GCFE
The GCFE is GIAC's certification for Windows host-based digital forensics, built around the SANS FOR500 body of knowledge and recognized across DFIR, law enforcement, and incident-response teams. It validates that you can collect, preserve, and analyze evidence from Windows systems and present defensible findings. The exam is open-book but unforgiving on time — 82 questions in three hours, with a hard 70% cut score — so a disorganized index or one weak objective can cost you the cert and a $999 retake. This page breaks down exactly what GCFE tests, how it's delivered, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the GCFE exam is built — at a glance
82
82 proctored multiple-choice questions. Many are scenario-based and reference forensic artifacts, timelines, and tool output you must interpret correctly.
3h
A three-hour clock — roughly two minutes per question. Open-book lookups eat time fast, so a tabbed, well-indexed reference set is essential.
70%
A fixed 70% minimum for versions from Dec 17, 2022. No curve — you need roughly 58 of 82 questions right to pass.
The GCFE is open book. You may bring printed material — SANS FOR500 course books, your own lab notes, and a custom index — but no electronic devices or digital copies. The candidates who pass comfortably are the ones whose index lets them find a registry path or artifact location in seconds rather than flipping through hundreds of pages.
A standalone GCFE attempt costs about $999 USD and includes two practice exams that mirror the live format. You get 120 days from activation to schedule and complete the attempt. A retake, if needed, is around $899 — which is why most candidates treat the practice tests as a hard gate before booking the real thing.
GIAC publishes objectives rather than fixed percentage weights — these are the GCFE domains
Evidence handling, chain of custody, acquisition, and the methodology of a defensible Windows examination.
Windows registry hives, system configuration, attached and USB device history, and host-level artifacts.
Reconstructing user activity: recent files, jump lists, shellbags, LNK files, and account behavior.
Execution evidence — prefetch, amcache/shimcache, and tracing which programs ran and when.
Browser structure and analysis across Chrome, Edge, and Firefox — history, cache, downloads, and session data.
Email analysis, cloud storage artifacts, Windows event log analysis, and forensic artifact techniques tying it together.
GIAC tests these objectives without publishing fixed percentage weights, so every domain is fair game. The exam rewards depth on Windows internals — registry, timelines, and artifact correlation — rather than broad surface knowledge, and it maps directly to the SANS FOR500: Windows Forensic Analysis course.
Two proctoring routes — and what to expect on test day
You take the exam from a private room on your own machine, monitored live through ProctorU. You'll complete a system check, an ID verification, and a webcam room scan before the exam unlocks. Your printed open-book materials are inspected on camera, and you must stay in frame for the full three hours.
Prefer a controlled environment? You can sit the same web-based exam at a Pearson VUE test center, where staff verify your ID, store your belongings, and check the printed materials you bring in. Either route delivers the identical 82-question, 70%-to-pass exam.
A valid, unexpired government photo ID with your name matching your GIAC account. The proctor verifies you before the exam unlocks.
Open-book material is allowed but inspected. Printed books, notes, and a personal index are fine; phones, laptops, and digital copies are not.
Once your attempt is activated you have 120 days to schedule and sit it. Plan your index-building and practice tests inside that window.
GCFE is built for hands-on Windows forensic examiners
No formal requirements — but it's a technical, detail-heavy exam
Difficulty: Being open-book lulls some candidates into under-preparing, but the GCFE is genuinely hard — it expects you to recall exact artifact locations, registry paths, and tool behavior under a tight clock. Most candidates invest weeks building a usable index and running the included practice tests. With a $999 attempt and an $899 retake on the line, the cost of a careless first sitting is steep.
The GCFE is a technical, time-boxed, open-book exam where a weak index or one shaky objective can sink an otherwise strong examiner. Exam Assist pairs you with a vetted digital-forensics specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your proctoring choice (ProctorU or Pearson VUE), your activation window, and your forensics background. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and the 70% cut score and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a GCFE specialist who maps the work around the Windows-forensics objectives, the open-book index, and the proctored environment — discreetly and confidentially.
You only pay once your passing result is confirmed on your official GIAC report. No verified result, nothing owed.
Start with an honest feasibility check and the full pay-after-you-pass arrangement.
Straight answers about the GCFE exam
Book your help and compare sibling forensics & GIAC exams
Pair with a vetted forensics specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Start the request GCIHGIAC's incident-response credential — the natural complement to GCFE for analysts working live intrusions.
View exam GCIANetwork traffic and intrusion analysis — pairs host forensics with packet-level detection skills.
View exam CHFIEC-Council's forensics certification — a broader cross-platform alternative to the Windows-focused GCFE.
View exam CatalogSee every certification and admissions test we support, from GIAC and CompTIA to AWS and the GMAT.
Open the catalogGet expert GCFE help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.