The GCIH exam is structured around four primary domains that encompass essential skills needed for incident handling. The first domain, Preparation and Planning (20%), focuses on strategizing for potential incidents, including establishing response plans and defining roles.
The second domain, Detection and Analysis (30%), covers identifying incidents through various means, such as log analysis and alerts from security tools. The third domain, Containment, Eradication, and Recovery (30%), emphasizes actions taken to limit damage, remove threats, and restore systems. Lastly, the Post-Incident Activity domain (20%) involves reviewing incidents to learn and improve future response efforts. Mastery of these topics is crucial for incident handling professionals.