GSNA logo
Focused certification exam prep
Start practice

What Is GSNA Certification?

TL;DR
  • GSNA is in abeyance - it cannot currently be purchased or registered for.
  • Existing holders keep the credential active by earning CPEs, not by retaking an exam.
  • The historical exam had 115 questions, a 3-hour limit, and a 73% passing score.
  • GSNA covers nine domains spanning UNIX/Linux, Windows, web applications, and risk assessment.

What GSNA Actually Is

The GIAC Systems and Network Auditor (GSNA) certification is a vendor-neutral credential issued by the Global Information Assurance Certification (GIAC), an ANAB-accredited body under ISO/IEC 17024 that is affiliated with the SANS Institute. GSNA was built to validate one specific and often underappreciated skill set: the ability to apply risk analysis techniques and conduct technical audits of core information systems - networks, perimeters, and applications - rather than simply configuring or defending them.

That distinction matters. Where many security certifications test whether you can build or harden a system, GSNA tests whether you can independently verify that a system is actually configured the way policy claims it is, find the gaps, and report them in a way leadership can act on. If you're trying to understand the credential from the ground up, our companion piece What Is GSNA? covers the naming and origin story in more depth, while GSNA Meaning and What Does GSNA Stand For? unpack the acronym itself for readers encountering it for the first time.

The Abeyance Status: What It Means for You

Critical Update: GSNA is currently in abeyance. It is no longer available for purchase, and the official certification page now displays an abeyance banner in place of a registration option. GIAC has not published a public timeline for reinstating or permanently retiring it.

For anyone researching GSNA today, this is the single most important fact. Abeyance status means GIAC has paused new registrations and exam attempts while the certification's future is under review. It does not mean the credential has been revoked, and it does not affect people who already hold it.

  • New candidates: Cannot currently register, purchase, or attempt the GSNA exam.
  • Existing holders: Can still renew the credential, but only through Continuing Professional Education (CPE) credits - there is no exam-based renewal path being offered right now.
  • Employers and recruiters: Should treat GSNA as a legacy-but-legitimate credential; holders earned it under a defined, proctored exam standard even though the exam is currently paused for new attempts.

If you're weighing whether to still pursue a related audit-focused credential path, our detailed breakdown at Is the GSNA Certification Worth It? Complete ROI Analysis 2026 walks through how the abeyance status should factor into that decision, and GSNA Certification Cost 2026: Complete Pricing Breakdown explains what the historical fee structure looked like before purchasing was suspended.

Exam Format and Historical Specifications

Because GSNA is in abeyance, the exam details below are historical - they describe what current and past holders sat for, and they remain relevant for anyone maintaining the credential or evaluating what it certifies. GIAC set these specifications through a scientific passing point study applied to all certification attempts on or after July 15, 2016, and reserves the right to change specifications without notice.

SpecificationDetail
Question Count115 questions
Time Limit3 hours
Passing Score73%
FormatLinear (non-adaptive), web-based
Reference MaterialsOpen book, printed materials permitted
Proctoring OptionsRemote via ProctorU, or onsite via Pearson VUE

The open-book, printed-materials-permitted policy is worth pausing on. GSNA was never designed to reward memorization of syntax; it was designed to test whether a candidate could locate, interpret, and apply audit checklists, benchmarks, and reference material under time pressure - a skill much closer to real-world audit work than a closed-book knowledge exam. For a full walkthrough of exactly how the 73% threshold is calculated and what it means for question-level margin, see GSNA Passing Score 2026: Exactly What You Need to Pass.

Key Takeaway

The 115-question, 3-hour, open-book format rewards candidates who bring organized reference material rather than those who try to memorize every command from scratch.

The Nine GSNA Domains

GIAC organizes GSNA around nine published objectives, each with its own outcome statement describing what a competent auditor should be able to do. Notably, the enterprise network domain has been explicitly updated to include cloud computing, containers, and physical networks - a sign that GIAC kept the content current even as the certification entered abeyance.

Domain 1: Auditing Access Control and Data Handling in Web Applications

Focuses on how access control models and data handling practices are implemented and verified within web applications.

  • Session and authorization control review
  • Sensitive data handling checks

Domain 2: Auditing the Enterprise Network

Covers evaluation of network architecture, segmentation, and perimeter controls - now explicitly extended to cloud environments, containers, and physical network infrastructure.

  • Cloud and container audit scope
  • Perimeter and segmentation review

Domain 3: Auditing UNIX and Linux Systems

Tests the ability to assess UNIX/Linux system configuration against security baselines.

  • File permission and service configuration checks
  • Baseline comparison techniques

Domain 4: Auditing Web Applications

Broader application-layer auditing beyond access control, including input handling and configuration weaknesses.

  • Application configuration review
  • Common vulnerability identification during audits

Domain 5: Auditing Windows Systems and Domains

Covers Windows and Active Directory domain configuration review from an audit perspective.

  • Domain policy and group configuration audit
  • Windows hardening baseline comparison

Domain 6: Risk Assessment for Auditors

Establishes the risk analysis techniques auditors apply before and during technical review work.

  • Risk scoring and prioritization methods
  • Translating technical findings into business risk

Domain 7: The Audit Process

Covers the structured methodology behind planning, executing, and reporting an audit engagement.

  • Audit planning and scoping
  • Evidence gathering and reporting standards

Domain 8: UNIX and Linux Logging and Continuous Monitoring

Focuses on log review and ongoing monitoring practices specific to UNIX/Linux environments.

