GIAC Certified Detection Analyst assessment
Proctored objective assessment using multiple-choice, multiple-response, or scenario-based items as specified by the provider.
- Type
- Written
- Delivery
- Both
- Questions
- 75
Passing score: 76 Percentage
Exam sections
Application and User Monitoring Analytics
Application and User Monitoring Analytics covers the decisions practitioners make before, during, and after implementing or evaluating this capability. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
Within the Application and User Monitoring Analytics objectives, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because Application and User Monitoring Analytics is likely to interact with other responsibilities rather than remain an isolated fact set. Revisit the exercise if the explanation cannot distinguish Application and User Monitoring Analytics from a neighboring blueprint area.
Application Protocol Analytics
This section treats application protocol analytics as an applied responsibility, including the surrounding inputs, controls, trade-offs, and evidence of success. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
In the context of GIAC Certified Detection Analyst, the Application Protocol Analytics objectives indicate that this domain may be assessed independently or as part of a scenario crossing other blueprint areas. Pay attention to the wording that changes scope, responsibility, risk, or the best next action.
Preparation tips
Create a one-page model of how Application Protocol Analytics connects to the preceding and following domains. Use scenario questions to rehearse boundary decisions and identify when another specialist or control is needed. Revisit the exercise if the explanation cannot distinguish Application Protocol Analytics from a neighboring blueprint area.
Asset and Network Analytics
Here the emphasis is on applying asset and network analytics to realistic technical, operational, governance, legal, or business situations. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
For Asset and Network Analytics, the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Turn every major objective in Asset and Network Analytics into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. Revisit the exercise if the explanation cannot distinguish Asset and Network Analytics from a neighboring blueprint area.
Azure and AWS Logging Overview
The Azure and AWS Logging Overview domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
Within the Azure and AWS Logging Overview objectives, this domain may be assessed independently or as part of a scenario crossing other blueprint areas. Pay attention to the wording that changes scope, responsibility, risk, or the best next action.
Preparation tips
Create a one-page model of how Azure and AWS Logging Overview connects to the preceding and following domains. Use scenario questions to rehearse boundary decisions and identify when another specialist or control is needed. Use GIAC Certified Detection Analyst and the Azure and AWS Logging Overview heading as the boundary for deciding how deeply to pursue adjacent material.
Defender and Sentinel Overview
This section treats defender and sentinel overview as an applied responsibility, including the surrounding inputs, controls, trade-offs, and evidence of success. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
For Defender and Sentinel Overview, expect Defender and Sentinel Overview to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Turn every major objective in Defender and Sentinel Overview into a decision question. Explain the preferred option, the risk in the strongest alternative, and the observation or artifact that would verify success. Revisit the exercise if the explanation cannot distinguish Defender and Sentinel Overview from a neighboring blueprint area.
Endpoint Analytics
The Endpoint Analytics domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
Within the Endpoint Analytics objectives, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because Endpoint Analytics is likely to interact with other responsibilities rather than remain an isolated fact set. Revisit the exercise if the explanation cannot distinguish Endpoint Analytics from a neighboring blueprint area.
Log Analysis and Alerting
The Log Analysis and Alerting domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
When GIAC Certified Detection Analyst reaches Log Analysis and Alerting, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because Log Analysis and Alerting is likely to interact with other responsibilities rather than remain an isolated fact set. Revisit the exercise if the explanation cannot distinguish Log Analysis and Alerting from a neighboring blueprint area.
Log Collection and Enrichment
Questions or tasks in Log Collection and Enrichment explore more than terminology: candidates need to recognize appropriate methods, dependencies, and failure conditions. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
When GIAC Certified Detection Analyst reaches Log Collection and Enrichment, assessment items can test recognition of a sound approach, diagnosis of an incorrect one, or completion of a practical step. Treat official weighting separately from any unofficial study emphasis.
Preparation tips
Build a small practice set for log collection and enrichment: one normal workflow, one deliberately broken case, and one comparison between competing approaches. Record what evidence confirms the correct outcome. Revisit the exercise if the explanation cannot distinguish Log Collection and Enrichment from a neighboring blueprint area.
SIEM Overview
This area examines how candidates work with siem overview when requirements, constraints, and expected outcomes must be reconciled. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
A candidate working through SIEM Overview should remember that the section is modeled as a blueprint domain rather than a separately timed exam part. Its concepts can still influence questions or tasks elsewhere in the assessment.
Preparation tips
Practice siem overview in the environment or professional context the credential targets. After each exercise, explain the dependencies, likely failure signals, and safe recovery or escalation path. Use GIAC Certified Detection Analyst and the SIEM Overview heading as the boundary for deciding how deeply to pursue adjacent material.
