Skip to main content

GIAC Defending Advanced Threats (GDAT)

Practitioner Certification
GIAC Defending Advanced Threats (GDAT)
dod_8140

Convey proficiency across the full picture of offensive and defensive security with the ability to prevent, detect, and respond to traditional and APT-style attacks.

The GIAC Defending Advanced Threats (GDAT) certification validates a practitioner’s command of both offensive and defensive domains in depth. GDAT certification holders are prepared to improve the IT environment to better prevent, detect, and respond to incidents, leveraging a thorough understanding of how advanced cyber adversaries operate.

Areas Covered

  • Understanding advanced persistent threat models and methods
  • Detecting and preventing payload deliveries, exploitation, and post-exploitation activities
  • Using cyber deception to gain intelligence for threat hunting and incident response
  • Conducting adversary emulation

Who is GDAT for?

  • All blue team personnel
  • All red team personnel
  • All purple team personnel
  • Security architects
  • IT administrators

Instructor Testimonial

The GDAT certification is unique in how it covers both offensive and defensive security topics in-depth. Holders of the GDAT certification have demonstrated advanced knowledge of how adversaries are penetrating networks, but also what security controls are effective to stop them. Next to knowing what controls are instrumental to prevent recent attacks, certified GDAT professionals know that prevent-only is not feasible and thus know how to detect and respond to attacks. Combining all these skills, they have the ability to prevent, detect, and respond to both traditional and APT-style attacks!

Erik Van BuggenhoutCourse Author, SANS SEC599

Exam Format

  • 1 proctored exam
  • 2 hours
  • Minimum passing score of 70%
  • 75 questions

Note: GIAC periodically reviews and may update certification specifications to ensure fairness, validity, and reliability. Using a psychometric standard-setting study, GIAC has set the passing score for the GDAT exam at 70% for all candidates who receive the exam version released on or after October 1, 2018.

To confirm the exam format and passing score that apply to your specific attempt, please refer to the Certification Information section of your GIAC account: https://exams.giac.org/pages/attempts.

Certification Delivery

GIAC certification attempts will be activated in your GIAC account after your application has been approved and according to the terms of your purchase. Details on delivery will be provided along with your registration confirmation upon payment. You will receive an email notification when your certification attempt has been activated in your account. You will have 120 days from the date of activation to complete your certification attempt.

NOTE: All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE. Click here for more information.

Woman Staring at Tablet

Exam Certification Objectives & Outcome Statements

  • Active Directory/DomainsThe candidate will demonstrate knowledge of the following domain topics as they relate to information security: authentication basics, Kerberos, common attacks against domains, and detecting attacks against domains.
  • Administrative AccessThe candidate will exhibit a proficiency in topics related to the impacts of privilege escalation, and the importance of concepts related to "least privilege" methodologies.
  • Adversary EmulationThe candidate will demonstrate knowledge of the following adversary emulation topics: basic concepts, common tools used, and key technical controls to consider.
  • Application ExploitationThe candidate will be able to summarize how; combining the software development lifecycle with threat modeling, employing proper patch management strategies, and other exploit mitigation techniques can improve the security of an organization against application exploitation.
  • Data ExfiltrationThe candidate will be able to compare and contrast common exfil strategies, summarize strategies for detecting C2 channels, and discuss pros and cons of performing deception techniques as a possible attack target.
  • InstallationThe candidate will be able to compare and contrast common persistence strategies and how organizations can be protected against them.
  • Lateral MovementThe candidate will be able to appraise different lateral movement strategies, as well as strategies and controls for detecting and preventing the successful execution of malicious payloads.
  • Payload DeliveryThe candidate will be able to appraise different payload delivery strategies, as well as strategies and controls focused on minimizing the likelihood of the successful delivery of malicious payloads.
  • Payload ExecutionThe candidate will be able to appraise different payload execution strategies, as well as strategies and controls for detecting and preventing the successful execution of malicious payloads.
  • Reconnaissance, Threat Handling, and Incident ResponseThe candidate will exhibit a proficiency in the following exploitation topics: fundamental reconnaissance, threat hunting strategies, and the incident response process.

Practice Tests

  • Practice exams are a simulation of the real exam, allowing you to become familiar with the test engine and style of questions
  • Practice exams can serve as a gauge to determine if your preparation methods are sufficient
  • The bank of practice questions is limited, so you may encounter the same question on multiple practice tests
  • Practice exams never include actual exam questions
  • Purchase a GDAT practice test here

How To Prepare

Other Resources

  • Training is available  in a variety of modalities including live training and OnDemand
  • Practical work experience can help ensure that you have mastered the skills necessary for certification
  • College level courses or self-paced study through other programs or materials may meet the needs for mastery
  • Understand the procedure to contest exam results

Find Affiliate Training

Explore affiliate training options to prepare for your GIAC certification exam.

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.