After completing the FOR572 course from SANS, I had an exam waiting for me.
GNFA, Network Forensic Analyst. The exam lasts at most 2 hours, contains 50 questions, and you need to pass with 60%. Which seems like a fairly low bar... the opposite is true. The exam is genuinely hard. Even though it's open book. The instructor recommended creating an index for the study materials; cheat sheets are also useful (tcp/ip, tcpdump, wireshark filters,...). None of that will get you the certification on its own though — there's still a significant percentage of questions where you need to show you actually know the stuff practically. I passed. I'm the 682nd holder of the GNFA worldwide. I can say I'm proud of myself.