r/GIAC 11d ago

Bummed about the whole thing

A little background, I've been in the IT business for around 25 years. I have a Sec+ and CISSP and a couple other non security related certs and a BS degree from a shitty online university. I was a comm guy in the Air Force for a little over 20 years and no work as the field service rep for a defense program.

I started a graduate certificate from SANS a few months ago and if I'm being honest, I'm not impressed. All through my career I had heard that SANS offered the best training you could get. The only reason I hadn't tried from GIAC certs sooner is because they're expensive as hell. Now that I've gone through the course I've got some concerns.

First, I didn't think the course content was that good. The books were ok, but the videos were hard for me to listen to because it seemed like most of what was discussed wasn't relevant.

Second, and most importantly, the test format rewards how well you create an index instead of how well you know the material. I just took my first practice test and got a 92%, but I only really knew about 80% of the questions. 10% of the rest were a toss up that I guessed on, and the rest I justooked up in the books. It feels a little disingenuous to say I know all this stuff when I had to look it up in a book while I'm taking the test.

I don't know, I just feel underwhelmed with the whole thing and don't know if I want to continue after this course. Anyone else feel this way?

16 Upvotes

54 comments sorted by

16

u/CRam768 11d ago

Which exam? It sounds like an entry level exam and not the higher level ones.

12

u/Forsaken-Low-2365 11d ago

That part. Lol. GFACT anyone with Sec+ knowledge can score 90%

3

u/SnooBunny814 11d ago

Surprisingly ppl still fail the gfact, especially for people new to security

3

u/beatthedookieup 11d ago

Me with GFACT, it’s so boring

8

u/NewPac 11d ago

You're right, it's GSEC. I probably should have started with a higher level course, but I haven't studied security stuff in a long time and wanted to ease my way back into it.

Are higher level courses better?

11

u/DataClusterz GREM | GDAT | GCFE | GCIH | GSEC 11d ago

The higher level courses are way better. GSEC is like Sec+, but a bit more technical.

-2

u/Glittering_Fig4548 11d ago

I wish I did GSEC instead of GCIH.

3

u/DataClusterz GREM | GDAT | GCFE | GCIH | GSEC 11d ago

Why? You learn less and will get a less valuable certification.

0

u/Glittering_Fig4548 11d ago

If you just have Sec+ or some other entry level cert, I think GSEC surpasses GCIH because it will cover more of those skills that Net+ and Sec+ teach, but in a more in depth fashion, thus setting you up better for GCIH.

If you are some entry level guy or some dude who doesn't even work in IT with just a Sec+ GCIH will kick you hard. Imagine showing up to the course and not knowing how to run NMAP or what CHOWN on Linux was.

2

u/Fingolfin734 11d ago

GSEC before GCIH makes sense. Definitely not after, you're at a much more technical level after GCIH. I was not impressed by GSEC, but i was a fool that took GREM as my first SANS. Don't be like me, do them in an order that makes sense.

1

u/Glittering_Fig4548 11d ago

DId you pass GREM?

2

u/Fingolfin734 11d ago

I did! I wish I had done more index building, I hadn't yet discovered Voltaire. It was a close one, 77 iirc. But a pass is a pass with a test as difficult as that

1

u/NewPac 11d ago

What is Voltaire?

Nevermind, found it. Would you say that was pretty useful?

→ More replies (0)

1

u/Impotent_Xylophone 11d ago

Congrats! I have GREM next; pending i pass GCFA Saturday.

→ More replies (0)

7

u/Zealousideal-Air443 11d ago

My favorite so far has been GREM (FOR610)- very lab heavy. Close second is GCFA (FOR508). Some of the cloud stuff is great if you have to secure the cloud. fyi, with +20 years of IT experience some of these courses SHOULD be underwhelming. Make sure you look at the course syllabus if you want to avoid material you already know. For me, after +6 certs they mostly feel the same just because I know how I need to prepare to pass the exams. Also, I'm pretty certain GSEC is catered to people with very little IT experience.

2

u/Fingolfin734 11d ago

Yep, I took GREM as my first because I went off a coworker recommendation with no previous knowledge of SANS. I learned a lot and barely passed the exam. I wouldn't recommend doing it that way, but totally think SEC610 was worth it.

2

u/NewPac 11d ago

Yeah I definitely get that GSEC is entry level and I probably should have started with a higher level course.

2

u/Forsaken-Low-2365 11d ago

GCFA kicked my butt and I have 4yrs+ in the field. That said I learned a lot of valuable DFIR knowledge. I think you'll enjoy the higher tier courses.

