GCIA logo
Focused certification exam prep
Start practice

GCIA Exam Domains 2026: Complete Guide to All 15 Content Areas

TL;DR
  • The 2026 GCIA objectives contain 15 unweighted domains - no single area dominates the 106-question exam.
  • You need 67% to pass on versions released on or after January 21, 2023, inside a 4-hour proctored window.
  • CyberLive tasks turn Tcpdump Filters, Wireshark Fundamentals, and SiLK questions into hands-on packet work, not just recall.
  • Printed books and notes are allowed open-book; digital references are prohibited during the exam.

GCIA Domain Overview: What GIAC Actually Tests

GIAC publishes a 15-domain objective list for the GCIA credential, and unlike some vendor certifications, none of these domains carries a published weight. That matters for how you prepare: you cannot skip Fragmentation because it "only" counts for a small slice of the exam, because GIAC does not disclose slices at all. Every domain is a candidate for questions, and several - particularly Network Forensics and Traffic Analysis, TCP, and IDS Rules - show up repeatedly across knowledge questions and CyberLive performance tasks alike.

This guide breaks down all 15 domains, groups them by function, and explains how they interact on the actual exam. If you want the broader exam-day picture first, our GCIA Study Guide 2026: How to Pass on Your First Attempt covers registration and pacing, while this article focuses specifically on content.

Unweighted Doesn't Mean Equal Effort: Because GIAC does not weight domains, treat depth of testable material as your guide, not guesswork about frequency. Domains like TCP and Network Forensics and Traffic Analysis simply have more sub-topics to master than a narrower domain like UDP and ICMP.

Foundation Domains: Protocols and Packet Structure

Five domains form the technical foundation the rest of the exam assumes you already know cold.

Domain 3: Concepts of TCP/IP and the Link Layer

Covers how data moves from the wire up through the stack, including addressing, encapsulation, and how link-layer behavior affects what an analyst sees in a capture.

  • ARP behavior and its forensic footprints
  • Encapsulation boundaries between layers

Domain 7: IP Headers

Field-by-field understanding of IPv4 headers - TTL, ID field, flags, options - and how attackers or misconfigured devices manipulate them.

  • Header field manipulation as an evasion technique
  • TTL-based OS fingerprinting clues

Domain 4: Fragmentation

One of the most conceptually dense domains. You must understand fragment reassembly, overlapping fragments, and how fragmentation is abused to evade IDS sensors.

  • Overlap and evasion techniques (teardrop-style attacks)
  • How different OS stacks reassemble fragments differently

Domain 12: TCP

The single most content-dense domain. Three-way handshake, flags, sequence and acknowledgment numbers, window scaling, and abnormal flag combinations used in scanning or evasion.

  • Flag combinations tied to specific scan types
  • Sequence number analysis in session hijacking scenarios

Domain 14: UDP and ICMP

Lighter in header complexity but frequently tested through ICMP type/code combinations and how UDP's stateless nature complicates detection.

  • ICMP type/code pairs used in reconnaissance
  • UDP-based tunneling indicators

Domain 8, IPv6, sits alongside these as its own tested area - expect questions on extension headers, addressing differences from IPv4, and how legacy IDS signatures written for IPv4 can miss IPv6 traffic entirely. If you're unsure how much depth these foundational domains require relative to the full exam, How Hard Is the GCIA Exam? Complete Difficulty Guide 2026 breaks down where most candidates report the steepest learning curve.

Analysis Domains: IDS, Forensics, and Detection Logic

Once you can read packets fluently, the exam shifts to what you do with that skill operationally.

Domain 5: IDS Fundamentals and Network Architecture

Sensor placement, span ports, network taps, and how architecture decisions determine what an IDS can and cannot see.

  • Choke point vs. full-visibility deployment tradeoffs
  • Where encryption blinds a sensor

Domain 1: Advanced IDS Concepts

Builds on fundamentals with evasion, insertion, and denial-of-service attacks against detection systems themselves, plus tuning to reduce false positives.

