- Exam Snapshot: Format, Fees, and Logistics
- The 15 GCFR Domains at a Glance
- AWS Facts You Must Recall Instantly
- Microsoft Azure and M365 Quick Reference
- Google Cloud and Workspace Quick Reference
- Kubernetes Incident Response Essentials
- Exam-Day Mechanics: Open Book, CyberLive, Timing
- A One-Week Final Review Schedule
- Renewal, CPEs, and Long-Term Maintenance
- FAQ
- GCFR has 82 questions, a 3-hour limit, and requires 62% to pass.
- All 15 domains span AWS, Azure, Google Cloud, M365, Workspace, and Kubernetes forensics.
- The exam is open book for printed materials only - no digital notes or PDFs allowed.
- CyberLive performance items test real commands in live virtual-machine environments, not just recall.
Exam Snapshot: Format, Fees, and Logistics
Before diving into domain-level details, anchor yourself to the raw numbers. GCFR is a single web-based exam, proctored remotely through ProctorU or in person at a Pearson VUE center. You get 82 questions in 3 hours, and a passing score is 62%. The exam window is tight compared to some study timelines - once you activate your attempt, you have 120 days to sit for it, so registration timing matters as much as content mastery.
Pricing breaks down as follows: a standard attempt is $999, a retake is $899, an attempt extension runs $479, a practice exam costs $399, and renewal after four years is $499 - all before tax. If you want the full breakdown of what's bundled with each option and how to budget for retakes, the GCFR Certification Cost 2026: Complete Pricing Breakdown article covers every line item in detail.
The 15 GCFR Domains at a Glance
GCFR's blueprint is unusually wide for a GIAC practitioner cert because it spans four major cloud ecosystems plus container orchestration. Memorize this list cold - it is the skeleton every practice question hangs on:
- Accessing and Investigating Google Workspace Evidence
- AWS Networking, VMs, and Storage
- Google Cloud Overview and IAM
- Google Cloud Storage and Networking
- Google Cloud Virtual Machines
- Google Workspace Fundamentals
- In-Cloud IR in AWS and Event-Driven Response
- Introduction to Cloud DFIR
- Kubernetes Overview, Logs, and Common Attacks
- Log Sources for Google Cloud IR
- Microsoft Azure Storage and Networking
- Microsoft Azure Virtual Machines
- Microsoft Unified Audit Log and Graph API
- Understanding IR in AWS
- Understanding Microsoft Azure and Log Sources
Notice the pattern: each cloud provider gets a "fundamentals/overview" domain, a "storage and networking" domain, a "virtual machines" domain, and an "IR/log sources" domain. Once you see that repeating structure, the exam feels far less like 15 random topics and more like four parallel tracks (AWS, Azure, Google Cloud, and identity-heavy SaaS) plus Kubernetes and a DFIR foundation. For a domain-by-domain breakdown with study priorities, see the GCFR Exam Domains 2026: Complete Guide to All 15 Content Areas.
Domain 8: Introduction to Cloud DFIR
This domain sets vocabulary and mental models used everywhere else on the exam - shared responsibility model boundaries, volatile vs. durable cloud evidence, and how forensic acquisition differs from on-prem disk imaging.
- Know which artifacts survive instance termination and which do not
- Understand why cloud IR relies more on logs/APIs than physical acquisition
AWS Facts You Must Recall Instantly
AWS content appears across three domains: AWS Networking, VMs, and Storage, Understanding IR in AWS, and In-Cloud IR in AWS and Event-Driven Response. Together these form the largest single-provider block on the exam.
- Networking/Storage: VPC flow logs, security groups vs. NACLs, S3 bucket policies and access logging, EBS snapshot forensics.
- Understanding IR in AWS: CloudTrail as the primary event log, GuardDuty findings, IAM access analyzer output, and how to reconstruct an attacker's API call sequence.
- In-Cloud IR and Event-Driven Response: Using EventBridge/Lambda for automated containment, isolating a compromised EC2 instance without destroying evidence, and snapshotting for offline analysis.
Microsoft Azure and M365 Quick Reference
Azure and Microsoft 365 evidence sources form another major cluster: Understanding Microsoft Azure and Log Sources, Microsoft Azure Storage and Networking, Microsoft Azure Virtual Machines, and Microsoft Unified Audit Log and Graph API.
- Azure Activity Log vs. Azure AD sign-in/audit logs - know which captures resource changes vs. identity events.
- NSGs, Azure Storage account access keys/SAS tokens, and how misconfigured blob containers get discovered during IR.
- Azure VM disk snapshotting and boot diagnostics as evidence sources.
- Unified Audit Log search limitations and how the Graph API is used to pull audit data programmatically at scale.
Key Takeaway
Graph API questions on GCFR often test why an investigator would query the API instead of the portal UI - throughput, filtering, and automation are the usual answers.
Google Cloud and Workspace Quick Reference
Google gets the most granular treatment of any provider, split across five domains: Google Cloud Overview and IAM, Google Cloud Storage and Networking, Google Cloud Virtual Machines, Log Sources for Google Cloud IR, Google Workspace Fundamentals, and Accessing and Investigating Google Workspace Evidence.
- IAM: Roles vs. permissions vs. policies, organization/folder/project hierarchy, and service account key abuse.
- Storage/Networking: Cloud Storage bucket IAM vs. ACLs, VPC firewall rules, Cloud NAT logging.
- Virtual Machines: Compute Engine disk snapshots, serial console logs, OS Login audit trail.
