- GCIA Domain Overview: What GIAC Actually Tests
- Foundation Domains: Protocols and Packet Structure
- Analysis Domains: IDS, Forensics, and Detection Logic
- Tooling Domains: Wireshark, Tcpdump, and SiLK
- How the Domains Map to Exam Mechanics
- Sequencing the 15 Domains Into a Study Plan
- Who Hires for GCIA-Validated Skills
- FAQ
- The 2026 GCIA objectives contain 15 unweighted domains - no single area dominates the 106-question exam.
- You need 67% to pass on versions released on or after January 21, 2023, inside a 4-hour proctored window.
- CyberLive tasks turn Tcpdump Filters, Wireshark Fundamentals, and SiLK questions into hands-on packet work, not just recall.
- Printed books and notes are allowed open-book; digital references are prohibited during the exam.
GCIA Domain Overview: What GIAC Actually Tests
GIAC publishes a 15-domain objective list for the GCIA credential, and unlike some vendor certifications, none of these domains carries a published weight. That matters for how you prepare: you cannot skip Fragmentation because it "only" counts for a small slice of the exam, because GIAC does not disclose slices at all. Every domain is a candidate for questions, and several - particularly Network Forensics and Traffic Analysis, TCP, and IDS Rules - show up repeatedly across knowledge questions and CyberLive performance tasks alike.
This guide breaks down all 15 domains, groups them by function, and explains how they interact on the actual exam. If you want the broader exam-day picture first, our GCIA Study Guide 2026: How to Pass on Your First Attempt covers registration and pacing, while this article focuses specifically on content.
Foundation Domains: Protocols and Packet Structure
Five domains form the technical foundation the rest of the exam assumes you already know cold.
Domain 3: Concepts of TCP/IP and the Link Layer
Covers how data moves from the wire up through the stack, including addressing, encapsulation, and how link-layer behavior affects what an analyst sees in a capture.
- ARP behavior and its forensic footprints
- Encapsulation boundaries between layers
Domain 7: IP Headers
Field-by-field understanding of IPv4 headers - TTL, ID field, flags, options - and how attackers or misconfigured devices manipulate them.
- Header field manipulation as an evasion technique
- TTL-based OS fingerprinting clues
Domain 4: Fragmentation
One of the most conceptually dense domains. You must understand fragment reassembly, overlapping fragments, and how fragmentation is abused to evade IDS sensors.
- Overlap and evasion techniques (teardrop-style attacks)
- How different OS stacks reassemble fragments differently
Domain 12: TCP
The single most content-dense domain. Three-way handshake, flags, sequence and acknowledgment numbers, window scaling, and abnormal flag combinations used in scanning or evasion.
- Flag combinations tied to specific scan types
- Sequence number analysis in session hijacking scenarios
Domain 14: UDP and ICMP
Lighter in header complexity but frequently tested through ICMP type/code combinations and how UDP's stateless nature complicates detection.
- ICMP type/code pairs used in reconnaissance
- UDP-based tunneling indicators
Domain 8, IPv6, sits alongside these as its own tested area - expect questions on extension headers, addressing differences from IPv4, and how legacy IDS signatures written for IPv4 can miss IPv6 traffic entirely. If you're unsure how much depth these foundational domains require relative to the full exam, How Hard Is the GCIA Exam? Complete Difficulty Guide 2026 breaks down where most candidates report the steepest learning curve.
Analysis Domains: IDS, Forensics, and Detection Logic
Once you can read packets fluently, the exam shifts to what you do with that skill operationally.
Domain 5: IDS Fundamentals and Network Architecture
Sensor placement, span ports, network taps, and how architecture decisions determine what an IDS can and cannot see.
- Choke point vs. full-visibility deployment tradeoffs
- Where encryption blinds a sensor
Domain 1: Advanced IDS Concepts
Builds on fundamentals with evasion, insertion, and denial-of-service attacks against detection systems themselves, plus tuning to reduce false positives.
- IDS evasion via fragmentation or obfuscation
- Signature tuning to reduce alert fatigue
Domain 6: Intrusion Detection System Rules
Writing and interpreting Snort-style rules - header options, rule options, and how rule logic maps to the traffic it's meant to catch.
- Constructing rules from a written attack description
- Interpreting existing rules to predict trigger conditions
Domain 9: Network Forensics and Traffic Analysis
Arguably the broadest domain on the exam. Reconstructing incidents from packet captures, flow data, and log correlation.
- Timeline reconstruction from multiple evidence sources
- Distinguishing normal baseline traffic from anomalies
Domain 2: Application Protocols
DNS, HTTP, SMTP, and other application-layer protocols as seen through packet analysis - how legitimate traffic looks versus abused or tunneled traffic.
- DNS tunneling and exfiltration indicators
- HTTP header anomalies signaling malicious activity
Domain 10, Packet Engineering, closes the loop by testing your ability to craft or manipulate packets deliberately - a skill that reinforces every domain above it because you're applying the same header and protocol knowledge in reverse.
Key Takeaway
Network Forensics and Traffic Analysis pulls from nearly every other domain, so studying it last - after IP Headers, TCP, and IDS Rules are solid - makes the material click faster than studying it first.
Tooling Domains: Wireshark, Tcpdump, and SiLK
Three domains are explicitly tool-based, and this is where the exam's CyberLive component becomes most relevant.
Domain 15: Wireshark Fundamentals
Filter syntax, following streams, applying display filters under time pressure, and reading Wireshark's interpretation of protocol fields.
