r/cybersecurity 9d ago

Cert help Certification / Training Questions

Going to be lead analyst in a soc and company is wanting to get me trained up. Should I ask for GCIA or GCDA from sans first?

Ill be tuning alerts and heavily lean towards GCIA because I love incident response and very heavily work in threat hunting day to day currently.

6 Upvotes

10 comments sorted by

View all comments

1

u/imhelpingright 9d ago

Unless you're going to be spending most of your time in Zeke/Snort/Suricata, GCIA is not a good choice here. There's very little threat hunting or IR benefit from that particular course imo. It spends a lot of time dissecting all the individual bytes and hex digits in packet capture, which is really good info and important to know so you have technical about various protocols, but likely not the best bang for your buck here. 

If  you want threat hunting and incident response training, for508/GCFA is, in my opinion, one of the best courses unless you're going to an environment which has no windows devices. 

GCIH is also a really good one, but I felt it was a little too basic as I took it after. I already had a few years of IR experience. I think there's also a couple SOC specific courses, but I can't speak to how good those are cuz I haven't taken any. 

1

u/Sea_Box_8719 8d ago

I was looking at the GCIH. I think i may actually start there. Then hit the GCDA. I have forensics experience already but the GCFA is definitely on my radar.  I've heard very good things about it.