- What Is A GFACT, Exactly?
- Who Issues the GFACT and Why It Matters
- Exam Format: Questions, Time, Passing Score
- The Nine GFACT Domains
- Who a GFACT Is Actually For
- Cost, Registration, and Renewal Mechanics
- The SEC275 Training Connection
- A Realistic Study Approach
- GFACT vs. Other Entry-Level Options
- Frequently Asked Questions
- A GFACT is a GIAC entry-level certification covering nine foundational cybersecurity domains, no prerequisites required.
- The exam is 75 questions, 2 hours, with a 71 percent minimum passing score.
- Attempts cost $399, and GFACT is one of the two cheapest GIAC certifications alongside GISF.
- Certification lasts four years and renews with 36 CPEs plus a $199 fee, or a retake.
What Is A GFACT, Exactly?
A GFACT is a credential earned by passing the GIAC Foundational Cybersecurity Technologies exam. It is not a job title, a degree, or a beginner's badge with no substance - it is a formally accredited personnel certification that verifies someone understands the technical building blocks underneath every other security specialty: hardware, operating systems, networking, programming logic, and core security concepts. When someone says "I hold a GFACT," they mean they passed a single proctored exam that GIAC has validated through a psychometric standard-setting study, the same rigor applied to GIAC's advanced certifications.
Unlike many entry-level IT badges that test memorized vocabulary, GFACT is designed to confirm a candidate can actually reason through foundational technical scenarios - how a filesystem stores data, how a switch forwards a frame, how a simple script executes. That distinction matters if you're evaluating whether the letters after someone's name reflect real understanding. For a full breakdown of what "GFACT" as an acronym and program represents, see our companion piece on GFACT meaning and the related explainer on what GFACT stands for.
Who Issues the GFACT and Why It Matters
GFACT is issued by the Global Information Assurance Certification body - GIAC - which is affiliated with the SANS Institute and accredited by ANAB under the ISO/IEC 17024 standard for personnel certification. That accreditation is not marketing fluff; it means GIAC's exam development, scoring, and psychometric processes are audited against an international standard, the same framework used for certifications in engineering, healthcare, and other regulated fields. This is part of why GFACT maps cleanly to DoD 8140 directives and NIST NICE work role frameworks - government and enterprise hiring pipelines can point to GFACT as evidence of a specific, standardized skill set rather than a vague "cybersecurity awareness" claim.
If you want the full institutional picture - history, governing body details, and how GFACT sits inside GIAC's broader catalog - the dedicated GFACT Certification overview and the What Is GFACT Certification? article both go deeper on that context.
Exam Format: Questions, Time, Passing Score
The GFACT exam is a single proctored test: 75 questions, a 2-hour window, and a minimum passing score of 71 percent for all exam versions released on or after July 24, 2021. That threshold isn't arbitrary - GIAC sets it through a formal standard-setting study rather than a round-number guess, which means it reflects the actual difficulty of the current question pool rather than a marketing-friendly figure.
You can sit for the exam two ways: remote proctoring through ProctorU, or onsite proctoring through Pearson VUE testing centers. Once you activate your attempt, you have 120 days to schedule and complete it - plenty of runway, but it's a hard deadline, not a suggestion. Missing a scheduled proctored appointment triggers a $175 reseating fee plus a 7-day extension, so treat your exam date like a real appointment, not a placeholder.
For the exact scoring mechanics and what 71 percent actually means question-by-question, read the dedicated GFACT Passing Score breakdown. If you're trying to gauge overall difficulty before committing, How Hard Is the GFACT Exam? and GFACT Pass Rate 2026 both address that question using the data GIAC actually publishes.
Key Takeaway
Two hours for 75 questions gives you roughly 96 seconds per question on average - tight enough that you should practice time-boxing decisions during prep, not just content review.
The Nine GFACT Domains
GIAC publishes nine official Certification Objectives and Outcome Statements, and the exam draws from nine corresponding content domains. Understanding what each domain actually demands - not just its title - is the single most important thing you can do before registering.
