- Important Status Check Before You Read Further
- How GIAC Structures the Nine GSNA Domains
- Domain 1: Auditing Access Control and Data Handling in Web Applications
- Domain 2: Auditing the Enterprise Network
- Domain 3: Auditing UNIX and Linux Systems
- Domain 4: Auditing Web Applications
- Domain 5: Auditing Windows Systems and Domains
- Domain 6: Risk Assessment for Auditors
- Domain 7: The Audit Process
- Domain 8: UNIX and Linux Logging and Continuous Monitoring
- Domain 9: Windows Logging and Continuous Monitoring
- Exam Mechanics Behind the Domains
- Scheduling the Nine Domains If You're Still Eligible
- Who Actually Uses This Domain List
- Frequently Asked Questions
- GSNA covers nine domains spanning web apps, enterprise networks, UNIX/Linux, and Windows auditing.
- The certification is in abeyance; it cannot currently be purchased or newly attempted.
- Historical exam: 115 questions, 3-hour limit, 73% minimum passing score, open book format.
- Domain 2 now explicitly folds in cloud computing, containers, and physical networks.
Important Status Check Before You Read Further
Before diving into content areas, understand where GSNA stands today. GIAC has placed the GSNA Systems and Network Auditor certification in abeyance, meaning it is no longer available for purchase and new candidates cannot register for an exam attempt. The official certification page now displays an abeyance banner where the registration button used to sit. If you already hold GSNA, you're not affected in terms of validity - you can still renew through Continuing Professional Education (CPE) credits on the normal four-year cycle. If you're researching this credential for the first time, the domain breakdown below still matters: it explains what GSNA validated, why employers still respect the credential on a resume, and what skill set to build if you're pursuing adjacent GIAC certifications instead.
How GIAC Structures the Nine GSNA Domains
GIAC publishes formal outcome statements for each GSNA objective, and the certification is deliberately built around the practical mechanics of a technical audit rather than pure theory. The nine domains split roughly into four functional clusters: audit methodology and risk (Domains 6 and 7), enterprise and network-level auditing (Domain 2), platform-specific auditing for UNIX/Linux and Windows (Domains 3 and 5), web application security auditing (Domains 1 and 4), and continuous monitoring/logging for both major operating system families (Domains 8 and 9). This structure mirrors the real workflow of an auditor: define scope and risk, examine the network perimeter, drill into specific systems and applications, then verify ongoing monitoring controls are actually working.
For a condensed version of this breakdown you can keep open while studying, see the GSNA Cheat Sheet. If you want a fuller explanation of how these domains translate into a study plan, the GSNA Study Guide walks through pacing in more detail.
Domain 1: Auditing Access Control and Data Handling in Web Applications
What This Domain Covers
This domain focuses on how web applications enforce authentication, authorization, session management, and data protection controls - and how an auditor verifies those controls actually work as designed rather than as documented.
- Evaluating role-based access control implementation against least-privilege principles
- Reviewing session handling, token expiration, and credential storage practices
- Assessing how sensitive data is classified, encrypted, and handled in transit and at rest
- Identifying gaps between documented access policy and actual enforced behavior
Domain 2: Auditing the Enterprise Network
What This Domain Covers
This is the broadest domain in the exam blueprint and has been explicitly expanded to include modern infrastructure. Candidates must be comfortable auditing traditional physical networks alongside cloud computing environments and containerized workloads.
- Perimeter defense review: firewalls, segmentation, and boundary controls
- Cloud computing configuration review and shared-responsibility gaps
- Container security posture and orchestration-layer exposure
- Physical network architecture, topology documentation, and change control
Domain 3: Auditing UNIX and Linux Systems
What This Domain Covers
This domain tests hands-on familiarity with UNIX and Linux system hardening and configuration review - the kind of work an auditor does directly on a host rather than through a dashboard.
- File permission structures, ownership, and SUID/SGID risk identification
- Service inventory and identification of unnecessary or misconfigured daemons
- Patch management verification and package integrity checks
- User account review, privilege escalation paths, and sudo configuration audit
Domain 4: Auditing Web Applications
What This Domain Covers
Where Domain 1 zooms in on access control and data handling specifically, Domain 4 covers the broader web application audit lifecycle - from architecture review through vulnerability identification.
- Input validation and injection-class vulnerability review methodology
- Application architecture mapping to identify trust boundaries
- Configuration review of web servers and application frameworks
- Documenting findings in a way that maps to business risk, not just technical severity
Domain 5: Auditing Windows Systems and Domains
What This Domain Covers
This domain mirrors Domain 3 but for the Windows ecosystem, including Active Directory domain structures rather than just standalone hosts.
- Group Policy Object review and enforcement verification
- Active Directory trust relationships, OU structure, and privileged group membership
- Local security policy configuration and baseline comparison
- Patch and update management verification across a domain environment
Domain 6: Risk Assessment for Auditors
What This Domain Covers
This is a foundational domain that underlies every other section of the exam. GIAC's outcome statements emphasize applying basic risk analysis techniques rather than memorizing a single risk framework.
- Asset identification and criticality ranking
- Threat and vulnerability pairing to estimate likelihood and impact
- Risk treatment options: accept, mitigate, transfer, avoid
- Communicating risk findings to non-technical stakeholders and management
Domain 7: The Audit Process
What This Domain Covers
This domain tests process discipline: planning an audit engagement, executing it, and reporting results in a defensible, repeatable way.
