GFACT (GIAC Foundational Cybersecurity Technologies) Practice Test
Build your confidence for GFACT (GIAC Foundational Cybersecurity Technologies). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
The GIAC Foundational Cybersecurity Technologies (GFACT) exam is a rigorous assessment designed to validate a candidate's understanding of the core technical concepts that underpin modern information security. It tests foundational knowledge across a broad spectrum of essential technologies, including operating systems, networking, cryptography, cloud fundamentals, and security operations. This exam is not focused on high-level theory but on the practical, hands-on knowledge required to understand how systems work, how they are connected, and how they can be secured. It is an ideal entry point for individuals transitioning into cybersecurity from other IT fields, recent graduates, or professionals seeking to formalize their foundational skills. By earning the GFACT certification, candidates demonstrate to employers a verified, vendor-neutral competency in the technical bedrock of cybersecurity, establishing credibility and readiness for more advanced roles and specialized certifications.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
A REST API accepts `PUT /users/17` to replace a user profile and `PATCH /users/17` to update only one field. Which distinction is correct?
A memory image shows a process with an injected DLL, open C2 socket, and no matching executable path on disk. Which conclusion is best?
A firewall rule generator uses `if sourceTrusted or destinationPublic:` to skip deeper inspection. A packet has `sourceTrusted=false` and `destinationPublic=true`. What does the expression evaluate to?
A team images a phone but forgets to record who handled it, when it was transferred, or where it was stored. Which weakness does this create?
A browser-history review shows visits to a fake login page, then successful cloud-console logins from an unusual ASN minutes later. Which artifact pairing is most useful?
Career Opportunities & Salary
Exam insights and study advice
In the real world, effective cybersecurity is impossible without a solid grasp of the underlying technologies. You cannot secure what you do not understand. The GFACT ensures practitioners can accurately diagnose issues, communicate effectively with system administrators and network engineers, and implement controls that are appropriate for the technology stack in use. This foundational knowledge prevents security from being a superficial overlay and instead makes it an integrated component of IT operations, leading to more resilient systems, fewer misconfigurations, and a stronger overall security posture for organizations.
What this exam covers
01Computer Hardware & Virtualization
Topics
- Understand key hardware components and their functions as well as associated memory concepts and understand virtualization and containers, their uses and advantages/disadvantages.
Learning objectives
- Understand key hardware components and their functions as well as associated memory concepts and understand virtualization and containers, their uses and advantages/disadvantages.
02Exploitation & Mitigation
Topics
- Be familiar with common exploit anatomy and methodology, as well as have a basic awareness and understanding of the tools used by attackers to achieve and increase system access, as well as appropriate mitigation strategies and techniques.
Learning objectives
- Be familiar with common exploit anatomy and methodology, as well as have a basic awareness and understanding of the tools used by attackers to achieve and increase system access, as well as appropriate mitigation strategies and techniques.
03Forensics & Post-Exploitation
Topics
- Be familiar with tools used in forensics investigations as well as their function, understand the stages of incident response, and understand the objectives of different types of forensics investigations and associated key artifacts and evidence. Understand post-exploitation goals and methodology including persistence, lateral movement, and exfiltration.
Learning objectives
- Be familiar with tools used in forensics investigations as well as their function, understand the stages of incident response, and understand the objectives of different types of forensics investigations and associated key artifacts and evidence. Understand post-exploitation goals and methodology including persistence, lateral movement, and exfiltration.
04Linux Foundations
Topics
- Have a working knowledge of most commonly used Linux commands, understand permissions and access control, and understand the key elements of Linux as it relates to file systems, architecture, and networking.
Learning objectives
- Have a working knowledge of most commonly used Linux commands, understand permissions and access control, and understand the key elements of Linux as it relates to file systems, architecture, and networking.
05Logic & Programming
Topics
- Be able to determine the result of basic logical operations, have a familiarity with programming syntax, constructs, and errors in popular languages, and understand how programs execute and the functions of memory allocations.
Learning objectives
- Be able to determine the result of basic logical operations, have a familiarity with programming syntax, constructs, and errors in popular languages, and understand how programs execute and the functions of memory allocations.
06Networking & Servers
Topics
- Understand core networking concepts, protocols, and understand different server types and their uses.
Learning objectives
- Understand core networking concepts, protocols, and understand different server types and their uses.
07Operating Systems, The Web, & Data Storage
Topics
- Understand the typical function and duties/task of the operating system, and be familiar with different file systems, web technology, and have some familiarity with cloud computing models and their advantages/disadvantages.
Learning objectives
- Understand the typical function and duties/task of the operating system, and be familiar with different file systems, web technology, and have some familiarity with cloud computing models and their advantages/disadvantages.
08Security Concepts
Topics
- Understand the concepts and terminology associated with cryptography, be familiar with ethical and legal concerns that are associated with hacking, understand the stages of an attack, and be familiar with key defensive strategies and concepts.
Learning objectives
- Understand the concepts and terminology associated with cryptography, be familiar with ethical and legal concerns that are associated with hacking, understand the stages of an attack, and be familiar with key defensive strategies and concepts.
09Windows Foundations
Topics
- Be familiar with key Windows CLI commands, understand permissions and access control, and understand the key elements of Windows as it relates to file systems, architecture, and networking.
Learning objectives
- Be familiar with key Windows CLI commands, understand permissions and access control, and understand the key elements of Windows as it relates to file systems, architecture, and networking.