GIAC GCIH (Certified Incident Handler)

GIAC / SANS Institute

Complete guide to passing the GIAC GCIH (Certified Incident Handler) exam on your first attempt.

Very HardHigh Search Volume
Key Information at a Glance
Cost

$2,499 (exam only; SANS training ~$7,000+)

Pass Rate

~62%

Validity

4 years (renewable with CPEs)

Region

Global

Provider

GIAC / SANS Institute

Salary Impact

$110k-$170k

Are you ready for GIAC GCIH (Certified Incident Handler)?

Loading quiz...

Complete Overview

The GIAC Certified Incident Handler (GCIH) is a hands-on incident response certification from GIAC, the certification arm of the SANS Institute, that tests whether you can detect an intruder already inside a network and drive the response to closure. It is taken by SOC analysts, incident responders, threat hunters, forensic examiners and system administrators who own the first hours of a breach, and GIAC lists a standalone certification attempt at $999 on its published pricing page. Most candidates reach it through SANS SEC504, Hacker Tools, Techniques, and Incident Handling, priced by SANS at $8,780 for the six-day course.

The exam is 106 questions in 4 hours, and GIAC sets the minimum passing score at 69% for the exam version released on or after 10 May 2025. It is a proctored web-based exam delivered either remotely through ProctorU or on-site at a Pearson VUE test centre, and it includes CyberLive items: live virtual machines inside the exam where you run real tools against real data rather than picking an answer about them. GIAC describes these lab systems as behaving like physical computers, so you install, attack, defend and run services during the test.

GCIH is open book in a very specific sense. GIAC lets you bring printed books, printed notes and a handwritten or printed index into the testing area, and prohibits every digital reference: no PDFs, no Word documents, no internet, no second computer. Hardcopy material that looks like practice questions and answers is also barred. That rule shapes the whole preparation strategy, because your index is the artefact that decides whether 4 hours is enough time.

GIAC publishes 15 exam certification objectives for GCIH covering password attacks, scanning and mapping, SMB security, exploitation and covert communications tools, endpoint attack and pivoting, three separate web application objectives, evasive and post-exploitation technique detection, cloud credential security, network and log investigations, malware and AI-assisted investigations, LLM use in offensive operations, and the PICERL and DAIR incident handling processes. GIAC does not publish percentage weights for these objectives, and the objective list is the only breakdown it gives, so build your study tracker from the 15 objective names rather than from a weighting.

A certification attempt gives you 120 days to sit the exam, extendable in 45-day blocks up to a 570-day maximum access period. The certification is valid for four years and renews on 36 CPE credits plus a $499 maintenance fee, or by passing the current version of the exam. GIAC is an ANAB-accredited ISO/IEC 17024 personnel certification body, which is why GCIH appears on federal and defence workforce qualification lists and why hiring managers in regulated sectors treat it as a verified credential rather than a self-declared one.

Why Get GIAC GCIH (Certified Incident Handler) Certified?

The CyberLive portion puts live virtual machines inside the exam, so a pass is evidence you operated real tooling under time pressure rather than recognising tool names on a multiple choice list. GIAC states these lab systems behave like physical computers and let you install, attack, defend and run services.

GIAC is an ANAB-accredited ISO/IEC 17024 personnel certification body, which is the accreditation that lets GCIH be written into federal, defence and regulated-industry job requirements as a hard qualification.

The 15 published objectives were refreshed to include AI-era content, with dedicated objectives for integrating LLMs with offensive operations and for malware and AI-assisted investigations, so the material maps to attacks teams are seeing now.

GCIH pairs directly with SANS SEC504, which SANS lists as six days or 38 self-paced hours, 38 CPE credits and 44 hands-on labs, running from incident response and scanning through password attacks, web application attacks and post-exploitation to a full-day capture-the-flag event.

The certification covers both sides of the incident: the PICERL and DAIR handling processes on the defensive side, and Nmap, Metasploit and Netcat tradecraft on the offensive side, so you can reason about what the intruder did next.

Renewal takes 36 CPE credits over four years plus a $499 maintenance fee, and CPEs earned from other SANS training, conference attendance and published work count, so upkeep folds into normal professional activity.

