Group Purchasing
Group Purchasing

What Is the GCDA Certification?

The GIAC Certified Detection Analyst (GCDA) certification validates a practitioner's aptitude in using SIEM tools and techniques. GCDA holders understand how to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity.

By the numbers

2 hrs

Exam duration

75

Questions

76%

Min. passing score

What GCDA Covers

GIAC publishes nine exam objectives for GCDA, and they group into five practical domains.

SIEM and Log Foundations

SIEM Overview and Log Collection and Enrichment cover the purpose and value of SIEM systems, common log types, and collection strategies.

Network and Endpoint Analytics

Application Protocol Analytics and Endpoint Analytics cover common protocols and host-specific logs and how each can be used for detection.

Assets, Baselines, and Users

Asset and Network Analytics and Application and User Monitoring Analytics cover asset discovery, the value of flow logs, and application and user baselines.

Cloud Logging and Monitoring

Azure and AWS Logging Overview and Defender and Sentinel Overview cover cloud-native logging in both platforms and Azure-native tools for enriching logs and responding to alerts.

Alerting and Analysis

Log Analysis and Alerting covers common approaches to aggregating and analyzing log data.

Prepare With This Course

SEC555: Detection Engineering and SIEM Analytics

How SEC555 Prepares You for GCDA

SEC555 aligns with the exam objectives that make up the GCDA certification:

  • Section 1, Detection Engineering and SIEM Architecture builds skills tested under SIEM Overview and Log Collection and Enrichment.
  • Section 2, Network and Endpoint Analytics aligns with Application Protocol Analytics and Endpoint Analytics.
  • Section 3, Asset Discovery, Baselines and UEBA builds skills tested under Asset and Network Analytics and Application and User Monitoring Analytics.
  • Section 4, Cloud Logging and Monitoring aligns with Azure and AWS Logging Overview and Defender and Sentinel Overview.
  • Section 5, Alerting and Detection Engineering Pipelines builds skills tested under Log Analysis and Alerting.

Across all five sections, 18 hands-on labs and a team-based Defend-the-Flag capstone challenge give you the chance to apply each skill in virtual machine and cloud lab environments before you sit the exam.

Read the full GCDA certification overview.

SEC555 Course Author

Nick Mitropoulos
Nick Mitropoulos

Nick Mitropoulos

CEO at Scarlet Dragonfly

Nick Mitropoulos is a SANS Certified Instructor and author of SEC555: Detection Engineering and SIEM Analytics. As CEO of Scarlet Dragonfly and a veteran of SOC and incident response leadership, he equips students with real-world skills in detection engineering. Nick also serves on the GIAC Advisory Board, SANS CISO Network, and faculty of the SANS Technology Institute.

Read more about Nick Mitropoulos

Who Should Pursue GCDA

SOC Analysts, Engineers, and Managers

Security Analysts, Engineers, and Architects

Detection Engineers and Detection Analysts

Threat Hunters and Cyber Threat Investigators

Technical Security Managers and Security Monitoring Specialists

System Administrators and CND Analysts

Frequently Asked Questions

The GIAC Certified Detection Analyst (GCDA) certification validates a practitioner's aptitude in using SIEM tools and techniques. Holders understand how to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity.

The GCDA exam is one proctored exam with 75 questions and a two-hour time limit. The minimum passing score is 76% for candidates who receive the exam version released on or after April 27, 2026. GIAC periodically reviews exam specifications, so check your GIAC account for the details that apply to your attempt.

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GCDA fits SOC analysts, engineers, and managers; security analysts, engineers, and architects; detection engineers and detection analysts; threat hunters and cyber threat investigators; technical security managers and security monitoring specialists; and system administrators and CND analysts.

SEC555: Detection Engineering and SIEM Analytics provides great training if you're thinking of pursuing GCDA. The course includes 18 hands-on labs run on Windows Server 2022, Slingshot, and Ubuntu 24.04 virtual machines plus Azure and AWS cloud labs, and it ends with a team-based Defend-the-Flag challenge. Practical work experience can also build the skills GIAC tests.

SANS Institute is a training organization. GIAC LLC is an independent certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012. Completion of SANS training is not required for GIAC certification, nor does it guarantee a passing exam result.

Ready to earn your GCDA certification?

Add the GCDA exam attempt when you register for SEC555.

Already trained? Register for the exam directly through GIAC, here.