Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Cloud Threat Detection

GIAC Cloud Threat Detection (GCTD)

The GIAC Cloud Threat Detection (GCTD) certification validates your ability to detect and investigate suspicious activity in cloud infrastructure. It is designed for security professionals who monitor, detect, and respond to threats across AWS and Azure environments. Earning GCTD proves you can leverage cloud-native tools, third-party solutions, and custom automations to defend cloud services effectively.

Exam formatMultiple choice
Duration120 minutes
DeliveryGIAC
Passing score70%
Free questions575

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Cloud Threat Detection proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
12objectives
102concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Cloud Threat Detection (GCTD) certification validates a practitioner's ability to detect and investigate suspicious activity in cloud infrastructure. It is designed for experienced professionals in cyber threat intelligence, secure cloud configuration, and critical practices for defending cloud solutions and services. GCTD holders demonstrate hands-on skills in monitoring Azure and AWS environments, analyzing cloud telemetry, and responding to threats in near-real-time.

The certification covers detecting attacks in the cloud, cloud investigations and cyber threat intelligence, and assessments and automation in AWS and Azure. It emphasizes practical, real-world skills—from configuring and accessing host, network, and application logs to using cloud analytic services and building automated detection and response workflows. Earning GCTD proves you can protect cloud environments by understanding attacker techniques and applying effective detection and investigation strategies.

Who it’s for

This certification is for anyone who performs monitoring, threat detection, or incident response in cloud environments, as well as those responsible for logging in a cloud environment. It is ideal for security analysts, security engineers, security architects, vulnerability assessors, and incident responders who work with AWS and Azure. Candidates should have practical experience with cloud security and be comfortable using cloud vendor-provided capabilities, third-party tools, and native command-line tools to detect and investigate threats. The certification is designed for professionals who want to validate their ability to defend cloud infrastructure effectively.

Recommended experience

Practical work experience in cloud security, threat detection, or incident response is recommended to ensure mastery of the skills necessary for certification. Experience monitoring and investigating threats in AWS and Azure environments; Familiarity with cloud logging, telemetry sources, and security analytics; Understanding of cloud automation and serverless functions for response workflows; Knowledge of containers, orchestration, and common cloud attack techniques

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Cloud Monitoring Foundations
  • Cloud Monitoring Fundamentals
  • Log Centralization
  • Network and Flow Monitoring
3 objectives · 116 free questions · 24 pages
Cloud Infrastructure Monitoring
  • Host OS Monitoring
  • Containers and Orchestration
  • Data and Storage Monitoring
  • Application and Proxy Monitoring
4 objectives · 210 free questions · 44 pages
Cloud Threat Detection and Response
  • Automated Detection and Response
  • Cyber Threat Intelligence for the Cloud
  • Cloud Vulnerability Analysis
3 objectives · 146 free questions · 30 pages
Cloud Provider Investigations
  • Investigating AWS Environments
  • Investigating Azure Environments
2 objectives · 103 free questions · 21 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Cloud Threat Detection
Exam formatMultiple choice
Duration120 minutes
Questions75 questions
Passing score70%
DeliveryGIAC
LanguagesEnglish
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Cloud Threat Detection

GIAC Cloud Threat Detection badgeCredential earnedGIAC Cloud Threat Detection Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does GCTD relate to other GIAC cloud certifications?

GCTD is a Practitioner certification focused on threat detection and response in cloud environments. It complements other GIAC cloud certifications like GIAC Cloud Security Automation (GCSA) and GIAC Cloud Security Architecture and Design (GCAD), which cover different aspects of cloud security.

Is there a hands-on or lab component in the GCTD exam?

The GCTD exam is a proctored, multiple-choice exam. It does not include a CyberLive hands-on component, unlike some other GIAC certifications.

What is the retake policy for the GCTD exam?

GIAC allows candidates to retake the exam after a waiting period. Specific retake policies are detailed in the GIAC terms and conditions on the official website.

Can I earn CPE credits for the GCTD certification by taking SANS courses?

Yes, SANS training courses and conferences are eligible for CPE credits toward GIAC certification renewal, including GCTD.

What job roles does the GCTD certification map to?

GCTD is designed for security analysts, security engineers, security architects, vulnerability assessors, and incident responders who work with cloud environments.

Is GCTD available in regions outside the United States?

GIAC exams are available globally through remote proctoring via ProctorU and onsite proctoring through PearsonVUE, subject to regional availability.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 575 questions, free, no account needed.