Payscale reports an average base salary of $114,000 for GCIH holders, drawn from 760 survey responses. GIAC publishes no salary data of its own, and the certification most often appears as a screening line on senior incident responder and DFIR consultant postings.

Exam Format & Structure

Duration

4 hours

Questions

106 questions

Passing Score

69% minimum, for the exam version released on or after 10 May 2025

Question Types

  • Knowledge and analysis questions drawn from the 15 published exam certification objectives
  • CyberLive performance-based items answered inside a live virtual machine
  • Scenario items requiring analysis of network and log data

Delivery Method

Proctored web-based exam, taken remotely through ProctorU or on-site at a Pearson VUE testing centre

Exam Domains & Topics

Incident response and cyber investigation
not published

GIAC tests understanding of the PICERL and DAIR incident handling processes and the practical obstacles that derail a response. This grouping also carries the investigative objectives: reconstructing activity from network and log data, and analysing malware with AI-assisted techniques. Expect questions that hand you evidence and ask what phase you are in and what action comes next.

Key Topics to Master:

  • PICERL phases: preparation, identification, containment, eradication, recovery, lessons learned
  • The DAIR incident handling process and how it differs from PICERL
  • Incident response challenges and common process failures
  • Network and log investigations across host and network sources
  • Malware analysis fundamentals
  • AI-assisted investigative techniques
  • Evidence handling and chain of custody during a live incident
  • Deciding when containment must precede full scoping
Scanning, mapping and SMB security
not published

This grouping covers discovery of networks and hosts, revealing services and vulnerabilities, and identifying and defending against scanning activity. It also carries the SMB objective, which asks about SMB features and vulnerabilities, discovering and accessing shares, and hardening the service. Nmap is the named tool in GIAC's own areas covered list.

Key Topics to Master:

  • Nmap host discovery, port scanning and service version detection
  • Interpreting scan output and fingerprinting results
  • Detecting and defending against scanning from the defender side
  • SMB protocol features and versions
  • Discovering and accessing SMB shares
  • SMB vulnerabilities and how to secure the service
  • Vulnerability identification during enumeration
  • Network mapping and target profiling
Passwords, credentials and cloud storage
not published

Three GIAC objectives sit here. Understanding Passwords asks you to identify password hashes, explain password weaknesses and secure passwords. Attacking Passwords asks for a detailed understanding of how password attacks are conducted. Securing Credentials and Data in the Cloud extends both to cloud environments, including insecure storage and mitigation.

Key Topics to Master:

  • Identifying password hash formats
  • Password weaknesses and policy failures
  • Conducting password attacks: guessing, cracking and spraying
  • Credential harvesting and reuse across systems
  • Cloud credential exposure and insecure storage
  • Defending and mitigating password attacks in cloud environments
  • Securing stored passwords and secrets
  • Detecting credential attacks in authentication logs
Exploitation tools, endpoint attack and pivoting
not published

GIAC names Metasploit as the exploitation framework and Netcat as the covert communications tool in its published objectives and areas covered. The endpoint objective asks you to identify and defend against endpoint-specific attacks and against pivoting through an environment. Questions test both the offensive mechanics and the defensive detection signal.

Key Topics to Master:

  • Metasploit framework structure, payloads and handlers
  • Netcat for covert communication and relays
  • Identifying exploitation tool artefacts on a host
  • Endpoint-specific attack techniques
  • Pivoting and lateral movement through an environment
  • Defending against and detecting pivoting
  • Exploit delivery and payload behaviour
  • Host-based indicators left by exploitation frameworks
Web application and API attacks
not published

Three separate GIAC objectives cover the web tier: exploiting insecure web application references, the basics of interacting with and abusing access to web APIs, and common web application injection attacks. Three of the fifteen objectives sit in this one tier, and CyberLive items here can require you to manipulate a real request rather than describe one.

