You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The GIAC Enterprise Incident Response (GEIR) certification validates your command of enterprise-class incident response and threat hunting tools and techniques. It is designed for incident response team leads, threat hunters, and forensic analysts who must understand attacker movement across Windows, Linux, macOS, containers, and cloud environments. Earning GEIR proves you can coordinate large-scale investigations and respond effectively to modern attacks.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The GIAC Enterprise Incident Response (GEIR) certification validates a practitioner's command of enterprise-class incident response and threat hunting tools and techniques. GEIR certification holders are qualified to employ analysis methodologies to understand attacker movement across varying functions and operating systems. The certification covers incident response team management and coordination, enterprise incident detection and threat hunting, large-scale event correlation and timeline analysis, and multi-platform artifact analysis across Windows, Linux, macOS, containers, and cloud environments.
GEIR is delivered through GIAC's CyberLive format, a hands-on exam that replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. Candidates work with full-scale virtual machines, real security tools, and authentic code to demonstrate real-world capability. The certification is ideal for incident response team leads, threat hunting professionals, experienced digital forensic analysts, enterprise detection engineers, and federal agents or law enforcement professionals looking to apply forensic skills at scale.
The GEIR certification is for incident response team leads and advanced practitioners, threat hunting professionals, experienced digital forensic analysts, enterprise detection engineers, and federal agents or law enforcement professionals. It is also suited for SANS DFIR alumni looking to apply their forensic skills at scale. Candidates should have a deep understanding of incident response methodologies and be comfortable working with enterprise-scale tools and data. The certification is designed for those who are ready to lead and execute effective incident response in complex environments.
Practical work experience in incident response and threat hunting is recommended to ensure mastery of the skills necessary for certification. Training is available in various modalities including live training and OnDemand. Hands-on experience with enterprise incident response and threat hunting; Familiarity with Windows, Linux, macOS, container, and cloud environments; Understanding of digital forensics and incident response methodologies; Experience with large-scale event correlation and timeline analysis
Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.
The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source
Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path GIAC (SANS) lays out, how the credential is kept, and where to book.
Step-by-step path to GIAC Enterprise Incident Responder
GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.
Register for the exam through GIAC (via ProctorU for remote, Pearson VUE for onsite), GIAC (SANS)’s authorized testing partner.
Schedule your examVisit the official GIAC (SANS) certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksGEIR is a Practitioner-level certification focused on enterprise-class incident response and threat hunting. It complements other GIAC DFIR certifications like GCFA and GNFA, which focus on forensic analysis and network forensics respectively. GEIR emphasizes large-scale incident response and multi-platform artifact analysis.
Yes, the GEIR exam uses GIAC's CyberLive format, which is a hands-on exam that replaces traditional multiple-choice testing with performance-based challenges in realistic lab environments. Candidates work with virtual machines, real security tools, and authentic code.
GIAC does not publicly specify a retake policy for the GEIR exam. Candidates should refer to their GIAC account or contact GIAC support for details on retake policies and waiting periods.
GIAC does not publicly specify the exact timing for score report availability. Candidates should check their GIAC account for score release information after completing the exam.
GEIR is designed for incident response team leads, threat hunting professionals, experienced digital forensic analysts, enterprise detection engineers, and federal agents or law enforcement professionals.
GIAC certifications can be renewed by retaking the same exam or by earning CPE credits. Passing a different GIAC exam does not automatically renew GEIR, but CPEs earned from other certifications may count toward renewal.
GIAC offers remote proctoring through ProctorU and onsite proctoring through Pearson VUE. Regional availability may vary; candidates should check their GIAC account for available options in their location.
Every domain, every objective, and every concept GIAC (SANS) measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
47 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 11 objectives, 97 concepts written under them, and free questions against every one. When GIAC (SANS) changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.