- GCIA stands for GIAC Certified Intrusion Analyst, awarded by GIAC after a 106-question, 4-hour proctored exam.
- Passing requires 67% on versions released January 21, 2023 or later, delivered via ProctorU or Pearson VUE.
- The exam costs $999, covers 15 unweighted domains, and includes CyberLive hands-on packet-analysis tasks.
- Core skills span traffic analysis, IDS rules, fragmentation, TCP/IP, Wireshark, tcpdump, and SiLK.
What Is A GCIA?
A GCIA is a person who holds the GIAC Certified Intrusion Analyst credential, a practitioner-level certification issued by GIAC, LLC - the certification body affiliated with the SANS Institute. The letters themselves refer to both the certification and the person who has earned it: someone is "a GCIA" the same way someone is "a CPA." The credential exists to validate that an analyst can look at raw network traffic, IDS/IPS alerts, and packet captures and correctly determine what happened, why it matters, and what to do next.
Unlike broad security-management certifications, the GCIA is deliberately narrow and technical. It focuses on the mechanics of packets, protocols, and detection logic rather than governance, risk, or policy. If you want the full breakdown of what each tested area covers, the GCIA Exam Domains 2026: Complete Guide to All 15 Content Areas walks through every domain in depth.
What GIAC Actually Certifies
GIAC administers, scores, and maintains the GCIA exam. The certification does not certify that you attended a class - it certifies that you passed a standardized, proctored test built from a fixed set of objectives. Those objectives are published as a current 2026 objective list containing 15 unweighted knowledge areas, meaning every domain is treated as equally important on paper, even though some appear more frequently in question form than others.
The objectives center on five recurring themes:
- Traffic analysis - reading and interpreting live and captured network flows
- IDS rules - writing and evaluating detection logic, primarily Snort-style syntax
- Network forensics - reconstructing events from packet evidence after the fact
- Packet engineering - understanding how packets are built, fragmented, and manipulated
- Tooling - fluency with Wireshark, tcpdump, and SiLK
There are no formal prerequisites to sit the exam, though GIAC recommends practical experience and preparation equivalent to the SANS SEC503 course. For a full rundown of eligibility nuances, see GCIA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Earns a GCIA and Who Hires Them
The GCIA is aimed squarely at people who spend their day looking at network traffic: SOC analysts (particularly Tier 2/3), intrusion detection specialists, network security monitoring engineers, threat hunters, and incident responders who need to read packet captures rather than just review dashboards. Some network forensics and law-enforcement digital investigation roles also list it as a preferred credential.
Employers value it because it is exam-proven rather than attendance-proven. A resume listing "GCIA" tells a hiring manager that the candidate has demonstrated - under proctored, time-boxed conditions - that they can parse IP headers, spot fragmentation attacks, and write a working IDS rule, not just that they sat through a week of lectures.
Key Takeaway
If your job title involves triaging alerts, analyzing PCAPs, or tuning IDS signatures, the GCIA maps almost directly to your daily responsibilities - it is not a generalist credential.
Exam Format, Fees, and Logistics
The GCIA exam is web-based and proctored, and it can be taken remotely through ProctorU or in person at a Pearson VUE test center, subject to attempt availability. It consists of 106 questions delivered over 4 hours, blending traditional knowledge and application questions with CyberLive tasks - live virtual-machine exercises where you actually manipulate tools like Wireshark or tcpdump rather than just answer multiple-choice items about them.
For any exam version released on or after January 21, 2023, the passing score is 67%. If you want the exact mechanics behind that number and how it's calculated, check GCIA Passing Score 2026: Exactly What You Need to Pass.
The exam is open book in a specific sense: printed books, printed notes, and printed indexes are allowed at the testing station, but digital reference material - laptops, tablets, PDFs, e-readers - is prohibited. This is a meaningful detail for prep: your index needs to be paper, tabbed, and fast to navigate under time pressure.
| Item | Detail |
|---|---|
| Certification attempt fee | $999 (no member differential) |
| Retake fee | $899 |
| Extension fee | $479 |
| Practice exam fee | $399 |
| Renewal fee | $499 (or 36 CPEs) |
| Certification validity | 4 years |
| Question count / time | 106 questions / 4 hours |
| Passing score (v. 1/21/2023+) | 67% |
Because these fees add up quickly, especially if a retake is needed, it's worth reading GCIA Certification Cost 2026: Complete Pricing Breakdown before you register, so the practice-exam and extension fees don't come as a surprise mid-process.
The 15 GCIA Domains at a Glance
Every GCIA question traces back to one of these 15 domains. None is officially weighted more heavily than another, but some - like TCP, IP Headers, and IDS Rules - tend to show up across multiple question styles because they're foundational to the others.
Domain 1: Advanced IDS Concepts
Evasion techniques, false positives/negatives, and detection logic beyond basic signature matching.
