GCFR logo
Focused certification exam prep
Start practice

GCFR Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • GCFR has 82 questions, a 3-hour limit, and requires 62% to pass.
  • All 15 domains span AWS, Azure, Google Cloud, M365, Workspace, and Kubernetes forensics.
  • The exam is open book for printed materials only - no digital notes or PDFs allowed.
  • CyberLive performance items test real commands in live virtual-machine environments, not just recall.

Exam Snapshot: Format, Fees, and Logistics

Before diving into domain-level details, anchor yourself to the raw numbers. GCFR is a single web-based exam, proctored remotely through ProctorU or in person at a Pearson VUE center. You get 82 questions in 3 hours, and a passing score is 62%. The exam window is tight compared to some study timelines - once you activate your attempt, you have 120 days to sit for it, so registration timing matters as much as content mastery.

Pricing breaks down as follows: a standard attempt is $999, a retake is $899, an attempt extension runs $479, a practice exam costs $399, and renewal after four years is $499 - all before tax. If you want the full breakdown of what's bundled with each option and how to budget for retakes, the GCFR Certification Cost 2026: Complete Pricing Breakdown article covers every line item in detail.

Quick Fact: GCFR is open book, but only for physical materials. Printed books, paper notes, and printed study guides are permitted in the exam session - digital files, tablets, and second monitors are not.

The 15 GCFR Domains at a Glance

GCFR's blueprint is unusually wide for a GIAC practitioner cert because it spans four major cloud ecosystems plus container orchestration. Memorize this list cold - it is the skeleton every practice question hangs on:

  1. Accessing and Investigating Google Workspace Evidence
  2. AWS Networking, VMs, and Storage
  3. Google Cloud Overview and IAM
  4. Google Cloud Storage and Networking
  5. Google Cloud Virtual Machines
  6. Google Workspace Fundamentals
  7. In-Cloud IR in AWS and Event-Driven Response
  8. Introduction to Cloud DFIR
  9. Kubernetes Overview, Logs, and Common Attacks
  10. Log Sources for Google Cloud IR
  11. Microsoft Azure Storage and Networking
  12. Microsoft Azure Virtual Machines
  13. Microsoft Unified Audit Log and Graph API
  14. Understanding IR in AWS
  15. Understanding Microsoft Azure and Log Sources

Notice the pattern: each cloud provider gets a "fundamentals/overview" domain, a "storage and networking" domain, a "virtual machines" domain, and an "IR/log sources" domain. Once you see that repeating structure, the exam feels far less like 15 random topics and more like four parallel tracks (AWS, Azure, Google Cloud, and identity-heavy SaaS) plus Kubernetes and a DFIR foundation. For a domain-by-domain breakdown with study priorities, see the GCFR Exam Domains 2026: Complete Guide to All 15 Content Areas.

Domain 8: Introduction to Cloud DFIR

This domain sets vocabulary and mental models used everywhere else on the exam - shared responsibility model boundaries, volatile vs. durable cloud evidence, and how forensic acquisition differs from on-prem disk imaging.

  • Know which artifacts survive instance termination and which do not
  • Understand why cloud IR relies more on logs/APIs than physical acquisition

AWS Facts You Must Recall Instantly

AWS content appears across three domains: AWS Networking, VMs, and Storage, Understanding IR in AWS, and In-Cloud IR in AWS and Event-Driven Response. Together these form the largest single-provider block on the exam.

  • Networking/Storage: VPC flow logs, security groups vs. NACLs, S3 bucket policies and access logging, EBS snapshot forensics.
  • Understanding IR in AWS: CloudTrail as the primary event log, GuardDuty findings, IAM access analyzer output, and how to reconstruct an attacker's API call sequence.
  • In-Cloud IR and Event-Driven Response: Using EventBridge/Lambda for automated containment, isolating a compromised EC2 instance without destroying evidence, and snapshotting for offline analysis.
High-Yield Reminder: Expect scenario questions that give you a partial CloudTrail excerpt and ask what happened - not "define CloudTrail." Practice reading raw log JSON, not just memorizing service names.

