Signal your readiness as an advanced defender, armed with a comprehensive range of technical expertise and the practical skills to implement advanced protection.
The GIAC Certified Enterprise Defender (GCED®) certification validates a practitioner’s knowledge and abilities in the areas of defensive network infrastructure, packet analysis, penetration testing, incident handling, and malware removal, building on the security skills measured by the GIAC Security Essentials certification. GCED® certification holders are equipped with more advanced technical skills that are needed to defend the enterprise environment and protect an organization as a whole.
Areas Covered
- Network and cloud-based defensive infrastructure
- Penetration testing, digital forensics, and incident response
- Network monitoring, forensics, and logging
- Packet analysis, intrusion analysis, and malware analysis
Who is GCED® for?
- Incident responders and penetration testers
- Security Operations Center engineers and analysts
- Network security professionals
- Anyone seeking technical in-depth knowledge about implementing comprehensive security solutions
Exam Format
- 1 proctored exam
- 3 hours
- Minimum passing score of 69%
- 115 questions
The GCED® certification exam is prepared, administered, and scored by GIAC as a standardized assessment, objectively measuring each candidate's knowledge and hands-on cybersecurity skills against a validated, industry-recognized standard.
Note: GIAC periodically reviews and may update certification specifications to ensure fairness, validity, and reliability. Using a psychometric standard-setting study, GIAC has set the passing score for the GCED exam at 69% for all candidates who receive the exam version released on or after October 1st, 2022.
To confirm the exam format and passing score that apply to your specific attempt, please refer to the Certification Information section of your GIAC account: https://exams.giac.org/pages/attempts.
Certification Delivery
GIAC certification attempts will be activated in your GIAC account after your application has been approved and according to the terms of your purchase. Details on delivery will be provided along with your registration confirmation upon payment. You will receive an email notification when your certification attempt has been activated in your account. You will have 120 days from the date of activation to complete your certification attempt.
NOTE: All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE. Click here for more information.

Exam Certification Objectives & Outcome Statements
- Attack Surface ManagementCandidates will demonstrate the ability to identify, assess, and prioritize attack surface exposures and vulnerabilities. Candidates will demonstrate familiarity with the MITRE ATT&CK and D3FEND frameworks, the use of open-source intelligence (OSINT) techniques to understand attacker reconnaissance and attack phases and be able to describe the phases of enterprise vulnerability management.
- Configuration Management and Automation WorkflowsCandidates will demonstrate the ability to maintain secure configurations and automate continuous hardening using modern defensive practices including mitigating configuration drift and leveraging automation and AI-assisted tools to manage configuration.
- Engineered Telemetry through Defensive ControlsCandidates will demonstrate the ability to implement and evaluate defensive controls that improve detection and reduce infrastructure exposure.
- Enterprise Security OperationsCandidates will demonstrate an understanding of how security operations center (SOC) processes and personnel support detection and event monitoring workflows. Candidates will demonstrate the ability to develop and optimize detection capabilities using security telemetry and analytics including the review and interpretation of common source and network log formats.
- Evidence Collection and VisibilityCandidates will demonstrate the ability to assess the accuracy and integrity of security records, baselines, and logs. Candidates will demonstrate the ability to evaluate how baselines and standards inform alert prioritization and recognize the importance of time and logging integrity for reliable analysis.
- Identity and Infrastructure HardeningCandidates will demonstrate the ability to implement identity and network controls that reduce attack paths and limit attacker movement. Candidates will identify and differentiate common attack vectors and techniques including reconnaissance, password-based attacks and command-and-control activity.
- Identity and Infrastructure RecordsCandidates will demonstrate the ability to analyze identity and network infrastructure records, including enterprise technologies such as Active Directory, RADIUS, and TACACS+ to determine system and user activity. Candidates will be able to recognize how logs can be enriched as they move from source to presentation as well as identify indicators of spoofing, poisoning and other malicious manipulation of infrastructure records.
- Incident Containment and RecoveryCandidates will demonstrate an understanding of the post-incident response processes and will demonstrate an ability to recognize common obstacles that can complicate containment, eradication, and recovery efforts
- Incident Investigation and AnalysisCandidates will demonstrate the ability to collect and analyze evidence to determine the scope of an incident, apply established incident detection and response methodologies to analyze host-based artifacts, and integrate threat intelligence to guide investigative and response activities
- Malware Analysis and Defensive ControlsCandidates will demonstrate the ability to determine when static and dynamic malware analysis is appropriate, characterize malicious behavior through interactive and network-based analysis, and apply analysis findings to improve threat detection and defensive controls across the enterprise.
- Malware Identification and TriageCandidates will demonstrate the ability to identify malware characteristics and assess indicators of compromise to support malware triage using tools and techniques to recognize common attack methodologies and symptoms of infection during early triage.
- Network Traffic Analysis and InvestigationCandidates will demonstrate the ability to analyze network traffic and forensic evidence to investigate security events using a variety of tools to examine packets, flows, and artifacts and will demonstrate the ability to configure, tune and interpret network intrusion detection/prevention systems, including the development and review of open source rules.
Practice Tests
- Practice exams are a simulation of the real exam, allowing you to become familiar with the test engine and style of questions
- Practice exams can serve as a gauge to determine if your preparation methods are sufficient
- The bank of practice questions is limited, so you may encounter the same question on multiple practice tests
- Practice exams never include actual exam questions
- Purchase a GCED practice test here
Other Resources
- Training is available in a variety of modalities including live training and OnDemand
- Practical work experience can help ensure that you have mastered the skills necessary for certification
- College level courses or self-paced study through other programs or materials may meet the needs for mastery
- Understand the procedure to contest exam results
- Use this justification letter to share key details of this certification opportunity with your boss




