GSLC logo
Focused certification exam prep
Start practice

GSLC Exam Domains 2026: Complete Guide to All 18 Content Areas

TL;DR
  • GIAC publishes 18 GSLC objectives with no percentage weights, so no single domain is "safe to skip."
  • The exam is 115 questions in 3 hours, requiring 70% to pass, with a 120-day attempt window.
  • GSLC is open book for printed materials only - no electronic resources or internet access allowed.
  • Domains span management topics (policy, projects, vendors) and technical topics (crypto, cloud, AI, networking).

GSLC Exam Overview: What You're Actually Facing

The GIAC Security Leadership Certification (GSLC) is unusual among GIAC credentials because it deliberately straddles management and technical territory. Instead of drilling deep into one discipline, GSLC spreads 18 objectives across cryptography, cloud, AI, networking, incident response, and program management. That breadth is the whole point: GSLC exists to validate that a security leader can speak intelligently across the entire portfolio a CISO or security manager oversees, not just one narrow specialty.

Structurally, the exam is a proctored, web-based test delivered remotely through ProctorU or in person via Pearson VUE. You get 115 questions and 3 hours, and you need 70% to pass. GIAC does not publish domain-by-domain percentage weights for GSLC, which means every one of the 18 areas listed below is fair game and none can be safely deprioritized. If you're still deciding whether this format suits you, our companion piece on how hard the GSLC exam actually is breaks down the difficulty curve in more depth.

No Weighting, No Shortcuts: Because GIAC does not disclose percentage weights for any of the 18 GSLC domains, candidates can't bank on a "top 3 domains carry 60% of the exam" strategy. Every domain deserves baseline coverage.

All 18 GSLC Domains, Explained

Here is the complete, current list of GSLC content areas as published by GIAC. Each one maps to real job tasks a security manager performs, which is why the exam questions tend to be scenario-based rather than pure definition recall.

  1. Cryptography Concepts for Managers
  2. Incident Response and Business Continuity
  3. Managing a Security Operations Center
  4. Managing Application Security
  5. Managing Artificial Intelligence
  6. Managing Cloud Security
  7. Managing Encryption and Privacy
  8. Managing Negotiations and Vendors
  9. Managing Projects
  10. Managing Security Awareness
  11. Managing Security Policy
  12. Managing System Security
  13. Managing the Program Structure
  14. Network Monitoring for Managers
  15. Network Security Architecture
  16. Networking Concepts for Managers
  17. Risk Management and Security Frameworks
  18. Vulnerability Management

We're building out standalone deep dives for each domain - start with GSLC Domain 1: Cryptography Concepts for Managers, GSLC Domain 2: Incident Response and Business Continuity, GSLC Domain 3: Managing a Security Operations Center, and GSLC Domain 4: Managing Application Security if you want domain-level detail beyond this overview.

The Management-Heavy Domains

A cluster of GSLC domains focuses squarely on the "leadership" half of the credential's name. These aren't technical trivia - they test whether you understand how security programs get funded, staffed, governed, and communicated.

Managing Projects

Candidates need working familiarity with project lifecycle stages, resource allocation tradeoffs, and how security initiatives get scoped and tracked against budget and timeline constraints.

  • Distinguishing project phases and typical deliverables at each stage
  • Recognizing scope creep and change-control scenarios in exam questions

Managing Negotiations and Vendors

This domain covers contract structuring, SLA negotiation leverage points, and vendor risk assessment - the kind of decisions a security manager makes when onboarding a new SaaS provider or renewing a managed-services contract.

  • Vendor risk tiering and due-diligence checkpoints
  • Negotiation tactics tied to security requirements, not just price

Managing Security Policy

Expect scenario questions on policy hierarchy - the difference between policy, standard, procedure, and guideline - plus how exceptions and enforcement get handled in a mature program.

  • Policy vs. standard vs. procedure distinctions
  • Exception-handling workflows and documentation expectations

Managing Security Awareness

This domain tests program design for training and culture change, including how to measure whether awareness efforts are actually reducing risky behavior rather than just checking a compliance box.

Managing the Program Structure

Covers how a security function is organized - reporting lines, roles and responsibilities, and how a program matures over time. Expect questions that ask you to identify gaps in an org's structure.

Risk Management and Security Frameworks also belongs in this cluster: candidates should be comfortable comparing framework philosophies (risk-based vs. controls-based approaches) and recognizing which framework fits which organizational context, without memorizing every clause of any single standard.

The Technical Domains

Balancing the management side, GSLC also expects genuine technical literacy - not implementation-level depth, but enough to make sound decisions and ask the right questions of technical staff.

DomainCore FocusTypical Question Style
Cryptography Concepts for ManagersSymmetric vs. asymmetric use cases, key management basicsScenario: which crypto approach fits a given requirement
Managing Encryption and PrivacyData protection obligations, encryption at rest/in transitApplying encryption controls to a privacy scenario
Network Security ArchitectureSegmentation, defense-in-depth layoutEvaluating an architecture diagram for weaknesses
Networking Concepts for ManagersProtocols, addressing, traffic flow fundamentalsIdentifying misconfigurations or traffic anomalies
Network Monitoring for ManagersLog sources, alerting logic, monitoring coverageChoosing monitoring priorities given limited resources
Managing System SecurityHardening, patching cadence, endpoint controlsPrioritizing remediation across a mixed environment
Vulnerability ManagementScanning cycles, remediation SLAs, risk-based prioritizationRanking vulnerabilities given business context
Managing Application SecuritySDLC integration, secure coding oversightSpotting where security review belongs in a dev pipeline
Managing a Security Operations CenterSOC staffing, escalation tiers, toolingDiagnosing SOC workflow bottlenecks
Incident Response and Business ContinuityIR lifecycle, BCP/DR integrationSequencing response steps under a scenario

Key Takeaway

Technical GSLC domains rarely ask you to configure anything - they ask you to make a management-level decision using technical facts. Study the "why" behind a control, not just the syntax.

