GFACT (GIAC Foundational Cybersecurity Technologies) Practice Test

150 questions available

Build your confidence for GFACT (GIAC Foundational Cybersecurity Technologies). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
75 Exam questions
2 hours Time Limit
Foundational Level
Your practice
150 Practice questions
2 hours 30 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 71 Published passing score for this certification.
Explore exam topics Official objectives from GIAC
GIAC150 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-06-11How we verify

Exam overview and details

The GIAC Foundational Cybersecurity Technologies (GFACT) exam is a rigorous assessment designed to validate a candidate's understanding of the core technical concepts that underpin modern information security. It tests foundational knowledge across a broad spectrum of essential technologies, including operating systems, networking, cryptography, cloud fundamentals, and security operations. This exam is not focused on high-level theory but on the practical, hands-on knowledge required to understand how systems work, how they are connected, and how they can be secured. It is an ideal entry point for individuals transitioning into cybersecurity from other IT fields, recent graduates, or professionals seeking to formalize their foundational skills. By earning the GFACT certification, candidates demonstrate to employers a verified, vendor-neutral competency in the technical bedrock of cybersecurity, establishing credibility and readiness for more advanced roles and specialized certifications.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Operating Systems, The Web, & Data Storage

A REST API accepts `PUT /users/17` to replace a user profile and `PATCH /users/17` to update only one field. Which distinction is correct?

Forensics & Post-Exploitation

A memory image shows a process with an injected DLL, open C2 socket, and no matching executable path on disk. Which conclusion is best?

Logic & Programming

A firewall rule generator uses `if sourceTrusted or destinationPublic:` to skip deeper inspection. A packet has `sourceTrusted=false` and `destinationPublic=true`. What does the expression evaluate to?

Forensics & Post-Exploitation

A team images a phone but forgets to record who handled it, when it was transferred, or where it was stored. Which weakness does this create?

Forensics & Post-Exploitation

A browser-history review shows visits to a fake login page, then successful cloud-console logins from an unusual ASN minutes later. Which artifact pairing is most useful?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In the real world, effective cybersecurity is impossible without a solid grasp of the underlying technologies. You cannot secure what you do not understand. The GFACT ensures practitioners can accurately diagnose issues, communicate effectively with system administrators and network engineers, and implement controls that are appropriate for the technology stack in use. This foundational knowledge prevents security from being a superficial overlay and instead makes it an integrated component of IT operations, leading to more resilient systems, fewer misconfigurations, and a stronger overall security posture for organizations.

What this exam covers

01Computer Hardware & Virtualization

Topics

  • Understand key hardware components and their functions as well as associated memory concepts and understand virtualization and containers, their uses and advantages/disadvantages.

Learning objectives

  • Understand key hardware components and their functions as well as associated memory concepts and understand virtualization and containers, their uses and advantages/disadvantages.

02Exploitation & Mitigation

Topics

  • Be familiar with common exploit anatomy and methodology, as well as have a basic awareness and understanding of the tools used by attackers to achieve and increase system access, as well as appropriate mitigation strategies and techniques.

Learning objectives

  • Be familiar with common exploit anatomy and methodology, as well as have a basic awareness and understanding of the tools used by attackers to achieve and increase system access, as well as appropriate mitigation strategies and techniques.

03Forensics & Post-Exploitation

Topics

  • Be familiar with tools used in forensics investigations as well as their function, understand the stages of incident response, and understand the objectives of different types of forensics investigations and associated key artifacts and evidence. Understand post-exploitation goals and methodology including persistence, lateral movement, and exfiltration.

Learning objectives

  • Be familiar with tools used in forensics investigations as well as their function, understand the stages of incident response, and understand the objectives of different types of forensics investigations and associated key artifacts and evidence. Understand post-exploitation goals and methodology including persistence, lateral movement, and exfiltration.

04Linux Foundations

Topics

  • Have a working knowledge of most commonly used Linux commands, understand permissions and access control, and understand the key elements of Linux as it relates to file systems, architecture, and networking.

Learning objectives

  • Have a working knowledge of most commonly used Linux commands, understand permissions and access control, and understand the key elements of Linux as it relates to file systems, architecture, and networking.

05Logic & Programming

Topics

  • Be able to determine the result of basic logical operations, have a familiarity with programming syntax, constructs, and errors in popular languages, and understand how programs execute and the functions of memory allocations.

Learning objectives

  • Be able to determine the result of basic logical operations, have a familiarity with programming syntax, constructs, and errors in popular languages, and understand how programs execute and the functions of memory allocations.

06Networking & Servers

Topics

  • Understand core networking concepts, protocols, and understand different server types and their uses.

Learning objectives

  • Understand core networking concepts, protocols, and understand different server types and their uses.

07Operating Systems, The Web, & Data Storage

Topics

  • Understand the typical function and duties/task of the operating system, and be familiar with different file systems, web technology, and have some familiarity with cloud computing models and their advantages/disadvantages.

Learning objectives

  • Understand the typical function and duties/task of the operating system, and be familiar with different file systems, web technology, and have some familiarity with cloud computing models and their advantages/disadvantages.

08Security Concepts

Topics

  • Understand the concepts and terminology associated with cryptography, be familiar with ethical and legal concerns that are associated with hacking, understand the stages of an attack, and be familiar with key defensive strategies and concepts.

Learning objectives

  • Understand the concepts and terminology associated with cryptography, be familiar with ethical and legal concerns that are associated with hacking, understand the stages of an attack, and be familiar with key defensive strategies and concepts.

09Windows Foundations

Topics

  • Be familiar with key Windows CLI commands, understand permissions and access control, and understand the key elements of Windows as it relates to file systems, architecture, and networking.

Learning objectives

  • Be familiar with key Windows CLI commands, understand permissions and access control, and understand the key elements of Windows as it relates to file systems, architecture, and networking.

Exam Details GFACT | $479 USD | 2 hours

Exam Code GFACT
Vendor GIAC
Exam Cost $479 USD
Passing Score 71
Time Limit 2 hours
Exam questions 75
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

I don't have a cybersecurity job yet. Is the GFACT right for me?

How much hands-on technical experience do I need before attempting the GFACT?

How does the GFACT differ from the CompTIA Security+?

What is the best way to prepare for the exam's breadth?

Is the exam multiple-choice only?