  1. How did you get your start in information security?
  2. How did you get your start in incident response and forensics?
  3. What do most people get wrong when it comes to incident response? Put another way, what is the most difficult part of incident response?
  4. What is the best way to communicate in incident response? How do you get information from the tech teams to the admins to the help desk to the end users and to management?
  5. What are some of the best incident response tracking tools or frameworks?
  6. In incident response, you are seeing the worst of the worst when things go wrong, what is the most frustrating security problem or vulnerability that you recognize when doing incident response?
  7. What is the most important thing in incident response from the following list: a. Knowing where all of your sensitive data lives b. Knowing which systems and applications you have and where they are located c. Knowing who owns the data and the applications or d. all of the above and why?
  8. What advice do you have for those trying to define what constitutes an incident? E.g. every piece of Spyware vs. a targeted attack stealing company secrets.
  9. If someone wanted to get started in forensics, where would they start?
  10. What is your preferred method of data destruction given the various ways to recover data from a drive? (Please say firearms...)
  11. What are the best methods available to thwart a computer forensics investigation?
  12. Who is your favorite SANS instructor?
  13. What advice do you have for those students going through the SANS CIAC certification programs? (And, do I have to paint my fingernails? Because I did, it helps)
  14. What is the value of certification in our field?
  15. More importantly, what is the value of continuing your certification process and keeping your certifications up-to-date?
  16. Martial arts question: Was EVERYONE Kung Fu fighting?
  17. Favorite martial arts movie?
  18. Best tip for someone who is learning how to shoot and going to the range for the first time?
  19. I'm a big fan of the Browning Buckmark, is this what you compete with?