
GIAC Certified Incident Handler
The GIAC Certified Incident Handler (GCIH) certification validates your ability to detect, respond to, and resolve computer security incidents using a wide range of essential security skills. It is designed for incident handlers, system administrators, and security practitioners who are first responders. Earning GCIH demonstrates you can manage security incidents by understanding common attack techniques, vectors, and tools.
682 practice questions · Updated 2026-07-30
6Domains
15Objectives
122Concepts
682Questions
GCIH Curriculum
Every domain, objective, and concept the GCIH exam measures.
- Incident Response Fundamentals
- Incident Response Process
- Cyber Investigation Principles
- Evidence Collection and Preservation
- Incident Triage and Prioritization
- Legal and Ethical Considerations
- Network Traffic Analysis
- Log Correlation and Analysis
- Evidence Collection and Preservation
- Timeline Reconstruction
- Attacker Activity Identification
- Tool Usage for Investigation
- Reporting and Documentation
- Malware Analysis Fundamentals
- Static Analysis Techniques
- Dynamic Analysis Techniques
- AI-Assisted Malware Detection
- AI in Incident Response
- Integrating AI with Traditional Analysis
- Ethical and Legal Considerations
- Identify evasion techniques
- Detect post-exploitation activity
- Analyze evasive malware behavior
- Apply detection strategies
- Exploitation Detection Fundamentals
- Covert Communications Tools Overview
- Network Traffic Analysis for Covert Channels
- Host-Based Detection of Covert Tools
- Log and Alert Correlation
- Response and Mitigation Strategies
- Endpoint Attack Vectors
- Endpoint Detection Techniques
- Pivoting Fundamentals
- Pivoting Detection
- Incident Response for Endpoint Attacks
- Incident Response for Pivoting
- Insecure Direct Object References (IDOR)
- Path Traversal
- Access Control Bypass
- Parameter Tampering
- Exploitation Techniques
- Mitigation Strategies
- API Authentication and Authorization
- API Input Validation and Injection
- API Rate Limiting and Abuse
- API Data Exposure and Privacy
- API Security Misconfigurations
- API Attack Detection and Logging
- API Incident Response and Mitigation
- SQL Injection Fundamentals
- SQL Injection Attack Techniques
- SQL Injection Mitigation
- Command Injection
- Command Injection Mitigation
- LDAP Injection
- LDAP Injection Mitigation
- XML Injection
- XML Injection Mitigation
- NoSQL Injection
- NoSQL Injection Mitigation
- ORM Injection
- ORM Injection Mitigation
- XPath Injection
- XPath Injection Mitigation
- Buffer Overflow Injection
- Buffer Overflow Mitigation
- Format String Injection
- Format String Mitigation
- HTTP Header Injection
- HTTP Header Injection Mitigation
- Email Header Injection
- Email Header Injection Mitigation
- Injection Attack Detection and Testing
- Injection Attack Defense in Depth
- Password Attack Fundamentals
- Password Cracking Techniques
- Password Spraying
- Credential Stuffing
- Pass-the-Hash Attacks
- Pass-the-Ticket Attacks
- Offline vs Online Attacks
- Mitigation Strategies
- Password Fundamentals
- Password Storage Mechanisms
- Password Cracking Techniques
- Password Policies and Best Practices
- Multi-Factor Authentication (MFA)
- Password Management Tools
- Password Attacks and Defense
- Cloud Credential Types
- Credential Storage Best Practices
- Multi-Factor Authentication (MFA) in Cloud
- Identity and Access Management (IAM) Policies
- Credential Rotation and Lifecycle
- Cloud Data Encryption
- Key Management Services
- Secure Data Storage Configurations
- Monitoring and Auditing Credential Use
- Incident Response for Cloud Credential Compromise
- Network Scanning Fundamentals
- Host Discovery Techniques
- Port Scanning Methods
- Service and Version Detection
- OS Fingerprinting
- Scanning Tools
- Firewall and IDS Evasion
- Scanning Countermeasures
- Interpreting Scan Results
- SMB Protocol Fundamentals
- SMB Versions and Differences
- SMB Authentication Mechanisms
- SMB Vulnerabilities and Exploits
- SMB Security Best Practices
- SMB Traffic Analysis and Monitoring
- SMB Incident Response Procedures
- LLM Integration Attack Surface
- Prompt Injection for Offensive Use
- LLM-Based Payload Generation
- Automating Reconnaissance with LLMs
- Evasion and Stealth via LLMs
- LLM Hallucination Exploitation
- Defensive Countermeasures for LLM Attacks
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCIH, so none is invented.