GIAC Open Source Intelligence Certification assessment
Proctored objective assessment using multiple-choice, multiple-response, or scenario-based items as specified by the provider.
- Type
- Written
- Delivery
- Both
- Questions
- 75
Passing score: 69 Percentage
Exam sections
Investigating Businesses
Investigating Businesses covers the decisions practitioners make before, during, and after implementing or evaluating this capability. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
Within the Investigating Businesses objectives, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Explain this domain aloud as if handing work to a colleague. Include prerequisites, common mistakes, security or governance implications, and how you would test that the result meets its objective. A final self-check should explain why Investigating Businesses matters to the candidate profile for this credential.
Investigating People
Questions or tasks in Investigating People explore more than terminology: candidates need to recognize appropriate methods, dependencies, and failure conditions. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
For Investigating People, prepare for applied interpretation: a familiar term may be embedded in a design, troubleshooting, governance, investigation, or implementation situation where several answers appear plausible.
Preparation tips
Practice investigating people in the environment or professional context the credential targets. After each exercise, explain the dependencies, likely failure signals, and safe recovery or escalation path. A final self-check should explain why Investigating People matters to the candidate profile for this credential.
Network Data and Infrastructure Analysis
The Network Data and Infrastructure Analysis domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
The blueprint's treatment of Network Data and Infrastructure Analysis indicates that the provider's outline defines the subject boundary, but individual items may combine it with neighboring domains. Read for constraints and desired outcomes before selecting or performing an action.
Preparation tips
Build a small practice set for network data and infrastructure analysis: one normal workflow, one deliberately broken case, and one comparison between competing approaches. Record what evidence confirms the correct outcome. A final self-check should explain why Network Data and Infrastructure Analysis matters to the candidate profile for this credential.
OSINT Methodology
The OSINT Methodology domain focuses on the concepts, actions, and judgment needed to use this part of the discipline effectively. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
In the context of GIAC Open Source Intelligence Certification, the OSINT Methodology objectives indicate that expect OSINT Methodology to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Alternate focused review with mixed-domain practice. The mixed sessions are important because OSINT Methodology is likely to interact with other responsibilities rather than remain an isolated fact set. A final self-check should explain why OSINT Methodology matters to the candidate profile for this credential.
Privacy and Operational Security Fundamentals
Within the wider assessment, Privacy and Operational Security Fundamentals tests whether a candidate can connect core principles with defensible execution and verification. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
For Privacy and Operational Security Fundamentals, expect Privacy and Operational Security Fundamentals to appear through choices, scenarios, or tasks that require application rather than simple recall. No section-specific question count or timing is assumed unless the provider publishes one.
Preparation tips
Explain this domain aloud as if handing work to a colleague. Include prerequisites, common mistakes, security or governance implications, and how you would test that the result meets its objective. Finish by relating Privacy and Operational Security Fundamentals to the credential's emphasis on Cyber Defense.
Searching, Collecting, and Processing Data
Questions or tasks in Searching, Collecting, and Processing Data explore more than terminology: candidates need to recognize appropriate methods, dependencies, and failure conditions. Candidates should understand its relationship to Cyber Defense and be able to explain how an outcome would be checked in practice.
Question notes
Within the Searching, Collecting, and Processing Data objectives, assessment items can test recognition of a sound approach, diagnosis of an incorrect one, or completion of a practical step. Treat official weighting separately from any unofficial study emphasis.
Preparation tips
Use official terminology as an index, then attach each term to an action, example, counterexample, and verification method. Revisit weak explanations until they no longer depend on memorized wording. Revisit the exercise if the explanation cannot distinguish Searching, Collecting, and Processing Data from a neighboring blueprint area.
