1. Home
  2. GIAC
  3. GCCC Exam Syllabus

GIAC GCCC Exam Syllabus

Start Free GCCC Exam Practice After Reviewing the Topics

Before starting your GCCC exam preparation, it is recommended to review the complete GIAC Critical Controls Certification exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free GCCC questions. We also provide premium GCCC practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

Vendor
GCCC
Exam Code
93
Total Questions
20
Total Exam Domains

START FREE GCCC EXAM PRACTICE

NO SIGNUP REQUIRED  •  100% FREE TO START

GCCC EXAM QUESTIONS

GIAC GCCC Exam Objectives

Section 1: Account Monitoring and Control
Weight:
-
The candidate will be familiar with processes and tools used to track/control/prevent/correct use of system and application accounts.
Section 2: Application Software Security
Weight:
-
The candidate will be familiar with the processes and tools organizations use to detect/prevent/correct security weaknesses in the development and acquisition of software applications.
Section 3: Background, History, Purpose & Implementation of the 20 CC
Weight:
-
The candidate will be familiar with the background, history, and purpose of the CIS Controls. The GIAC Critical Controls Certification exam is aligned with the current release, CIS Controls V7.1.
Section 4: Boundary Defense
Weight:
-
The candidate will be familiar with the processes and tools used to detect/prevent/correct the flow of information transferring networks of different trust levels.
Section 5: Continuous Vulnerability Management
Weight:
-
The candidate will be familiar with the processes and tools used to detect/prevent/correct security vulnerabilities in the configurations of devices that are listed and approved in the asset inventory database.
Section 6: Controlled Access Based on the Need to Know
Weight:
-
The candidate will be familiar with the processes and tools used to track/control/prevent/correct secure access to information according to the formal determination of persons, computers, and applications have a need and right to access information based on an approved classification.
Section 7: Controlled Use of Administrative Privileges
Weight:
-
The candidate will be familiar with processes and tools used to track/control/prevent/correct use, assignment and configuration of administrative privileges on computers, networks, and applications.
Section 8: Data Protection
Weight:
-
The candidate will be familiar with the processes and tools used to track/control/prevent/correct data transmission and storage, based on the data's content and classification.
Section 9: Data Recovery Capability
Weight:
-
The candidate will be familiar with processes and tools used to properly backup critical information with a proven methodology for timely recovery of the critical information.
Section 10: Email & Web Browser Protections
Weight:
-
The candidate will be familiar with the processes and tools used to defend email and web based internet traffic from abuse through the use of filters and hardened clients.
Section 11: Implement a Security Awareness and Training Program
Weight:
-
The candidate will be familiar with processes and tools to make sure an organization understands the technical skill gaps with their workforce and develop a plan to fill the gaps.
Section 12: Incident Response and Management
Weight:
-
The candidate will be familiar with process and tools to make sure an organization has a properly tested plan with trained resources for dealing with adverse events.
Section 13: Inventory and Control of Hardware Assets
Weight:
-
The candidate will be familiar with the processes and tools used to track/control/prevent/correct network access by devices based on an asset inventory of which devices are allowed to connect to the network.
Section 14: Inventory and Control of Software Assets
Weight:
-
The candidate will be familiar with the processes and tools organizations use to track/control/prevent/correct installation and execution of software on computers based on an asset inventory of approved software.
Section 15: Limitation and Control of Network Ports
Weight:
-
The candidate will be familiar with processes and tools used to track/control/prevent/correct use of ports, protocols, and services on networked devices.
Section 16: Maintenance, Monitoring, and Analysis of Audit Logs
Weight:
-
The candidate will be familiar with the processes and tools used to detect/prevent/correct use of systems and information based on audit logs of events that are consider significant or could impact the security of an organization.
Section 17: Malware Defenses
Weight:
-
The candidate will be familiar with the processes and tools used to detect/prevent/correct installation and execution of malicious software on all devices.
Section 18: Penetration Tests and Red Team Exercises
Weight:
-
The candidate will be familiar with process and tools used to simulate attacks against a network to validate the overall security of an organization.
Section 19: Secure Configurations for Hardware and Software
Weight:
-
The candidate will be familiar with the processes and tools organizations use to track/control/prevent/correct security weaknesses in the configurations of the hardware and software of devices based on a formal configuration management and change control process.
Section 20: Secure Configurations for Network Devices
Weight:
-
The candidate will be familiar with processes and tools used to track/control/prevent/correct security weaknesses in the configurations in network devices based on formal configuration management and change controls processes.
Info