±Your Account
Membership:
New Today: 0
New Yesterday: 0
Overall: 24209
Visitors: 31±Latest Webinar
±Latest Articles
· Android Forensics
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Go to page Previous 1, 2, 3 Next
I used indexing for the GCIH -GIAC Certified Incident Handler. What I did was make an excel sheet with the Exam Certification Objectives and list the page where it could be find.
You still need to know the material and how to locate it fast.
GCFA v. GCFE
Re: GCFA v. GCFE
Posted: Mon Sep 26, 2011 6:51 pm
Josh,
Sorry you did not pass. I took it and passed, so I will be getting my plaque this week.
I think the key for me was going over the book and indexing EVERYTHING. I had over 40 place holders in the three books and it helped tremendously when I took the open book test to have the detailed index that I had. Hopefully you will not be too discouraged and try to retake the certification course. I agree it was not easy and there were questions outside of what the reviews had, but overall it was pretty much covered in the book.
good luck!
Sorry you did not pass. I took it and passed, so I will be getting my plaque this week.
I think the key for me was going over the book and indexing EVERYTHING. I had over 40 place holders in the three books and it helped tremendously when I took the open book test to have the detailed index that I had. Hopefully you will not be too discouraged and try to retake the certification course. I agree it was not easy and there were questions outside of what the reviews had, but overall it was pretty much covered in the book.
good luck!
-

diorillo - Newbie
Re: GCFA v. GCFE
Posted: Tue Sep 27, 2011 8:43 am
That's what I did too. I had them everywhere on all three books. What books were you using? Maybe that's my problem.
-

Joshsevo - Senior Member
Re: GCFA v. GCFE
Posted: Thu Sep 29, 2011 11:25 pm
- diorilloJosh,
Sorry you did not pass. I took it and passed, so I will be getting my plaque this week.
I think the key for me was going over the book and indexing EVERYTHING. I had over 40 place holders in the three books and it helped tremendously when I took the open book test to have the detailed index that I had. Hopefully you will not be too discouraged and try to retake the certification course. I agree it was not easy and there were questions outside of what the reviews had, but overall it was pretty much covered in the book.
good luck!
I used indexing for the GCIH -GIAC Certified Incident Handler. What I did was make an excel sheet with the Exam Certification Objectives and list the page where it could be find.
You still need to know the material and how to locate it fast.
-

felixdz - Newbie
Re: GCFA v. GCFE
Posted: Fri Oct 07, 2011 4:08 pm
What books did you use? The name of it? Where did you get it?
-

Joshsevo - Senior Member
Re: GCFA v. GCFE
Posted: Mon Oct 10, 2011 2:33 am
I did GCFE off the back of the SANS408 course so had the courseware. Fully agree with indexing, I did almost exactly the same with Word and the course objectives. I also put together an Excel file - a 'cheat sheet' - with lists of (e.g.) File System info across different OS versions, Event Codes, etc etc.
-

Cults14 - Senior Member
Re: GCFA v. GCFE
Posted: Wed Oct 26, 2011 1:23 pm
I took both the 508 and the 408. Without a doubt to me the 508 was 10x harder then the 408. There were times in the 508 class I was just gonna toss my laptop across the room. My instructor was Dave Hull.
I took the 408 after the 508, I know a bit backwards. My instructor for 408 was Ovie Caroll. They taught us the new material but were in the process of writing up the test at the time of the class.
Both instructors were great.
As was mentioned I found 408 to be more basic general information and it was all about using the GUI tools. Where as the 508 was all command line and it was very LONNNNGGG command lines. I get the gist of the SIFT kit but in real life I could not imagine using that thing at all and I expressed that in class.
Personally I feel the GCFA should hold more weight then the GCFE since it is the 2nd step in the forensic classes if you get what I'm saying.
I took the 408 after the 508, I know a bit backwards. My instructor for 408 was Ovie Caroll. They taught us the new material but were in the process of writing up the test at the time of the class.
Both instructors were great.
As was mentioned I found 408 to be more basic general information and it was all about using the GUI tools. Where as the 508 was all command line and it was very LONNNNGGG command lines. I get the gist of the SIFT kit but in real life I could not imagine using that thing at all and I expressed that in class.
Personally I feel the GCFA should hold more weight then the GCFE since it is the 2nd step in the forensic classes if you get what I'm saying.
-

Bobbynyc - Member
Re: GCFA v. GCFE
Posted: Tue Nov 08, 2011 11:38 am
I did my GCFA self study without SANS's books... let me tell you it was rough... what I did was drafted a book I dubbed "The Constitution" and researched what type of questions would be on the test as much as possible.... I had all of the cheat sheets, I printed out every law I could possibly imagine (The laws were probably the hardest on the test for me as I did not know the German laws to well)
I have no experience with the GCFE... but I've always been curious and I kind of want to take it just to say that I did
I have no experience with the GCFE... but I've always been curious and I kind of want to take it just to say that I did
-

ckimmel - Member
















