GSNA logo
Focused certification exam prep
Start practice

GSNA Exam Domains 2026: Complete Guide to All 9 Content Areas

TL;DR
  • GSNA covers nine domains spanning web apps, enterprise networks, UNIX/Linux, and Windows auditing.
  • The certification is in abeyance; it cannot currently be purchased or newly attempted.
  • Historical exam: 115 questions, 3-hour limit, 73% minimum passing score, open book format.
  • Domain 2 now explicitly folds in cloud computing, containers, and physical networks.

Important Status Check Before You Read Further

Before diving into content areas, understand where GSNA stands today. GIAC has placed the GSNA Systems and Network Auditor certification in abeyance, meaning it is no longer available for purchase and new candidates cannot register for an exam attempt. The official certification page now displays an abeyance banner where the registration button used to sit. If you already hold GSNA, you're not affected in terms of validity - you can still renew through Continuing Professional Education (CPE) credits on the normal four-year cycle. If you're researching this credential for the first time, the domain breakdown below still matters: it explains what GSNA validated, why employers still respect the credential on a resume, and what skill set to build if you're pursuing adjacent GIAC certifications instead.

Why This Guide Still Matters: Existing GSNA holders need the domain map to plan CPE activity and keep skills current. Hiring managers evaluating past GSNA holders need to know what the credential actually tested. Both audiences benefit from a precise, domain-by-domain breakdown rather than a vague summary.

How GIAC Structures the Nine GSNA Domains

GIAC publishes formal outcome statements for each GSNA objective, and the certification is deliberately built around the practical mechanics of a technical audit rather than pure theory. The nine domains split roughly into four functional clusters: audit methodology and risk (Domains 6 and 7), enterprise and network-level auditing (Domain 2), platform-specific auditing for UNIX/Linux and Windows (Domains 3 and 5), web application security auditing (Domains 1 and 4), and continuous monitoring/logging for both major operating system families (Domains 8 and 9). This structure mirrors the real workflow of an auditor: define scope and risk, examine the network perimeter, drill into specific systems and applications, then verify ongoing monitoring controls are actually working.

For a condensed version of this breakdown you can keep open while studying, see the GSNA Cheat Sheet. If you want a fuller explanation of how these domains translate into a study plan, the GSNA Study Guide walks through pacing in more detail.

Domain 1: Auditing Access Control and Data Handling in Web Applications

What This Domain Covers

This domain focuses on how web applications enforce authentication, authorization, session management, and data protection controls - and how an auditor verifies those controls actually work as designed rather than as documented.

  • Evaluating role-based access control implementation against least-privilege principles
  • Reviewing session handling, token expiration, and credential storage practices
  • Assessing how sensitive data is classified, encrypted, and handled in transit and at rest
  • Identifying gaps between documented access policy and actual enforced behavior

Domain 2: Auditing the Enterprise Network

What This Domain Covers

This is the broadest domain in the exam blueprint and has been explicitly expanded to include modern infrastructure. Candidates must be comfortable auditing traditional physical networks alongside cloud computing environments and containerized workloads.

  • Perimeter defense review: firewalls, segmentation, and boundary controls
  • Cloud computing configuration review and shared-responsibility gaps
  • Container security posture and orchestration-layer exposure
  • Physical network architecture, topology documentation, and change control
Why the Cloud Update Matters: GIAC's decision to explicitly add cloud computing and containers to Domain 2 reflects how enterprise networks actually look today. An auditor working strictly from a 2015-era network diagram would miss the majority of a modern attack surface.

Domain 3: Auditing UNIX and Linux Systems

What This Domain Covers

This domain tests hands-on familiarity with UNIX and Linux system hardening and configuration review - the kind of work an auditor does directly on a host rather than through a dashboard.

