GCFW or GCIA? Or..?
I have a college degree in network security (information systems) and my Security+ (passed with a 900), and Network+. I know a little bit about system administration and system hardening from school, and from playing around with Windows Server and Linux Red Hat. I have one year experience in the Information Assurance/Cyber Security field. I write policy documents about the security of interconnections between two different agencies. My company recently promoted me, gave me a big raise, and offered to pay for training. I need to decide which training I want.
I want more technical experience, and I originally thought about taking the GSEC, or the CCNA Security, and getting the official training for either. But after talking to a senior manager (in Cyber Security) that routinely helps others figure out what career path to take, and which certifications to take, he said that the GSEC is not really looked upon as better than the Security+ by the industry at this time, and a friend of mine that took and passed the GSEC a few years ago said that it is basically half Security+ knowledge, and half system admin knowledge, and the sys admin part of it is really hard. He said that he took the SANS class and the cert test as a few others in his company and was the only one that passed because of the in depth Windows questions. He only knew enough about that because he had been a sys admin for several years. The senior manager I talked to recommended the GCIA, the GCIH, or the GCFA. He especially recommended the GCIH, although he said that it might be better to have the GCIA before taking the GCIH, and then the GCFA would be after that. But, that I could just skip to the GCIH if I wanted.
I am interested in all of those things, but once I looked more into it, I realized that I may want to take the GCFW first. I work with perimeter security concepts, and knowing more about the technical aspects of that may help me in my current job, as well as future jobs. I am not sure what I want to do yet. I do like the policy, but I don't see it being satisfying long term. I do network diagrams, and write detailed descriptions of security features. I have a built in BS filter, and know how to verify the information, but additional technical network design/structure concepts would help. I have always been interested in VPNs, and the technical details of NAT and routing/switching, and I am also a little interested in security auditing. I feel like in depth packet analysis like in the GCIA is something I want to learn, but I think I may want to do that a little later on, after I have more of a foundation in Security.Incident handling sounds really cool too, but I don't really want to work in a SOC at this time.
I found this site by searching about the practical applications of the training/certifications. I read a post that mentioned that the GCFW and the GCIA having a lot of overlapping material. I was wondering if I could take the GCIA because it is more recognized and "valuable" and still learn about what I was attracted to in the GCFW. Which parts overlap?
Also, I am worried about the difficulty of these, because I am still sort of a beginner. Any advice is appreciated.