- GSNA is in abeyance - it cannot currently be purchased or registered for.
- Existing holders keep the credential active by earning CPEs, not by retaking an exam.
- The historical exam had 115 questions, a 3-hour limit, and a 73% passing score.
- GSNA covers nine domains spanning UNIX/Linux, Windows, web applications, and risk assessment.
What GSNA Actually Is
The GIAC Systems and Network Auditor (GSNA) certification is a vendor-neutral credential issued by the Global Information Assurance Certification (GIAC), an ANAB-accredited body under ISO/IEC 17024 that is affiliated with the SANS Institute. GSNA was built to validate one specific and often underappreciated skill set: the ability to apply risk analysis techniques and conduct technical audits of core information systems - networks, perimeters, and applications - rather than simply configuring or defending them.
That distinction matters. Where many security certifications test whether you can build or harden a system, GSNA tests whether you can independently verify that a system is actually configured the way policy claims it is, find the gaps, and report them in a way leadership can act on. If you're trying to understand the credential from the ground up, our companion piece What Is GSNA? covers the naming and origin story in more depth, while GSNA Meaning and What Does GSNA Stand For? unpack the acronym itself for readers encountering it for the first time.
The Abeyance Status: What It Means for You
For anyone researching GSNA today, this is the single most important fact. Abeyance status means GIAC has paused new registrations and exam attempts while the certification's future is under review. It does not mean the credential has been revoked, and it does not affect people who already hold it.
- New candidates: Cannot currently register, purchase, or attempt the GSNA exam.
- Existing holders: Can still renew the credential, but only through Continuing Professional Education (CPE) credits - there is no exam-based renewal path being offered right now.
- Employers and recruiters: Should treat GSNA as a legacy-but-legitimate credential; holders earned it under a defined, proctored exam standard even though the exam is currently paused for new attempts.
If you're weighing whether to still pursue a related audit-focused credential path, our detailed breakdown at Is the GSNA Certification Worth It? Complete ROI Analysis 2026 walks through how the abeyance status should factor into that decision, and GSNA Certification Cost 2026: Complete Pricing Breakdown explains what the historical fee structure looked like before purchasing was suspended.
Exam Format and Historical Specifications
Because GSNA is in abeyance, the exam details below are historical - they describe what current and past holders sat for, and they remain relevant for anyone maintaining the credential or evaluating what it certifies. GIAC set these specifications through a scientific passing point study applied to all certification attempts on or after July 15, 2016, and reserves the right to change specifications without notice.
| Specification | Detail |
|---|---|
| Question Count | 115 questions |
| Time Limit | 3 hours |
| Passing Score | 73% |
| Format | Linear (non-adaptive), web-based |
| Reference Materials | Open book, printed materials permitted |
| Proctoring Options | Remote via ProctorU, or onsite via Pearson VUE |
The open-book, printed-materials-permitted policy is worth pausing on. GSNA was never designed to reward memorization of syntax; it was designed to test whether a candidate could locate, interpret, and apply audit checklists, benchmarks, and reference material under time pressure - a skill much closer to real-world audit work than a closed-book knowledge exam. For a full walkthrough of exactly how the 73% threshold is calculated and what it means for question-level margin, see GSNA Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
The 115-question, 3-hour, open-book format rewards candidates who bring organized reference material rather than those who try to memorize every command from scratch.
The Nine GSNA Domains
GIAC organizes GSNA around nine published objectives, each with its own outcome statement describing what a competent auditor should be able to do. Notably, the enterprise network domain has been explicitly updated to include cloud computing, containers, and physical networks - a sign that GIAC kept the content current even as the certification entered abeyance.
Domain 1: Auditing Access Control and Data Handling in Web Applications
Focuses on how access control models and data handling practices are implemented and verified within web applications.
- Session and authorization control review
- Sensitive data handling checks
Domain 2: Auditing the Enterprise Network
Covers evaluation of network architecture, segmentation, and perimeter controls - now explicitly extended to cloud environments, containers, and physical network infrastructure.
- Cloud and container audit scope
- Perimeter and segmentation review
Domain 3: Auditing UNIX and Linux Systems
Tests the ability to assess UNIX/Linux system configuration against security baselines.
- File permission and service configuration checks
- Baseline comparison techniques
Domain 4: Auditing Web Applications
Broader application-layer auditing beyond access control, including input handling and configuration weaknesses.
- Application configuration review
- Common vulnerability identification during audits
Domain 5: Auditing Windows Systems and Domains
Covers Windows and Active Directory domain configuration review from an audit perspective.
- Domain policy and group configuration audit
- Windows hardening baseline comparison
Domain 6: Risk Assessment for Auditors
Establishes the risk analysis techniques auditors apply before and during technical review work.
- Risk scoring and prioritization methods
- Translating technical findings into business risk
Domain 7: The Audit Process
Covers the structured methodology behind planning, executing, and reporting an audit engagement.
