GIAC Certified Incident Handler

GIAC (SANS Institute) · GCIH · Professional

GIAC (SANS Institute) · GIAC/SANS

GIAC Certified Incident Handler

GCIHactiveProfessional
Official GIAC (SANS Institute) source · giac.org

GCIH · ● Active · Professional · GIAC (SANS Institute)

Every URL must link to the official cert page or current vendor documentation. Status reflects 2026 incident response landscape; GIAC maintained as active certifier.


Exam facts

FieldValue
Cost$999 USD (exam only); $8,780 for SANS SEC504 course
Duration4 hours (240 minutes)
Questions106 questions (all scored)
Passing69% (approximately 73 out of 106 questions)
FormatMultiple choice; open-book (printed materials allowed)
DeliveryPearson VUE or SANS OnVUE proctored
LanguagesEnglish
Valid4 years
Renewal36 CPE credits + $479 maintenance fee per 4-year cycle
PrerequisitesNone; self-study or SANS SEC504 recommended
Released1999 (original); current format 2000+
RetiringN/A — active, not retiring

Vendor source — GIAC Certified Incident Handler ↗
Official exam guide — GCIH Certification Exam Guide ↗
Exam objectives — Exam Domains & Topics ↗


About

The GIAC Certified Incident Handler (GCIH) is a professional-level certification for IT security professionals responsible for identifying, responding to, and containing security incidents. First offered by SANS in 1999, GCIH validates hands-on competency in the incident handling process, network reconnaissance, attack analysis, and defensive containment. Unlike many certs, GCIH is open-book — candidates may bring printed notes, reference materials, and a custom index — making it an accessible entry point to security incident response for those transitioning from adjacent IT domains (network administration, system administration, threat intelligence). The cert is widely recognized in incident-response teams and SOC environments as a baseline professional credential.


Domain context — Security/Incident Response

Incident response (IR) is the process of detecting, analyzing, containing, eradicating, and recovering from confirmed security incidents. This domain spans defensive capabilities (network monitoring, log analysis, forensic tools), investigative methods (timeline reconstruction, artifact analysis), threat intelligence (attacker tactics / tools), and stakeholder communication (incident severity, remediation steps). IR teams operate under time pressure and incomplete information; the best responders combine deep technical knowledge with structured incident-handling procedures.

Read full deep dive — GIAC/SANS Ecosystem →


Topics covered

  • Incident Handling Concepts & Processes — incident classification, triage, severity, documentation, response workflows, legal/compliance context
  • Network Reconnaissance & Traffic Analysis — packet inspection, flow analysis, identifying scanning / enumeration patterns, ARP / DNS / DHCP artifacts
  • Network Attacks (Exploits & Evasion) — buffer overflows, stack-based attacks, Web application attacks (SQLi, XSS), shellcode, evasion techniques
  • Password Attacks & Credential Compromise — password cracking tools, hash analysis, pass-the-hash, lateral movement via stolen credentials
  • Privilege Escalation — kernel exploits, misconfigured services, file permissions abuse, UAC bypass, token impersonation
  • Lateral Movement & Persistence — maintaining access post-compromise, creating backdoors, scheduled tasks, registry persistence, service persistence
  • Data Exfiltration — detection of data theft indicators, covert channels, anti-forensics, evidence preservation
  • Defensive Tools & Log Analysis — IDS/IPS evasion, Windows Event Log analysis, syslog review, tool fingerprinting (Snort, Suricata, OSSEC)
  • Incident Response Tools & Techniques — packet capture (tcpdump, Wireshark), memory analysis, malware analysis basics, live response procedures

Source: GIAC GCIH Exam Blueprint ↗


Common skills at Security/Incident Response · Professional

Shared technical and operational competencies for incident-response professionals regardless of specific certification.

  • Incident triage & severity classification (CVSS, business impact)
  • Packet analysis & network traffic interpretation (tcpdump, Wireshark)
  • Windows & Linux log interpretation (Event Viewer, syslog, auth.log)
  • Timeline reconstruction & event correlation (multiple data sources)
  • Threat intelligence integration (indicators of compromise, attacker tactics)
  • Chain-of-custody & evidence handling (legal admissibility)
  • Communication with non-technical stakeholders (severity escalation, remediation steps)
  • Incident documentation & post-mortem reporting

Recommended courses at Security/Incident Response · Professional

ProviderTitleCostURL
SANS InstituteSEC504: Hacker Tools, Techniques, and Incident Handling$8,780
SANS Institute (Self-Paced)SEC504 OnDemand$1,600–$2,000
Udemy (Mike Chapple)GCIH Exam Prep Course$15–$50
CybraryGCIH Incident Handler Certification PrepFree–$99
INE (Infosec Institute)GCIH On-Demand Training$499–$999

Course-selection rule: SEC504 is the canonical gold-standard course; OnDemand offers flexibility. Udemy and Cybrary serve self-paced learners with tight budgets. Choose based on learning style (live instructor, video on-demand, text-based).


