GCED: GIAC Certified Enterprise Defender Exam Practice Test

176 questions available

Build your confidence for GCED: GIAC Certified Enterprise Defender Exam. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
115 Exam questions
3 hours Time Limit
Your practice
176 Practice questions
2 hours 56 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 70 Published passing score for this certification.
Explore exam topics Official objectives from GIAC
GIAC176 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-09-26How we verify

Exam overview and details

The GIAC Certified Enterprise Defender (GCED) certification validates a professional's ability to defend enterprise networks through comprehensive threat detection, incident response, and security architecture management. Administered by GIAC, a globally recognized leader in cybersecurity certification, the GCED exam assesses practical, hands-on skills in identifying advanced persistent threats (APTs), implementing defensive countermeasures, and managing enterprise-scale security operations. Achieving this certification demonstrates mastery of the core technical competencies required to protect complex, heterogeneous network environments against sophisticated adversaries. It is a key credential for security analysts, incident responders, and network defenders seeking to prove their expertise in aligning defensive strategies with organizational risk management objectives. The GCED is highly regarded for its rigorous, performance-based validation of skills that are immediately applicable in real-world enterprise security roles, making certified professionals valuable assets in securing critical infrastructure and sensitive data.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Intrusion Detection and Packet Analysis

A packet capture shows repeated SYN packets from many spoofed-looking addresses to one server, with few completed handshakes. Which detection conclusion is best?

Intrusion Detection and Packet Analysis

An analyst sees TCP retransmissions and duplicate ACKs during a file transfer alert. Which conclusion is most careful?

Network Forensics, Logging, and Event Management

During a GCED-aligned enterprise defense review, an investigator uses DHCP logs to identify a host by IP during an incident. Which caveat is most important?

Intrusion Detection and Packet Analysis

A Zeek conn.log entry shows a workstation making thousands of short outbound connections to sequential IPs on TCP/445. Which activity is most likely?

Interactive and Manual Malware Analyses

A binary contains strings for PowerShell commands, WMI classes, and scheduled task names, but dynamic analysis shows no execution. What is the best next step?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

The GCED certification is a significant career differentiator that signals to employers a validated, expert-level competency in enterprise defense. In an industry where proven skills are paramount, GCED holders are recognized for their ability to perform critical defensive operations, leading to enhanced credibility, increased earning potential, and eligibility for senior technical and leadership roles. It is often a preferred or required qualification for positions in Security Operations Centers (SOCs), incident response teams, and government agencies, providing a tangible advantage in a competitive job market and establishing the holder as a subject-matter expert in network defense methodologies.

What this exam covers

01Defending Network Protocols

Topics

  • The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.

Learning objectives

  • The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.

02Defensive Infrastructure and Tactics

Topics

  • The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.

Learning objectives

  • The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.

03Digital Forensics Concepts and Application

Topics

  • The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.

Learning objectives

  • The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.

04Incident Response Concepts and Application

Topics

  • The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.

Learning objectives

  • The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.

05Interactive and Manual Malware Analyses

Topics

  • The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.

Learning objectives

  • The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.

06Intrusion Detection and Packet Analysis

Topics

  • The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.

Learning objectives

  • The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.

07Malware Analysis Concepts and Basic Analysis Techniques

Topics

  • The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.

Learning objectives

  • The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.

08Network Forensics, Logging, and Event Management

Topics

  • The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.

Learning objectives

  • The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.

09Network Security Monitoring Concepts and Application

Topics

  • The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.

Learning objectives

  • The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.

10Penetration Testing Application

Topics

  • The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.

Learning objectives

  • The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.

11Penetration Testing Concepts

Topics

  • The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.

Learning objectives

  • The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.

Exam Details GCED | $949 USD | 3 hours

Exam Code GCED
Vendor GIAC
Exam Cost $949 USD
Passing Score 70
Time Limit 3 hours
Exam questions 115
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

What are the typical job roles for a GCED certified professional?

What is the recommended experience level before attempting the GCED exam?

How does the GCED differ from other GIAC certifications like the GCIH?

What is the exam format and duration?

Is training required to sit for the GCED exam?