
GIAC Enterprise Incident Responder
The GIAC Enterprise Incident Response (GEIR) certification validates your command of enterprise-class incident response and threat hunting tools and techniques. It is designed for incident response team leads, threat hunters, and forensic analysts who must understand attacker movement across Windows, Linux, macOS, containers, and cloud environments. Earning GEIR proves you can coordinate large-scale investigations and respond effectively to modern attacks.
503 practice questions · Updated 2026-07-30
5Domains
11Objectives
97Concepts
503Questions
GEIR Curriculum
Every domain, objective, and concept the GEIR exam measures.
- Incident Response Lifecycle
- Incident Response Team Roles
- Incident Classification and Triage
- Incident Response Procedures
- Communication and Coordination
- Legal and Regulatory Considerations
- Post-Incident Activities
- Enterprise Visibility Architecture
- Data Source Identification
- Log Collection and Aggregation
- Network Visibility
- Endpoint Visibility
- Cloud and Virtualized Environment Visibility
- Visibility Gaps and Limitations
- Incident Scoping Fundamentals
- Scoping Techniques
- Scope Expansion and Containment
- Documentation and Reporting of Scope
- Triage Fundamentals
- Triage Process Workflow
- Automated Triage Techniques
- Prioritization Criteria
- Data Sources and Enrichment
- Handling Alert Fatigue
- Human-in-the-Loop Decision Making
- Metrics and Continuous Improvement
- Cloud Service Models
- Cloud Deployment Models
- Shared Responsibility Model
- Virtualization Fundamentals
- Cloud Storage and Data Lifecycle
- Cloud APIs and Management Plane
- Cloud Identity and Access Management
- Cloud Logging and Monitoring
- Cloud Incident Response Fundamentals
- Cloud Service Models and Shared Responsibility
- Cloud Evidence Acquisition
- Cloud Log Sources and Analysis
- Cloud Metadata and Instance Forensics
- Container and Orchestration Forensics
- Cloud Network Traffic Analysis
- Cloud Incident Containment and Remediation
- Cloud Forensic Challenges and Legal Considerations
- Container Runtime Fundamentals
- Container Image Layers and Overlay Filesystems
- Container Namespaces and Isolation
- Container Control Groups (cgroups)
- Container Orchestration Basics
- Container Artifacts for Forensics
- Container Runtime Events and Logging
- Container Process and Network Visibility
- Container Image and Registry Forensics
- Container Isolation and Escape Indicators
- Modern attack detection fundamentals
- Attack lifecycle and kill chain mapping
- Detection of initial access vectors
- Detection of execution and persistence
- Detection of privilege escalation and lateral movement
- Detection of command and control (C2)
- Detection of data exfiltration
- Detection of defense evasion
- Correlation and alert triage
- Incident response integration
- Linux File System Hierarchy
- Essential Linux Commands
- File Permissions and Ownership
- Process Management
- User and Group Administration
- Package Management
- System Logging
- Networking Basics
- Shell Scripting Fundamentals
- Text Processing Tools
- Linux file system hierarchy
- File metadata and timestamps
- Process and memory artifacts
- User and authentication artifacts
- Persistence mechanisms
- Log analysis fundamentals
- Network configuration and connections
- File system integrity and hashing
- Acquisition and preservation basics
- macOS File System Layout
- macOS Plist Files
- macOS Logging Mechanisms
- macOS User and Account Management
- macOS Application and Process Management
- macOS Network Configuration
- macOS Security Features
- macOS File System Layout
- macOS Artifacts Overview
- macOS User and Account Management
- macOS Process and Application Execution
- macOS Network and Connectivity Artifacts
- macOS Persistence Mechanisms
- macOS Security and Privacy Features
- macOS Logging and Auditing
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GEIR, so none is invented.