Domain 1: Computer Hardware & Virtualization
Covers how physical components (CPU, memory, storage, I/O) interact, plus how virtualization abstracts hardware for VMs and cloud instances.
- Understand hypervisor types and virtual machine isolation basics
Domain 2: Exploitation & Mitigation
Introduces how vulnerabilities are discovered and exploited at a conceptual level, paired with the defensive controls that mitigate them.
- Know common vulnerability classes and matching mitigation strategies
Domain 3: Forensics & Post-Exploitation
Focuses on evidence handling, artifact analysis, and what happens technically after a system is compromised.
- Recognize where forensic artifacts persist across file systems and logs
Domain 4: Linux Foundations
Tests command-line fluency, file permissions, process management, and basic shell operations - hands-on labs in the associated course are built specifically around this.
- Practice navigating and manipulating a Linux filesystem from the terminal
Domain 5: Logic & Programming
Covers programming fundamentals - variables, loops, conditionals, functions - as a lens for understanding how software (and malware) actually behaves.
- Be able to trace the logic of a short script without running it
Domain 6: Networking & Servers
Addresses the OSI/TCP-IP model, common protocols, addressing, and how servers handle client requests.
- Know how a packet moves from client to server at each layer
Domain 7: Operating Systems, The Web, & Data Storage
Blends OS architecture concepts with how web requests function and how data is stored and retrieved.
- Understand client-server web architecture and basic database storage concepts
Domain 8: Security Concepts
Establishes the CIA triad, risk fundamentals, authentication/authorization, and core security terminology used across every other domain.
- Master the vocabulary - it underpins questions in every other domain too
Domain 9: Windows Foundations
Mirrors the Linux domain but for Windows: registry basics, permissions, processes, and administrative tools.
- Compare Windows and Linux permission models side by side while studying
Because these nine domains span hardware, two operating systems, networking, programming, and applied security concepts simultaneously, GFACT tests breadth more than depth. That's intentional - it's a foundations exam. For a domain-by-domain study weighting strategy and objective-level detail, the GFACT Exam Domains Guide is the most thorough resource to pair with this overview.
Who a GFACT Is Actually For
GIAC positions GFACT explicitly as an entry-level credential - there are no prerequisites, and no prior certification or degree is required to register. In practice, the people who pursue it fall into a few recognizable groups:
- Career changers moving into IT or security from an unrelated field who need a credential that proves baseline technical competence.
- Students still in or just out of school who want a recognized certification before their first job search.
- New IT and cybersecurity hires whose employer wants a standardized skills baseline across a team.
- Business professionals in adjacent roles (compliance, project management, sales engineering) who need technical literacy without becoming full-time practitioners.
- Self-driven learners and re-skilling program participants, including military transition and workforce development cohorts.
Because GFACT maps to DoD 8140 directives and NIST NICE work roles, it's also recognized in government and defense-adjacent hiring, which is part of why searches for GFACT jobs and compensation expectations keep growing. If you're weighing whether the credential translates into measurable career or pay outcomes, the GFACT Salary Guide and Is the GFACT Certification Worth It? articles walk through that analysis without relying on invented numbers.
Cost, Registration, and Renewal Mechanics
A GFACT attempt costs $399. If you don't pass, a retake is $199, and if you need more time before your attempt window closes, an extension is $199. These fees put GFACT alongside GISF as one of the two cheapest certifications in GIAC's entire catalog - most GIAC specialty exams run considerably higher, so GFACT's pricing is itself a signal of its intended entry-level audience.
| Item | Cost |
|---|---|
| Certification attempt | $399 |
| Retake | $199 |
| Attempt extension | $199 |
| Renewal | $199 |
| Practice exam (official) | $189 |
Once activated, an attempt must be completed within 120 days. Certification itself is valid for four years. To renew, you need 36 CPE credits accumulated within that active four-year window plus the renewal fee - or you can simply retake the current version of the exam. Work experience counts toward CPEs at a rate of 1 credit per month, capped at 12 per year, so relevant job time alone won't fully cover the 36-credit requirement without some additional training or activity. One quirk worth noting: renewed certifications extend four years from the current expiration date, not from the date you actually renew - and GIAC lists no grace period after expiration, so letting the clock run out means starting over. For the complete fee schedule and renewal math laid out year by year, see GFACT Certification Cost: Complete Pricing Breakdown. Eligibility specifics, including confirmation that there truly are no prerequisites, are covered in GFACT Requirements 2026, and scheduling logistics around the 120-day window are detailed in GFACT Exam Dates 2026.