The Newer Additions: AI and Cloud

Two domains reflect how fast the security leadership job has changed: Managing Artificial Intelligence and Managing Cloud Security. Managing Artificial Intelligence covers governance concerns around AI adoption inside an organization - data handling, model risk, and oversight responsibilities that a security leader now has to own even without being a data scientist. Managing Cloud Security covers shared-responsibility thinking, cloud-specific misconfiguration risks, and how traditional controls translate (or don't) into cloud environments.

These domains tend to trip up candidates who studied from older security-management material, since neither topic existed in the same form a few years ago. If you're using outdated notes or a hand-me-down study guide, cross-check it against the current objective list before you assume your material is complete - our GSLC study guide walks through building a current, domain-aligned prep plan from scratch.

Watch for Stale Materials: Because Managing Artificial Intelligence is a newer objective, older third-party study guides may omit it entirely. Verify any resource against GIAC's current 18-domain outline before relying on it.

Registration, Fees, and Exam-Day Mechanics

Domain mastery only matters if you also get the logistics right. GSLC registration and delivery details worth locking in before you schedule:

  • Cost: A certification attempt is $999. A retake runs $899, a practice exam is $399, and renewal is $499 (or 36 CPE credits instead of paying to retest).
  • Format: 115 questions, 3-hour time limit, 70% required to pass.
  • Attempt window: Once purchased, your attempt stays active for 120 days - plan your prep timeline backward from that deadline.
  • Delivery: Remote via ProctorU or in person via Pearson VUE - pick whichever fits your environment and comfort with remote proctoring.
  • Open-book rules: Printed books, printed notes, and a printed index are allowed. Electronic devices, internet access, and anything resembling practice-test dumps are explicitly prohibited.
  • Validity: The credential lasts 4 years before you need to renew.

For a full breakdown of what the exam and any add-ons will actually cost you across a certification cycle, see GSLC certification cost: complete pricing breakdown.

Key Takeaway

Because GSLC is open book, your index quality often matters more than raw memorization - build a tabbed, cross-referenced index across all 18 domains before exam day.

Sequencing 18 Domains Into a Study Plan

With no published weighting, a reasonable approach is to group the 18 domains into related clusters and move through them in blocks rather than jumping randomly. This keeps related concepts - like the three network domains, or the two crypto/privacy domains - close together in your memory.

Week 1

Foundations and Governance

  • Managing Security Policy, Managing the Program Structure, Risk Management and Security Frameworks
  • Build your index tabs for governance terminology
Week 2

People and Process

  • Managing Projects, Managing Negotiations and Vendors, Managing Security Awareness
  • Practice scenario questions on vendor risk and budget tradeoffs
Week 3

Network and Systems

  • Networking Concepts for Managers, Network Security Architecture, Network Monitoring for Managers, Managing System Security
  • Diagram-based review of segmentation and monitoring coverage
Week 4

Response, Risk, and Emerging Tech

  • Incident Response and Business Continuity, Vulnerability Management, Managing a Security Operations Center, Managing Application Security, Managing Cloud Security, Managing Artificial Intelligence, Cryptography Concepts for Managers, Managing Encryption and Privacy
  • Full-length practice exam under open-book, timed conditions

Adjust the pacing to your own timeline, but keep the clustering logic - it mirrors how questions on the real exam tend to draw connections across adjacent domains. For a more detailed week-by-week breakdown tied to the 120-day attempt window, see the full GSLC study guide, and if you want to gauge realistic difficulty before committing to a schedule, check what the pass rate data shows.

Who Actually Hires for GSLC Skills

GSLC's cross-domain design mirrors the actual job description for security managers, IT security officers, and rising CISOs who need to speak fluently to both technical teams and executive stakeholders. Because the domains cover vendor negotiation, program structure, and cloud/AI governance alongside technical fundamentals, it's a natural fit for professionals moving from a hands-on security role into a leadership track. If you're evaluating whether this credential lines up with your career goals, GSLC jobs and the GSLC salary guide cover the roles and compensation context in more detail, and our ROI analysis weighs the certification cost against career upside.

Still unclear on the basics of what this letter combination even represents? Start with What Is GSLC?, GSLC Meaning, or What Does GSLC Stand For? for the plain-language explanation before diving into domain-level prep. Our broader GSLC Certification overview and GSLC training resources are also useful starting points if you're mapping out a full prep path, and you can practice against domain-aligned questions any time on our GSLC practice test platform.

Practice With Purpose: Rather than grinding generic question banks, drill practice questions domain-by-domain on the main practice test hub so you can see exactly where your weak spots sit among the 18 objectives before exam day.

FAQ

Does GIAC weight any GSLC domain more heavily than others?

No. GIAC publishes all 18 GSLC objectives without percentage weights, so candidates should prepare broadly rather than betting on a subset of domains.

Can I bring digital notes into the GSLC exam?

No. The exam is open book only for printed books, printed notes, and a printed index. Electronic resources and internet access are prohibited.

How long do I have to finish once I register?

Your attempt remains active for 120 days from purchase, so plan your study schedule to comfortably finish within that window.

What score do I need across the 18 domains to pass?

You need 70% overall on the 115-question exam within the 3-hour time limit; there's no separate passing threshold per domain.

How do I keep my GSLC current after the domains I studied change?

GSLC is valid for 4 years. You can renew with 36 CPE credits or by retaking the current version of the exam, which will reflect any updated domain list.

Ready to pass your GSLC exam?

Put this into practice with free GSLC questions across every exam domain.