  • File permission structures, ownership, and SUID/SGID risk identification
  • Service inventory and identification of unnecessary or misconfigured daemons
  • Patch management verification and package integrity checks
  • User account review, privilege escalation paths, and sudo configuration audit

Domain 4: Auditing Web Applications

What This Domain Covers

Where Domain 1 zooms in on access control and data handling specifically, Domain 4 covers the broader web application audit lifecycle - from architecture review through vulnerability identification.

  • Input validation and injection-class vulnerability review methodology
  • Application architecture mapping to identify trust boundaries
  • Configuration review of web servers and application frameworks
  • Documenting findings in a way that maps to business risk, not just technical severity

Domain 5: Auditing Windows Systems and Domains

What This Domain Covers

This domain mirrors Domain 3 but for the Windows ecosystem, including Active Directory domain structures rather than just standalone hosts.

  • Group Policy Object review and enforcement verification
  • Active Directory trust relationships, OU structure, and privileged group membership
  • Local security policy configuration and baseline comparison
  • Patch and update management verification across a domain environment

Domain 6: Risk Assessment for Auditors

What This Domain Covers

This is a foundational domain that underlies every other section of the exam. GIAC's outcome statements emphasize applying basic risk analysis techniques rather than memorizing a single risk framework.

  • Asset identification and criticality ranking
  • Threat and vulnerability pairing to estimate likelihood and impact
  • Risk treatment options: accept, mitigate, transfer, avoid
  • Communicating risk findings to non-technical stakeholders and management

Domain 7: The Audit Process

What This Domain Covers

This domain tests process discipline: planning an audit engagement, executing it, and reporting results in a defensible, repeatable way.

  • Scoping an audit engagement and defining objectives with stakeholders
  • Evidence collection standards and chain-of-custody considerations
  • Structuring findings, severity ratings, and remediation recommendations in a report
  • Follow-up verification that remediation actions were actually implemented

Key Takeaway

Domains 6 and 7 are conceptual anchors - mastering risk assessment logic and audit reporting structure makes every platform-specific domain (3, 4, 5) easier to apply in context.

Domain 8: UNIX and Linux Logging and Continuous Monitoring

What This Domain Covers

This domain shifts from point-in-time configuration review to ongoing detection capability on UNIX and Linux systems.

  • Syslog configuration, log centralization, and retention policy review
  • Identifying gaps in audit logging for privileged commands
  • Continuous monitoring tool integration and alert threshold evaluation
  • Verifying log integrity controls to prevent tampering

Domain 9: Windows Logging and Continuous Monitoring

What This Domain Covers

The Windows counterpart to Domain 8, focused on event log architecture and monitoring within Active Directory environments.

  • Windows Event Log categories, forwarding, and centralized collection
  • Auditing policy configuration for account logon and object access events
  • Detecting monitoring blind spots across domain controllers and member servers
  • Aligning continuous monitoring output with incident response triggers

Exam Mechanics Behind the Domains

Understanding domain content is only half the picture - knowing how those domains were tested matters just as much for anyone evaluating a past attempt or advising others. Historically, the GSNA exam consisted of 115 questions delivered in a 3-hour, linear (non-adaptive) format, meaning every candidate saw a fixed sequence rather than an algorithm that adjusted difficulty in real time. The exam was open book, with printed materials permitted, and delivered web-based under proctored conditions - either remotely through ProctorU or onsite through Pearson VUE testing centers.

The minimum passing score was set at 73%, based on a scientific passing-point study applied to all candidates who received certification attempts on or after July 15, 2016. That threshold applied uniformly across all nine domains combined rather than requiring a minimum score in each individual area. For a deeper breakdown of how that score was calculated and what it meant practically, see GSNA Passing Score 2026.

Exam AttributeSpecification
Total Questions115
Time Limit3 hours
Passing Score73% minimum
FormatLinear, web-based, open book
Proctoring OptionsProctorU (remote) or Pearson VUE (onsite)
Certification Validity4 years, renewed via CPEs

There was no formal prerequisite to sit the exam, though O*NET classifies the credential at an Associate's degree education level, typically paired with more than two years of relevant work experience or a core-level GIAC certification. If you're assessing whether you would have qualified, or how eligibility worked historically, GSNA Requirements 2026 covers that in detail.

