Areas Covered
- Detecting attacks in the cloud
- Cloud investigations and cyber threat intelligence
- Assessments and automation in AWS and Azure
Who is GCTD for?
- Anyone who performs monitoring, threat detection, or incident response
- Anyone responsible for logging in a cloud environment
- Security Analysts
- Security Engineers
- Security Architects
- Vulnerability Assessors
- Incident Responders
Exam Format
- 1 proctored exam
- 75 questions
- 2 hours
- Minimum passing score of 70%
Delivery
NOTE: All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE. Click here for more information.
GIAC certification attempts will be activated in your GIAC account after your application has been approved and according to the terms of your purchase. Details on delivery will be provided along with your registration confirmation upon payment. You will receive an email notification when your certification attempt has been activated in your account. You will have 120 days from the date of activation to complete your certification attempt.
Exam Certification Objectives & Outcome Statements
- Application and Proxy Monitoring The candidate will demonstrate a hands-on ability to monitor Azure and AWS application logs including web servers, proxies, and load balancers.
- Automated Detection and Response The candidate will demonstrate an understanding of cloud automation options and serverless functions used to create automated response workflows.
- Cloud Monitoring Fundamentals The candidate will demonstrate an understanding of the unique security concerns related to the cloud, as well as a knowledge of cloud access, monitoring, and data collection sources.
- Cloud Vulnerability Analysis The candidate will demonstrate the ability to conduct a basic vulnerability assessment and perform data discovery activities.
- Containers and Orchestration The candidate will demonstrate an understanding of containers and orchestration, as well as common threats and log sources.
- Cyber Threat Intelligence for the Cloud The candidate will demonstrate an understanding of types and sources of cyber threat intelligence and their use.
- Data and Storage Monitoring The candidate will demonstrate a hands-on ability to monitor Azure and AWS buckets, databases, and storage services.
- Host OS Monitoring The candidate will demonstrate a hands-on ability to configure and access operating system logs for Windows, Linux, and macOS virtual machines.
- Investigating AWS Environments The candidate will demonstrate the ability to perform discovery and investigation tasks using AWS consoles and services.
- Investigating Azure Environments The candidate will demonstrate the ability to perform discovery and investigation tasks using Azure consoles and services.
- Log Centralization The candidate will demonstrate an understanding of data centralization, shipping, and enrichment in Azure and AWS cloud environments.
- Network and flow Monitoring The candidate will demonstrate a hands-on ability to configure and access network and flow logs in Azure and AWS cloud environments.
Other Resources
- Training is available in a variety of modalities including live conference training, online, and self-study.
- Practical work experience can help ensure that you have mastered the skills necessary for certification.
- College-level courses or study through another program may meet the needs for mastery.
- The procedure to contest exam results can be found at https://www.giac.org/policies/feedback
Practice Tests
- These tests are a simulation of the real exam allowing you to become familiar with the test engine and style of questions.
- Practice exams are a gauge to determine if your preparation methods are sufficient.
- The practice bank questions are limited so you may encounter the same question on practice tests when multiple practice tests are purchased.
- Practice exams never include actual exam questions.
- Purchase a GCTD practice test here.
- GIAC recommends leveraging additional study methods for test preparation.