- The GCFE certification-objective list is organized into 10 named domains covering browsers, email, logs, and user artifacts.
- The exam is 82 questions, 3 hours, 70% to pass, with CyberLive hands-on tasks mixed into multiple-choice items.
- Exam-only registration costs $999; the associated SANS course is FOR500: Windows Forensic Analysis, purchased separately.
- The exam is open book, but internet access and practice-question collections are prohibited during the attempt.
GCFE Exam Structure Overview
The GIAC Certified Forensic Examiner (GCFE) credential is built around a published set of certification objectives that GIAC groups into 10 distinct content areas. Unlike vague "study everything" guidance, GIAC's domain structure tells candidates precisely what categories of forensic knowledge the exam engine draws questions from. Understanding those 10 areas - not just skimming a syllabus - is the difference between studying broadly and studying with a map.
The exam itself is a single web-based, proctored assessment: 82 questions delivered in a 3-hour window, combining traditional multiple-choice items with hands-on CyberLive virtual-machine tasks where you actually manipulate forensic artifacts inside a live environment rather than just answering about them abstractly. A minimum score of 70% is required to pass. For a full breakdown of how that scoring threshold works in practice, see our dedicated piece on the GCFE passing score.
The 10 GCFE Content Areas
GIAC's published objectives for the GIAC Certified Forensic Examiner exam are organized into these 10 domains:
- Browser Forensic Artifacts
- Browser Structure and Analysis
- Cloud Storage Analysis
- Digital Forensic Fundamentals
- Email Analysis
- Event Log Analysis
- File and Program Analysis
- Forensic Artifact Techniques
- System and Device Analysis
- User Artifact Analysis
Notice that browsers get two dedicated domains and artifacts/techniques show up in multiple places under different framing - that repetition is a signal about how central browser and general artifact analysis are to real forensic casework, and by extension to the exam. If you want a condensed one-page version of this list to keep on your desk during final review, our GCFE cheat sheet distills each domain into quick-reference bullets.
Domain-by-Domain Breakdown
Below is what each domain actually demands from a candidate, based on the skill area it represents rather than generic forensic trivia.
Domain 1: Browser Forensic Artifacts
Covers what evidence browsers leave behind - history entries, downloads, cached content, session data, and cookies - and how an examiner recovers and interprets that evidence during an investigation.
- Recognize artifact types across different browser evidence stores
- Interpret timestamps and activity sequences tied to browsing sessions
Domain 2: Browser Structure and Analysis
Distinct from Domain 1, this focuses on the underlying structure of browser data - how databases and file formats are organized internally - and the analytical process for parsing them correctly.
- Understand how browser data is physically stored and structured
- Apply correct analysis methodology rather than relying on a single tool's output
Domain 3: Cloud Storage Analysis
Addresses evidence tied to cloud-synced storage services, including how local artifacts reflect cloud activity and what an examiner can and cannot conclude from local evidence alone.
- Identify local traces left by cloud sync clients
- Distinguish local artifact evidence from cloud-side data limitations
Domain 4: Digital Forensic Fundamentals
The foundational domain - core forensic principles, methodology, and terminology that underpin every other domain on the exam.
- Understand chain-of-custody and evidence-handling concepts
- Know foundational terminology used consistently across the other nine domains
Domain 5: Email Analysis
Covers examination of email artifacts, message stores, headers, and related metadata used to reconstruct communication activity.
- Interpret email header and metadata fields
- Recognize common email storage formats and how to extract data from them
Domain 6: Event Log Analysis
Focuses on system and application event logs as a timeline-building resource, including how to correlate log entries with other artifact evidence.
- Read and interpret event log structure and entry types
- Correlate log timestamps with other artifacts to build an activity timeline
Domain 7: File and Program Analysis
Examines evidence of file usage and program execution - what ran, when, and how that activity is recorded on the system.
- Identify artifacts showing program execution history
- Interpret file metadata related to access and modification activity
Domain 8: Forensic Artifact Techniques
A methods-focused domain covering the techniques examiners apply across artifact types generally, rather than one specific artifact category.
- Apply consistent extraction and interpretation techniques across evidence types
- Understand technique limitations and when supplemental analysis is needed
Domain 9: System and Device Analysis
Covers system-level and device-level evidence, including configuration artifacts and information tied to devices connected to or used with the system under examination.
- Identify system configuration artifacts relevant to an investigation
- Recognize evidence of device connections and usage history
Domain 10: User Artifact Analysis
Focuses on artifacts tied specifically to user activity - profile data, recently accessed items, and other user-context evidence used to attribute actions to a specific user account.
- Interpret user-profile artifacts and recent-activity indicators
- Connect user-specific evidence to broader case timelines
How Domains Translate to Exam Questions
GIAC does not publish a fixed percentage weight for each of the 10 domains on the public certification page, and your candidate account is the source that identifies the attempt-specific exam specifications for your registered attempt. What this means practically: don't chase a leaked "weighting chart" from a forum. Instead, treat all 10 domains as fair game and prioritize depth over guessing which one is "worth more." For a broader discussion of how difficult candidates typically find this spread of material, read How Hard Is the GCFE Exam?
