GCIH · ● Active · Professional · GIAC (SANS Institute)
Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 incident response landscape; GIAC maintained as active certifier.
Exam facts
| Field | Value |
|---|---|
| Cost | $999 USD (exam only); $8,780 for SANS SEC504 course |
| Duration | 4 hours (240 minutes) |
| Questions | 106 questions (all scored) |
| Passing | 69% (approximately 73 out of 106 questions) |
| Format | Multiple choice; open-book (printed materials allowed) |
| Delivery | Pearson VUE or SANS OnVUE proctored |
| Languages | English |
| Valid | 4 years |
| Renewal | 36 CPE credits + $479 maintenance fee per 4-year cycle |
| Prerequisites | None; self-study or SANS SEC504 recommended |
| Released | 1999 (original); current format 2000+ |
| Retiring | N/A — active, not retiring |
Vendor source — GIAC Certified Incident Handler ↗
Official exam guide — GCIH Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗
About
The GIAC Certified Incident Handler (GCIH) is a professional-level certification for IT security professionals responsible for identifying, responding to, and containing security incidents. First offered by SANS in 1999, GCIH validates hands-on competency in the incident handling process, network reconnaissance, attack analysis, and defensive containment. Unlike many certs, GCIH is open-book — candidates may bring printed notes, reference materials, and a custom index — making it an accessible entry point to security incident response for those transitioning from adjacent IT domains (network administration, system administration, threat intelligence). The cert is widely recognized in incident-response teams and SOC environments as a baseline professional credential.
Domain context — Security/Incident Response
Incident response (IR) is the process of detecting, analyzing, containing, eradicating, and recovering from confirmed security incidents. This domain spans defensive capabilities (network monitoring, log analysis, forensic tools), investigative methods (timeline reconstruction, artifact analysis), threat intelligence (attacker tactics / tools), and stakeholder communication (incident severity, remediation steps). IR teams operate under time pressure and incomplete information; the best responders combine deep technical knowledge with structured incident-handling procedures.
Read full deep dive — GIAC/SANS Ecosystem →
Topics covered
- Incident Handling Concepts & Processes — incident classification, triage, severity, documentation, response workflows, legal/compliance context
- Network Reconnaissance & Traffic Analysis — packet inspection, flow analysis, identifying scanning / enumeration patterns, ARP / DNS / DHCP artifacts
- Network Attacks (Exploits & Evasion) — buffer overflows, stack-based attacks, Web application attacks (SQLi, XSS), shellcode, evasion techniques
- Password Attacks & Credential Compromise — password cracking tools, hash analysis, pass-the-hash, lateral movement via stolen credentials
- Privilege Escalation — kernel exploits, misconfigured services, file permissions abuse, UAC bypass, token impersonation
- Lateral Movement & Persistence — maintaining access post-compromise, creating backdoors, scheduled tasks, registry persistence, service persistence
- Data Exfiltration — detection of data theft indicators, covert channels, anti-forensics, evidence preservation
- Defensive Tools & Log Analysis — IDS/IPS evasion, Windows Event Log analysis, syslog review, tool fingerprinting (Snort, Suricata, OSSEC)
- Incident Response Tools & Techniques — packet capture (tcpdump, Wireshark), memory analysis, malware analysis basics, live response procedures
Source: GIAC GCIH Exam Blueprint ↗
Common skills at Security/Incident Response · Professional
Shared technical and operational competencies for incident-response professionals regardless of specific certification.
- Incident triage & severity classification (CVSS, business impact)
- Packet analysis & network traffic interpretation (tcpdump, Wireshark)
- Windows & Linux log interpretation (Event Viewer, syslog, auth.log)
- Timeline reconstruction & event correlation (multiple data sources)
- Threat intelligence integration (indicators of compromise, attacker tactics)
- Chain-of-custody & evidence handling (legal admissibility)
- Communication with non-technical stakeholders (severity escalation, remediation steps)
- Incident documentation & post-mortem reporting
Recommended courses at Security/Incident Response · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| SANS Institute | SEC504: Hacker Tools, Techniques, and Incident Handling | $8,780 | ↗ |
| SANS Institute (Self-Paced) | SEC504 OnDemand | $1,600–$2,000 | ↗ |
| Udemy (Mike Chapple) | GCIH Exam Prep Course | $15–$50 | ↗ |
| Cybrary | GCIH Incident Handler Certification Prep | Free–$99 | ↗ |
| INE (Infosec Institute) | GCIH On-Demand Training | $499–$999 | ↗ |
Course-selection rule: SEC504 is the canonical gold-standard course; OnDemand offers flexibility. Udemy and Cybrary serve self-paced learners with tight budgets. Choose based on learning style (live instructor, video on-demand, text-based).