- Scoping an audit engagement and defining objectives with stakeholders
- Evidence collection standards and chain-of-custody considerations
- Structuring findings, severity ratings, and remediation recommendations in a report
- Follow-up verification that remediation actions were actually implemented
Key Takeaway
Domains 6 and 7 are conceptual anchors - mastering risk assessment logic and audit reporting structure makes every platform-specific domain (3, 4, 5) easier to apply in context.
Domain 8: UNIX and Linux Logging and Continuous Monitoring
What This Domain Covers
This domain shifts from point-in-time configuration review to ongoing detection capability on UNIX and Linux systems.
- Syslog configuration, log centralization, and retention policy review
- Identifying gaps in audit logging for privileged commands
- Continuous monitoring tool integration and alert threshold evaluation
- Verifying log integrity controls to prevent tampering
Domain 9: Windows Logging and Continuous Monitoring
What This Domain Covers
The Windows counterpart to Domain 8, focused on event log architecture and monitoring within Active Directory environments.
- Windows Event Log categories, forwarding, and centralized collection
- Auditing policy configuration for account logon and object access events
- Detecting monitoring blind spots across domain controllers and member servers
- Aligning continuous monitoring output with incident response triggers
Exam Mechanics Behind the Domains
Understanding domain content is only half the picture - knowing how those domains were tested matters just as much for anyone evaluating a past attempt or advising others. Historically, the GSNA exam consisted of 115 questions delivered in a 3-hour, linear (non-adaptive) format, meaning every candidate saw a fixed sequence rather than an algorithm that adjusted difficulty in real time. The exam was open book, with printed materials permitted, and delivered web-based under proctored conditions - either remotely through ProctorU or onsite through Pearson VUE testing centers.
The minimum passing score was set at 73%, based on a scientific passing-point study applied to all candidates who received certification attempts on or after July 15, 2016. That threshold applied uniformly across all nine domains combined rather than requiring a minimum score in each individual area. For a deeper breakdown of how that score was calculated and what it meant practically, see GSNA Passing Score 2026.
| Exam Attribute | Specification |
|---|---|
| Total Questions | 115 |
| Time Limit | 3 hours |
| Passing Score | 73% minimum |
| Format | Linear, web-based, open book |
| Proctoring Options | ProctorU (remote) or Pearson VUE (onsite) |
| Certification Validity | 4 years, renewed via CPEs |
There was no formal prerequisite to sit the exam, though O*NET classifies the credential at an Associate's degree education level, typically paired with more than two years of relevant work experience or a core-level GIAC certification. If you're assessing whether you would have qualified, or how eligibility worked historically, GSNA Requirements 2026 covers that in detail.
Scheduling the Nine Domains If You're Still Eligible
For candidates who already hold an active attempt voucher or are studying from existing materials, sequencing matters. The conceptual domains (Risk Assessment for Auditors and The Audit Process) establish vocabulary and structure that make the platform-specific domains click faster, so they belong early in a study block rather than as an afterthought.
Foundations
- Domain 6: Risk Assessment for Auditors
- Domain 7: The Audit Process
Network and Perimeter
- Domain 2: Auditing the Enterprise Network (including cloud and container coverage)
Platform Auditing
- Domain 3: Auditing UNIX and Linux Systems
- Domain 5: Auditing Windows Systems and Domains
Applications and Monitoring
- Domain 1 and Domain 4: Web application access control and broader auditing
- Domain 8 and Domain 9: UNIX/Linux and Windows logging and continuous monitoring
This sequencing isn't arbitrary busywork - it follows the same logical flow an actual audit engagement follows: assess risk, scope the network, drill into systems, then verify ongoing monitoring. If you want a full narrative walkthrough of pacing, review budgets, and practice test integration, the GSNA Study Guide expands on this weekly structure. For a realistic sense of how much friction to expect from the platform-specific domains, How Hard Is the GSNA Exam? breaks down difficulty by content area.
Who Actually Uses This Domain List
GIAC built GSNA for a specific set of roles: auditors, managers overseeing an audit or security team, security professionals, system administrators, network administrators, and anyone responsible for implementing continuous monitoring processes. That target audience explains why the domain list balances technical depth (UNIX, Linux, and Windows system internals) with process discipline (risk assessment and audit reporting) - the credential was never meant purely for penetration testers or purely for compliance generalists, but for the hybrid role that has to do both.
If you're trying to understand how this maps to job titles and compensation ranges, GSNA Jobs and GSNA Salary Guide 2026 cover that ground. For candidates weighing whether pursuing GIAC training and adjacent certifications is worthwhile given the current abeyance status, Is the GSNA Certification Worth It? lays out the tradeoffs directly.
To reinforce domain-level recall once you understand the structure, working through scenario-based practice questions on our practice test platform is one of the more efficient ways to check whether you can apply a concept under time pressure rather than just recognize it on a flashcard. The same platform at the main practice site groups sample items loosely by these nine areas so you can target weak spots directly.
Frequently Asked Questions
GIAC does not publish a fixed percentage weight per domain, and it reserves the right to change certification specifications without notice. Treat the nine domains as content areas to master broadly rather than assuming a specific question count per domain.
No. GSNA is currently in abeyance and is not available for purchase or new registration. The domain content remains useful as a skills reference, but new certification attempts are not possible at this time.
No. Renewal for existing holders is handled entirely through CPE credits over the four-year certification cycle, not through a retest of the domain content.
Candidates from a networking background often find Domain 3 (UNIX and Linux Systems) and Domain 5 (Windows Systems and Domains) the most demanding, since both require hands-on host-level configuration knowledge rather than perimeter-level network skills.
Yes. GIAC's published outcome statement for the enterprise network objective explicitly includes cloud computing, containers, and physical networks, reflecting how modern enterprise infrastructure is actually deployed.