Key Topics to Master:

  • Insecure direct object references and other insecure reference patterns
  • Interacting with web APIs and abusing access controls
  • SQL injection techniques and detection
  • Command injection and other injection classes
  • Cross-site scripting variants
  • Session handling and authentication bypass
  • Reading web server logs for attack evidence
  • Proxying and modifying HTTP requests
Evasion, post-exploitation and offensive LLM use
not published

GIAC asks you to identify and defend against an attacker already in the environment, covering persistence methods, how intruders hide their presence, and how they achieve actions on objectives. Paired with it is the newer objective on integrating LLMs with offensive operations, which covers LLM risks and AI-specific defensive strategies.

Key Topics to Master:

  • Persistence mechanisms on Windows and Linux
  • Anti-forensic and presence-hiding techniques
  • Actions on objectives: collection, staging and exfiltration
  • Detecting post-exploitation activity in telemetry
  • LLM use in offensive operations
  • AI-specific risks and defensive strategies
  • Living-off-the-land binaries and abuse of native tooling
  • Threat hunting for an established intruder

Recommended Study Plan

Week 1: Register, scope the exam, and set up a lab
6-8 hours
  • 1Read the GCIH page on giac.org and copy all 15 exam certification objectives into a tracking spreadsheet with a confidence column
  • 2Buy or activate the certification attempt and note your 120-day deadline in a calendar
  • 3Build a lab with a Windows target, a Linux target and a Kali or SANS Slingshot attacker VM
  • 4Read GIAC's exam preparation best practices page and the Proctored Exam Quick Reference Guide
  • 5Decide now whether you will test with ProctorU remotely or at a Pearson VUE centre, because the seat availability differs
Week 2: SEC504 Section 1: incident response and cyber investigations
10-12 hours
  • 1Work through the incident response material and write out PICERL and DAIR side by side, phase by phase
  • 2Practise a full tabletop on a ransomware scenario and record where containment and eradication decisions conflict
  • 3Start your index: one row per concept with book number, page number and a short cue phrase
  • 4Complete every lab in this section, then repeat the two you were slowest on
  • 5Collect log samples from your lab hosts so you have real data to investigate later
Week 3: Scanning, mapping and SMB
10-12 hours
  • 1Run Nmap against your lab subnet with varied scan types and record the differences in output and in what the target logged
  • 2Enumerate SMB shares on the Windows target and then apply hardening, retesting after each change
  • 3Add the scanning and SMB objectives to your index with tool flags spelled out, since flags are what you forget under time pressure
  • 4Write a short detection note for each scan type describing what a defender would see
Week 4: Passwords, hashes and cloud credential exposure
10-12 hours
  • 1Build a reference sheet of hash formats and how to tell them apart on sight, and put it early in your index
  • 2Run password attacks against lab accounts and observe the authentication events generated
  • 3Study the cloud credential objective specifically, covering insecure storage of keys and secrets
  • 4Take your first GIAC practice test if your attempt included them, and use it purely to find weak objectives
Week 5: Exploitation frameworks, Netcat and pivoting
12-14 hours
  • 1Complete Metasploit labs end to end, including selecting payloads and configuring handlers
  • 2Use Netcat for a bind shell, a reverse shell and a file transfer, and record the network artefacts each leaves
  • 3Set up a pivot through a compromised host and document the detection opportunities at each hop
  • 4Index the tool syntax pages, not the explanatory prose, because syntax is what CyberLive items demand
Week 6: Web application and API attacks
12-14 hours
  • 1Work all three web objectives: insecure references, API abuse, and injection attacks
  • 2Practise injection against a deliberately vulnerable application in your lab until you can do it without notes
  • 3Practise intercepting and modifying HTTP requests through a proxy so the CyberLive workflow is muscle memory
  • 4Review web server and application logs from your own attacks and write the detection signature you would deploy
Week 7: Post-exploitation, evasion and AI-related objectives
12-14 hours
  • 1Establish persistence three different ways on the Windows target and then hunt for each one
  • 2Study the evasive and post-exploitation objective against your own artefacts rather than reading it abstractly
  • 3Read GIAC's LLM offensive operations objective and the corresponding SEC504 Section 5 material on AI attacks
  • 4Complete malware analysis labs and index the triage workflow as a numbered procedure
Week 8: Finish and stress-test the index
10-12 hours
  • 1Complete the index across all six course books, sorted alphabetically, with book and page for every entry
  • 2Colour-code by book so you can grab the right physical volume without reading the header
  • 3Have a colleague call out 20 random terms and time how long each lookup takes, targeting under 30 seconds
  • 4Print and bind the index, since digital copies are prohibited in the exam room
  • 5Add a separate tool-syntax appendix for Nmap, Metasploit and Netcat
Week 9: Practice test one under exam conditions
8-10 hours
  • 1Sit a full practice test in 4 hours using only printed material, replicating the real constraint
  • 2Log every question where you had to look something up and how long the lookup took
  • 3Rebuild index entries for every slow lookup, since the fix is almost always the index, not the knowledge
  • 4Redo the CyberLive-style hands-on tasks you fumbled, in your own lab
Week 10: Close the gaps the practice test exposed
10-12 hours
  • 1Rework the two lowest-scoring objectives from the practice test using the SEC504 labs, not just the reading
  • 2Re-run the CTF material from SEC504 Section 6 to rehearse working under time pressure
  • 3Confirm your ProctorU technical requirements or book your Pearson VUE seat now
  • 4Check that the first and last name on your GIAC account exactly matches your photo ID
Week 11: Practice test two and final calibration
8-10 hours
  • 1Sit the second practice test and compare scores objective by objective against the first
  • 2Aim comfortably above 69% on the practice test before scheduling, because CyberLive items consume time the practice test does not model well
  • 3Do a full dry run of your exam-day setup: desk, printed books, index, ID documents
  • 4Rehearse the CyberLive workflow of switching between the question pane and the live virtual machine
Week 12: Exam week
6-8 hours
  • 1Review only your index and your tool-syntax appendix, not new material
  • 2Confirm both forms of ID are current, original and issued by the country you are testing in
  • 3Sit the exam with all printed books physically arranged in the order you use them
  • 4Record your score report and, if you passed, start logging CPEs immediately toward the 36 needed in four years

