Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Incident Handler

GCIH

The GIAC Certified Incident Handler (GCIH) certification validates your ability to detect, respond to, and resolve computer security incidents using a wide range of essential security skills. It is designed for incident handlers, system administrators, and security practitioners who are first responders. Earning GCIH demonstrates you can manage security incidents by understanding common attack techniques, vectors, and tools.

682 practice questions · Updated 2026-07-30

6Domains
15Objectives
122Concepts
682Questions

GCIH Curriculum

Every domain, objective, and concept the GCIH exam measures.

  1. Incident Response Fundamentals
  2. Incident Response Process
  3. Cyber Investigation Principles
  4. Evidence Collection and Preservation
  5. Incident Triage and Prioritization
  6. Legal and Ethical Considerations

Network and Log Investigations

7 concepts · 40 questions
  1. Network Traffic Analysis
  2. Log Correlation and Analysis
  3. Evidence Collection and Preservation
  4. Timeline Reconstruction
  5. Attacker Activity Identification
  6. Tool Usage for Investigation
  7. Reporting and Documentation

Malware and AI Assisted Investigations

7 concepts · 49 questions
  1. Malware Analysis Fundamentals
  2. Static Analysis Techniques
  3. Dynamic Analysis Techniques
  4. AI-Assisted Malware Detection
  5. AI in Incident Response
  6. Integrating AI with Traditional Analysis
  7. Ethical and Legal Considerations

  1. Identify evasion techniques
  2. Detect post-exploitation activity
  3. Analyze evasive malware behavior
  4. Apply detection strategies
  1. Exploitation Detection Fundamentals
  2. Covert Communications Tools Overview
  3. Network Traffic Analysis for Covert Channels
  4. Host-Based Detection of Covert Tools
  5. Log and Alert Correlation
  6. Response and Mitigation Strategies

Endpoint Attack and Pivoting

6 concepts · 44 questions
  1. Endpoint Attack Vectors
  2. Endpoint Detection Techniques
  3. Pivoting Fundamentals
  4. Pivoting Detection
  5. Incident Response for Endpoint Attacks
  6. Incident Response for Pivoting

  1. Insecure Direct Object References (IDOR)
  2. Path Traversal
  3. Access Control Bypass
  4. Parameter Tampering
  5. Exploitation Techniques
  6. Mitigation Strategies

Web Application API Attacks

7 concepts · 49 questions
  1. API Authentication and Authorization
  2. API Input Validation and Injection
  3. API Rate Limiting and Abuse
  4. API Data Exposure and Privacy
  5. API Security Misconfigurations
  6. API Attack Detection and Logging
  7. API Incident Response and Mitigation

Web Application Injection Attacks

25 concepts · 80 questions
  1. SQL Injection Fundamentals
  2. SQL Injection Attack Techniques
  3. SQL Injection Mitigation
  4. Command Injection
  5. Command Injection Mitigation
  6. LDAP Injection
  7. LDAP Injection Mitigation
  8. XML Injection
  9. XML Injection Mitigation
  10. NoSQL Injection
  11. NoSQL Injection Mitigation
  12. ORM Injection
  13. ORM Injection Mitigation
  14. XPath Injection
  15. XPath Injection Mitigation
  16. Buffer Overflow Injection
  17. Buffer Overflow Mitigation
  18. Format String Injection
  19. Format String Mitigation
  20. HTTP Header Injection
  21. HTTP Header Injection Mitigation
  22. Email Header Injection
  23. Email Header Injection Mitigation
  24. Injection Attack Detection and Testing
  25. Injection Attack Defense in Depth

Attacking Passwords

8 concepts · 41 questions
  1. Password Attack Fundamentals
  2. Password Cracking Techniques
  3. Password Spraying
  4. Credential Stuffing
  5. Pass-the-Hash Attacks
  6. Pass-the-Ticket Attacks
  7. Offline vs Online Attacks
  8. Mitigation Strategies

Understanding Passwords

7 concepts · 39 questions
  1. Password Fundamentals
  2. Password Storage Mechanisms
  3. Password Cracking Techniques
  4. Password Policies and Best Practices
  5. Multi-Factor Authentication (MFA)
  6. Password Management Tools
  7. Password Attacks and Defense
  1. Cloud Credential Types
  2. Credential Storage Best Practices
  3. Multi-Factor Authentication (MFA) in Cloud
  4. Identity and Access Management (IAM) Policies
  5. Credential Rotation and Lifecycle
  6. Cloud Data Encryption
  7. Key Management Services
  8. Secure Data Storage Configurations
  9. Monitoring and Auditing Credential Use
  10. Incident Response for Cloud Credential Compromise

Scanning and Mapping

9 concepts · 45 questions
  1. Network Scanning Fundamentals
  2. Host Discovery Techniques
  3. Port Scanning Methods
  4. Service and Version Detection
  5. OS Fingerprinting
  6. Scanning Tools
  7. Firewall and IDS Evasion
  8. Scanning Countermeasures
  9. Interpreting Scan Results

SMB Security

7 concepts · 49 questions
  1. SMB Protocol Fundamentals
  2. SMB Versions and Differences
  3. SMB Authentication Mechanisms
  4. SMB Vulnerabilities and Exploits
  5. SMB Security Best Practices
  6. SMB Traffic Analysis and Monitoring
  7. SMB Incident Response Procedures

  1. LLM Integration Attack Surface
  2. Prompt Injection for Offensive Use
  3. LLM-Based Payload Generation
  4. Automating Reconnaissance with LLMs
  5. Evasion and Stealth via LLMs
  6. LLM Hallucination Exploitation
  7. Defensive Countermeasures for LLM Attacks
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIH, so none is invented.