Microsoft Azure and M365 Quick Reference

Azure and Microsoft 365 evidence sources form another major cluster: Understanding Microsoft Azure and Log Sources, Microsoft Azure Storage and Networking, Microsoft Azure Virtual Machines, and Microsoft Unified Audit Log and Graph API.

  • Azure Activity Log vs. Azure AD sign-in/audit logs - know which captures resource changes vs. identity events.
  • NSGs, Azure Storage account access keys/SAS tokens, and how misconfigured blob containers get discovered during IR.
  • Azure VM disk snapshotting and boot diagnostics as evidence sources.
  • Unified Audit Log search limitations and how the Graph API is used to pull audit data programmatically at scale.

Key Takeaway

Graph API questions on GCFR often test why an investigator would query the API instead of the portal UI - throughput, filtering, and automation are the usual answers.

Google Cloud and Workspace Quick Reference

Google gets the most granular treatment of any provider, split across five domains: Google Cloud Overview and IAM, Google Cloud Storage and Networking, Google Cloud Virtual Machines, Log Sources for Google Cloud IR, Google Workspace Fundamentals, and Accessing and Investigating Google Workspace Evidence.

  • IAM: Roles vs. permissions vs. policies, organization/folder/project hierarchy, and service account key abuse.
  • Storage/Networking: Cloud Storage bucket IAM vs. ACLs, VPC firewall rules, Cloud NAT logging.
  • Virtual Machines: Compute Engine disk snapshots, serial console logs, OS Login audit trail.
  • Log Sources: Cloud Audit Logs (Admin Activity, Data Access, System Event) and how to pivot from an alert to raw log entries.
  • Workspace: Admin console audit logs, Drive/Gmail log events, and login/OAuth token investigations.

Because Google-related content spans six of the fifteen domains, underestimating it is one of the most common mistakes candidates make. If you're weighing how much time this section deserves relative to others, the GCFR Study Guide 2026: How to Pass on Your First Attempt walks through weighting your prep by domain density rather than by provider familiarity.

Kubernetes Incident Response Essentials

Domain 9, Kubernetes Overview, Logs, and Common Attacks, is the newest-feeling material for many candidates coming from a traditional cloud-security background. Key facts to lock in:

  • Control plane components (API server, etcd, scheduler, controller manager) and where each logs activity.
  • kubectl audit logs and how RBAC misconfigurations enable privilege escalation.
  • Common attack patterns: exposed dashboards, container escape, malicious image pulls, and lateral movement between pods.
  • Where forensic evidence lives when a pod terminates - ephemeral storage vs. persistent volumes vs. centralized logging.
Watch For: Kubernetes questions frequently combine networking (Domain 2/4/11 concepts) with orchestration logic, so review CNI-level networking alongside pod-level attacks rather than in isolation.

Exam-Day Mechanics: Open Book, CyberLive, Timing

GCFR follows the standard GIAC practitioner exam rules with two features that change how you prepare:

  • Open book, physical only. Printed books, tabbed printouts, and handwritten notes are allowed. No laptops, tablets, second screens, or PDF readers. Build a paper index during study, not a digital one.
  • CyberLive performance items. A portion of the 82 questions drop you into a real virtual-machine environment where you run actual commands against cloud consoles, CLIs, or logs - not just multiple choice recall. This is why hands-on lab time matters more here than for purely knowledge-based certifications.
  • 120-day activation window. Once you register, the clock starts. Don't activate before your study plan is realistically finished.

For a deeper look at exactly how the scoring works and what 62% means in practice across question types, read GCFR Passing Score 2026: Exactly What You Need to Pass. And if you're still deciding whether your background is strong enough to attempt it, How Hard Is the GCFR Exam? Complete Difficulty Guide 2026 breaks down the difficulty curve by domain.

