How to Pass the GIAC Certified Incident Handler GCIH in 2026: Format, Cost, Domains and Study Plan

What the GCIH tests, what it costs, how the open book format works, why defenders fail it and a six week study plan across its 15 objectives.

What the GIAC Certified Incident Handler GCIH is and who it is for

The GIAC Certified Incident Handler (GCIH) validates hands on skill in detecting, responding to and recovering from security incidents. It covers attacker tactics and techniques alongside the defensive workflows needed to handle them, which makes it one of the most practical blue team certifications available. It is aligned to the SANS course SEC504: Hacker Tools, Techniques, and Incident Handling.

It is for you if you work in incident response, a security operations centre or a blue team role and want a credential that proves you understand both sides of an attack.

GIAC Certified Incident Handler GCIH at a glance

Item Detail
Exam code GCIH
Questions 106
Time allowed 4 hours (240 minutes)
Passing score 69%
Exam fee US$999 per attempt
Certification valid for 4 years

The exam is open book. Check GIAC’s site for the current delivery options when you book.

What is on the exam

GIAC lists 15 objectives with no weights, so plan to cover all of them. They group naturally into six areas.

Incident response and investigation. Incident response and cyber investigation, plus network and log investigations. You need to know the correct next step when you are handed an incident part way through, and how to read traffic and log evidence to work out what an attacker has done.

Scanning, endpoints and SMB. Scanning and mapping, endpoint attack and pivoting, and SMB security. The exam expects you to follow an attacker from finding a target to gaining a foothold on one machine and moving from it to others, and to know what traces each stage leaves for a defender.

Passwords and credentials. Understanding passwords, attacking passwords, and securing credentials and data in the cloud. This covers how passwords are stored and attacked, and how credentials and data held in cloud services are exposed and protected.

Web application attacks. Web application injection attacks, web application API attacks, and exploiting insecure web application references. You should be able to recognise these attacks from requests and responses, understand why they work and know the defences against them.

Detecting attacker tools and evasion. Detecting exploitation and covert communications tools, and detecting evasive and post-exploitation techniques. Expect questions on what a given tool does, what its output means, and how you would spot an attacker who is trying to hide or who has already got in.

Malware and AI. Malware and AI assisted investigations, and integrating LLMs with offensive operations. The emphasis is on recognising what malicious code is doing on a system, how AI can support an investigation, and how attackers can put large language models to work.

Why people fail it

The GCIH covers the full incident response lifecycle from both sides of the attack. On one side sit reconnaissance, exploitation, privilege escalation and lateral movement. On the other sit detection, containment, eradication and recovery. Candidates who know incident response well but have not studied attacker techniques consistently get caught out, because a large part of the exam asks how an attack works before it asks how to stop it.

The open book format is the second trap. It sounds like a safety net, and candidates relax their preparation because of it. In practice, 106 questions in four hours does not leave time to search the books for most answers. If you have not built a way to find things quickly, the books slow you down rather than help, and you end up short of time on questions you could have answered from memory.

Finally, the sheer breadth. Fifteen objectives, from web application attacks to password attacks to malware, means there is no single area you can lean on. A candidate strong in network analysis and weak in web attacks will find the gaps exposed, and with a 69% pass mark there is little room for a whole topic to go badly.

A study plan that fits the exam

Six weeks. With no weights to follow, the plan starts with incident response and the attacker path through a network, because the other objectives build on them, and saves the last week for timed practice with your index.

  1. Week 1: incident response and investigation. How an investigation runs from start to finish, then network and log investigations. Start your index now, one line per concept with where to find it. Try the free GCIH practice questions at the end of the week to see how GIAC frames its scenarios.
  2. Week 2: scanning, endpoints and SMB. Scanning and mapping, endpoint attack and pivoting, and SMB security, followed step by step as an attacker would. Run the common tools in a lab where you can, so their output looks familiar.
  3. Week 3: passwords and credentials. Understanding and attacking passwords, then securing credentials and data in the cloud. Work the matching questions in the GCIH practice question pack and read every explanation, including those for the wrong options.
  4. Week 4: web application attacks. Injection attacks, API attacks and insecure web application references, how to spot each in requests and logs, and the defences against them.
  5. Week 5: detection, malware and AI. Detecting attacker tools and evasion, then malware, AI assisted investigations and LLMs in offensive operations. End with a mixed set across all 15 objectives and note which you answered slowest.
  6. Week 6: timed runs. Use the questions only PDF for full sittings against the four hour limit, with your index beside you. Every time you reach for a book and cannot find the answer fast, fix the index. Spend the remaining days on your weakest area.

On exam day

You have four hours for 106 questions, and the exam is open book. Bring the materials you have prepared and your index, organised so you can find anything in moments. Check GIAC’s current rules on what materials are allowed and how delivery works for your booking before the day, so nothing is taken away from you at the start.

Answer from memory first and use the books to confirm, not to learn. If a question needs a long search, flag it if the interface allows, answer the ones you know, and come back. Watch the clock, because open book tempts you to recheck answers you already had right. The passing score is 69%, so aim for steady accuracy across every topic rather than perfection in one.

Frequently asked questions

Is the GCIH really open book?

Yes. You can use reference material during the exam. That helps only if you can find what you need quickly, which is why a good index matters more than the amount of paper you bring. Check GIAC’s rules for exactly which materials are permitted.

What happens if I fail? Can I retake it?

You can, but each attempt costs US$999, so a failure is expensive. GIAC publishes its retake policy, including any waiting period and retake pricing, on its website, so read it before you book. Do your timed practice with your index before the first attempt rather than after it.

Is the practice question pack enough on its own?

No. The pack is 842 practice questions mapped to the GCIH exam objectives, with an explanation for every answer and every wrong option, plus a questions only PDF for timed runs. It is a way to find your gaps before GIAC does and to get used to how the exam asks things. It is not a course. It will not replace SEC504 or your own study material, and it will not give you the hands on feel for the tools that a lab does.

How long is the GCIH valid?

The certification is valid for 4 years. Check GIAC’s renewal requirements well before it expires.

When you are ready to practise, get the 842 question GCIH pack for US$39, pass or your money back.