- Understand how attackers try to blind or bypass sensors
Domain 5: IDS Fundamentals and Network Architecture
Where sensors sit in a network, what they can and can't see, and how architecture shapes visibility.
- Know the tradeoffs of inline vs. passive tap deployment
Domain 6: Intrusion Detection System Rules
Writing and reading Snort-style rules, including options, thresholds, and rule logic ordering.
- Be able to write a rule from a described attack pattern, not just recognize one
Domain 9: Network Forensics and Traffic Analysis
Reconstructing an incident timeline purely from captured traffic and log artifacts.
- Practice tying flow data back to a specific host and session
Domain 15: Wireshark Fundamentals
Filter syntax, stream following, and statistics views used to isolate suspicious traffic quickly.
- CyberLive tasks often require live filtering, so speed matters
The remaining domains - Application Protocols, Concepts of TCP/IP and the Link Layer, Fragmentation, IP Headers, IPv6, Packet Engineering, SiLK and Other Traffic Analysis Tools, TCP, Tcpdump Filters, and UDP and ICMP - round out the objective list and are covered in far more granular detail in the GCIA Exam Domains 2026: Complete Guide to All 15 Content Areas.
Core Technical Skills You Must Master
Beyond memorizing domain names, the exam expects fluency with specific technical operations. A few examples that come up repeatedly:
- Byte-level header parsing - identifying fields in an IP or TCP header from a hex dump, not just a diagram
- Fragmentation math - calculating offsets and reassembly behavior, including overlapping fragment attacks
- tcpdump filter construction - writing BPF expressions to isolate specific traffic under time pressure
- SiLK flow analysis - using flow-based tools to analyze traffic at scale when full packet capture isn't available
- IPv6 header differences - knowing how extension headers change fragmentation and addressing behavior versus IPv4
These are hands-on skills, which is exactly why CyberLive tasks exist in the exam - GIAC wants proof you can execute, not just recognize the right multiple-choice answer.
Scheduling Prep Around the Domains
Because the domains vary in how conceptual versus hands-on they are, it helps to sequence study rather than review everything in parallel. A simple approach: front-load the protocol fundamentals, then layer detection and forensics skills on top once the underlying packet structures are second nature.
Protocol Foundations
- Concepts of TCP/IP and the Link Layer, IP Headers, TCP, UDP and ICMP, IPv6
Packet Manipulation
- Fragmentation, Packet Engineering, Application Protocols
Detection and Tooling
- IDS Fundamentals and Network Architecture, Intrusion Detection System Rules, Advanced IDS Concepts, Tcpdump Filters, Wireshark Fundamentals, SiLK and Other Traffic Analysis Tools
Integration and Practice
- Network Forensics and Traffic Analysis, full-length practice exams, index building
For a more detailed week-by-week plan with specific resources and index-building tactics, see the GCIA Study Guide 2026: How to Pass on Your First Attempt. If you're still evaluating how much time this actually requires, How Hard Is the GCIA Exam? Complete Difficulty Guide 2026 covers the realistic difficulty curve based on the domain mix above.
Is a GCIA Worth Pursuing?
Whether the GCIA is the right move depends on your role and career trajectory more than on the certification alone. It carries genuine weight in SOC, intrusion detection, and network forensics hiring specifically because it tests applied skill under proctored conditions rather than rewarding course attendance. It is less relevant if your work is primarily governance, cloud architecture, or application security with little packet-level exposure.
Because the certification lasts 4 years before requiring renewal - either through 36 CPEs or a retake - it's a multi-year commitment worth weighing against your specific job function and growth plans. A deeper look at how the credential tends to affect compensation and role eligibility is available in the GCIA Salary Guide 2026: Complete Earnings Analysis.
Running timed practice on realistic questions before you commit to the $999 attempt fee is one of the lower-risk ways to gauge readiness. You can get a feel for the question style and pacing over at GCIA Exam Prep before locking in a test date.
Frequently Asked Questions
GCIA stands for GIAC Certified Intrusion Analyst, a credential issued by GIAC, LLC covering network traffic analysis, IDS rules, and packet forensics.
No. There are no formal prerequisites. GIAC recommends practical experience and preparation equivalent to SANS SEC503, but self-study candidates can register directly.
The exam has 106 questions administered over 4 hours, combining knowledge, application, and CyberLive hands-on tasks.
Yes, printed books, printed notes, and printed indexes are permitted. Digital reference materials, including laptops and tablets, are not allowed.
It's valid for 4 years. You can renew by earning 36 CPEs and paying the $499 renewal fee, or by retaking the exam.
For a broader look at how this credential fits alongside related titles and terminology, browse the site's other explainers, including GCIA Certification and GCIA Cheat Sheet 2026: One-Page Review of Must-Know Facts, or head back to GCIA Exam Prep to start practicing against exam-style questions.