
GIAC Certified Enterprise Defender
The GIAC Certified Enterprise Defender (GCED) certification validates advanced defensive skills across network infrastructure, packet analysis, penetration testing, incident handling, and malware removal. Designed for incident responders, SOC engineers, and network security professionals, it proves you can implement comprehensive security solutions that protect the enterprise as a whole. Earning GCED signals readiness to defend complex environments with hands-on, practical expertise.
493 practice questions · Updated 2026-07-30
GCED Curriculum
Every domain, objective, and concept the GCED exam measures.
- Network Protocol Fundamentals
- Common Network Protocols
- Protocol Vulnerabilities
- Protocol Analysis and Monitoring
- Protocol Hardening and Defense
- Defensive Infrastructure Components
- Defense-in-Depth Strategy
- Network Segmentation and Zoning
- Deception and Honeypots
- Traffic Analysis and Monitoring
- Incident Response Tactics
- Threat Intelligence Integration
- Intrusion Detection Fundamentals
- IDS Types and Placement
- Detection Methods
- Packet Capture and Analysis Tools
- Protocol Analysis
- Traffic Flow Analysis
- IDS Evasion Techniques
- Alert Correlation and False Positives
- Incident Response Integration
- Network Security Monitoring (NSM) Fundamentals
- NSM Data Sources
- NSM Collection Methods
- NSM Analysis Techniques
- NSM Tools and Technologies
- NSM Workflow and Process
- NSM Deployment Considerations
- NSM Challenges and Limitations
- Incident Response Lifecycle
- Incident Response Team Roles
- Incident Classification and Prioritization
- Incident Response Procedures and Playbooks
- Evidence Collection and Preservation
- Forensic Analysis Techniques
- Containment, Eradication, and Recovery Strategies
- Communication and Reporting
- Legal and Ethical Considerations
- Digital Forensics Fundamentals
- Forensic Process and Methodology
- Evidence Handling and Chain of Custody
- Forensic Imaging and Data Acquisition
- File System and Artifact Analysis
- Memory Forensics
- Network Forensics
- Anti-Forensics and Countermeasures
- Forensic Reporting and Documentation
- Network Forensics Fundamentals
- Network Traffic Capture
- Network Traffic Analysis
- Log Management Principles
- Event Correlation and Analysis
- SIEM Implementation and Use
- Log Sources and Formats
- Evidence Handling and Chain of Custody
- Malware Analysis Overview
- Basic Static Analysis
- Basic Dynamic Analysis
- Sandboxing and Isolation
- Identifying Malware Indicators
- Analyzing Malware Behavior
- Interactive Malware Analysis Fundamentals
- Manual Malware Analysis Techniques
- Static Analysis in Interactive Context
- Dynamic Analysis in Interactive Context
- Tool Usage for Interactive Analysis
- Environment Setup for Safe Analysis
- Behavioral Observation and Logging
- Code Tracing and Debugging
- Packing and Obfuscation Handling
- Indicators of Compromise (IOCs) Extraction
- Documentation and Reporting
- Penetration Testing Overview
- Penetration Testing Methodologies
- Penetration Testing Phases
- Rules of Engagement
- Legal and Ethical Considerations
- Types of Penetration Testing
- Reporting and Documentation
- Penetration Testing Fundamentals
- Penetration Testing Methodologies
- Reconnaissance Techniques
- Vulnerability Identification
- Exploitation Techniques
- Post-Exploitation Activities
- Reporting and Remediation
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCED, so none is invented.