- GIAC publishes 18 GSLC objectives with no percentage weights, so no single domain is "safe to skip."
- The exam is 115 questions in 3 hours, requiring 70% to pass, with a 120-day attempt window.
- GSLC is open book for printed materials only - no electronic resources or internet access allowed.
- Domains span management topics (policy, projects, vendors) and technical topics (crypto, cloud, AI, networking).
GSLC Exam Overview: What You're Actually Facing
The GIAC Security Leadership Certification (GSLC) is unusual among GIAC credentials because it deliberately straddles management and technical territory. Instead of drilling deep into one discipline, GSLC spreads 18 objectives across cryptography, cloud, AI, networking, incident response, and program management. That breadth is the whole point: GSLC exists to validate that a security leader can speak intelligently across the entire portfolio a CISO or security manager oversees, not just one narrow specialty.
Structurally, the exam is a proctored, web-based test delivered remotely through ProctorU or in person via Pearson VUE. You get 115 questions and 3 hours, and you need 70% to pass. GIAC does not publish domain-by-domain percentage weights for GSLC, which means every one of the 18 areas listed below is fair game and none can be safely deprioritized. If you're still deciding whether this format suits you, our companion piece on how hard the GSLC exam actually is breaks down the difficulty curve in more depth.
All 18 GSLC Domains, Explained
Here is the complete, current list of GSLC content areas as published by GIAC. Each one maps to real job tasks a security manager performs, which is why the exam questions tend to be scenario-based rather than pure definition recall.
- Cryptography Concepts for Managers
- Incident Response and Business Continuity
- Managing a Security Operations Center
- Managing Application Security
- Managing Artificial Intelligence
- Managing Cloud Security
- Managing Encryption and Privacy
- Managing Negotiations and Vendors
- Managing Projects
- Managing Security Awareness
- Managing Security Policy
- Managing System Security
- Managing the Program Structure
- Network Monitoring for Managers
- Network Security Architecture
- Networking Concepts for Managers
- Risk Management and Security Frameworks
- Vulnerability Management
We're building out standalone deep dives for each domain - start with GSLC Domain 1: Cryptography Concepts for Managers, GSLC Domain 2: Incident Response and Business Continuity, GSLC Domain 3: Managing a Security Operations Center, and GSLC Domain 4: Managing Application Security if you want domain-level detail beyond this overview.
The Management-Heavy Domains
A cluster of GSLC domains focuses squarely on the "leadership" half of the credential's name. These aren't technical trivia - they test whether you understand how security programs get funded, staffed, governed, and communicated.
Managing Projects
Candidates need working familiarity with project lifecycle stages, resource allocation tradeoffs, and how security initiatives get scoped and tracked against budget and timeline constraints.
- Distinguishing project phases and typical deliverables at each stage
- Recognizing scope creep and change-control scenarios in exam questions
Managing Negotiations and Vendors
This domain covers contract structuring, SLA negotiation leverage points, and vendor risk assessment - the kind of decisions a security manager makes when onboarding a new SaaS provider or renewing a managed-services contract.
- Vendor risk tiering and due-diligence checkpoints
- Negotiation tactics tied to security requirements, not just price
Managing Security Policy
Expect scenario questions on policy hierarchy - the difference between policy, standard, procedure, and guideline - plus how exceptions and enforcement get handled in a mature program.
- Policy vs. standard vs. procedure distinctions
- Exception-handling workflows and documentation expectations
Managing Security Awareness
This domain tests program design for training and culture change, including how to measure whether awareness efforts are actually reducing risky behavior rather than just checking a compliance box.
Managing the Program Structure
Covers how a security function is organized - reporting lines, roles and responsibilities, and how a program matures over time. Expect questions that ask you to identify gaps in an org's structure.
Risk Management and Security Frameworks also belongs in this cluster: candidates should be comfortable comparing framework philosophies (risk-based vs. controls-based approaches) and recognizing which framework fits which organizational context, without memorizing every clause of any single standard.
The Technical Domains
Balancing the management side, GSLC also expects genuine technical literacy - not implementation-level depth, but enough to make sound decisions and ask the right questions of technical staff.
| Domain | Core Focus | Typical Question Style |
|---|---|---|
| Cryptography Concepts for Managers | Symmetric vs. asymmetric use cases, key management basics | Scenario: which crypto approach fits a given requirement |
| Managing Encryption and Privacy | Data protection obligations, encryption at rest/in transit | Applying encryption controls to a privacy scenario |
| Network Security Architecture | Segmentation, defense-in-depth layout | Evaluating an architecture diagram for weaknesses |
| Networking Concepts for Managers | Protocols, addressing, traffic flow fundamentals | Identifying misconfigurations or traffic anomalies |
| Network Monitoring for Managers | Log sources, alerting logic, monitoring coverage | Choosing monitoring priorities given limited resources |
| Managing System Security | Hardening, patching cadence, endpoint controls | Prioritizing remediation across a mixed environment |
| Vulnerability Management | Scanning cycles, remediation SLAs, risk-based prioritization | Ranking vulnerabilities given business context |
| Managing Application Security | SDLC integration, secure coding oversight | Spotting where security review belongs in a dev pipeline |
| Managing a Security Operations Center | SOC staffing, escalation tiers, tooling | Diagnosing SOC workflow bottlenecks |
| Incident Response and Business Continuity | IR lifecycle, BCP/DR integration | Sequencing response steps under a scenario |
Key Takeaway
Technical GSLC domains rarely ask you to configure anything - they ask you to make a management-level decision using technical facts. Study the "why" behind a control, not just the syntax.