- Audit planning and scoping
- Evidence gathering and reporting standards
Domain 8: UNIX and Linux Logging and Continuous Monitoring
Focuses on log review and ongoing monitoring practices specific to UNIX/Linux environments.
- Log source identification and review
- Continuous monitoring process design
Domain 9: Windows Logging and Continuous Monitoring
The Windows equivalent of Domain 8, covering event log analysis and monitoring workflows.
- Windows event log interpretation
- Monitoring integration with audit findings
Because these nine domains span operating systems, applications, networks, and process, no single study track covers them evenly. For a domain-by-domain breakdown of weighting and study order, see GSNA Exam Domains 2026: Complete Guide to All 9 Content Areas, and for a candid assessment of which domains trip up most candidates, read How Hard Is the GSNA Exam? Complete Difficulty Guide 2026.
Who Pursues (and Hires For) GSNA
GSNA was never aimed exclusively at "security people." Its target audience is deliberately cross-functional:
- Internal and external auditors responsible for technical IT audit work
- Managers overseeing an audit or security team
- Security professionals who need to formalize audit methodology
- System administrators and network administrators who support or respond to audits
- Anyone implementing continuous monitoring processes across UNIX/Linux or Windows environments
This breadth is part of why GSNA holders show up in job titles ranging from IT auditor to compliance analyst to security engineer. If you're mapping GSNA against real job postings, GSNA Jobs catalogs the roles where the credential is most commonly listed, and GSNA Salary Guide 2026: Complete Earnings Analysis looks at how it's positioned relative to adjacent audit and security certifications.
Eligibility and Recertification
GSNA has no formal, enforced prerequisite - anyone could historically register and sit the exam. That said, O*NET classifies the credential at an Associate's degree education level, with an associated work-experience benchmark of more than two years, or possession of a core-level GIAC certification as an alternative path. In practice, this makes GSNA best suited to candidates who already have some operational exposure to the systems they'll be auditing, even without a formal gatekeeping requirement. A full breakdown of these expectations is available in GSNA Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Once earned, GSNA is valid for four years. Renewal is handled entirely through CPE credits - there is no requirement to retake the exam, and given the current abeyance status, CPE-based renewal is now the only path available to maintain the credential at all.
Preparing If You Already Hold GSNA
Even though new registrations are paused, plenty of readers arrive here already holding GSNA and needing to refresh domain knowledge for CPE activities, internal training, or simply to keep their audit skills sharp. A lightweight, domain-anchored review schedule works better than generic study advice here, because the nine domains don't require equal time - technical domains (UNIX/Linux, Windows) demand hands-on practice, while process domains (Audit Process, Risk Assessment) are better reviewed through case-study reading.
Process Foundations
- Review Domain 7 (Audit Process) and Domain 6 (Risk Assessment) outcome statements
- Re-read GIAC's published objectives for accuracy against current cloud/container updates
UNIX/Linux Technical Review
- Refresh Domain 3 configuration-auditing checklists
- Practice Domain 8 log review on a lab UNIX/Linux system
Windows and Web Application Review
- Revisit Domain 5 domain-policy audit steps
- Work through Domains 1 and 4 web application audit scenarios
Network and Monitoring Synthesis
- Study Domain 2's expanded cloud/container/physical network scope
- Consolidate Domain 9 monitoring notes alongside Domain 8 for cross-platform comparison
For candidates who sat the exam previously or are refreshing for CPE purposes, GSNA Study Guide 2026: How to Pass on Your First Attempt offers a more exhaustive resource list, and GSNA Cheat Sheet 2026: One-Page Review of Must-Know Facts is a fast reference for reviewing all nine domains in one sitting. You can also run through scenario-style questions on our practice test platform to keep audit reasoning sharp between renewal cycles.
If you're researching whether GSNA is still the right credential to list on a resume or reference in interviews, our broader overview at GSNA Certification and the qualifying question What Is A GSNA? both address how to talk about the credential given its current abeyance status. And if you're specifically building a training plan around the nine domains, GSNA Training lays out format options for structured review.
Frequently Asked Questions
No. GSNA is currently in abeyance, meaning it is not available for purchase or new registration. The official certification page displays an abeyance banner instead of a registration option.
No. Existing holders renew GSNA through CPE credits only. There is currently no exam-based renewal path being offered.
Historically, GSNA consisted of 115 questions with a 3-hour time limit and a 73% passing score, delivered as a linear, open-book, web-based exam proctored via ProctorU or Pearson VUE.
There is no formal, enforced prerequisite, though O*NET associates the credential with an Associate's degree education level and either more than two years of relevant experience or a core-level GIAC certification.
GSNA spans nine domains: web application access control and auditing, enterprise network auditing (including cloud, containers, and physical networks), UNIX/Linux and Windows systems auditing, risk assessment, the audit process itself, and continuous monitoring/logging for both UNIX/Linux and Windows.