Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 71 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Web Applications
GWAPT with Live & OnDemand - review
EH-Net
May 19, 2013, 09:45:49 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
GWAPT with Live & OnDemand - review
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: GWAPT with Live & OnDemand - review (Read 6787 times)
0 Members and 1 Guest are viewing this topic.
alucian
Full Member
Offline
Posts: 225
GWAPT with Live & OnDemand - review
«
on:
December 20, 2011, 03:34:58 PM »
Hello guys,
As I already mentioned I was studying for SANS GWAPT. Today the nightmare ended.
I did the live course with Kevin Johnson at the end of August, in Ottawa. I can tell you that Kevin is a good teacher, he has a lot of experience and he knows how to animate a class. The class was mixed, some were advanced in the field, others (like me) had some basic knowledge, and there were some who barely stayed awake. There is a lot of information in the course. Some days are easier, but day 4 – client side discovery- was really difficult to digest.
After the course I started to read the books, listen to the mp3’s, and I redid all the labs. After I read once all the books I did the OnDemand questions. Surprise
Failed some chapters.
The advantage with the questions from OnDemand is that you can do them anytime you want, and you can repeat them. I did them until I pass all the questionnaires. I didn't used the books when I answered. Some of the questions were easy, for some of them you could even get the answer from the books. There were some good questions that made you think a little bit.
Also, there was a repetition of some questions.
Two weeks ago I did the first practice test. I scored 83%, and I finished the exam in one hour. It wasn’t very difficult. A little bit different than the OnDemand, but OK. You could answer a lot of question just by looking in the book. Yesterday I did the second practice exam. I scored 90% in about 50 minutes. Almost 15% of the questions were similar with the ones in the first exam.
I thought that I was smart
and well prepared.
This morning I sat for the real exam. WHAT A DIFFERENCE
There are questions where you can find the answer in the books, but for most of them the answer is at the bottom of the page, where the details are.
The biggest difference was in the questions that presented you some code (html, php, javascript..) and you had to answer to some questions:
- You intercepted this file through the proxy. Which is your next step?
- What file should you investigate giving the code??
- What attack can you perform giving the php code?
- …
They were very interesting and difficult (at least for me). I say difficult because the questions on OnDemand and the practice exams made me believe that this is another theoretical exam, with some practical knowledge, but it was very “practical”.
In order to pass the exam, unless you are really experienced, you need:
- The books
- To practice all the labs, to know the tools, and go the extra mile with the labs
- To study hard
I think that for someone with a web programmer background will be easier to understand the code in the exam, but there are other questions where you should have at least a basic knowledge about the whole IT environment.
For someone who wants to pass the exam I recommend to buy the course, and even buy the OnDemand. Do the questions on the OnDemand without the manuals and you’ll be surprised
For the beginners in the web penetration testing I would recommend to start with something else (eLS maybe), because I don’t think they’ll have enough time to do it (unless they are geniuses or unemployed).
So, for the final exam I had 85% in 1h50 minutes, but I felt a carrot in my back during the exam
I am happy, and this was an interesting experience (this is my first SANS).
«
Last Edit: December 20, 2011, 04:33:52 PM by alucian
»
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
lorddicranius
Sr. Member
Offline
Posts: 447
Re: GWAPT with Live & OnDemand - review
«
Reply #1 on:
December 20, 2011, 03:52:38 PM »
Gratz! Thanks for the review and the study tips, much appreciated
«
Last Edit: December 21, 2011, 10:17:55 AM by lorddicranius
»
Logged
GSEC, eCPPT, Sec+
Eleven
Full Member
Offline
Posts: 120
Re: GWAPT with Live & OnDemand - review
«
Reply #2 on:
December 20, 2011, 07:49:34 PM »
Thanks for the review, and congrats on passing! From the way it started I was worried you failed.
Logged
hayabusa
Hero Member
Offline
Posts: 1630
Re: GWAPT with Live & OnDemand - review
«
Reply #3 on:
December 20, 2011, 09:25:02 PM »
Congrats, alucian! One of these days, I'm gonna be able to swing the cost for GWAPT (hopefully sooner than later,) so it's nice to hear others' 'war stories.'
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: GWAPT with Live & OnDemand - review
«
Reply #4 on:
December 20, 2011, 09:49:20 PM »
Hey Alucian!
Congrats! Be sure to update your signature with your new cert. I've heard similar stories regarding practice exams and then finally sitting for the real examination. Do you think someone who went through the Web Application Hackers Handbook would be prepped enough for the class?
Logged
eCPPT, GCIH, OSCP, OSWP
Seen
Full Member
Offline
Posts: 134
Re: GWAPT with Live & OnDemand - review
«
Reply #5 on:
December 21, 2011, 01:24:05 AM »
What if you just signed up for the OnDemand as opposed to the vLive or something like that? Does the OnDemand leave out things that are in the live course? I like to work at my own pace, so if I ever save up enough money for GWAPT, I would probably do the OnDemand. I have an insane memory, but it only works if I have time to process the information. Taking the live class I'd learn all the material so fast that I'd probably not retain it that well after the exam.
Logged
Sec+, eCPPT
UNIX
Hero Member
Offline
Posts: 1234
Re: GWAPT with Live & OnDemand - review
«
Reply #6 on:
December 21, 2011, 02:39:41 AM »
Congrats, alucian!