  • Log source identification and review
  • Continuous monitoring process design

Domain 9: Windows Logging and Continuous Monitoring

The Windows equivalent of Domain 8, covering event log analysis and monitoring workflows.

  • Windows event log interpretation
  • Monitoring integration with audit findings

Because these nine domains span operating systems, applications, networks, and process, no single study track covers them evenly. For a domain-by-domain breakdown of weighting and study order, see GSNA Exam Domains 2026: Complete Guide to All 9 Content Areas, and for a candid assessment of which domains trip up most candidates, read How Hard Is the GSNA Exam? Complete Difficulty Guide 2026.

Who Pursues (and Hires For) GSNA

GSNA was never aimed exclusively at "security people." Its target audience is deliberately cross-functional:

  • Internal and external auditors responsible for technical IT audit work
  • Managers overseeing an audit or security team
  • Security professionals who need to formalize audit methodology
  • System administrators and network administrators who support or respond to audits
  • Anyone implementing continuous monitoring processes across UNIX/Linux or Windows environments

This breadth is part of why GSNA holders show up in job titles ranging from IT auditor to compliance analyst to security engineer. If you're mapping GSNA against real job postings, GSNA Jobs catalogs the roles where the credential is most commonly listed, and GSNA Salary Guide 2026: Complete Earnings Analysis looks at how it's positioned relative to adjacent audit and security certifications.

Practical Note: Because GSNA blends audit process (Domain 7), risk assessment (Domain 6), and hands-on technical review (Domains 1-5, 8-9), it's one of the few GIAC credentials aimed as much at process-and-reporting skill as at technical depth.

Eligibility and Recertification

GSNA has no formal, enforced prerequisite - anyone could historically register and sit the exam. That said, O*NET classifies the credential at an Associate's degree education level, with an associated work-experience benchmark of more than two years, or possession of a core-level GIAC certification as an alternative path. In practice, this makes GSNA best suited to candidates who already have some operational exposure to the systems they'll be auditing, even without a formal gatekeeping requirement. A full breakdown of these expectations is available in GSNA Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Once earned, GSNA is valid for four years. Renewal is handled entirely through CPE credits - there is no requirement to retake the exam, and given the current abeyance status, CPE-based renewal is now the only path available to maintain the credential at all.

Preparing If You Already Hold GSNA

Even though new registrations are paused, plenty of readers arrive here already holding GSNA and needing to refresh domain knowledge for CPE activities, internal training, or simply to keep their audit skills sharp. A lightweight, domain-anchored review schedule works better than generic study advice here, because the nine domains don't require equal time - technical domains (UNIX/Linux, Windows) demand hands-on practice, while process domains (Audit Process, Risk Assessment) are better reviewed through case-study reading.

Week 1

Process Foundations

  • Review Domain 7 (Audit Process) and Domain 6 (Risk Assessment) outcome statements
  • Re-read GIAC's published objectives for accuracy against current cloud/container updates
Week 2

UNIX/Linux Technical Review

  • Refresh Domain 3 configuration-auditing checklists
  • Practice Domain 8 log review on a lab UNIX/Linux system
Week 3

Windows and Web Application Review

  • Revisit Domain 5 domain-policy audit steps
  • Work through Domains 1 and 4 web application audit scenarios
Week 4

Network and Monitoring Synthesis

  • Study Domain 2's expanded cloud/container/physical network scope
  • Consolidate Domain 9 monitoring notes alongside Domain 8 for cross-platform comparison

For candidates who sat the exam previously or are refreshing for CPE purposes, GSNA Study Guide 2026: How to Pass on Your First Attempt offers a more exhaustive resource list, and GSNA Cheat Sheet 2026: One-Page Review of Must-Know Facts is a fast reference for reviewing all nine domains in one sitting. You can also run through scenario-style questions on our practice test platform to keep audit reasoning sharp between renewal cycles.

If you're researching whether GSNA is still the right credential to list on a resume or reference in interviews, our broader overview at GSNA Certification and the qualifying question What Is A GSNA? both address how to talk about the credential given its current abeyance status. And if you're specifically building a training plan around the nine domains, GSNA Training lays out format options for structured review.

Frequently Asked Questions

Can I still register for the GSNA exam?

No. GSNA is currently in abeyance, meaning it is not available for purchase or new registration. The official certification page displays an abeyance banner instead of a registration option.

If I already hold GSNA, do I need to retake the exam to keep it?

No. Existing holders renew GSNA through CPE credits only. There is currently no exam-based renewal path being offered.

What was the passing score and format for the GSNA exam?

Historically, GSNA consisted of 115 questions with a 3-hour time limit and a 73% passing score, delivered as a linear, open-book, web-based exam proctored via ProctorU or Pearson VUE.

Is there a prerequisite to earn GSNA?

There is no formal, enforced prerequisite, though O*NET associates the credential with an Associate's degree education level and either more than two years of relevant experience or a core-level GIAC certification.

What topics does GSNA actually cover?

GSNA spans nine domains: web application access control and auditing, enterprise network auditing (including cloud, containers, and physical networks), UNIX/Linux and Windows systems auditing, risk assessment, the audit process itself, and continuous monitoring/logging for both UNIX/Linux and Windows.

Ready to pass your GSNA exam?

Put this into practice with free GSNA questions across every exam domain.