SEC536: Adversarial AI - Penetration Testing AI Systems


The GNFA certification confirms that you can carry out advanced analysis of network forensic artifacts. GIAC's own certification page names the practitioners it targets, including incident response team members, forensic analysts, threat hunters, SOC personnel, and network defenders, all of whom need to read normal and abnormal network activity and analyze it through logs, packet captures, and network metadata.
The GNFA exam is a single proctored test with 66 questions, a 3 hour time limit, and a minimum passing score of 70%. GIAC administers it through its CyberLive testing environment. Because GIAC periodically reviews exam specifications, confirm the current format in the Certification Information section of your GIAC account before your attempt.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GNFA is built for incident response team members and forensicators expanding their scope from endpoints to the network, threat hunters and SOC analysts, law enforcement officers and federal investigators, network defenders and engineers taking on more investigative work, and information security managers who need to understand network forensics to manage risk and lead their teams. GIAC's own audience language and FOR572's Who Should Attend list point to largely the same group.
FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response is the SANS course built for GNFA. Across six sections, it covers network evidence acquisition, protocol and log analysis, NetFlow, encryption, and protocol reverse engineering, backed by 20 hands-on labs and a capstone case built entirely on network evidence. Explore FOR572.