GIAC Certified Incident Handler (GCIH)
Credential: GIAC Certified Incident Handler (GCIH)
Credentialing Agency: Global Information Assurance Certification (GIAC)
Renewal Period: 4 years
The GIAC Certified Incident Handler (GCIH) is an intermediate skill level certification for individuals who are responsible for incident handling/incident response. Incident handlers manage security incidents by understanding common attack techniques, vectors and tools as well as defending against and/or responding to such attacks when they occur. The GCIH certification focuses on detecting, responding, and resolving computer security incidents and covers the following security techniques: the steps of the incident handling process, detecting malicious applications and network activity, common attack techniques that compromise hosts, detecting and analyzing system and network vulnerabilities, and continuous process improvement by discovering the root causes of incidents. There are no prerequisites for this certification.
More information can be found on the certifying agency's website.
GIAC Certified Incident Handler (GCIH)
MINIMUM REQUIREMENTS
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for becoming eligible. Listed are the minimum requirements based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
RECERTIFICATION SUMMARY
Renewal Period: 4 years
AGENCY CONTACT INFORMATION
Global Information Assurance Certification (GIAC)
8120 Woodmont Avenue
Suite 205
Bethesda, MD 20814
Phone: (301) 654-7267
Fax: (301) 951-0140
Email: info@giac.org
Other REQUIREMENTS
The GIAC Certified Incident Handler (GCIH) credential has the following other requirements:
- All GIAC-certified individuals agree to uphold and be bound by the GIAC Code of Ethics.
Written Exam
- Incident Handling: Identification
- Incident Handling: Overview and Preparation
- Client Attacks
- Covering Tracks: Networks
- Covering Tracks: Systems
- Denial of Service Attacks
- Incident Handling: Containment
- Incident Handling: Eradication, Recovery, and Lessons Learned
- Network Attacks
- Overflow Attacks
- Password Attacks
- Reconnaissance
- Scanning: Discovery and Mapping
- Scanning: Techniques and Defense
- Session Hijacking and Cache Poisoning
- Techniques for maintaining access
- Web Application Attacks
- Worms, Bots & Bot-Nets
Exam Preparation Resources
There are a number of resources available to help you prepare for the GIAC Certified Incident Handler (GCIH) examination:
- Best Sources
- General References
- Related Courses
- Related Training
Testing Information
Testing for this credential is handled by Pearson VUE. The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
For more information on the Global Information Assurance Certification (GIAC) testing process, visit the agency website.
RECERTIFICATION
GIAC Certified Incident Handler (GCIH)
Renewal Period: 4 years