Ready to pass GIAC GCIH (Certified Incident Handler)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$1250$625

Best Study Resources

GIAC GCIH certification page

Official exam page

The authoritative source for the 106-question format, the 4-hour limit, the 69% minimum passing score and all 15 exam certification objectives with their outcome statements. Check it before you trust any third-party summary of the blueprint.

Free

SANS SEC504: Hacker Tools, Techniques, and Incident Handling

Official training course

The course GIAC maps GCIH to. Six days or 38 self-paced hours, 38 CPE credits and 44 hands-on labs, structured across incident response, scanning and enumeration, password attacks and exploit frameworks, web application attacks, post-exploitation and AI attacks, and a capture-the-flag day.

$8,780 USD listed by SANS

GIAC practice tests

Official practice exam

The only practice material built from the same item bank style as the live exam. Use them to test your index under time pressure, not just your recall.

$399 each standalone; two are included when a certification attempt is bundled with SANS training

GIAC pricing page

Official reference

Lists the $999 certification attempt, $899 retake, $399 practice exam, $479 attempt extension and $499 certification renewal, plus the note that additional renewals within two years of a full-price renewal cost $249.

Free

GIAC retakes and extensions policy

Official policy

Sets out the 120-day attempt window, the 30-day mandatory wait after a failure, the non-waivable 14-day minimum, the 45-day extension blocks with a limit of 10, the 570-day maximum access period and the one-year lockout after three failed attempts.

Free

GIAC exam preparation best practices

Official guidance

GIAC's own advice on building a systematic colour-coded index and why creating it yourself beats borrowing one. It also confirms all printed books, notes and study guides are allowed and digital items are not.

Free

GIAC proctoring information

Official logistics guide

Explains the two delivery routes, ProctorU remote and Pearson VUE on-site across more than 3,500 centres, and links the Proctored Exam Quick Reference Guide and the Remote Proctor Guide.

Free

GIAC disability accommodation policy

Official policy

Describes how GIAC applies the framework of the Americans with Disabilities Act and Section 504 of the Rehabilitation Act, how approved accommodations are communicated by email, and the appeal process if a request is declined.