  • IDS evasion via fragmentation or obfuscation
  • Signature tuning to reduce alert fatigue

Domain 6: Intrusion Detection System Rules

Writing and interpreting Snort-style rules - header options, rule options, and how rule logic maps to the traffic it's meant to catch.

  • Constructing rules from a written attack description
  • Interpreting existing rules to predict trigger conditions

Domain 9: Network Forensics and Traffic Analysis

Arguably the broadest domain on the exam. Reconstructing incidents from packet captures, flow data, and log correlation.

  • Timeline reconstruction from multiple evidence sources
  • Distinguishing normal baseline traffic from anomalies

Domain 2: Application Protocols

DNS, HTTP, SMTP, and other application-layer protocols as seen through packet analysis - how legitimate traffic looks versus abused or tunneled traffic.

  • DNS tunneling and exfiltration indicators
  • HTTP header anomalies signaling malicious activity

Domain 10, Packet Engineering, closes the loop by testing your ability to craft or manipulate packets deliberately - a skill that reinforces every domain above it because you're applying the same header and protocol knowledge in reverse.

Key Takeaway

Network Forensics and Traffic Analysis pulls from nearly every other domain, so studying it last - after IP Headers, TCP, and IDS Rules are solid - makes the material click faster than studying it first.

Tooling Domains: Wireshark, Tcpdump, and SiLK

Three domains are explicitly tool-based, and this is where the exam's CyberLive component becomes most relevant.

Domain 15: Wireshark Fundamentals

Filter syntax, following streams, applying display filters under time pressure, and reading Wireshark's interpretation of protocol fields.

  • Building compound display filters quickly
  • Interpreting Wireshark's expert info flags

Domain 13: Tcpdump Filters

Command-line filter construction using BPF syntax - a different skill from Wireshark's GUI filters and tested separately for good reason.

  • Writing BPF expressions for specific header conditions
  • Combining host, port, and protocol filters

Domain 11: SiLK and Other Traffic Analysis Tools

Flow-based analysis tools for working with NetFlow-style data at scale, useful when full packet capture isn't available.

  • Interpreting flow records vs. full packet captures
  • Using SiLK to spot volumetric anomalies

These three domains are why the GCIA exam includes CyberLive virtual-machine tasks rather than relying purely on multiple-choice recall. You'll be expected to actually run filters and interpret real output, not just recognize correct syntax in a list of answer choices.

Domain GroupDomains IncludedPrimary Skill Tested
FoundationTCP/IP Concepts, IP Headers, Fragmentation, TCP, UDP/ICMP, IPv6Header-level protocol literacy
AnalysisIDS Fundamentals, Advanced IDS, IDS Rules, Network Forensics, Application Protocols, Packet EngineeringApplied detection and investigation
ToolingWireshark Fundamentals, Tcpdump Filters, SiLKHands-on tool proficiency (CyberLive)

How the Domains Map to Exam Mechanics

The GCIA exam is a web-based, proctored test with 106 questions delivered in a 4-hour window. Questions combine straightforward knowledge checks with application-style scenarios, plus CyberLive tasks that put you inside a virtual machine to run actual commands. You'll need 67% correct on versions released on or after January 21, 2023 to pass.

Testing happens remotely through ProctorU or on-site through Pearson VUE, depending on attempt availability. The exam is open-book in the traditional sense - printed books, notes, and printed indexes are allowed - but digital reference material of any kind is prohibited, so your index tabs and printed notes need to be organized before you sit down, not searchable during the test. For the precise scoring mechanics behind that 67% threshold, see GCIA Passing Score 2026: Exactly What You Need to Pass.

Fee Structure to Plan Around: The certification attempt itself costs $999 with no member discount. A retake runs $899, an extension is $479, a practice exam is $399, and renewal after your 4-year certification period costs $499 (or 36 CPEs instead of retesting). Full breakdowns of every fee scenario are in GCIA Certification Cost 2026: Complete Pricing Breakdown.

There's no formal prerequisite to sit the exam, though GIAC recommends practical experience and SANS SEC503 or equivalent preparation before attempting it. If you're checking whether you're ready to register, GCIA Requirements 2026: Eligibility, Prerequisites & How to Qualify walks through what "equivalent preparation" typically looks like in practice.

