forensics, Logging, and Event Management
3 objectives · 142 free questions · 30 pages
Malware Analysis
  • Malware Analysis Concepts and Basic Analysis Techniques
  • Interactive and Manual Malware Analyses
2 objectives · 96 free questions · 20 pages
Penetration Testing
  • Penetration Testing Concepts
  • Penetration Testing Application
2 objectives · 87 free questions · 18 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Certified Enterprise Defender
Exam formatProctored exam
Duration180 minutes
Questions115 questions
Passing score69%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Certified Enterprise Defender

GIAC Certified Enterprise Defender badgeCredential earnedGIAC Certified Enterprise Defender Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does GCED relate to the GIAC Security Essentials (GSEC) certification?

GCED builds on the security skills measured by the GSEC certification, providing more advanced technical skills needed to defend the enterprise environment. While GSEC is not a mandatory prerequisite, it is a recommended foundation.

Is there a hands-on or lab component in the GCED exam?

The GCED exam is a proctored, web-based exam that objectively measures knowledge and hands-on cybersecurity skills. While it does not use the CyberLive format, it assesses practical skills through scenario-based questions.

What is the retake policy for the GCED exam?

GIAC does not publish a specific retake policy for the GCED exam. Candidates should refer to their GIAC account for details on exam attempts and any applicable waiting periods.

How soon will I receive my GCED exam results?

GIAC does not publish a specific timeline for score reporting. Candidates should check their GIAC account for score availability after the exam attempt.

What job roles does the GCED certification map to?

GCED is designed for incident responders, penetration testers, SOC engineers and analysts, and network security professionals who need advanced technical skills to defend enterprise environments.

Can I recertify GCED by passing a different GIAC exam?

Yes, GIAC allows renewal by retaking the GCED exam or by earning 36 CPE credits over four years. Passing a different GIAC exam may also contribute to CPE credits, but it does not automatically renew GCED unless it is the same exam.

Are there regional differences in GCED exam delivery?

GIAC offers remote proctoring through ProctorU and onsite proctoring through PearsonVUE, which are available in many regions. Specific availability may vary by location.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 493 questions, free, no account needed.