FillAwful wrote: » I can only speak for GCIA. I agree with EW, the only materials I used for GCIA were what SANS provided. The **** sheets were very necessary for quickly checking packet offsets. I did find this blog MalwareJake: Packet analysis practice part 1 where the author provides some practice questions for hex packet analysis. You should be able to do these types of questions quickly and without much effort to pass the GCIA. Any materials to supplement understanding of Snort and Bro could be helpful, but I have no proven resources. The SANS material is ample to cover the exam (as it should be) and is worth acquiring. Good luck!
E Double U wrote: » Besides on the job experience, the materials provided during SANS training were all I used for the GCIH.