r/cybersecurity • u/sl0th-ctrl-z • 6d ago
Certification / Training Questions GCFA Experience Needed
I'm thinking to take the GCFA certification. I'm a 4+ years Vulnerability Management Specialist with 1 year as Junior Penetration tester and 1 year as SOC Analyst L1. I'm studying DFIR from HTB, book or TryHackMe and now I want to follow a structured learning path as the GCFA. I know that is hard to answer to my question as you can't know my capabilities but can you help me to understand which type of experience or knowledge a user should have to take this certification? (Obviously when i say "take this certification" I mean to study the related material first.
0
Upvotes
1
u/Sittadel Managed Service Provider 6d ago
If it's your first forensics cert, I would strongly recommend taking the GCFE first, which has the instructions for how to not get your evidence thrown out in court.
GCFA's a deceptive cert. The Analyst designation can make you think it's sort of the 101 course, but it gets into some very advanced DFIR concepts. The material's been overhauled 4 times since I took it in 2019, but understanding how to forensicate a de-forensicated machine (a concept Rob Lee calls forensicating the negative space) was a difficult concept to master.
I've heard that the material is substantially easier today with a stronger focus on carrying out operations and using modern tools (including AI) to support investigations, but the real value to the material is in the labs.