Free

GIAC certification renewal page

Official policy

Confirms the two renewal routes: collect 36 CPE credits over four years, or retake and pass the current exam. Use the renewal dashboard to track credits as you earn them rather than reconstructing them in year four.

Free

Your own lab of Windows, Linux and attacker virtual machines

Self-built practice environment

CyberLive items are answered inside live systems, so reading about Nmap flags or Netcat relays does not transfer. A three-VM lab lets you rehearse the exact workflows the performance-based items require.

Free using evaluation images and open-source distributions

Common Mistakes to Avoid

Treating open book as a substitute for knowing the material, and planning to look up most answers.

You have 4 hours for 106 questions plus CyberLive labs, which averages roughly two minutes per item before any lab time. Look-ups should confirm a detail you already half-remember. Aim to answer at least 70% of questions without touching a book.

Building the index in the last week, or downloading someone else's index.

Build the index as you work through each SEC504 section, then spend a dedicated week refining it, because the act of writing entries is where the page numbers become memorable. A borrowed index uses someone else's mental model and someone else's page numbers if the course version differs.

Bringing digital reference material, expecting the exam to allow a PDF of the course books.

GIAC prohibits anything stored electronically during the exam, including PDF and Word documents, and the exam is not open internet or open computer. Print and bind everything, including your index and any tool cheat sheets.

Preparing for a purely multiple-choice exam and being surprised by the CyberLive virtual machines.

CyberLive items drop you into a live lab system where you run real tools against real data. Rehearse the mechanics in your own lab: launching the tool, reading its output and getting to an answer, not just recognising the tool name.

Indexing prose rather than syntax, so the tool pages are the hardest ones to find.

Keep a separate printed appendix of exact command syntax for Nmap, Metasploit and Netcat, with the flags spelled out. Under exam pressure the recall failure is almost never conceptual, it is which flag does which thing.

Studying the offensive tooling and skipping the incident handling process because it looks like memorisation.

GIAC has a dedicated objective on the PICERL and DAIR processes and on incident response challenges. Learn both process models phase by phase and be able to place a scenario in the correct phase, because process questions are among the fastest points available.

Ignoring the newer AI-related objectives because they were not in older versions of the course.

GIAC now publishes objectives on integrating LLMs with offensive operations and on malware and AI-assisted investigations. Older study guides and community notes predate these. Work from the current objective list on the GIAC page, not from a forum post.

Registering the attempt and then letting the 120-day clock run down while waiting for a training slot.

An attempt allows 120 days, extendable in 45-day blocks with a maximum of 10 extensions and a 570-day total access period. Extensions cost $479 each. Schedule your exam date first and build the study plan backwards from it.

Booking the exam under a name that does not exactly match the photo ID you will present.

GIAC requires the first and last names on the appointment to match your IDs, and a mismatch at a testing centre means you are turned away and charged a $175 seating fee to rebook. Check the spelling on your GIAC account against your passport or licence weeks in advance.

Exam Day Tips

  • 1

    Bring two forms of current, original identification issued by the country you are testing in, or a passport from your country of citizenship plus a second ID. Photocopies and digital images are rejected.

  • 2

    Your primary ID needs your first and last name, a photo and a signature. Your secondary ID needs your name plus either a photo or a signature. Confirm both before you leave home.

  • 3

    Carry every printed book you own for the course. GIAC allows an armful of hardcopy books and notes, including original course material and your own handwritten or printed notes and index.

  • 4

    Leave behind anything that resembles practice questions and answers in printed form. GIAC prohibits hardcopy material that looks like an exam dump, and a proctor can remove it.

  • 5

    Arrange your books in the order you use them before the timer starts, with the index on top and the tool-syntax appendix within reach. Rearranging books during a 4-hour exam costs real minutes.

  • 6

    If you test remotely with ProctorU, run the technical check on the same machine, network and room you will use, not on a different laptop. Remote check-in adds time before your exam clock begins.

  • 7

    If you test at a Pearson VUE centre, arrive early enough to complete check-in and locker storage. There are more than 3,500 Pearson VUE centres, so pick one you can reach without a stressful commute.