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| GIAC Official | GCIH Practice Test (included in SEC504 course) | Included | ↗ |
| GIAC Official | Standalone Practice Exam Bundle | $399 | ↗ |
| Whizlabs | GCIH Practice Test | $49–$99 | ↗ |
| MeasureUp | GIAC Certified Incident Handler Practice Test | $129–$199 | ↗ |
| PracticeTestGeeks | GCIH Exam Prep & Mock Tests | $39–$79 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| GCIH GIAC Certified Incident Handler All-in-One Exam Guide | Mike Chapple, David Seidl | McGraw-Hill Education | 2019 | 978-1260461626 | ↗ |
| SANS SEC504 Course Materials (Official) | SANS Instructors | SANS Institute | 2024–2026 | N/A | ↗ |
| Incident Response & Computer Forensics (3rd Ed.) | Jason T. Lighty | McGraw-Hill | 2014 | 978-0071798686 | ↗ |
Book rule: The Chapple/Seidl All-in-One guide is the dedicated GCIH study resource. SANS course materials are the authoritative reference; SEC504 OnDemand includes them digitally. Lighty's IR handbook provides foundational incident-response methodology beyond any single cert.
Typical job titles at Security/Incident Response · Professional
Incident Response Analyst · Security Operations Center (SOC) Analyst (Senior) · Threat Hunter · Incident Commander · Security Analyst (Incident Focus) · Digital Forensics Analyst
(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GCIH as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $69,000 – $144,000 annually | Glassdoor ↗ · PayScale ↗ · ZipRecruiter ↗ |
| ZAR | R1,150,000 – R2,400,000 annually (estimated at 1 USD = 16.6 ZAR, May 2026) | Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction) |
| GBP | £50,000 – £95,000 annually | IT Jobs Watch ↗ (incident response roles) |
| EUR | €60,000 – €110,000 annually (DE/FR/NL average) | IT Job Trends ↗ |
Salary rule: USD data cited from PayScale and ZipRecruiter (Feb–May 2026 surveys). ZAR converted from USD at prevailing exchange rate; no region-specific ZA incident-response salary data available. GBP and EUR derived from general IR role postings; certs in demand typically place at upper ranges. Salaries vary by location, team size, employer type (government, enterprise, startup, consulting), and years of experience.
Skills validated
Concrete technologies, protocols, and tools this exam actually tests.
- Network protocols — TCP/IP, ICMP, DNS, DHCP, ARP, HTTP/HTTPS
- Attack tools & frameworks — Nmap, Metasploit, Wireshark, tcpdump, John the Ripper, Hashcat
- Log analysis tools — Windows Event Viewer, Linux syslog, Splunk (basic), ELK stack awareness
- Defensive tools — Snort, Suricata, OSSEC, host-based firewalls
- Windows forensics & analysis — Registry hives, Event Log artifacts, file system artifacts (MFT, $LogFile)
- Linux log locations & formats — /var/log/auth.log, syslog, kernel logs, systemd journals
- Malware analysis foundations — static analysis, dynamic analysis, sandbox tools (basic)
- Incident handling methodologies — NIST SP 800-61, incident triage, containment strategies
- Chain of custody & evidence preservation — file hashing (MD5, SHA), write-blockers, forensic imaging
Related certifications
- Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — adds deep forensic analysis post-incident
- Stacks with: GIAC Reverse Engineering Malware (GREM) ↗ — complements attacker-tool analysis
- Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth certification
- Equivalent (different vendor): Certified SOC Analyst (CYSA+) ↗ — CompTIA's SOC-focused credential
- Vendor overview: GIAC/SANS Vendor Overview ↗
Sources
- GIAC Certified Incident Handler (GCIH): https://www.giac.org/certifications/certified-incident-handler-gcih
- SANS SEC504 Course: https://www.sans.org/cyber-security-courses/hacker-techniques-incident-handling
- GIAC Pricing: https://www.giac.org/pricing
- PayScale GCIH Salary Data: https://www.payscale.com/research/US/Certification=SANS%2FGIAC_Certified_Incident_Handler_(GCIH)/Salary
- ZipRecruiter GCIH Salary: https://www.ziprecruiter.com/Salaries/Gcih-Salary
- Unihackers GCIH Certification Guide: https://unihackers.com/certifications/gcih
- FlashGenius GCIH ROI Analysis: https://flashgenius.net/blog-article/is-gcih-worth-it-exam-fees-training-costs-salary-roi-2026
Last verified: 2026-05-01
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Incident Response Domain
Vendor overview: GIAC/SANS Overview