Exam ElementDetail
Question Count82 questions
Time Limit3 hours
Passing Score62%
DeliveryProctorU (remote) or Pearson VUE (onsite)
Activation Window120 days
Attempt Cost$999 (retake $899)
Certification Validity4 years
Renewal36 CPEs, $499 fee

A One-Week Final Review Schedule

This cheat sheet assumes you've already done the bulk of your studying. In the final week before your exam window closes, use domain density - not personal comfort - to allocate review time.

Day 1-2

AWS Cluster

  • Review AWS Networking, VMs, and Storage
  • Drill CloudTrail/GuardDuty scenarios from Understanding IR in AWS and In-Cloud IR/Event-Driven Response
Day 3-4

Google Cluster

  • Cover Google Cloud IAM, Storage/Networking, and Virtual Machines
  • Practice pivoting from an alert to Cloud Audit Log entries (Log Sources for Google Cloud IR)
  • Review Workspace admin console and Drive/Gmail audit trails
Day 5

Azure and M365

  • Azure Activity Log vs. Azure AD sign-in logs
  • Unified Audit Log and Graph API query logic
Day 6

Kubernetes and DFIR Foundations

  • Control plane logging and RBAC escalation paths
  • Revisit Introduction to Cloud DFIR concepts that tie everything together
Day 7

CyberLive Simulation and Index Build

  • Run through hands-on labs in a live VM/console if available
  • Finalize your printed index by domain, tabbed for quick lookup

This is deliberately not a generic Pomodoro or spaced-repetition template - it's structured around which domains cluster by provider, since GCFR rewards recognizing that repeating four-part pattern across AWS, Azure, and Google Cloud. For a longer-horizon plan that starts from zero, the GCFR Study Guide 2026 lays out a multi-week version of this same logic.

Renewal, CPEs, and Long-Term Maintenance

GCFR stays active for four years. To renew, you need 36 CPEs and to pay the $499 renewal fee - no need to retake the full exam if you stay current. Start logging CPE-eligible activity (training, conference sessions, relevant work experience) early rather than scrambling in year four.

Before you even book your first attempt, confirm you meet the eligibility expectations outlined in GCFR Requirements 2026: Eligibility, Prerequisites & How to Qualify, and check GCFR Exam Dates 2026: Testing Windows, Deadlines & Scheduling so your 120-day activation window doesn't collide with other commitments.

Career Context: GCFR is aimed at practitioners doing incident response and forensics across multi-cloud and SaaS environments - roles that increasingly sit at the intersection of security operations and cloud engineering. If you're evaluating whether the credential translates into better job prospects or pay, the GCFR Salary Guide 2026: Complete Earnings Analysis and Is the GCFR Certification Worth It? Complete ROI Analysis 2026 articles go deeper, and GCFR Jobs outlines the kinds of roles that list it as a preferred qualification.

To stress-test your recall of the exact material summarized above, run through timed questions on our GCFR practice test platform - it's the fastest way to see which of these fifteen domains still need work before exam day. You can also revisit the practice test homepage anytime to reset a fresh simulated attempt under real time pressure.

FAQ

Is this cheat sheet enough to pass GCFR on its own?

No. This page is a compressed reference for final review, not a substitute for hands-on lab work and full domain study. Use it alongside a complete plan like the one in the GCFR Study Guide.

Can I bring digital notes into the GCFR exam?

No. GIAC practitioner exams, including GCFR, are open book for printed materials only. Digital notes, tablets, and PDF readers are not permitted during the session.

What exactly is a CyberLive question on GCFR?

CyberLive items place you inside a live virtual-machine environment where you perform real actions - such as querying logs or navigating a cloud console - rather than selecting a multiple-choice answer alone.

How many of the 82 questions cover Google Cloud and Workspace?

Google-related content spans six of the fifteen domains (Overview and IAM, Storage and Networking, Virtual Machines, Log Sources, Workspace Fundamentals, and Investigating Workspace Evidence), making it the most heavily represented provider on the blueprint.

What happens if I don't pass within the 120-day window?

You would need to purchase a retake ($899) or an attempt extension ($479) depending on your situation, since the original activation period has a fixed 120-day limit.

Ready to pass your GCFR exam?

Put this into practice with free GCFR questions across every exam domain.