JDMurray said: Please post some links to this certification.
chrisone said: The eLearnSecurity Incident Response Professional certification will require that you take the necessary INE IHRP course. If you just want to take the exam, I don't think this will be a wise decision and a waste of your $400. Ultimately if you choose to take the exam without the course, I advise you to look at the syllabus, note all the topics and do your own googling for tutorials on each topic until you have mastered them. The eCIR is a highly technical certification that requires advanced knowledge of networks, systems and cyber attacks. Anyone can attempt the certification exam; however, below are suggested skills to possess for a successful outcome:Letters of engagement and the basics related to an Incident Response engagementAdvanced networking conceptsKnowledge of Incident Response processes and methodologiesPacket/traffic analysisAbility to correlate events and logsFamiliarly with tools such as Wireshark, ELK & SplunkCyber crime Techniques, Tactics & ProceduresDetection of all stages of the “Cyber Kill Chain”Familiarity with ELK and Splunk searchesAbility to effectively analyze thousands of events within a SIEMGood understanding of Windows (and Sysmon) eventsAttacker activity detection through process analysisGood luck on your journey.