Scheduling the Nine Domains If You're Still Eligible

For candidates who already hold an active attempt voucher or are studying from existing materials, sequencing matters. The conceptual domains (Risk Assessment for Auditors and The Audit Process) establish vocabulary and structure that make the platform-specific domains click faster, so they belong early in a study block rather than as an afterthought.

Week 1

Foundations

  • Domain 6: Risk Assessment for Auditors
  • Domain 7: The Audit Process
Week 2

Network and Perimeter

  • Domain 2: Auditing the Enterprise Network (including cloud and container coverage)
Week 3

Platform Auditing

  • Domain 3: Auditing UNIX and Linux Systems
  • Domain 5: Auditing Windows Systems and Domains
Week 4

Applications and Monitoring

  • Domain 1 and Domain 4: Web application access control and broader auditing
  • Domain 8 and Domain 9: UNIX/Linux and Windows logging and continuous monitoring

This sequencing isn't arbitrary busywork - it follows the same logical flow an actual audit engagement follows: assess risk, scope the network, drill into systems, then verify ongoing monitoring. If you want a full narrative walkthrough of pacing, review budgets, and practice test integration, the GSNA Study Guide expands on this weekly structure. For a realistic sense of how much friction to expect from the platform-specific domains, How Hard Is the GSNA Exam? breaks down difficulty by content area.

Who Actually Uses This Domain List

GIAC built GSNA for a specific set of roles: auditors, managers overseeing an audit or security team, security professionals, system administrators, network administrators, and anyone responsible for implementing continuous monitoring processes. That target audience explains why the domain list balances technical depth (UNIX, Linux, and Windows system internals) with process discipline (risk assessment and audit reporting) - the credential was never meant purely for penetration testers or purely for compliance generalists, but for the hybrid role that has to do both.

If you're trying to understand how this maps to job titles and compensation ranges, GSNA Jobs and GSNA Salary Guide 2026 cover that ground. For candidates weighing whether pursuing GIAC training and adjacent certifications is worthwhile given the current abeyance status, Is the GSNA Certification Worth It? lays out the tradeoffs directly.

Practical Note: Because GSNA is in abeyance, the domain list is now primarily useful as a skills framework and as context for hiring managers evaluating existing holders, rather than as a live exam blueprint for new candidates.

To reinforce domain-level recall once you understand the structure, working through scenario-based practice questions on our practice test platform is one of the more efficient ways to check whether you can apply a concept under time pressure rather than just recognize it on a flashcard. The same platform at the main practice site groups sample items loosely by these nine areas so you can target weak spots directly.

Frequently Asked Questions

Are all nine GSNA domains weighted equally on the exam?

GIAC does not publish a fixed percentage weight per domain, and it reserves the right to change certification specifications without notice. Treat the nine domains as content areas to master broadly rather than assuming a specific question count per domain.

Can I still take the GSNA exam to prove mastery of these domains?

No. GSNA is currently in abeyance and is not available for purchase or new registration. The domain content remains useful as a skills reference, but new certification attempts are not possible at this time.

If I already hold GSNA, do I need to restudy all nine domains to renew?

No. Renewal for existing holders is handled entirely through CPE credits over the four-year certification cycle, not through a retest of the domain content.

Which domain is hardest for candidates with a pure networking background?

Candidates from a networking background often find Domain 3 (UNIX and Linux Systems) and Domain 5 (Windows Systems and Domains) the most demanding, since both require hands-on host-level configuration knowledge rather than perimeter-level network skills.

Does Domain 2 really cover cloud and containers now?

Yes. GIAC's published outcome statement for the enterprise network objective explicitly includes cloud computing, containers, and physical networks, reflecting how modern enterprise infrastructure is actually deployed.

Ready to pass your GSNA exam?

Put this into practice with free GSNA questions across every exam domain.