Passed GCIA (SEC503)
Disclaimer: I'm enrolled in the SANS master program and now have completed GSEC, GCIH. GWAPT, and GCIA.
I have to say I really enjoyed this course after I started to actually absorb the information. Going through book 1 and 2 the first time was mentally draining but after the 3rd go around, everything started to come together. So for anyone taking this class in the future, don't get overwhelmed with the first two books, give it time and you'll start absorbing the concepts. Once you grasp the information in the first two books, I believe books 3,4, and 5 are cake...just understand how to use tcpdump, tshark, wireshark, snort, and bro (run through the labs 2-3 times and you'll be a good spot).
Tips for the exam:
**Bring the following with you**
1) A chart that shows you the conversion between decimal/hex/binary (very useful, you dont' want to be converting hex during the exam if you don't have to)
2) Print out a few IP and TCP headers in hex format and label each field...doing this alone helped me solve 8-10 problems
3) Print out all of the ICMP codes (I used this: erg.abdn.ac.uk/users/gorry/course/inet-pages/icmp-code.html)
4) Print out a list of examples for: tcpdump commands, wireshark commands, tshark commands, snort rules, bro scripts, silk commands
SANS provides a book with tcpdump and wireshark commands but I found my personal list to help more
5) The practice exams will tell you where you stand...I received a 87% on my second practice exam and received an 87% on my actual test
6) Great website to test your skills during and after the class: www.malware-traffic-analysis.net/