Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Incident Response and Cyber InvestigationsPreview
More in this section
37 more related questions in Pro version
Summary
Verify what happened, build defensible scope from multiple evidence sources, contain proportionately, preserve evidence, eradicate the actual foothold, and validate recovery. GCIH expects responders to move between response and investigation as new evidence changes the picture.
Section 2Scanning, Enumeration, Exploitation, and SMBPreview
More in this section
37 more related questions in Pro version
Summary
Know what the scanner or exploitation tool is proving, what it is not proving, and how the same behavior appears to defenders. GCIH blends attacker-tool literacy with defensive interpretation.
Section 3Password and Cloud AttacksPreview
More in this section
37 more related questions in Pro version
Summary
Separate password storage, online authentication abuse, offline cracking, alternate authentication material, and cloud-session abuse. The exam frequently gives clues that distinguish one attack economy or evidence source from another.
Section 4Web and API AttacksPreview
More in this section
37 more related questions in Pro version
Summary
GCIH web questions are usually root-cause questions. Decide whether the failure is object authorization, injection/data-vs-code separation, unsafe browser output handling, API inventory/governance, resource abuse, or business-flow abuse.
Section 5Post-Exploitation, Pivoting, Persistence, and AIPreview
More in this section
37 more related questions in Pro version
Summary
After initial compromise, identify what the attacker is doing now: executing, maintaining persistence, obtaining credentials, moving laterally, evading defenses, communicating with C2, or manipulating AI-integrated systems. Map the observed behavior, not the tool name.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.