- Building compound display filters quickly
- Interpreting Wireshark's expert info flags
Domain 13: Tcpdump Filters
Command-line filter construction using BPF syntax - a different skill from Wireshark's GUI filters and tested separately for good reason.
- Writing BPF expressions for specific header conditions
- Combining host, port, and protocol filters
Domain 11: SiLK and Other Traffic Analysis Tools
Flow-based analysis tools for working with NetFlow-style data at scale, useful when full packet capture isn't available.
- Interpreting flow records vs. full packet captures
- Using SiLK to spot volumetric anomalies
These three domains are why the GCIA exam includes CyberLive virtual-machine tasks rather than relying purely on multiple-choice recall. You'll be expected to actually run filters and interpret real output, not just recognize correct syntax in a list of answer choices.
| Domain Group | Domains Included | Primary Skill Tested |
|---|---|---|
| Foundation | TCP/IP Concepts, IP Headers, Fragmentation, TCP, UDP/ICMP, IPv6 | Header-level protocol literacy |
| Analysis | IDS Fundamentals, Advanced IDS, IDS Rules, Network Forensics, Application Protocols, Packet Engineering | Applied detection and investigation |
| Tooling | Wireshark Fundamentals, Tcpdump Filters, SiLK | Hands-on tool proficiency (CyberLive) |
How the Domains Map to Exam Mechanics
The GCIA exam is a web-based, proctored test with 106 questions delivered in a 4-hour window. Questions combine straightforward knowledge checks with application-style scenarios, plus CyberLive tasks that put you inside a virtual machine to run actual commands. You'll need 67% correct on versions released on or after January 21, 2023 to pass.
Testing happens remotely through ProctorU or on-site through Pearson VUE, depending on attempt availability. The exam is open-book in the traditional sense - printed books, notes, and printed indexes are allowed - but digital reference material of any kind is prohibited, so your index tabs and printed notes need to be organized before you sit down, not searchable during the test. For the precise scoring mechanics behind that 67% threshold, see GCIA Passing Score 2026: Exactly What You Need to Pass.
There's no formal prerequisite to sit the exam, though GIAC recommends practical experience and SANS SEC503 or equivalent preparation before attempting it. If you're checking whether you're ready to register, GCIA Requirements 2026: Eligibility, Prerequisites & How to Qualify walks through what "equivalent preparation" typically looks like in practice.
Sequencing the 15 Domains Into a Study Plan
Because none of the domains are weighted, the smartest sequencing isn't based on exam frequency - it's based on dependency. Foundation domains have to come first because analysis and tooling domains assume you can already read a header without hesitation.
Foundation Protocols
- TCP/IP and Link Layer, IP Headers, Fragmentation
- Drill header fields until they're automatic, not looked-up
Transport Layer Depth
- TCP flags, sequencing, and handshake anomalies
- UDP and ICMP type/code pairs, plus IPv6 addressing differences
Detection Logic
- IDS Fundamentals and Network Architecture, then Advanced IDS Concepts
- Write and dissect IDS rules until rule syntax feels natural
Tools and Forensics Integration
- Wireshark Fundamentals, Tcpdump Filters, SiLK - practice hands-on, not just reading syntax
- Finish with Network Forensics and Traffic Analysis, Application Protocols, and Packet Engineering as integrative review
This sequencing is deliberately not a generic weekly template - it follows the actual dependency chain of the 15 domains themselves. For a more detailed walkthrough of pacing and resource selection across the full prep window, our GCIA Study Guide 2026: How to Pass on Your First Attempt pairs well with this domain-by-domain breakdown. Once you've built a study rhythm, running timed drills on our GCIA practice test platform is the fastest way to confirm which domains still need reinforcement before exam day.
Who Hires for GCIA-Validated Skills
The 15 domains aren't academic - they map directly onto day-to-day SOC and incident response work. Analysts who need to distinguish real intrusions from noise rely on exactly the skills tested in Network Forensics and Traffic Analysis, IDS Rules, and the three tooling domains. Employers hiring for intrusion detection analyst, SOC analyst, and network security monitoring roles frequently list GCIA as a preferred or required credential precisely because it validates hands-on packet skills rather than just theory.
If you're evaluating whether this certification fits your career trajectory, GCIA Jobs outlines common role titles, and GCIA Salary Guide 2026: Complete Earnings Analysis covers compensation patterns. For a broader cost-versus-benefit view before you commit to the $999 exam fee, Is the GCIA Certification Worth It? Complete ROI Analysis 2026 is worth reading alongside this domain guide.
Curious about baseline pass outcomes across the certification, not just domain content? GCIA Pass Rate 2026: What the Data Shows puts these 15 domains into context against overall exam performance, and GCIA Exam Dates 2026: Testing Windows, Deadlines & Scheduling helps you plan registration around your domain-by-domain prep timeline.
FAQ
No. GIAC's current objective list treats all 15 domains as unweighted, meaning questions can come from any area without a published emphasis on one over another.
Fragmentation and Packet Engineering tend to be the most conceptually abstract without hands-on practice, since they involve reasoning about reassembly and crafted packets rather than straightforward header lookups.
You need working fluency rather than rote memorization, since CyberLive tasks require you to actually apply filters in a virtual machine environment, not just recognize correct syntax from a list.
Yes. The GCIA exam is open-book for printed materials, including notes and indexes, but digital reference material of any kind is not permitted during the test.
No formal prerequisite exists. GIAC recommends practical experience and SEC503 or equivalent preparation, but you can register and sit the exam without completing that course.