Logged
3xban
Hero Member
Offline
Posts: 605
Re: GWAPT with Live & OnDemand - review
«
Reply #7 on:
December 21, 2011, 07:30:14 AM »
Nice write-up Alucian! Yeah those GIAC practice exams do give you a bit of false hope
I sticky noted the hell out of my course manuals and made up a nifty index so I can remember to flip to whatever page in whatever manual I needed. Those 2 hours go pretty fast. The biggest advantage is to know the material so you don't have to use the books unless you hit those really tough questions.
Congrats on the Win!
Logged
Certs: GCWN
(@)Dewser
ziggy_567
Sr. Member
Offline
Posts: 361
Re: GWAPT with Live & OnDemand - review
«
Reply #8 on:
December 21, 2011, 08:00:24 AM »
I'm assuming when you took the exam it was the new 75 question format instead of the older 150 question format.
If that's the case, the newer format includes questions that are less memorization type question and more applying knowledge questions. They're often described as being "harder," but I would say its not so much that they're harder. They just better measure your total grasp of the subject. Isn't this what you want from a certification anyway?
I've yet to actually take one of the new formatted exams, but I imagine the reason that the practice exams weren't exactly respresentative of the actual exam is that the question banks for practice tests generally come from retired/old exam questions. (I don't think that's 100% of the case but some are.) Therefore, with the new format, there just hasn't been enough time for the practice test question banks to get many of the newer style questions.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
alucian
Full Member
Offline
Posts: 225
Re: GWAPT with Live & OnDemand - review
«
Reply #9 on:
December 21, 2011, 08:52:40 AM »
@ ziggy_567
Indeed, it was the 75 questions exam. After the exam the value of this certification increased in my eyes. They are really testing your knowledge and your experience.
@ Seen
I did the live course because the company paid for it. It was like a little vacation. I even made new friends
The company also paid for the OnDemand and the exam.
In terms of knowledge there is no difference between the live class, the OnDemand or the course only. The OnDemand is like someone is reading the book for you. The real difference with OnDemand is with the questions, not the material.
If you only buy the course, without vLive, without OnDemand, you'll receive the books, the labs, and the mp3's. The mp3 were recorded during one live training, and they include all the class material, all the stories, all the jokes.
Even if you take the live class you will have to start from the beginning, because in the class you can't assimilate all the knowledge. Especially day 4 (Ajax, JSON, WSDL, Flash...). On our class it was silence
I admint that I was completely lost. Even on mp3's you'll see that there are no comments, and you'll believe that it was recorded in a studio
This is the day that makes the difference between this course and a regular book (WAHH2)
@ xXxKrisxXx
I don't think that by reading the WAHH2 you'll be able to pass the exam. You need the official manuals, because you have at least 10 questions where you can go in the manual and read the answer.
Also, the WAHH doesn't go in the same detail about Ajax, about python, php, WebServices, Flash...
Plus, with the course you'll receive two virtual machines: one is the target and the other one is a custom version of Samurai WTF. You have a lot of exercises to perform during the course, and you can even go an extra mile (recommended).
Keep in mind that you have 5 books, labs to do in 4 months. Sounds like a lot of time, but when you have a family and a job ... it becomes a problem.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Seen
Full Member
Offline
Posts: 134
Re: GWAPT with Live & OnDemand - review
«
Reply #10 on:
December 21, 2011, 03:44:12 PM »
Thanks, I guess I'll do OnDemand then if I ever get the money.
Logged
Sec+, eCPPT
docrice
Newbie
Offline
Posts: 27
Re: GWAPT with Live & OnDemand - review
«
Reply #11 on:
December 22, 2011, 10:36:58 PM »
I just started the OnDemand for 542, and since my web skills are very weak this will be a good stretch for me. I've taken several other SANS courses and while they were all challenging in their own ways, I already had at least some experience in the subject matter before taking them. 542 should be a huge smack in the face for me.
In my experience, GIAC practice exams are pretty similar to the actual exam. It's interesting to hear that GWAPT's is different, but I assume this might also be at least partially due to the updated exam format.
Logged
GSEC, GCFW, GCIA, GCIH, GWAPT, GAWN, OSWP, WCNA, CCNA, CCNA Security, [...and other resume filler]
Hopefully-useful stuff I've written:
http://kimiushida.com/bitsandpieces/articles/
iamnowonmai
Newbie
Offline
Posts: 2
Re: GWAPT with Live & OnDemand - review
«
Reply #12 on:
December 23, 2011, 02:45:13 PM »
Quote from: ziggy_567 on December 21, 2011, 08:00:24 AM
If that's the case, the newer format includes questions that are less memorization type question and more applying knowledge questions. They're often described as being "harder," but I would say its not so much that they're harder. They just better measure your total grasp of the subject. Isn't this what you want from a certification anyway?
I've yet to actually take one of the new formatted exams, but I imagine the reason that the practice exams weren't exactly respresentative of the actual exam is that the question banks for practice tests generally come from retired/old exam questions. (I don't think that's 100% of the case but some are.) Therefore, with the new format, there just hasn't been enough time for the practice test question banks to get many of the newer style questions.
Correct that the cognitive level of a question doesn't map to the difficulty in a linear fashion.
Incorrect that the practice questions are old and used to be certification questions.
Merry Christmas to you all
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: Red Team/Blue Team
(0) by
n37sh@rk
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.