The SEC275 Training Connection
GFACT has an associated (but not mandatory) training course: SANS SEC275, Foundations, authored by SANS CTO James Lyne. The course is built around hands-on labs in Linux, encryption, and programming - direct hands-on practice mapped to Domains 4, 5, and portions of 8. It's worth noting that even though the course leans heavily on lab work, the GFACT exam itself is not CyberLive (GIAC's hands-on lab exam format used for some other certifications) - it's a standard proctored knowledge exam. That means SEC275 is a preparation vehicle, not a testing format requirement; you can absolutely study independently and never touch the official course, though its lab structure explains why so many candidates report that practicing actual Linux commands and simple scripts beats passive reading. Our GFACT Training resource compares SEC275 against self-study paths in more detail.
A Realistic Study Approach
Because GFACT spans nine unrelated technical areas rather than one deep specialty, the most efficient prep sequence groups related domains together instead of studying them in numeric order. Pairing Linux Foundations with Windows Foundations lets you study permissions and process management comparatively; pairing Networking & Servers with Operating Systems, The Web, & Data Storage builds one coherent mental model of how a request travels from client to disk.
Security Concepts + Hardware & Virtualization
- Build the vocabulary (Domain 8) that every other domain assumes you already know
- Learn hardware/VM basics (Domain 1) before layering OS concepts on top
Linux + Windows Foundations
- Do hands-on command-line practice for both operating systems back to back
- Compare permission models directly rather than studying each in isolation
Networking & Servers + Web/Data Storage
- Trace a full request path from client through network layers to server storage
Logic & Programming + Exploitation/Forensics
- Read and trace short scripts, then connect that logic to how exploits and forensic artifacts actually work
GFACT vs. Other Entry-Level Options
Because GFACT sits at the very bottom of GIAC's certification ladder in terms of prerequisites and price, it's often compared to other beginner-friendly security credentials. The main differentiator is breadth: GFACT's nine domains intentionally span hardware, two operating systems, networking, and programming logic in one exam, rather than concentrating on a single narrow topic. That's also why it pairs naturally with a hands-on practice test - you can drill weak domains individually rather than re-reading dense material, which is exactly the kind of targeted repetition we built our practice exams on the main GFACT Exam Prep site to support.
If you're still deciding whether "GFACT" refers to the exam, the certification, or the credential holder, that terminology distinction is worth thirty seconds of reading - see What Is GFACT? and What Does GFACT Mean? for the precise usage differences, since people casually use all three interchangeably in job postings and LinkedIn profiles.
Key Takeaway
GFACT's value is breadth, not depth - treat it as proof you understand how every layer of a computing environment connects, not as a deep specialization credential.
Frequently Asked Questions
No. A GFACT verifies foundational technical knowledge across nine domains through a single 75-question exam - it's a credential, not a degree, and typically takes weeks to prepare for rather than years.
No. GIAC lists no prerequisites for GFACT, which is why it's marketed toward career changers, students, and new hires with no prior security background.
The initial attempt is $399. Retakes and extensions are $199 each, and renewal every four years costs $199 plus 36 CPE credits, or a full retake of the current exam version.
No. Despite the associated SEC275 course being lab-heavy, the GFACT exam itself is not CyberLive - it's a standard proctored, multiple-choice-style knowledge exam taken via ProctorU or Pearson VUE.
GIAC lists no grace period after expiration. Once your four-year validity period ends without renewal, you would need to retake the current exam version to regain certification.