Group Purchasing
Group Purchasing

What Is the GSEC Certification?

The GIAC Security Essentials (GSEC) certification validates a practitioner’s understanding of information security beyond terminology and concepts. Holders demonstrate they are qualified for hands-on IT systems roles addressing security tasks.

By the numbers

4 hrs

Exam duration

106

Questions

72%

Min. passing score

What GSEC Covers

The certification’s 26 published objectives group into six practical domains, matching SEC401’s own section structure.

Network Security and Cloud Essentials

Defensible Network Architecture, Networking and Protocols, Virtualization/Cloud/AI Essentials, Wireless Network Security.

Defense in Depth

Defense in Depth, Access Control and Password Management, Security Frameworks and CIS Controls, Data Loss Prevention and Mobile Device Security.

Vulnerability Management and Response

Vulnerability Scanning and Penetration Testing, Malicious Code and Exploit Mitigation, Web Communication Security, Log Management and SIEM, Incident Handling and Response.

Data Security Technologies

Cryptography, Cryptography Application, Network Security Devices, Endpoint Security.

Windows and Azure Security

indows Security Infrastructure, Windows as a Service, Windows Access Controls, Enforcing Windows Security Policy, Windows Automation/Auditing/Forensics, Windows Services and Microsoft Cloud.

Containers, Linux, and Mac Security

Linux Fundamentals, Linux Security and Hardening, Container and MacOS Security.

Prepare With This Course

SEC401: Security Essentials

How SEC401 Prepares You for GSEC

SEC401 is built around the exam objectives that make up the GSEC certification:

  • Section 1, Network Security and Cloud Essentials builds skills tested under Defensible Network Architecture, Networking and Protocols, Virtualization/Cloud Security and AI Essentials, and Wireless Network Security. 
  • Section 2, Defense in Depth aligns with Defense in Depth, Access Control and Password Management, Security Frameworks and CIS Controls, and Data Loss Prevention and Mobile Device Security. 
  • Section 3, Vulnerability Management and Response aligns with Vulnerability Scanning and Penetration Testing, Malicious Code and Exploit Mitigation, Web Communication Security, Log Management and SIEM, and Incident Handling and Response. 
  • Section 4, Data Security Technologies aligns with Cryptography, Cryptography Application, Network Security Devices, and Endpoint Security. 
  • Section 5, Windows and Azure Security aligns with Windows Security Infrastructure, Windows as a Service, Windows Access Controls, Enforcing Windows Security Policy, Windows Automation/Auditing/Forensics, and Windows Services and Microsoft Cloud. 
  • Section 6, Containers, Linux, and Mac Security aligns with Linux Fundamentals, Linux Security and Hardening, and Container and MacOS Security.

Across all six sections, 20 hands-on labs and four continuous compromise scenarios at a fictitious organization called Alpha Incorporated give you the chance to apply each skill before you sit the exam. 

Read the full GSEC certification overview here.

SEC401 Author

Bryan Simon
Bryan Simon

Bryan Simon

CEO at Xploit Security Inc.

Bryan is a SANS Senior Instructor and author of SEC401. With 30+ years of cybersecurity experience and 22 GIAC certifications—including the prestigious GSE—he's trained professionals from the FBI, NATO, and the UN. He is the CEO of Xploit Security Inc.

Read more about Bryan Simon

Who It's For

Security Engineers, Analysts, and Administrators

Security Managers and Team Leads

IT Engineers and Supervisors Moving into Security

Auditors and Operations Personnel

Forensic Analysts and Penetration Testers

Frequently Asked Questions

The GIAC Security Essentials (GSEC) certification validates a practitioner's understanding of information security beyond terminology and concepts. Holders demonstrate they are qualified for hands-on IT systems roles addressing security tasks.

The GSEC exam is a single proctored attempt, 106 questions, with a 4-hour time limit and a minimum passing score of 72%.

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC's renewal page

GSEC is designed for security engineers, analysts, and administrators, security managers and team leads, IT engineers and supervisors moving into security, auditors and operations personnel, and forensic analysts and penetration testers.

SEC401: Security Essentials is built around GSEC's exam objectives, with 20 hands-on labs and four continuous compromise scenarios built around a fictitious organization, Alpha Incorporated.

Ready to earn your GSEC certification?

Add the GSEC exam attempt when you register for SEC401

Already trained? Register for the exam directly through GIAC here.