yoba222 wrote: » I suggest GCIH for blue team too.
E Double U wrote: » Agreed! Also, GPEN for red team.
JasminLandry wrote: » I would add GXPN and GWAPT as well to red team.
stryder144 wrote: » Under Blue Team I would also place the CCNA: Cyber Ops and Security certs plus Logical Operations Cybersec First Responder (admittedly not much market share for this one but has some pretty good information).
TechGuru80 wrote: » Honestly if you are going to have a lot of GIAC certs...I would put GSEC in there. The core GIAC certs are GSEC, GCIH, and GCIA...so for blue team all three should be there. GCWN probably can be an optional, unless you are engineering your environment and not using like CIS group policies.
jallen2020 wrote: » Hmmm...I was going back and forth on the GCIH for the Blue Team, but seems it only has a small section on incident handling, and mainly is a Ethical Hacking intro...is this not the case? I feel like we can train incident handling ourselves. Also, which is more difficult, the GPEN or the OSCP? I'm trying to have a logical progression from easiest-ish to most difficult.
jallen2020 wrote: » I've heard the CSA+ and CCNA: Cyber Ops Material is pretty similar in knowledge level at least...is it not?
higherho wrote: » OSCP is more difficult than GPEN because it's a Practical certification were GPEN is more of the same "here is questions and give us answers" type exam. It doesn't test you the same way OSCP does. Which is one reason why I respect OSCP and OSCE a lot more than any other certification for this type of work. You know those people know what they are doing or at least have a higher confidence level that they should. It's the CCIE of security certifications.
TechGuru80 wrote: » Idk if you realize it but the GIAC GSE has a written and hands on lab and covers GSEC/GCIH/GCIA...unlike the OSCP/OSCE which only cover pentesting (a subset of security).