The Newer Additions: AI and Cloud
Two domains reflect how fast the security leadership job has changed: Managing Artificial Intelligence and Managing Cloud Security. Managing Artificial Intelligence covers governance concerns around AI adoption inside an organization - data handling, model risk, and oversight responsibilities that a security leader now has to own even without being a data scientist. Managing Cloud Security covers shared-responsibility thinking, cloud-specific misconfiguration risks, and how traditional controls translate (or don't) into cloud environments.
These domains tend to trip up candidates who studied from older security-management material, since neither topic existed in the same form a few years ago. If you're using outdated notes or a hand-me-down study guide, cross-check it against the current objective list before you assume your material is complete - our GSLC study guide walks through building a current, domain-aligned prep plan from scratch.
Registration, Fees, and Exam-Day Mechanics
Domain mastery only matters if you also get the logistics right. GSLC registration and delivery details worth locking in before you schedule:
- Cost: A certification attempt is $999. A retake runs $899, a practice exam is $399, and renewal is $499 (or 36 CPE credits instead of paying to retest).
- Format: 115 questions, 3-hour time limit, 70% required to pass.
- Attempt window: Once purchased, your attempt stays active for 120 days - plan your prep timeline backward from that deadline.
- Delivery: Remote via ProctorU or in person via Pearson VUE - pick whichever fits your environment and comfort with remote proctoring.
- Open-book rules: Printed books, printed notes, and a printed index are allowed. Electronic devices, internet access, and anything resembling practice-test dumps are explicitly prohibited.
- Validity: The credential lasts 4 years before you need to renew.
For a full breakdown of what the exam and any add-ons will actually cost you across a certification cycle, see GSLC certification cost: complete pricing breakdown.
Key Takeaway
Because GSLC is open book, your index quality often matters more than raw memorization - build a tabbed, cross-referenced index across all 18 domains before exam day.
Sequencing 18 Domains Into a Study Plan
With no published weighting, a reasonable approach is to group the 18 domains into related clusters and move through them in blocks rather than jumping randomly. This keeps related concepts - like the three network domains, or the two crypto/privacy domains - close together in your memory.
Foundations and Governance
- Managing Security Policy, Managing the Program Structure, Risk Management and Security Frameworks
- Build your index tabs for governance terminology
People and Process
- Managing Projects, Managing Negotiations and Vendors, Managing Security Awareness
- Practice scenario questions on vendor risk and budget tradeoffs
Network and Systems
- Networking Concepts for Managers, Network Security Architecture, Network Monitoring for Managers, Managing System Security
- Diagram-based review of segmentation and monitoring coverage
Response, Risk, and Emerging Tech
- Incident Response and Business Continuity, Vulnerability Management, Managing a Security Operations Center, Managing Application Security, Managing Cloud Security, Managing Artificial Intelligence, Cryptography Concepts for Managers, Managing Encryption and Privacy
- Full-length practice exam under open-book, timed conditions
Adjust the pacing to your own timeline, but keep the clustering logic - it mirrors how questions on the real exam tend to draw connections across adjacent domains. For a more detailed week-by-week breakdown tied to the 120-day attempt window, see the full GSLC study guide, and if you want to gauge realistic difficulty before committing to a schedule, check what the pass rate data shows.
Who Actually Hires for GSLC Skills
GSLC's cross-domain design mirrors the actual job description for security managers, IT security officers, and rising CISOs who need to speak fluently to both technical teams and executive stakeholders. Because the domains cover vendor negotiation, program structure, and cloud/AI governance alongside technical fundamentals, it's a natural fit for professionals moving from a hands-on security role into a leadership track. If you're evaluating whether this credential lines up with your career goals, GSLC jobs and the GSLC salary guide cover the roles and compensation context in more detail, and our ROI analysis weighs the certification cost against career upside.
Still unclear on the basics of what this letter combination even represents? Start with What Is GSLC?, GSLC Meaning, or What Does GSLC Stand For? for the plain-language explanation before diving into domain-level prep. Our broader GSLC Certification overview and GSLC training resources are also useful starting points if you're mapping out a full prep path, and you can practice against domain-aligned questions any time on our GSLC practice test platform.
FAQ
No. GIAC publishes all 18 GSLC objectives without percentage weights, so candidates should prepare broadly rather than betting on a subset of domains.
No. The exam is open book only for printed books, printed notes, and a printed index. Electronic resources and internet access are prohibited.
Your attempt remains active for 120 days from purchase, so plan your study schedule to comfortably finish within that window.
You need 70% overall on the 115-question exam within the 3-hour time limit; there's no separate passing threshold per domain.
GSLC is valid for 4 years. You can renew with 36 CPE credits or by retaking the current version of the exam, which will reflect any updated domain list.
- GSLC Domain 1: Cryptography Concepts for Managers - Complete Study Guide 2026
- GSLC Domain 2: Incident Response and Business Continuity - Complete Study Guide 2026
- GSLC Domain 3: Managing a Security Operations Center - Complete Study Guide 2026
- GSLC Domain 4: Managing Application Security - Complete Study Guide 2026