  • 8

    Budget your time against 106 questions in 240 minutes and expect CyberLive items to take longer than a text question. GIAC does not let you review or change an answer once submitted, but it does let you skip between 10 and 15 questions depending on the exam version, and skipped questions return at the end as time allows.

  • 9

    For each CyberLive item, read the whole task before touching the virtual machine, then decide which single tool answers it. The lab is a means to an answer, not an open-ended exercise.

  • 10

    GIAC gives you 15 minutes of break time inside the exam, taken in one block or split into two sessions using the Take a Break button. The clock restarts automatically at the 15-minute mark whether you are back or not, so plan the break around a question boundary rather than mid-lab.

Career Paths & Salary Ranges

Incident responder

Owns the response from detection through eradication and recovery. GCIH maps almost exactly to this role because the PICERL and DAIR objectives and the network and log investigation objective are the daily work.

Payscale puts the GCIH average base salary at $114,000; this role sits close to it

SOC analyst, tier 2 or tier 3

Triages escalated alerts and decides which are real intrusions. The scanning detection, endpoint attack and post-exploitation objectives are what separate a tier 3 analyst from a tier 1 alert closer.

Below Payscale's $114,000 GCIH average at tier 2, closer to it at tier 3

Threat hunter

Searches for intruders no alert has caught, which is precisely the GIAC objective on identifying an attacker already in the environment, their persistence methods and how they hide their presence.

At or above Payscale's $114,000 GCIH average

Digital forensics and incident response consultant

Deploys into client breaches on short notice. Consulting firms weight GIAC certifications heavily because ANAB accreditation makes the credential defensible to clients and their insurers.

Above Payscale's $114,000 GCIH average, with consulting firms paying for on-call availability

Security engineer with detection responsibility

Builds the detections that catch the techniques GCIH covers. Knowing what Metasploit, Netcat and SMB enumeration actually emit on the wire and on the host is what makes the rules fire on real activity.

Around Payscale's $114,000 GCIH average

Federal or defence cybersecurity role

GIAC's ANAB-accredited ISO/IEC 17024 status is why GCIH appears in defence and federal workforce qualification requirements, where a named certification is a condition of holding the position.

Set by pay grade rather than by certification; Payscale's $114,000 GCIH average is a private-sector comparison

Prerequisites & Requirements

  • GIAC does not require any certification, degree or minimum years of experience to register a GCIH attempt.
  • SANS lists recommended background for SEC504: basic networking knowledge including TCP/IP and DNS, working understanding of Windows and Linux, foundational cybersecurity principles and comfort with the command line.
  • Training is not mandatory. GIAC allows a standalone certification attempt without attending SEC504, though the open-book format is built around having course books to index.
  • A certification attempt gives you 120 days to sit the exam, so register when you are ready to study rather than months ahead.
  • You must be able to present two forms of current, original identification at check-in, and minors require GIAC's separate minor agreement.

Frequently Asked Questions

How many questions is the GCIH exam and how long do I get?

The GCIH exam is 106 questions with a 4-hour time limit. That works out to roughly two minutes per question before any time spent on the CyberLive hands-on items, which take longer than text questions.

What is the passing score for GCIH?

GIAC sets the minimum passing score at 69% for the GCIH exam version released on or after 10 May 2025. GIAC adjusts cut scores between exam versions, so confirm the figure on the GCIH page on giac.org before you sit.

What happens if I fail the GCIH exam?

You must wait 30 days before retaking, and you can purchase a retake. Purchasing a retake extends your attempt deadline by 60 days in total, which includes the waiting period. A waiver of the 30-day wait can be requested, but a mandatory 14-day wait applies to all candidates and cannot be waived.

How many times can I retake GCIH?

After three failed attempts your certification attempt is closed as unsuccessfully completed and you must wait one year before starting a new attempt. GIAC allows a waiver request to sit one final retake before that lockout applies, which requires documentation of at least 30 hours of additional training.

How much does GCIH cost?

GIAC's published pricing lists a standard certification attempt at $999 and a retake at $899, in US dollars and excluding sales tax. A practice exam is $399, an attempt extension is $479 and a certification renewal is $499. GIAC publishes one global price list rather than regional pricing.