- Log Sources: Cloud Audit Logs (Admin Activity, Data Access, System Event) and how to pivot from an alert to raw log entries.
- Workspace: Admin console audit logs, Drive/Gmail log events, and login/OAuth token investigations.
Because Google-related content spans six of the fifteen domains, underestimating it is one of the most common mistakes candidates make. If you're weighing how much time this section deserves relative to others, the GCFR Study Guide 2026: How to Pass on Your First Attempt walks through weighting your prep by domain density rather than by provider familiarity.
Kubernetes Incident Response Essentials
Domain 9, Kubernetes Overview, Logs, and Common Attacks, is the newest-feeling material for many candidates coming from a traditional cloud-security background. Key facts to lock in:
- Control plane components (API server, etcd, scheduler, controller manager) and where each logs activity.
- kubectl audit logs and how RBAC misconfigurations enable privilege escalation.
- Common attack patterns: exposed dashboards, container escape, malicious image pulls, and lateral movement between pods.
- Where forensic evidence lives when a pod terminates - ephemeral storage vs. persistent volumes vs. centralized logging.
Exam-Day Mechanics: Open Book, CyberLive, Timing
GCFR follows the standard GIAC practitioner exam rules with two features that change how you prepare:
- Open book, physical only. Printed books, tabbed printouts, and handwritten notes are allowed. No laptops, tablets, second screens, or PDF readers. Build a paper index during study, not a digital one.
- CyberLive performance items. A portion of the 82 questions drop you into a real virtual-machine environment where you run actual commands against cloud consoles, CLIs, or logs - not just multiple choice recall. This is why hands-on lab time matters more here than for purely knowledge-based certifications.
- 120-day activation window. Once you register, the clock starts. Don't activate before your study plan is realistically finished.
For a deeper look at exactly how the scoring works and what 62% means in practice across question types, read GCFR Passing Score 2026: Exactly What You Need to Pass. And if you're still deciding whether your background is strong enough to attempt it, How Hard Is the GCFR Exam? Complete Difficulty Guide 2026 breaks down the difficulty curve by domain.
| Exam Element | Detail |
|---|---|
| Question Count | 82 questions |
| Time Limit | 3 hours |
| Passing Score | 62% |
| Delivery | ProctorU (remote) or Pearson VUE (onsite) |
| Activation Window | 120 days |
| Attempt Cost | $999 (retake $899) |
| Certification Validity | 4 years |
| Renewal | 36 CPEs, $499 fee |
A One-Week Final Review Schedule
This cheat sheet assumes you've already done the bulk of your studying. In the final week before your exam window closes, use domain density - not personal comfort - to allocate review time.
AWS Cluster
- Review AWS Networking, VMs, and Storage
- Drill CloudTrail/GuardDuty scenarios from Understanding IR in AWS and In-Cloud IR/Event-Driven Response
Google Cluster
- Cover Google Cloud IAM, Storage/Networking, and Virtual Machines
- Practice pivoting from an alert to Cloud Audit Log entries (Log Sources for Google Cloud IR)
- Review Workspace admin console and Drive/Gmail audit trails
Azure and M365
- Azure Activity Log vs. Azure AD sign-in logs
- Unified Audit Log and Graph API query logic
Kubernetes and DFIR Foundations
- Control plane logging and RBAC escalation paths
- Revisit Introduction to Cloud DFIR concepts that tie everything together
CyberLive Simulation and Index Build
- Run through hands-on labs in a live VM/console if available
- Finalize your printed index by domain, tabbed for quick lookup
This is deliberately not a generic Pomodoro or spaced-repetition template - it's structured around which domains cluster by provider, since GCFR rewards recognizing that repeating four-part pattern across AWS, Azure, and Google Cloud. For a longer-horizon plan that starts from zero, the GCFR Study Guide 2026 lays out a multi-week version of this same logic.
Renewal, CPEs, and Long-Term Maintenance
GCFR stays active for four years. To renew, you need 36 CPEs and to pay the $499 renewal fee - no need to retake the full exam if you stay current. Start logging CPE-eligible activity (training, conference sessions, relevant work experience) early rather than scrambling in year four.
Before you even book your first attempt, confirm you meet the eligibility expectations outlined in GCFR Requirements 2026: Eligibility, Prerequisites & How to Qualify, and check GCFR Exam Dates 2026: Testing Windows, Deadlines & Scheduling so your 120-day activation window doesn't collide with other commitments.
To stress-test your recall of the exact material summarized above, run through timed questions on our GCFR practice test platform - it's the fastest way to see which of these fifteen domains still need work before exam day. You can also revisit the practice test homepage anytime to reset a fresh simulated attempt under real time pressure.
FAQ
No. This page is a compressed reference for final review, not a substitute for hands-on lab work and full domain study. Use it alongside a complete plan like the one in the GCFR Study Guide.
No. GIAC practitioner exams, including GCFR, are open book for printed materials only. Digital notes, tablets, and PDF readers are not permitted during the session.
CyberLive items place you inside a live virtual-machine environment where you perform real actions - such as querying logs or navigating a cloud console - rather than selecting a multiple-choice answer alone.
Google-related content spans six of the fifteen domains (Overview and IAM, Storage and Networking, Virtual Machines, Log Sources, Workspace Fundamentals, and Investigating Workspace Evidence), making it the most heavily represented provider on the blueprint.
You would need to purchase a retake ($899) or an attempt extension ($479) depending on your situation, since the original activation period has a fixed 120-day limit.
Ready to pass your GCFR exam?
Put this into practice with free GCFR questions across every exam domain.