cshkuru wrote: » I am slowly grinding away at this. The class is interesting but not as fast paced as ICS410, also I have to keep stopping because I am trying to bust out time at work and that is hard somedays.
cshkuru wrote: » Just took the eaxm- I really did not feel ready for it but this was the last day I could schedule before my 4 months was up (I actually have until the 3rd but couldn't find a workable slot). I passed, but I don't know how I just felt completely unprepared as I was taking the exam. Here is what I can tell you without breaking NDA - know the phases of the Intelligence Life Cycle by heart. Also know how to read and write YARA rules and the phases of the Active Cyber Defense Cycle. It was a tough test, far tougher, in my opinion, than the CISSP, even taking into account the difference in time and number of questions, or the GICSP which is the other GIAC cert i have.
cshkuru said: I did the course materials and labs, then read the books again as I indexed. I probably should have done the labs again. My index was done in the following format. I also listened to the audio repeatedly as I drove to and from work, probably 4 complete times thru. Subj: Book: Page: Tool: Protocol: Comments: After I indexed I sorted on the tools and protocols and gave them each their own section. In the comments I either put in a short description or common command formats. I also put in the index, a copy of the purdue model, a copy of the diamond model, a copy of the acdc cycle and a short write up of various ics protocols and common function codes etc. All told my bound index was about 28 pages (14 front and back).
jachockey012 said: Would you be breaking NDA if you shared your index? I am not trying to use it on the test I am building mine right now and would like to opportunity to see a different style because what you described is not how I am doing it. I understand that a major portion of sans courses is the ability to index, so if you dont want to share publicly thats fine.
Would you be breaking NDA if you shared your index? I am not trying to use it on the test I am building mine right now and would like to opportunity to see a different style because what you described is not how I am doing it.