SEC536: Adversarial AI - Penetration Testing AI Systems


The GCIL certification proves you can manage a cyber incident from declaration to closure and lead a mixed incident management team back to normal operations. GCIL holders show they can prepare for, assess, handle, track, and document incidents, develop and improve the incident management team and process, and identify and respond to the specific incident types (cloud, email, credential, ransomware, and supply chain attacks) that make up the bulk of major incidents.
The GCIL exam is one proctored exam with 75 questions over 2 hours, with a minimum passing score of 70%. GIAC periodically reviews exam specifications, so confirm the current format in your GIAC account before you sit the exam.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GCIL is built for security professionals responsible for managing incidents, incident managers, security and information security managers and team leads, SOC managers, IR team leads, compliance and privacy officers, CISOs and information security officers, and legal, HR, PR, and communications staff who need to know what will be expected of them once an incident is declared. It also fits newly appointed security officers and technically skilled staff who've recently been given incident commander responsibilities.
LDR553: Cyber Incident Management is the SANS course built to prepare you for the GCIL exam. It's a 5-day, 30-hour course, available in-person, live virtual, or OnDemand self-paced, built around a single continuous incident scenario that maps directly to the certification's exam objectives across its five sections. LDR553: Cyber Incident Management