- Overview of the GCED Exam Blueprint
- Domains 1-2: Defending Network Protocols and Infrastructure
- Domains 3-4: Forensics and Incident Response Concepts
- Domains 5-7: Malware Analysis Track
- Domains 8-9: Network Forensics and Monitoring
- Domains 10-11: Penetration Testing Track
- How the 11 Domains Map to the 115 Questions
- Sequencing Your Prep Across the Domains
- Frequently Asked Questions
- GCED tests 11 objectives spanning network defense, forensics, malware analysis, and penetration testing.
- The exam has 115 questions, a 3-hour limit, and requires 69% on versions from October 1, 2022 onward.
- Registration costs $999, with 120 days from activation to schedule via ProctorU or Pearson VUE.
- Hard-copy books, printed notes, and indexes are permitted; electronic references and internet access are not.
Overview of the GCED Exam Blueprint
The GIAC Certified Enterprise Defender credential is built around 11 published objectives that GIAC uses to write, score, and validate every version of the exam. Unlike certifications that lean heavily into one skill area, GCED spreads its content across network defense, digital forensics, incident response, malware analysis, and penetration testing. That breadth is the point: the certification exists to prove a candidate can defend an enterprise network end-to-end, not just operate one tool or follow one playbook.
This guide walks through all 11 domains in the order GIAC lists them, explains what each one actually demands from a test-taker, and shows how they fit together into a single 115-question, three-hour exam. If you want a broader look at exam mechanics, pacing, and the open-book rules, the GCED Study Guide 2026: How to Pass on Your First Attempt pairs well with this domain breakdown.
Domains 1-2: Defending Network Protocols and Infrastructure
Domain 1: Defending Network Protocols covers the protocol-level knowledge every enterprise defender needs before touching a single security tool. Expect questions on how common protocols behave under normal conditions versus how attackers abuse them, plus the defensive controls that mitigate protocol-level weaknesses.
Defending Network Protocols
Candidates must be able to identify protocol misuse in traffic captures and pick the correct mitigation for a given scenario.
- Behavior of core TCP/IP and application-layer protocols
- Common protocol-based attack techniques
- Defensive configuration choices that reduce protocol exposure
Domain 2: Defensive Infrastructure and Tactics moves from individual protocols to the architecture around them-segmentation, access control, defense-in-depth layering, and the tactical decisions a defender makes when designing or hardening a network.
Defensive Infrastructure and Tactics
This domain tests architectural judgment as much as memorized facts.
- Network segmentation and zoning strategies
- Placement of defensive controls within a layered architecture
- Tactical trade-offs between security and operational impact
Domains 3-4: Forensics and Incident Response Concepts
Domain 3: Digital Forensics Concepts and Application asks candidates to apply forensic methodology to enterprise scenarios-evidence handling, chain of custody, and analysis of artifacts pulled from compromised systems. Domain 4: Incident Response Concepts and Application follows naturally, testing the structured process of detecting, containing, and recovering from an incident inside a real organizational environment.
Digital Forensics Concepts and Application
- Evidence acquisition and preservation practices
- Artifact analysis from disk, memory, and system logs
- Legally sound documentation of findings
Incident Response Concepts and Application
- Incident response lifecycle stages and decision points
- Containment strategies that limit lateral movement
- Coordination between technical response and business stakeholders
These two domains frequently show up together in scenario-based questions, since a realistic incident response question almost always requires a forensic decision embedded inside it. If you're trying to gauge how demanding this combination is relative to other domains, How Hard Is the GCED Exam? Complete Difficulty Guide 2026 breaks down where candidates typically lose the most points.
Domains 5-7: Malware Analysis Track
GCED dedicates three separate objectives to malware, making it one of the heaviest thematic clusters on the exam. Domain 7: Malware Analysis Concepts and Basic Analysis Techniques establishes the foundation-static analysis, basic behavioral observation, and terminology. Domain 5: Interactive and Manual Malware Analyses pushes further into hands-on dynamic analysis, sandboxing behavior, and manual code inspection. Domain 6: Intrusion Detection and Packet Analysis, while framed around detection, ties directly back into recognizing malicious traffic generated by the malware covered in the other two domains.
Malware Analysis Concepts and Basic Analysis Techniques
- Static analysis of suspicious binaries
- Identifying indicators of compromise from file properties
- Basic behavioral triage before deeper analysis
Interactive and Manual Malware Analyses
- Controlled dynamic execution and sandbox observation
- Manual code-level inspection techniques
- Documenting behavior for incident response handoff
Intrusion Detection and Packet Analysis
- Reading packet captures to spot malicious activity
- Tuning detection logic to reduce false positives
- Correlating network signatures with known malware behavior
Domains 8-9: Network Forensics and Monitoring
Domain 8: Network Forensics, Logging, and Event Management centers on reconstructing events from logs, SIEM output, and network traffic after the fact. Domain 9: Network Security Monitoring Concepts and Application is the proactive counterpart-continuous monitoring, alerting logic, and the operational discipline of a security operations function watching traffic in real time.
