GIAC GCIH Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Domain Attacks | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against Domain attacks in Windows environments. |
| Scanning and Mapping | - The candidate will demonstrate an understanding the fundamentals of how to identify, defend against, and mitigate against scanning; to discover and map networks and hosts, and reveal services and vulnerabilities. |
| Web App Attacks | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against Web Application Attacks. |
| Physical Access Attacks | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against physical access attacks. |
| Metasploit | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against the use of Metasploit. |
| Covering Tracks on Hosts | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against methods attackers use to remove evidence of compromise on hosts. |
| Memory and Malware Investigations | - The candidate will demonstrate an understanding of the steps necessary to perform basic memory forensics, including collection and analysis of processes and network connections and basic malware analysis. |
| Incident Handling and Digital Investigations | - The candidate will demonstrate an understanding of what Incident Handling is, why it is important, an understanding of the PICERL incident handling process, and industry best practices in Incident Handling and Digital Investigations. |
| Password Attacks | - The candidate will demonstrate a detailed understanding of the three methods of password cracking. |
| Network Investigations | - The candidate will demonstrate an understanding of the steps necessary to perform effective digital investigations of network data. |
| SMB Scanning | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate reconnaissance and scanning of SMB services. |
| Covering Tracks on the Network | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against methods attackers use to remove evidence of compromise on the network. |
| Reconnaissance and Open-Source Intelligence | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate public and open source reconnaissance techniques. |
| Drive-By Attacks | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against drive-by attacks in modern environments. |
| Netcat | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against the use of covert tools such as netcat. |
| Endpoint Attacks and Pivoting | - The candidate will demonstrate an understanding of how to identify, defend against, and mitigate against attacks against endpoints and attack pivoting. |
Choosing our GCIH exam quiz will be a wise decision that you make, because this decision may have a great impact in your future development. Having the certificate may be something you have always dreamed of, because it can prove that you have certain strength. Our GCIH exam questions can provide you with services with pretty quality and help you obtain a certificate. Our learning materials are made after many years of practical efforts and their quality can withstand the test of practice. Therefore, our GCIH learning materials can help you get a great financial return in the future and you will have a good quality of life.
Functional Features
Our GCIH exam questions can meet your needs to the maximum extent, and our learning materials are designed to the greatest extent from the customer's point of view. So you don't have to worry about the operational complexity. As soon as you enter the learning interface of our system and start practicing our GCIH learning materials on our Windows software, you will find small buttons on the interface. These buttons show answers, and you can choose to hide answers during your learning of our GCIH exam quiz so as not to interfere with your learning process. You can click these buttons to proofread your answers after you finish your studies. If you want to record important content, we also provide enough space for you to take notes. In short, you will find the functionality and practicality of our GCIH exam questions during the learning process. We will also continue to innovate and improve functionality to provide you with better services.
GCIH Structure
The test GCIH is the only benchmark necessary for obtaining the GIAC Certified Incident Handler designation. Also, it’s a proctored exam and candidates should pay a registration fee of $1,999 to be eligible for it. To add more, the exam includes 100 to 150 inquiries with different levels of complexity and structure. The candidates should know that they will have only 4 hours to reply to as many questions as possible and get a passing score of 70%.
What is the duration, language, and format of GCIH Exam
Format: Multiple choices, multiple answers
- Length of Examination: 4 Hours
- Language: English
- Number of Questions: 150
- Passing score: 73%
Providing System Services
To ensure that you have a more comfortable experience before you choose to purchase our GCIH exam quiz, we provide you with a trial experience service. Once you decide to purchase our learning materials, we will also provide you with all-day service. If you have any questions, you can contact our specialists. We will provide you with thoughtful service. Even if you unfortunately fail to pass the GCIH exam, you will also receive our refund of our learning materials. With our trusted service, our learning materials will never make you disappointed.
Topics Tested in GIAC GCIH Validation
The candidates who want to get the minimum passing score in the GCIH exam will need to demonstrate that they are proficient in the following topics:
- Becoming able to proficiently handle any incident and understanding how the PICERL incident management process works;
- Defending against drive-by attacks when working with modern software environments;
- Understanding the fundamental concepts related to mapping and scanning as well as discovering the most important network hosts and identifying the vulnerabilities;
- Discerning how to defend against attacks that might appear on the network;
- Grasping how to identify the attack pivoting and threats against endpoints as well as knowing how to defend against them;
- Identifying any attacks on the Domain and defending against them when operating a Windows environment;
- Mitigating against attacks against the Web Application and defending against such threats;
- Scanning and mitigating reconnaissance of different types of SMB services.
- Understanding how to defend against attacks and mitigate each situation to gather evidence and identify the sources;
- Identifying and mitigating against any attacks that might affect the physical access into the network;
- Finding out about different techniques related to open and public source reconnaissance and knowing how to defend against them;
- Performing malware and memory investigations as well as collecting and analyzing the network connections and processes involved in this forensics;
- Understanding how to mitigate and defend against Netcat or other convert tools;
- Becoming able to identify and mitigate against the Metasploit use;
- Accelerating solid knowledge of the three methods used for preventing password cracking;
- Developing the necessary steps for developing professional digital investigations and working with different types of network data;
Reference: http://www.giac.org/certification/certified-incident-handler-gcih
Versions Can Meet Different Needs
There are different versions of our GCIH learning materials. Whether you like to study on the computer or like to read paper materials, our learning materials can meet your needs. If you are used to reading paper study materials for most of the time, you can eliminate your concerns. Our GCIH exam quiz takes full account of customers' needs in this area. Because our PDF version of the learning material is available for customers to print, so that your free time is fully utilized, and you can often consolidate your knowledge. Everything you do will help you pass the GCIH exam and get your GIAC certificate. Of course, the APP and PC versions are also very popular. They can simulate the actual operation of the test environment, and users can perform mock tests for a limited time. And it has the practicality of correcting online error and other functions. The three versions of GCIH exam questions all have the feature that they have no limit on the number of users, so you will not encounter the problem of not obtaining our learning materials.

855 Customer Reviews