Sequencing the 15 Domains Into a Study Plan

Because none of the domains are weighted, the smartest sequencing isn't based on exam frequency - it's based on dependency. Foundation domains have to come first because analysis and tooling domains assume you can already read a header without hesitation.

Weeks 1-2

Foundation Protocols

  • TCP/IP and Link Layer, IP Headers, Fragmentation
  • Drill header fields until they're automatic, not looked-up
Weeks 3-4

Transport Layer Depth

  • TCP flags, sequencing, and handshake anomalies
  • UDP and ICMP type/code pairs, plus IPv6 addressing differences
Weeks 5-6

Detection Logic

  • IDS Fundamentals and Network Architecture, then Advanced IDS Concepts
  • Write and dissect IDS rules until rule syntax feels natural
Weeks 7-8

Tools and Forensics Integration

  • Wireshark Fundamentals, Tcpdump Filters, SiLK - practice hands-on, not just reading syntax
  • Finish with Network Forensics and Traffic Analysis, Application Protocols, and Packet Engineering as integrative review

This sequencing is deliberately not a generic weekly template - it follows the actual dependency chain of the 15 domains themselves. For a more detailed walkthrough of pacing and resource selection across the full prep window, our GCIA Study Guide 2026: How to Pass on Your First Attempt pairs well with this domain-by-domain breakdown. Once you've built a study rhythm, running timed drills on our GCIA practice test platform is the fastest way to confirm which domains still need reinforcement before exam day.

Who Hires for GCIA-Validated Skills

The 15 domains aren't academic - they map directly onto day-to-day SOC and incident response work. Analysts who need to distinguish real intrusions from noise rely on exactly the skills tested in Network Forensics and Traffic Analysis, IDS Rules, and the three tooling domains. Employers hiring for intrusion detection analyst, SOC analyst, and network security monitoring roles frequently list GCIA as a preferred or required credential precisely because it validates hands-on packet skills rather than just theory.

If you're evaluating whether this certification fits your career trajectory, GCIA Jobs outlines common role titles, and GCIA Salary Guide 2026: Complete Earnings Analysis covers compensation patterns. For a broader cost-versus-benefit view before you commit to the $999 exam fee, Is the GCIA Certification Worth It? Complete ROI Analysis 2026 is worth reading alongside this domain guide.

Curious about baseline pass outcomes across the certification, not just domain content? GCIA Pass Rate 2026: What the Data Shows puts these 15 domains into context against overall exam performance, and GCIA Exam Dates 2026: Testing Windows, Deadlines & Scheduling helps you plan registration around your domain-by-domain prep timeline.

Renewal Reality Check: GCIA is valid for 4 years. You renew with 36 CPEs or by retaking the exam, at a $499 renewal fee. That means the domain knowledge you build now has a defined shelf life - plan continuing education around whichever domains evolve fastest, particularly IPv6 and tooling.

FAQ

Are any of the 15 GCIA domains weighted more heavily than others?

No. GIAC's current objective list treats all 15 domains as unweighted, meaning questions can come from any area without a published emphasis on one over another.

Which domain is hardest to self-study without lab practice?

Fragmentation and Packet Engineering tend to be the most conceptually abstract without hands-on practice, since they involve reasoning about reassembly and crafted packets rather than straightforward header lookups.

Do I need to memorize Wireshark and tcpdump syntax exactly?

You need working fluency rather than rote memorization, since CyberLive tasks require you to actually apply filters in a virtual machine environment, not just recognize correct syntax from a list.

Can I bring a printed cheat sheet covering all 15 domains into the exam?

Yes. The GCIA exam is open-book for printed materials, including notes and indexes, but digital reference material of any kind is not permitted during the test.

Is SANS SEC503 required before attempting the GCIA exam?

No formal prerequisite exists. GIAC recommends practical experience and SEC503 or equivalent preparation, but you can register and sit the exam without completing that course.

Ready to pass your GCIA exam?

Put this into practice with free GCIA questions across every exam domain.