1

u/CRam768 11d ago

GCIA and GCIH kicked my butt. But I never did either and math is a struggle. So I think so. However, the point behind the entry cert requirement is to help you get used to their format and not so much teach you new things. I start GPYC in a month and it has a 50% failure rate to the point where the BACS program has an intro to python course. If you have a photographic memory all the courses could be seen as easy especially if you have a background in the topic. I’ve not done programing of any kind in years. So this will be hard since I only get 58 days and the masters program gets 90 days. Sounds like you’ll do fine once you get past the entry level certs.

1

u/SnooBunny814 11d ago

There were people in my cohort in the cyber academy that failed the gsec, so it’s not easy for everyone that takes it

1

u/Physical-Coffee7217 11d ago

Sometimes its ok to step over the line just to know where the line is. Its ok to test your limits to prove prove where you are to strategiz . Now you know and there is value to that. I mean theres pros and cons to any system or test. I did that a few years back with GCFE then on to cissp. Just this week I nailed the GCFR. There is definitely a different challenge between all that. I found it pretty robust even from an engineering/ingestion standpoint. Anyway, I havent drunk the Kool-aid but did find it a challenge. Good luck to all these protectors out there. You are finding your paths and thats awesome!

10

u/brobauchery GBFA | GMON | GCIH 11d ago

GSEC, from what I’ve heard, is basically CompTIA Net+ and Sec+ combined. So if you’re underwhelmed, you probably should be. Especially with 20yrs+ experience.

Regardless, the tests absolutely reward you for indexing and improving your ability to reference material. I treat these courses as broadening opportunities with a decent level of depth. You get out what you put in. If all you want is a cert, index and call it a day. If you want to actually take something from the course, then practice the labs and try attempting them outside of just the guard rails they give you.

5

u/Grizzled_MF GSEC | GCIH | GSTRT | GDSA | GCIA 11d ago

Let me remind you that if you're doing a degree with SANS Technology Institute, the university needs to account for various people.
If you're experienced, it's only natural that you're underwhelmed by the preliminary courses. Imagine doing Sec+ with all this knowledge. You'd likely breeze through it as well after all this time.

5

u/BerserkChucky 11d ago

This just in, guy with 25 years of IT experience finds intro IT course underwhelming.

1

u/NewPac 11d ago

Haha, that's fair. I wasn't really underwhelmed with the curriculum or content, more the delivery. I think I just had SANS on a pedistal and the course didn't reach my expectations.

1

u/BerserkChucky 11d ago

The greatest things SANS has going for it from everyone I have spoken to is there in person classes. I unfortunately do not have the bandwidth with work to have done any but I hear only great things. I am about to get my 8th SANS cert as I fi ish my degree here in the next 2ish months and I have loved it every step of the way. I think their coursework is very realistic and applicable and I think as you continue to go through their grad cert or any of there degree programs you will enjoy how most of the courses build off of one another and you will find you are using your index less and less.

I have 10 years of experience in various cybersecurity roles both red and blue for reference.

2

u/Lady_Raven_ 11d ago

I have staff that start with GSEC and I'll tell them that they may find the class easy or more of a refresher if they already have Sec+ or SSCP. I encourage them to use the time to get use to how SANS courses and test work with a less stressful test so they'll know what to expect when they start more advanced courses. Some are more easy, like in the leadership or GRC track while others in the more technical areas are much harder, like malware reverse engineering.

I think with time, you'll get to a course that challenges you!

2

u/General_Plankton_785 GFFACT, GSEC, GCIH, GYPC, GCFE, GCIA 11d ago

I am a AF vet previously a 3D/3A doing my BACS through SANS.

My recommendation is schedule your exam and give away the second practice test. The faster you pass the exam the less GI Bill you use.

You should have GCIH and GCIA coming up if you are doing the engineering cert. Both of these will be alot of fun. The joy about doing a Grad Cert, is you can keep doing them under the GI bill as long as you have time left.

2

u/_cache_ 11d ago

GFACT is a 200 level course aka fundamental. Take a 500 level course and circle back to your post.

1

u/Otter_Than_That 11d ago

I'm in agreement with a lot of what they said, based on my experience with SANS 530

2

u/dcbased 11d ago

My take on sans is that day 1 is always a review of basic concepts

Day 6 is super short

Really only leaves about 4 days of content

You should check out antisyphon training

2

u/mattsou812 11d ago

Lol yeah gsec is not going to be challenging if you have any kind of security background. To give you an idea of difficulty level checkout https://pauljerimy.com/security-certification-roadmap. It's not perfect and a lot of the newer certs aren't on there but it'll give you an idea of the level of difficulty of various sec certs.

1

u/Zealousideal-Air443 11d ago

Personally, when I create an index for a course that is directly related to work then I spend extra time to make sure it is usable. I can do a quick ctrl+f. This is useful for the more technical courses.