Practice exams

ProviderTitleCostURL
GIAC OfficialGCIH Practice Test (included in SEC504 course)Included
GIAC OfficialStandalone Practice Exam Bundle$399
WhizlabsGCIH Practice Test$49–$99
MeasureUpGIAC Certified Incident Handler Practice Test$129–$199
PracticeTestGeeksGCIH Exam Prep & Mock Tests$39–$79

Books

TitleAuthorPublisherYearISBNURL
GCIH GIAC Certified Incident Handler All-in-One Exam GuideMike Chapple, David SeidlMcGraw-Hill Education2019978-1260461626
SANS SEC504 Course Materials (Official)SANS InstructorsSANS Institute2024–2026N/A
Incident Response & Computer Forensics (3rd Ed.)Jason T. LightyMcGraw-Hill2014978-0071798686

Book rule: The Chapple/Seidl All-in-One guide is the dedicated GCIH study resource. SANS course materials are the authoritative reference; SEC504 OnDemand includes them digitally. Lighty's IR handbook provides foundational incident-response methodology beyond any single cert.


Typical job titles at Security/Incident Response · Professional

Incident Response Analyst · Security Operations Center (SOC) Analyst (Senior) · Threat Hunter · Incident Commander · Security Analyst (Incident Focus) · Digital Forensics Analyst

(Job titles drawn from current job-board postings (Glassdoor, LinkedIn, Indeed) that list GCIH as required or strongly preferred.)


Salary

RegionRangeSource
USD$69,000 – $144,000 annuallyGlassdoor ↗ · PayScale ↗ · ZipRecruiter ↗
ZARR1,150,000 – R2,400,000 annually (estimated at 1 USD = 16.6 ZAR, May 2026)Derived from USD ranges; region-specific data unavailable — use ICT professional rates (Pnet, CareerJunction)
GBP£50,000 – £95,000 annuallyIT Jobs Watch ↗ (incident response roles)
EUR€60,000 – €110,000 annually (DE/FR/NL average)IT Job Trends ↗

Salary rule: USD data cited from PayScale and ZipRecruiter (Feb–May 2026 surveys). ZAR converted from USD at prevailing exchange rate; no region-specific ZA incident-response salary data available. GBP and EUR derived from general IR role postings; certs in demand typically place at upper ranges. Salaries vary by location, team size, employer type (government, enterprise, startup, consulting), and years of experience.


Skills validated

Concrete technologies, protocols, and tools this exam actually tests.

  • Network protocols — TCP/IP, ICMP, DNS, DHCP, ARP, HTTP/HTTPS
  • Attack tools & frameworks — Nmap, Metasploit, Wireshark, tcpdump, John the Ripper, Hashcat
  • Log analysis tools — Windows Event Viewer, Linux syslog, Splunk (basic), ELK stack awareness
  • Defensive tools — Snort, Suricata, OSSEC, host-based firewalls
  • Windows forensics & analysis — Registry hives, Event Log artifacts, file system artifacts (MFT, $LogFile)
  • Linux log locations & formats — /var/log/auth.log, syslog, kernel logs, systemd journals
  • Malware analysis foundations — static analysis, dynamic analysis, sandbox tools (basic)
  • Incident handling methodologies — NIST SP 800-61, incident triage, containment strategies
  • Chain of custody & evidence preservation — file hashing (MD5, SHA), write-blockers, forensic imaging

Related certifications

  • Stacks with: GIAC Certified Forensic Analyst (GCFA) ↗ — adds deep forensic analysis post-incident
  • Stacks with: GIAC Reverse Engineering Malware (GREM) ↗ — complements attacker-tool analysis
  • Prerequisite for: GIAC Certified Enterprise Defender (GCED) ↗ — defense-in-depth certification
  • Equivalent (different vendor): Certified SOC Analyst (CYSA+) ↗ — CompTIA's SOC-focused credential
  • Vendor overview: GIAC/SANS Vendor Overview ↗

Sources


Last verified: 2026-05-01
Parent ecosystem: GIAC/SANS Vendor Overview
Parent domain: Security/Incident Response Domain
Vendor overview: GIAC/SANS Overview

Rate this cert
Was this helpful?
Comments ()
0/2000