Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Certified Incident Handler

The GIAC Certified Incident Handler (GCIH) certification validates your ability to detect, respond to, and resolve computer security incidents using a wide range of essential security skills. It is designed for incident handlers, system administrators, and security practitioners who are first responders. Earning GCIH demonstrates you can manage security incidents by understanding common attack techniques, vectors, and tools.

Exam formatCyberLive hands-on testing with performance-based challenges in realistic lab environments
Duration240 minutes
DeliveryGIAC
Passing score69%
Free questions682

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Certified Incident Handler proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

6domains
15objectives
122concepts
US $499exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Certified Incident Handler (GCIH) certification validates a practitioner's ability to detect, respond to, and resolve computer security incidents using a wide range of essential security skills. GCIH certification holders are qualified to defend against attacks when they occur, managing security incidents by understanding common attack techniques, vectors, and tools.

The certification covers incident handling and computer crime investigation, computer and network hacker exploits, and hacker tools such as Nmap, Metasploit, and Netcat. It signals readiness to manage real threats from detection to remediation, demonstrating effective incident handling skills and applying insight into attackers' techniques.

Who it’s for

This certification is for incident handlers, incident handling team leads, system administrators, security practitioners, and security architects. It is also for any security personnel who are first responders to security incidents. Candidates should be comfortable with core security concepts and ready to apply hands-on skills in realistic lab environments to detect, respond to, and resolve incidents.

Recommended experience

Practical work experience can help ensure that you have mastered the skills necessary for certification. Training is available in a variety of modalities including live training and OnDemand. Practical work experience in incident handling or related security roles; College level courses or self-paced study through other programs or materials; Familiarity with common attack techniques, vectors, and tools

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Incident Response and Investigation
  • Incident Response and Cyber Investigation
  • Network and Log Investigations
  • Malware and AI Assisted Investigations
3 objectives · 139 free questions · 28 pages
Attack Techniques and Detection
  • Detecting Evasive and Post-Exploitation Techniques
  • Detecting Exploitation and Covert Communications Tools
  • Endpoint Attack and Pivoting
3 objectives · 123 free questions · 26 pages
Web Application Security
  • Exploiting Insecure Web Application References
  • Web Application API Attacks
  • Web Application Injection Attacks
3 objectives · 172 free questions · 35 pages
Credential and Access Security
  • Attacking Passwords
  • Understanding Passwords
  • Securing Credentials and Data in the Cloud
3 objectives · 122 free questions · 26 pages
Network and Infrastructure Security
  • Scanning and Mapping
  • SMB Security
2 objectives · 94 free questions · 19 pages
Emerging Technologies and Offensive Operations
  • Integrating LLMs with Offensive Operations
1 objectives · 32 free questions · 7 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Certified Incident Handler
Exam formatCyberLive hands-on testing with performance-based challenges in realistic lab environments
Duration240 minutes
Questions106 questions
Passing score69%
DeliveryGIAC
PricingUS $499
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Certified Incident Handler

GIAC Certified Incident Handler badgeCredential earnedGIAC Certified Incident Handler Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

What is the CyberLive exam format?

CyberLive is a hands-on exam format that replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. It uses virtual machines, real security tools, and authentic code to validate real-world capability.

How does the GCIH exam relate to the GIAC Security Professional (GSP) portfolio certification?

GCIH is one of GIAC's Practitioner certifications that can be used toward earning the GIAC Security Professional (GSP) portfolio certification. GSP requires completing any three Practitioner certifications and any two Applied Knowledge certifications.

Can I take the GCIH exam remotely?

Yes. GIAC offers two proctoring options: remote proctoring through ProctorU and onsite proctoring through PearsonVUE.

What job roles does the GCIH certification map to?

The GCIH certification is for incident handlers, incident handling team leads, system administrators, security practitioners, security architects, and any security personnel who are first responders.

How do I prepare for the GCIH exam?

GIAC recommends training in a variety of modalities including live training and OnDemand. Practice tests are available to simulate the real exam and gauge your preparation. Practical work experience and college-level courses can also help ensure mastery.

What is the passing score for the GCIH exam?

The minimum passing score for the GCIH exam is 69%. This applies to all candidates who receive the exam version released on or after May 10th, 2025.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 682 questions, free, no account needed.