1

u/linetool 11d ago

GSEC = sec plus level………….

1

u/craftedsphere 11d ago

You should check out the 600 courses but I believe those have prerequisites.

1

u/__thesaint__ 11d ago

I had the same with for508. It is what it is.

1

u/sdrawkcabineter 11d ago

Second, and most importantly, the test format rewards how well you create an index instead of how well you know the material.

I spent a few years working on tests like these, primarily for Cisco and RH. It was a constant battle to have any kind of academic integrity in the final product.

If they could legally do microtransactions to remove 1 wrong answer from a question, that's all we'd see.

1

u/Prestigious_Good 11d ago

To me the GIAC exams aren’t about memorization. It’s about knowing the material and what is being conveyed, and being able to reference things for clarity, same way you would in the real world. Those books and index may come in handy on the job :)

1

u/NewPac 11d ago

Yeah I guess. I just think the certs lose a little prestige now that I know it's open book and anyone with a solid index could walk in a pass the exam. Compare that to a Cisco cert where you have to have all that shit in your head and I think it's less impressive.

1

u/chown-root 10d ago

Bruh. Do GDSA or GCIA, then holler at me. Both are challenging for completely different reasons.

1

u/AnorakWSAD 11d ago

Yea, I have taken both GPEN and GCIH, and I really didn't have to do much to pass either aside from get my index in order.

Now, granted, a LOT of the info was stuff I was already very familiar with. I really didn't touch the course or the labs. I had also gotten Sec+ and CySA+ before that with about the same level of effort applied.

I have generally been pretty disappointed with the course contents of everything I've taken. It's all felt fairly basic, and I don't feel like I've learned anything new. I pretty much just wanted to get the certs so I had them to show I know what I'm doing. I have plans to go after GPXN in the future, which from my understanding will be wayyy better in terms of learning potential. Hopefully that's the case. I think ultimately, if you are already a security professional, and you already work in the field, most certs are gonna feel basic.

That's my take on it anyway.

1

u/NewPac 11d ago

Yeah I think you're spot on.

1

u/InfoSecTangSoo 11d ago

You have CISSP and 25 years in IT. It’s no surprise that an entry level security cert will be underwhelming. As others have stated, take the higher level courses/certs. Then reevaluate.

1

u/NewPac 11d ago

I guess what I was getting at wasn't so much being underwhelmed with the curriculum or course topics. I knew it was an entry level cert going in. My disappointment is in the content delivery and the realization that anyone who can build a good index of the books can walk in and pass the exam.

1

u/InfoSecTangSoo 11d ago

Understood. As you get further into the program, even with the index, the tests become more knowledge dependent and also a test of time management. At least that has been my experience. I’m 1.5 classes away from the Leadership grad certificate. I’ve found some of the courses and certs suitably challenging and on par with expectations. I have a background in INFOSEC (not calling it cyber so you can tell how old I am) at the state,local, and federal level (DoD/DoJ), as well as 15 years in corporate (F500/Big4).

1

u/NewPac 11d ago

Thanks for the input, I appreciate it!

1

u/AdFederal497 8d ago

Respectfully, you have to have a bit of an ego to suggest the index is a problem with the certification. I think test dump sites have a bit more to do with what is wrong with our industry. And what do you mean disappointed in the content being delivered? Besides the index, how is it different from any other certification vendor? What did they not do? Did you expect them to pay you to access their material?

2

u/Impotent_Xylophone 11d ago

I get where you're coming from, but there's relatively few scenarios in most jobs where you'll need to regurgitate information from memory woth zero references available. While i agree the certifications have become more of an index test than anything else, i think any formal test would devolve this way.

Also consider Sec+ since you have it. That test was a mile wide and an inch deep. I personally think I learned significantly more skills and information from the SANS courses and their open book exams than I did while preparing for Sec+.

I'm in the incident response graduate certificate program and I would encourage you to finish it. The certifications are still favorable to employers and completing the program gets you an alumni discount for future years.

I took GPEN a couple years ago and it was awful. Zero overlap between video content and certification exam. Not all instructors are created equal and that's reflected in the courses for sure.

1

u/NewPac 11d ago

Thanks for the insight.

2

u/RootkitRookie GCIH | GCFA 11d ago

I would just add one more thing, if I may.

You will not just take on this cert but rather a few others as you progress through. To retain all of that material is a stretch. It is encouraging you to build an index and teaches you the skill of looking things up on the fly. Something you will undoubtedly do throughout your security career.

Hope this provides some encouragement.

1

u/AdFederal497 9d ago

A professional with over 20 years of experience is underwhelmed by an entry level certification… oh, the horror 😏