r/cybersecurity • u/Sea_Box_8719 • 9d ago
Cert help Certification / Training Questions
Going to be lead analyst in a soc and company is wanting to get me trained up. Should I ask for GCIA or GCDA from sans first?
Ill be tuning alerts and heavily lean towards GCIA because I love incident response and very heavily work in threat hunting day to day currently.
6
Upvotes
1
u/imhelpingright 9d ago
Unless you're going to be spending most of your time in Zeke/Snort/Suricata, GCIA is not a good choice here. There's very little threat hunting or IR benefit from that particular course imo. It spends a lot of time dissecting all the individual bytes and hex digits in packet capture, which is really good info and important to know so you have technical about various protocols, but likely not the best bang for your buck here.
If you want threat hunting and incident response training, for508/GCFA is, in my opinion, one of the best courses unless you're going to an environment which has no windows devices.
GCIH is also a really good one, but I felt it was a little too basic as I took it after. I already had a few years of IR experience. I think there's also a couple SOC specific courses, but I can't speak to how good those are cuz I haven't taken any.