Key Takeaway
Because the candidate portal - not third-party blogs - identifies your specific exam specifications, always verify current domain details against your own account rather than assuming a fixed public breakdown.
| Domain Cluster | What It Tests | Practical Study Focus |
|---|---|---|
| Browser (Domains 1-2) | Browser artifacts and underlying data structure | Practice parsing browser databases, not just reading tool summaries |
| Communication & Cloud (3, 5) | Email and cloud-sync evidence | Study header formats and cloud client sync artifacts side by side |
| System Activity (6, 7, 9) | Logs, program execution, device/system artifacts | Build timelines correlating logs with execution and device evidence |
| Methodology (4, 8, 10) | Fundamentals, general techniques, user attribution | Anchor every artifact type back to sound forensic methodology |
Mapping a Study Schedule to the Domains
A generic study calendar won't help much here - what matters is sequencing the 10 domains so foundational material comes first and artifact-heavy material gets the most repetition. Below is one way to structure preparation time around the GCFE domain list specifically, rather than a one-size-fits-all template.
Foundations First
- Work through Digital Forensic Fundamentals before anything artifact-specific
- Build a personal glossary of terminology used across the other nine domains
Browsers and Communication
- Pair Browser Forensic Artifacts with Browser Structure and Analysis in the same study block
- Move into Email Analysis and Cloud Storage Analysis while browser concepts are fresh
System-Level Evidence
- Practice Event Log Analysis alongside File and Program Analysis to build timeline correlation skills
- Layer in System and Device Analysis for connected-device and configuration artifacts
Techniques and User Attribution, Then Review
- Cover Forensic Artifact Techniques and User Artifact Analysis last, since both draw on everything before them
- Take the official practice test and revisit weak domains using open-book index tabs
For a more detailed week-by-week plan with resource recommendations, our GCFE Study Guide expands on this sequencing with specific practice recommendations tied to the FOR500 course material.
Who Hires for GCFE-Validated Skills
The 10 domains above map closely to day-to-day work performed by digital forensic examiners, incident response analysts, and law enforcement digital evidence specialists - roles where browser history, email records, event logs, and user-attribution artifacts routinely become case evidence. Because the associated training is SANS FOR500: Windows Forensic Analysis, the certification is closely tied to Windows-endpoint investigation work specifically, which shows up in corporate incident response teams, government forensic labs, and consulting firms handling breach investigations.
If you're evaluating whether this specialization fits your career path, our guides on GCFE jobs and GCFE salary expectations go into more depth on typical employers and compensation considerations. And if you're still weighing whether the investment makes sense against alternatives, Is the GCFE Certification Worth It? walks through the return-on-investment question directly.
Registration, Format, and Retake Mechanics
Beyond content, several mechanical details affect how you prepare for and take the exam:
- Delivery: ProctorU remote proctoring or Pearson VUE test centers, depending on what's authorized for your registered attempt.
- Time limit: Complete the attempt within 120 days of activation.
- Open-book rules: Hardcopy books, printed notes, and an index are allowed; internet access, personal electronic devices, and practice-question or answer collections are prohibited.
- Answer behavior: Submitted answers cannot be changed once locked in, but skipped questions can be revisited before finishing.
- Tools provided: A calculator and scratch notepad are built into the exam engine.
- Cost: $999 for the exam-only attempt; $899 for a retake; $399 for the standalone official practice test; $479 for an attempt extension. Training is purchased separately.
- Failed-attempt wait: A 30-day waiting period applies before a retake.
- Validity and renewal: Certification lasts 4 years, renewable via 36 CPEs plus a $499 renewal fee, or through a renewal examination route.
For a complete cost breakdown across all these line items, see GCFE Certification Cost 2026, and for eligibility and prerequisite details, check GCFE Requirements. Scheduling logistics and testing windows are covered separately in GCFE Exam Dates 2026.
Before committing to a test date, it's worth running through practice scenarios that mirror the CyberLive format on our practice test platform, since reading about artifact analysis and actually performing it inside a virtual machine are different skills entirely. Pairing that hands-on practice with a general understanding of what GCFE certification signals to employers helps frame why the domain list is structured the way it is - every domain reflects a task a working examiner actually performs, not an academic checkbox.
Frequently Asked Questions
GIAC organizes its published certification objectives for the GIAC Certified Forensic Examiner into 10 domains, ranging from Digital Forensic Fundamentals to User Artifact Analysis.
The public certification page lists the 10 domain headings, but attempt-specific exam specifications are identified through your candidate account, so always confirm current details there rather than relying on assumed percentages.
Since the associated training is SANS FOR500: Windows Forensic Analysis, domains like Browser Forensic Artifacts, Event Log Analysis, File and Program Analysis, and System and Device Analysis align closely with that course's Windows-endpoint focus.
Yes, the exam is open book with hardcopy books, printed notes, and an index permitted, but internet access, personal electronic references, and practice-question or answer collections are not allowed.
A failed attempt requires a 30-day waiting period before retaking, and the retake fee is $899, separate from the original $999 exam-only registration.