GIAC · 2026 Edition
A complete preparation guide, edited by Johnson Ajibi, a network and security engineer with 12+ years' experience. Covers the exam format,all 15 blueprint domains, a week-by-week study plan, and proven tips for passing first time.
2–4 months
Prep time
Intermediate
Difficulty
60–90
Exam questions
700/1000
Pass mark
Exam code
GCIH
Full name
GIAC Certified Incident Handler
Vendor
GIAC
Duration
90 minutes
Questions
~0 items
Passing score
700/1000 (scaled)
Domains covered
15 blueprint domains
Recommended experience
Foundational IT knowledge recommended
Typical prep time
2–4 months
Domain percentage weights are not currently available for this exam. The checklist below is still useful for planning your study.
Phase 1
Securing Credentials and Data in Cloud
Tip: Start with the official Securing Credentials and Data in Cloud objectives, then practise questions on it.
Phase 2
Endpoint Attack and Pivoting
Tip: Cover the Endpoint Attack and Pivoting objectives, then answer practice questions to confirm you can apply them.
Phase 3
SMB Security
Tip: Cover the SMB Security objectives, then answer practice questions to confirm you can apply them.
Phase 4
Malware and AI-Assisted Investigations
Tip: Cover the Malware and AI-Assisted Investigations objectives, then answer practice questions to confirm you can apply them.
Phase 5
Understanding Passwords
Tip: Cover the Understanding Passwords objectives, then answer practice questions to confirm you can apply them.
Phase 6
Detecting Exploitation and Covert Communication Tools
Tip: Cover the Detecting Exploitation and Covert Communication Tools objectives, then answer practice questions to confirm you can apply them.
Phase 7
Detecting Evasive and Post-Exploitation Techniques
Tip: Cover the Detecting Evasive and Post-Exploitation Techniques objectives, then answer practice questions to confirm you can apply them.
Phase 8
Integrating LLMs with Offensive Operations
Tip: Cover the Integrating LLMs with Offensive Operations objectives, then answer practice questions to confirm you can apply them.
Phase 9
Network and Log Investigations
Tip: Cover the Network and Log Investigations objectives, then answer practice questions to confirm you can apply them.
Phase 10
Exploiting Insecure Web App References
Tip: Cover the Exploiting Insecure Web App References objectives, then answer practice questions to confirm you can apply them.
Phase 11
Web App API Attacks
Tip: Cover the Web App API Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 12
Web App Injection Attacks
Tip: Cover the Web App Injection Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 13
Incident Response and Cyber Investigation
Tip: Cover the Incident Response and Cyber Investigation objectives, then answer practice questions to confirm you can apply them.
Phase 14
Attacking Passwords
Tip: Cover the Attacking Passwords objectives, then answer practice questions to confirm you can apply them.
Phase 15
Scanning and Mapping
Tip: Finish with Scanning and Mapping, then re-test your weakest earlier domain before a mock exam.
Study the official exam blueprint — weight percentages tell you exactly where to invest prep time.
Practise scenario-based questions regularly — every modern cert exam is scenario-heavy.
Use spaced repetition to retain what you've learned (Courseiva does this automatically).
Book your exam date once you're scoring 80%+ consistently on practice tests.
Review explanations for every wrong answer, not just the question — the 'why' is what makes it stick.
Apply everything in this guide with adaptive practice questions, detailed answer explanations, and domain analytics.