Do I have to take SANS SEC504 to sit GCIH?

No. GIAC has no training requirement and you can buy a standalone certification attempt. SANS lists SEC504 at $8,780, and the open-book format assumes you have printed reference material, so self-study candidates need to assemble and index their own.

Is GCIH really open book, and what can I bring?

GCIH is open book for printed material only. GIAC allows an armful of hardcopy books and notes including original course material, plus handwritten or printed notes and an index. Digital material is prohibited, so no PDFs, no Word documents, no internet and no second computer. Printed material that looks like practice questions and answers is also banned.

What is CyberLive on the GCIH exam?

CyberLive items are hands-on questions answered inside live virtual machines within the exam. GIAC describes them as full-scale lab systems that behave like physical computers, where you install, attack, defend and run services using real security tools and authentic code.

How long do I have to sit the exam after I register?

A certification attempt gives you 120 days to complete the exam. You can buy extensions that add 45 days each, up to 10 extensions, and the total access period across all extensions and retakes is capped at 570 days. Each extension is $479.

Where can I take the GCIH exam?

Two routes are available: remote proctoring through ProctorU from your own location, or on-site at a Pearson VUE testing centre, of which GIAC says there are more than 3,500 worldwide. GIAC notes that both options may not be available for every attempt, and lists sanctioned countries where neither route can be used.

What ID do I need for the GCIH exam?

Two forms of personal ID, both current and original, issued by the country in which you are testing. If they are not issued by that country, a passport from your country of citizenship is required as the primary ID plus a second form. The primary ID must show your first and last name, photo and signature. The secondary must show your name plus a photo or signature.

What if the name on my booking does not match my ID?

You will not be permitted to take the exam. GIAC states that a first and last name mismatch at a testing centre results in being turned away, and a $175 seating fee applies if you want to schedule a new appointment. Check your GIAC account name against your ID well before exam day.

How long is GCIH valid and how do I renew it?

GCIH is valid for four years. You renew either by collecting 36 CPE credits over the four-year cycle and paying the $499 certification maintenance fee, or by retaking and passing the current version of the exam. Additional renewals registered within two years of paying a full-price $499 renewal cost $249 each.

What counts as a CPE credit for GCIH renewal?

GIAC's renewal dashboard tracks credits earned through training, industry events and other professional activities. SANS courses carry published CPE values, and SEC504 itself is worth 38 CPE credits, so a single further SANS course covers a large share of the 36 required.

Are accommodations available for candidates with disabilities?

Yes. GIAC provides accommodations to customers with a documented disability within the framework of the Americans with Disabilities Act as amended, including Section 504 of the Rehabilitation Act. Approved accommodations and scheduling instructions are sent by email, and declined requests come with the reasons and an appeal process.

When do I find out whether I passed?

GIAC delivers a score report at the end of the exam session through your GIAC account. GIAC does not publish a fixed turnaround figure on its public pages, so treat any specific number of days you read elsewhere as unverified.

How does the GCIH score scale work?

GIAC reports a percentage score against a published minimum passing percentage, currently 69% for the version released on or after 10 May 2025. The score report also breaks your performance down by objective, which is the most useful artefact if you need to retake.

How does GCIH compare to CompTIA CySA+ and to GCFA?

CySA+ is a broader, cheaper analyst certification with no live-lab virtual machines of the CyberLive kind and no open-book allowance. GCFA, the GIAC Certified Forensic Analyst, goes deeper into forensic artefact analysis and threat hunting after an incident, while GCIH concentrates on running the response itself and on understanding the attacker tooling. Many DFIR practitioners take GCIH first and GCFA second.

Is GIAC accredited, and does GCIH count for defence workforce requirements?

GIAC is an active accredited ISO/IEC 17024 personnel certification body through ANAB. That accreditation is the basis on which GCIH appears in federal and defence workforce qualification frameworks, so check the current version of the relevant framework for the specific work role you are targeting.

50% OFF

Pass GIAC GCIH (Certified Incident Handler), Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $625
$625
$125050% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund