GCCC logo
Focused certification exam prep
Start practice

GCCC Exam Domains 2026: Complete Guide to All 19 Content Areas

TL;DR
  • GCCC covers 19 objectives: the 18 CIS Controls v8 plus a governance/background domain.
  • The exam has 75 questions, a 2-hour limit, and requires a 71% score to pass.
  • Domain 5 (background, standards, governance) underpins terminology used across all other 18 domains.
  • Open-book rules allow hardcopy references only - no electronic files or internet access.

Overview: Why 19 Domains Instead of 18 Controls

If you've looked at the CIS Critical Security Controls framework before, you already know it has 18 controls in version 8. So why does GIAC list 19 certification objectives for the GCCC exam? The answer is Domain 5: Background on CIS Controls, Standards, and Governance. This extra domain doesn't map to a specific technical control - instead it covers the history, structure, and governance model behind the CIS Controls themselves, including how the controls relate to other frameworks and how implementation groups (IG1, IG2, IG3) are defined.

This matters more than it might seem. Questions from Domain 5 tend to show up as framing questions elsewhere in the exam - you can't correctly answer a scenario about Data Protection or Audit Log Management if you don't understand how CIS structures safeguards versus sub-controls. For a full walkthrough of how difficult this combination of governance theory and technical control detail actually is in practice, see our GCCC exam difficulty guide.

Fast Fact: The GCCC exam is explicitly aligned with CIS Controls v8, not v7 or v7.1. If your study material references "Basic," "Foundational," and "Organizational" control categories from older versions, you're using outdated terminology.

The 19 GCCC Domains Explained

Below is a working breakdown of each domain as it appears on the GIAC objectives outline. Treat this as your master checklist - cross-reference it against whatever GCCC study guide or course material you're using to make sure nothing is skipped.

Domain 1: Access Control Management

Focuses on how organizations grant, track, and revoke access to enterprise assets and data based on need-to-know and least privilege.

  • Difference between access control lists, role-based access, and attribute-based access

Domain 2: Account Management

Covers the lifecycle of user and administrator accounts, from provisioning to deactivation, plus dedicated admin accounts.

  • Centralized account inventory and disabling dormant accounts

Domain 3: Application Software Security

Deals with secure development lifecycle practices, application vulnerability management, and vendor-supplied software risk.

  • WAF deployment and separating production from test environments

Domain 4: Audit Log Management

Tests knowledge of log collection, retention, and correlation practices needed to detect and investigate incidents.

  • Centralized log collection and time synchronization across assets

Domain 5: Background on CIS Controls, Standards, and Governance

Establishes the conceptual foundation - implementation groups, safeguard structure, and how CIS Controls relate to other compliance frameworks.

  • IG1/IG2/IG3 prioritization logic

Domain 6: Continuous Vulnerability Management

Covers scanning cadence, remediation timelines, and risk-based prioritization of discovered vulnerabilities.

  • Automated vs. manual vulnerability scanning tradeoffs

Domain 7: Data Protection

Addresses data classification, encryption at rest and in transit, and data loss prevention controls.

  • Data inventory and classification schemas

Domain 8: Data Recovery

Focuses on backup strategy, recovery testing, and protecting backup data from ransomware and tampering.

  • Isolated/offline backup requirements

Domain 9: Email and Web Browser Protections

Tests understanding of anti-phishing controls, browser hardening, and email filtering technologies like DMARC.

  • Disabling unnecessary browser/email plugins

Domain 10: Incident Response Management

Covers IR planning, roles, communication procedures, and post-incident review processes.

  • Tabletop exercises and IR plan maintenance cadence

Domain 11: Inventory and Control of Enterprise Assets

Deals with maintaining an accurate, continuously updated inventory of all hardware connected to the network.

  • DHCP logging and active discovery tools

Domain 12: Inventory and Control of Software Assets

Parallel to Domain 11 but for software - tracking authorized/unauthorized applications and removing unsupported software.

  • Allowlisting vs. blocklisting approaches

Domain 13: Malware Defenses

Covers anti-malware tooling, centralized management, and behavioral detection versus signature-based detection.

  • Disabling autorun and autoplay on removable media

Domain 14: Network Infrastructure Management

Focuses on secure network device configuration, architecture documentation, and remote access security.

  • Network segmentation principles

Domain 15: Network Monitoring and Defense

Distinct from Domain 4/14 - this covers active monitoring tools, intrusion detection, and traffic filtering.

  • Difference between IDS and IPS deployment models

Domain 16: Penetration Testing

Tests knowledge of pen test scoping, remediation validation, and how testing integrates with vulnerability management.

  • Purple team exercises vs. traditional red/blue testing

Domain 17: Secure Configuration of Enterprise Assets and Software

One of the densest domains - covers baseline configurations, hardening standards, and configuration drift management.

  • Automated configuration management tools

Domain 18: Security Awareness and Skills Training

Covers building a security culture, role-specific training, and measuring training effectiveness.

  • Phishing simulation programs

Domain 19: Service Provider Management

Addresses third-party risk, vendor inventory, and contractual security requirements for outsourced services.

  • Classifying service providers by data sensitivity handled

How Domain Weighting Actually Works on the Exam

GIAC does not publish an official percentage breakdown per domain for the GCCC, and you should be skeptical of any resource that claims exact weighting numbers - those figures aren't part of GIAC's published cert facts. What you can rely on is the structural reality of the exam: 75 questions across 19 domains means, mathematically, some domains will appear more than others, and larger controls (like Domain 17's configuration management or Domain 11's asset inventory) tend to have more testable sub-points simply because CIS itself allocates more safeguards to them.

Rather than chase unofficial weighting rumors, focus on depth of understanding across every domain. The GCCC passing score of 71% means you have some margin for missed questions, but with only 75 items total, each question carries real weight - you can't afford to blank out on an entire domain.

Key Takeaway

Don't try to guess which domains are "worth more." Build competence across all 19 - a domain you dismiss as minor could still cost you the 2-3 questions that separate a pass from a retake.

Mapping a Study Schedule to the Domains

Generic study techniques only go so far here - what matters is sequencing your review around how the domains relate to each other. Domain 5's governance concepts should come first because they establish vocabulary used throughout the other 18 domains. From there, group related domains together: asset and software inventory (11, 12) pair naturally with secure configuration (17) and vulnerability management (6), while access control (1), account management (2), and malware defenses (13) form another logical cluster around endpoint protection.

Week 1

Foundation and Asset Domains

  • Domain 5 governance concepts
  • Domains 11 & 12 (asset/software inventory)
  • Domain 17 secure configuration basics
Week 2

Identity and Endpoint Domains

  • Domains 1 & 2 (access and account management)
  • Domain 13 malware defenses
  • Domain 6 vulnerability management
Week 3

Data, Network, and Detection Domains

  • Domains 7 & 8 (data protection and recovery)
  • Domains 14 & 15 (network management and monitoring)
  • Domain 4 audit log management
Week 4

Process and People Domains

  • Domains 9, 10, 16, 18, 19
  • Full-length practice exam review
  • Weak-domain drilling

For a deeper walkthrough of pacing this across a full prep cycle, including how to layer in official GIAC index-building time, see the complete GCCC study guide. And if you want a compact reference you can flip through during final review, our GCCC cheat sheet condenses all 19 domains into one page.

Exam Format, Fees, and Logistics

Understanding the domains only matters if you also understand the mechanics of sitting the exam. The GCCC is a 75-question, 2-hour exam with a 71% passing score, and it's open book for hardcopy materials only - electronic files, internet access, and anything resembling actual exam questions are prohibited during the test. This is a detail candidates frequently get wrong, assuming "open book" means any format of notes.

ItemDetail
Certification attempt fee$999
Retake fee$899
GIAC practice exam$399
Question count75
Time limit2 hours
Passing score71%
Attempt window120 days
DeliveryProctorU (remote) or Pearson VUE (onsite)
Certification validity4 years
Renewal36 CPEs or retake exam, plus $499 fee

For a full cost breakdown including how the renewal fee and retake economics factor into total cost of ownership, read our GCCC certification cost guide. If you're still deciding whether the investment makes sense given your career goals, the GCCC ROI analysis walks through that decision in detail. You can also check current GCCC exam dates and scheduling windows before registering.

Registration Tip: Your 120-day attempt window starts when you register, not when you feel "ready." Map your domain study schedule to this window before you pay, so you're not rushing through Domains 16-19 in the final week.

Who Actually Tests on These Domains

The GCCC isn't a generic security credential - it's built specifically for roles that implement, audit, or manage CIS Controls-based programs. That includes security control assessors, compliance analysts, systems administrators moving into security operations, and auditors who need to speak fluently about safeguards across all 19 domains covered here. Understanding this context matters when you're deciding how deep to go on domains like Service Provider Management or Security Awareness and Skills Training, which are process-heavy rather than technically deep.

If you're researching whether this aligns with your career path, our guides on GCCC jobs and the GCCC salary guide break down where this credential tends to open doors. For broader context on the credential itself - including how it fits alongside other GIAC certifications - see What Is GCCC Certification? and our overview of the GCCC Certification generally.

Before you commit to a registration date, it's worth confirming you meet any organizational prerequisites your employer may require - see GCCC requirements and eligibility for details, since GIAC itself has no formal prerequisite beyond payment and scheduling.

A Note on Practice Testing

Reading domain descriptions is not the same as answering scenario-based questions under time pressure. Working through realistic practice questions on our GCCC practice test platform is the fastest way to find out which of the 19 domains you're actually weak on, versus which ones you only think you understand.

It's worth repeating: the domain list itself is not a study plan, it's a map. Many candidates read through all 19 objectives, feel confident, and then discover during timed practice on the practice exam site that specific safeguards within Domains 6, 15, and 17 trip them up because those domains blend technical detail with governance language from Domain 5. Running full-length timed sets before exam day - not just reading - is what actually surfaces those gaps.

Frequently Asked Questions

How many domains does the GCCC exam cover?

The GCCC covers 19 certification objectives: the 18 CIS Critical Security Controls (v8) plus one background domain on CIS Controls history, standards, and governance.

Does GIAC publish official percentage weighting for each domain?

No. GIAC does not publish an official per-domain scoring breakdown for the GCCC. Candidates should prepare across all 19 domains rather than rely on unofficial weighting claims.

Which domain should I study first?

Domain 5 (Background on CIS Controls, Standards, and Governance) is a strong starting point because it introduces terminology and structural concepts referenced throughout the other 18 domains.

Can I bring notes into the GCCC exam to reference during domain-specific questions?

Yes, the GCCC is open book for hardcopy references only. Electronic files, internet access, and any materials resembling actual exam questions are not permitted.

Do all 19 domains carry equal difficulty?

Not necessarily in terms of question count, but each domain requires genuine understanding. Domains like Secure Configuration of Enterprise Assets and Software and Network Monitoring and Defense tend to feel denser due to broader technical scope.

Ready to pass your GCCC exam?

Put this into practice with free GCCC questions across every exam domain.