Since I managed to get one of the first certifications in my professional career not too long ago (which I sure as hell shared on a LinkedIn post, don’t feel preassured to give it some love wink wink nudge nudge), I wanted to share what it entailed and the overall process and resources I had access to.

Quality of the course offered by INE

It was actually really good! What I paid for included both the corresponding course and a voucher for the certification exam, and I have to say INE’s platform was very good. The content covered in the course covered everything evaluated and there really wasn’t any disparity between what I saw in the course and what I got as exam questions; the instructor himself was great, so shoutouts to Brian Olliff!

One thing I will be a bit critical about of, however, is related to one of the sections covered: it used a text-to-speech instructor. Brian’s classes had some additional information that only people with experience in the field would cover, not to mention the feel of the lessons is way less interactive and fun; I mostly just read the slides in these classes since the information didn’t really differ much from what the text-to-speech voice was saying. I know this isn’t really a deal-breaker for some people, but I still felt like it was right to point it out.

Content seen throughout the course

It mainly covered the process of performing threat hunts in an actual professional environment (what a surprise, huh?). It does introduce specific lingo and good practices that, if you lack the actual experience in threat hunting, will definitely help you get a better feel of the type of work done.

In the more technical side of the course, it mainly focuses on Wireshark, Splunk and ELK. Nothing too crazy as it covers the basics (and cases like combining them with MITRE ATT&CK mapping, for example), but it definitely helps if you’ve had any experience with them prior. I myself haven’t had experience with Splunk or ELK up till this point, but having experience writing SQL queries DEFINITELY helped me a lot.

As mentioned, it didn’t go too in depth on what all of these different applications can do, but the level it covered really doesn’t deviate much from what you’d see in a starter SOC or threat hunting role; the one app where the course did explore a bit more in depth and also showed some alternatives for (for example, for CLI usage) was Wireshark, so nice little bonus there.

Additional resources provided by INE

Alongside the classes there were quizzes and labs. The quizzes were super useful since a big part of the exam are multi-choice questions and the quiz questions themselves were a good way to test what you learnt from the corresponding lesson (or how good your note-taking skills are!). I think only on very few occassions I had to quickly look up something as I wasn’t 100% sure it was covered during the lesson, but other than that you can bet that all the answers can be found in the videos.

The labs themselves were an incredible additional resource, especially for the Splunk and ELK sections of the course if you haven’t had experience with them before (also saves you a TON of time setting everything up from scratch in a custom workspace). They covered what was seen in the corresponding lesson and had a task to complete (or set of tasks, mostly in sequential order) and, if needed, they also provide a step-by-step guide; these guides are very well done too so I can definitely recommend checking them out in case you get stuck.

The exam itself

The exam had a time limit of 12 (twelve) hours and was divided in four main sections:

  1. Multi-choice questions
  2. Wireshark practical problems
  3. Splunk practical problems
  4. ELK practical problems

For the multi-choice questions, the structure was exactly the same as the quizzes found throughout the course. For the practical problems you had access to web instances (pretty much the same type of instances provided for the labs) that had already installed and configured the software needed to solve the tasks. It felt kind of similar to a CTF in the sense a lot of the tasks involved finding a specific flag and you’d have to do some digging around, but the tasks were actually quite fun!

The difficulty itself wasn’t anything too crazy but it wasn’t extremely easy either. I won’t/can’t reveal any question of the test itself of course, but there was this specific task to solve in the Wireshark section that I had to leave for last; we’d seen an incredibly similar situation in one of the classes but damn did the case in the exam absolutely throw me off. Other than that though, fairly straight forward; I definitely recommend getting comfortable with MITRE ATT&CK as it’s involved quite a bit in a lot of the practical problems.

So, is it worth it?

Overall, I’m extremely happy with the quality of both the certification and the course itself! Other than the text-to-speech section that really irked me, the content of the classes was great and the quizzes and test labs helped tremendously to get a better understanding of the content seen.

I’ll address the comically large elephant in the room, however: yes, you can definitely use LLMs during the exam as it’s open book. I myself did not use any, as I paid for a course and a certification where I wanted to test MY own learning and I did not find any purpose in third-partying my brain, but it’s definitely something you can use. “Hate the game, not the player” and all that jazz, and I’m inclined to agree, but my personal recommendation is that you don’t use any. I know most (if not all) jobs en(force/courage) LLM usage and it can definitely help speed things up, but if you can’t solve a basic-mid level task or don’t understand how anything works you won’t be able to do anything if suddenly there are no more tokens being provided, so please, take that into consideration.