GIAC Certifications Explained: Which One Should You Take?

GIAC certifications are expensive, respected, and poorly understood outside the people who already hold them. The catalogue is large and the four-letter codes are opaque. Here is what each of the main ones is actually for.

GSEC, the foundation

GIAC Security Essentials. Broad coverage of security fundamentals at a level well beyond Security+, aimed at people who already work in the field rather than those entering it.

Take it if you want a rigorous general credential and your employer is paying. The syllabus is wide, which makes it harder than its foundational label suggests.

GSEC questions.

GCIH, incident handling

Certified Incident Handler. Attack techniques from the defender's perspective, and how to detect, contain and recover.

Take it if you work in a SOC or on an incident response team. It is the most directly applicable GIAC credential for defensive practitioners and probably the best starting point for most people.

GCIH questions.

GCIA, intrusion analysis

Certified Intrusion Analyst. Deep packet analysis, traffic patterns, IDS and network forensics.

Take it if your work involves reading network traffic. This is the most technically demanding of the network-focused GIAC exams and assumes real comfort with protocols.

GCIA questions.

GCFA, forensics

Certified Forensic Analyst. Advanced digital forensics, memory analysis and timeline reconstruction.

Take it if you do forensic work or want to move into it. Highly specialised and highly regarded within that specialism, close to useless outside it.

GCFA questions.

Why GIAC exams are different

They are open book. You may bring printed material, and experienced candidates build indexed binders during preparation.

That sounds generous and is not. The exams are timed such that looking things up costs you, so the index exists to confirm details you already broadly know rather than to teach you during the exam. Candidates who plan to read their way through fail.

The cost problem

GIAC certifications are among the most expensive in the industry, particularly bundled with SANS training. That pricing is aimed squarely at employers with training budgets.

If you are paying yourself, the honest calculation is whether your market asks for GIAC by name. In government, defence and financial services it frequently does. Elsewhere, CySA+ or PenTest+ deliver more recognition per dollar.

Where to start

GCIH for most defensive practitioners. GSEC if you want breadth first. GCIA or GCFA only once you know that packet analysis or forensics is where you want to specialise.


We cover GSEC, GCIH, GCIA and GCFA with full explanations for every answer. Browse GIAC sets.

Practice for these exams

See free questions for every exam →

Back to blog