Network Forensics, Logging, and Event Management
- Correlating log sources across firewalls, hosts, and applications
- Reconstructing an attack timeline from disparate event data
- Event management workflows for enterprise-scale logging
Network Security Monitoring Concepts and Application
- Building and interpreting monitoring baselines
- Selecting sensors and placement for maximum visibility
- Distinguishing benign anomalies from active threats
Domains 10-11: Penetration Testing Track
The final pair of objectives shifts perspective from defender to attacker. Domain 11: Penetration Testing Concepts covers methodology, rules of engagement, and the structured phases of an authorized assessment. Domain 10: Penetration Testing Application applies those concepts practically-scoping realistic scenarios, choosing techniques, and interpreting results the way an enterprise defender would use them to prioritize remediation.
Penetration Testing Concepts
- Standard testing methodologies and phase ordering
- Scoping, authorization, and rules of engagement
- Reporting expectations for enterprise stakeholders
Penetration Testing Application
- Selecting techniques appropriate to a given target environment
- Interpreting test results for defensive prioritization
- Translating offensive findings into hardening recommendations
Including offensive concepts alongside defensive, forensic, and monitoring content is what distinguishes GCED from narrower certifications-it explains why the credential appeals to employers hiring for blended blue-team and analyst roles, a topic covered in more depth on the GCED Jobs page.
How the 11 Domains Map to the 115 Questions
GIAC does not publish a fixed percentage weighting for each objective, so no domain should be assumed "safe to skip." With 115 total questions distributed across 11 areas, even a domain that receives lighter coverage can still swing several points-enough to matter against the 69% passing threshold. For an exact breakdown of what that threshold means in practice, see GCED Passing Score 2026: Exactly What You Need to Pass.
| Domain Cluster | Domains Included | Primary Skill Tested |
|---|---|---|
| Network Defense | 1, 2 | Protocol and infrastructure hardening |
| Forensics & Response | 3, 4, 8 | Evidence handling and event reconstruction |
| Malware Analysis | 5, 6, 7 | Static, dynamic, and traffic-based detection |
| Monitoring | 9 | Continuous visibility and alerting |
| Penetration Testing | 10, 11 | Offensive methodology and application |
Key Takeaway
Treat each of the 11 domains as independently testable rather than assuming heavier study time on one cluster will compensate for gaps in another.
Sequencing Your Prep Across the Domains
A practical way to move through 11 domains without losing momentum is to group them by the clusters above and study one cluster at a time, ending with a full-length timed run to simulate the actual 115-question, three-hour format.
Network Defense
- Work through Domains 1-2 with protocol capture exercises
Forensics and Response
- Study Domains 3, 4, and 8 together using log and artifact walkthroughs
Malware and Monitoring
- Cover Domains 5, 6, 7, and 9 with sample analysis and traffic review
Penetration Testing and Review
- Finish Domains 10-11, then run full practice exams under timed conditions
Because GIAC exams remain open book for printed materials, build your index during this phase rather than after-organize it by domain number so you can flip directly to the right section under time pressure. The GCED Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful companion for condensing each domain into quick-reference form.
Before locking in a study calendar, confirm your eligibility and testing window details through GCED Requirements 2026: Eligibility, Prerequisites & How to Qualify and GCED Exam Dates 2026: Testing Windows, Deadlines & Scheduling, since your 120-day activation clock starts as soon as registration is complete.
Running realistic practice questions against each of the 11 domains on the main GCED practice test platform is one of the most direct ways to find which objectives still need attention before exam day. Repeating domain-specific question sets on the practice site also helps calibrate pacing against the three-hour limit.
Frequently Asked Questions
GIAC does not publish fixed per-domain percentages, so candidates should prepare each of the 11 objectives thoroughly rather than assuming any single domain carries more weight than the others.
Domain 10 (Penetration Testing Application) and Domain 11 (Penetration Testing Concepts) cover offensive methodology, scoping, and result interpretation from a defender's perspective.
Domains 5, 6, and 7 break malware analysis into basic/static techniques, interactive/manual analysis, and packet-level detection, reflecting the different stages an enterprise defender uses to analyze a threat.
Yes. GIAC exams are open book for hard-copy books, notes, and indexes, but electronic references and internet access are not permitted during the proctored session.
GIAC does not publish an exact question count per domain, so candidates should assume broad, even coverage across all 11 objectives rather than concentrated blocks tied to specific domains.