GCFE passed

in GIAC
I took the OnDemand FOR-408 (Computer Forensic Investigations - Windows In-Depth) course. I've spent about a week at the beginning of May to watch all the videos and do all the assessment quizzes. I did not have the time to do any practice labs for the course. I was busy at work.
My OnDemand course and certification attempt will expire at the end of this month. So I took a practice test on Monday and passed without any preparation. I took another practice test on Thursday and passed again. 90% of the questions are the same as the first attempt.
I sat for the real test today and passed. First time to sit on a GIAC cert. and with open books test. Most of the answers for the exam are found textually on the SANS course books. If you did a good index of the books, you can pass the exam with little preparation.
SANS is preparing a new version of the OnDemand FOR-408 course. When I bought the course, the description said it will show FTK and EnCase. But the course video showed only FTK, even if there are slides about EnCase in the book. You got a Windows 7 Home Premium VMware virtual machine with the course but the Windows license is not included. You need to buy yourself a retail Windows 7 Home Premium license (not volume license) to activate Windows on the VM.
My OnDemand course and certification attempt will expire at the end of this month. So I took a practice test on Monday and passed without any preparation. I took another practice test on Thursday and passed again. 90% of the questions are the same as the first attempt.
I sat for the real test today and passed. First time to sit on a GIAC cert. and with open books test. Most of the answers for the exam are found textually on the SANS course books. If you did a good index of the books, you can pass the exam with little preparation.
SANS is preparing a new version of the OnDemand FOR-408 course. When I bought the course, the description said it will show FTK and EnCase. But the course video showed only FTK, even if there are slides about EnCase in the book. You got a Windows 7 Home Premium VMware virtual machine with the course but the Windows license is not included. You need to buy yourself a retail Windows 7 Home Premium license (not volume license) to activate Windows on the VM.
Knowledge has no value if it is not shared.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
Comments
Good job on the pass, by the way. Did you feel 408 was worth the money?
You could work on a non-activated Windows 7. It will have the "This version of Windows is not genuine" message at the bottom of your desktop. But I hope that it will come at least with an activated Windows 7 license, since I paid over 4K dollars for the course.
The practice and real tests are 4-hour format, 150 short questions with multiple choice answers. There's only one answer per question to choose. There's no drag-and-drop question à la Microsoft exam. They show your score on screen for every 15 questions.
I feel the FOR-408 course did not worth 4K dollars. I was aiming at the advanced FOR-508 course but I failed the assessment test for it. Because I did not know about some e-Discovery terminology and methodology, and about Firefox artifacts (I mainly use Internet Explorer). If I've read a book about digital forensic or e-Discovery before taking the assignment test, I would pass.
I took the FOR-408 anyway hoping to learn about EnCase and then challenging the EnCE cert. But they removed the EnCase portion of the course. If you're an experienced Windows desktop admin or a MCTS 70-680, you won't learn much from this course. The instructor talked a lot about anecdotes and jokes. The slides and videos are not in HD. When you view it in full screen, the image is blurred. With the OnDemand version, you don't get the image file for the last day e-Discory challenge of the course. The slides and text notes are "protected" inside the browser. You can't copy and paste it to a text editor. They also disabled the mouse right click button.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
The OnDemand materials is done in the Java window and as such they've disabled copy / paste functions, presumably to protect their intellectual property. I think the objective is to have students rely on the written paper-based materials. I understand that point of view, but there's actually a discussion right now on the SANS Advisory Board list discussing electronic formats for the textbooks. Offensive Security provides all their materials in e-format, but they watermark your personal information on there for attribution.
If anything, at least let SANS know about your feelings. Hopefully it'll improve things.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
There's often a special deal for their courses if you're on their mailing list. When I bought mine, there was a 15% off from the regular price. Right now, I think there's a $1500 rebate if you take some SANS community course before August 15th, 2012. For the qualifying online course, you can get a $850 discount if registered before July 25th, 2012. And if you pre-purchase an upcoming OnDemand course, you can get a 25% off.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
http://www.sans.org/ondemand/specials
They change it from time to time. Sometimes it's like a free Mac mini, other times it's a 25% discount.
Knowledge can cure ignorance, but intelligence cannot cure stupidity.
Yesterday, I took my GCFE exam and passed the exam. It took roughly 14 days to prepare for the exam with 3 to 4 hrs a day. I went through the ondemand videos and Indexed my SANS course book. I did not read the book which was not a good idea as you will miss certain key points which were not covered in the on demand video. The questions were more on concepts and how it been applied. I had a very few direct questions which I can answer without referring the book.
This is my first GIAC exam and open book was really a challenge for me.
I suggest you all to go through the book atleast once and highlight the important words as you will be left with very little time to search for keywords during the exam.
Also, have a constant watch on the "Time" as it flies away very easily and you have on average 90 to 95 seconds to answer one question.
I did not look at the online scores (Which is populated on your screen for every 15 questions) as it makes me feel more nervous. This sometimes boosts your confidence when you are scoring high but most of the time it will test your emotions and concentration. Especially if your scores are dropping.
Finally I managed to finish my exam with three seconds left and the best of all I PASSED. All the very best for everybody who is preparing for this exam.
Regards,
Santhosh
GCFE, CISA, CISSP, CCSA
http://adarsh.amazonwebservices.ninja
Current Studying : GPEN |GCNF|CISSP??
Current Reading : CISSP| CounterHack|Gray Hat Hacking
Completed 2019 : GCIH
Free Reading : History Books
Current Studying : GPEN |GCNF|CISSP??
Current Reading : CISSP| CounterHack|Gray Hat Hacking
Completed 2019 : GCIH
Free Reading : History Books
Masters of Information Systems Management with Enterprise Information Security - Walden University
Masters of Science in Information Assurance - Western Governors University
Masters of Science Cyber Security/Digital Forensics - University of South Florida