GIAC Incident Handler (GCIH) Exam Prep
Detect, contain, and eradicate intrusions using the incident handling lifecycle.
Tuition
$299
Intermediate
Level
6
Modules
24
Lessons
6
Graded quizzes
10 hours
Estimated time
What you will be able to do
- Run the six-step incident handling process end to end
- Recognise reconnaissance and scanning tradecraft in real telemetry
- Explain common exploitation and privilege escalation techniques defensively
- Detect persistence, lateral movement and command and control
- Contain and eradicate an intrusion without destroying evidence
- Recover systems and write a defensible incident report
- Pass a timed practice exam covering the GCIH objective areas
What is inside
6 modules, 24 lessons. Each module ends in a graded quiz.
- 01
Incident Response Foundations: PICERL and DAIR
Covers the GCIH Incident Response and Cyber Investigation domain at its foundation: the six phase PICERL handling process, the dynamic loop that the DAIR model describes, and how both map onto the plans, teams, and toolkits that real response depends on. You learn what each phase must produce, how containment decisions are actually made under pressure, and how eradication, recovery, and lessons learned convert one bad week into permanent defensive improvement. Every lesson closes with exam style checks, and the module ends with a fifteen question domain quiz.
4 lessons · 15 quiz questions
- 02
Reconnaissance, Scanning, and SMB Exposure
Covers the GCIH exam area spanning scanning and mapping together with SMB security. You learn how an organization is profiled from public sources, what host discovery, port scanning, and vulnerability scanning look like from the defender's side of the wire, and how to read scan output without drowning in noise. The module closes with Server Message Block, the protocol that carries most Windows lateral movement, and the signing, segmentation, and logging controls that blunt it.
4 lessons · 15 quiz questions
- 03
Passwords: Attack, Cracking, and Defense
Covers the GCIH domain spanning understanding passwords and attacking passwords, from how credentials are stored and hashed to how guessing, spraying, and offline cracking actually work. Every technique is taught from the responder's seat: what the activity produces in telemetry, how to scope and contain it, and which control removes the exposure. The module closes with modern password policy, phishing resistant authentication, and a fifteen question domain quiz.
4 lessons · 15 quiz questions
- 04
Web Application and API Attacks
Covers the GCIH domain spanning exploitation of insecure web application references, web application API attacks, and web application injection attacks. You learn how attackers map an application, how direct object references and API authorization gaps turn into bulk data exposure, how SQL and command injection reach the interpreter, and how cross site scripting is used against the browser, always with the telemetry that reveals each technique and the controls that stop it. Every lesson ends with exam style checks, and the module closes with a fifteen question domain quiz.
4 lessons · 15 quiz questions
- 05
Endpoint Exploitation, Pivoting, and Evasion
Covers the GCIH domain spanning endpoint attack and pivoting, detection of exploitation and covert communications tooling, and detection of evasive post exploitation technique. You learn how initial access, in memory implants, covert channels, privilege escalation, lateral movement, persistence, and anti-forensics appear in real telemetry, and which controls prevent or contain each one. Every lesson closes with exam style checks, and the module ends with a fifteen question domain quiz.
4 lessons · 15 quiz questions
- 06
Investigations: Network, Logs, Malware, Cloud, and AI
Covers the GCIH domain spanning network and log investigations, malware and AI assisted investigation, securing credentials and data in the cloud, and the defensive implications of adversaries integrating large language models into offensive operations. You learn how to reduce a packet capture to the few conversations that matter, how to collect and normalize logs so a timeline holds up, how to triage a suspicious file safely, and how cloud credentials leak, get abused, and get revoked for real. Every lesson ends with exam style checks, and the module closes with a fifteen question domain quiz.
4 lessons · 15 quiz questions