This question is for the admins and otherwise legit experts and pros. I'm studying to become a professional ethical hacker and wanted your perspective on what certifications are most desirable to obtain. I've been prepping for the CEH and was planning to take it the beginning of Sept. I've passed the last few simulated exams and am comfortable in my preparedness, however am rethinking whether obtaining that credential or seeking another certification such as certified pentester, ect. I've goggled and found mixed reviews about the worthiness of CEH and wanted your expertise on which cert you all believe is most worthwhile in terms of a career in the industry. Thank you in advance for any info or advice you can provide. Greatly appreciated!
Forum Thread: Question to the Admins/Experts on Certifications
- Hot
- Active
-
Forum Thread: How to Track Who Is Sms Bombing Me . 4 Replies
2 mo ago -
Forum Thread: Removing Pay-as-You-Go Meter on Loan Phones. 1 Replies
2 mo ago -
Forum Thread: Hydra Syntax Issue Stops After 16 Attempts 3 Replies
2 mo ago -
Forum Thread: moab5.Sh Error While Running Metasploit 17 Replies
3 mo ago -
Forum Thread: Execute Reverse PHP Shell with Metasploit 1 Replies
4 mo ago -
Forum Thread: Install Metasploit Framework in Termux No Root Needed M-Wiz Tool 1 Replies
5 mo ago -
Forum Thread: Hack and Track People's Device Constantly Using TRAPE 35 Replies
6 mo ago -
Forum Thread: When My Kali Linux Finishes Installing (It Is Ready to Boot), and When I Try to Boot It All I Get Is a Black Screen. 8 Replies
7 mo ago -
Forum Thread: HACK ANDROID with KALI USING PORT FORWARDING(portmap.io) 12 Replies
7 mo ago -
Forum Thread: Hack Instagram Account Using BruteForce 208 Replies
7 mo ago -
Forum Thread: Metasploit reverse_tcp Handler Problem 47 Replies
9 mo ago -
Forum Thread: How to Train to Be an IT Security Professional (Ethical Hacker) 22 Replies
9 mo ago -
Metasploit Error: Handler Failed to Bind 41 Replies
10 mo ago -
Forum Thread: How to Hack Android Phone Using Same Wifi 21 Replies
10 mo ago -
How to: HACK Android Device with TermuX on Android | Part #1 - Over the Internet [Ultimate Guide] 177 Replies
10 mo ago -
How to: Crack Instagram Passwords Using Instainsane 36 Replies
10 mo ago -
Forum Thread: How to Hack an Android Device Remotely, to Gain Acces to Gmail, Facebook, Twitter and More 5 Replies
10 mo ago -
Forum Thread: How Many Hackers Have Played Watch_Dogs Game Before? 13 Replies
10 mo ago -
Forum Thread: How to Hack an Android Device with Only a Ip Adress 55 Replies
11 mo ago -
How to: Sign the APK File with Embedded Payload (The Ultimate Guide) 10 Replies
11 mo ago
-
How To: Use Burp & FoxyProxy to Easily Switch Between Proxy Settings
-
How To: Crack Password-Protected Microsoft Office Files, Including Word Docs & Excel Spreadsheets
-
How To: Find Identifying Information from a Phone Number Using OSINT Tools
-
How To: Find Vulnerable Webcams Across the Globe Using Shodan
-
How To: Dox Anyone
-
Steganography: How to Hide Secret Data Inside an Image or Audio File in Seconds
-
How To: Top 10 Things to Do After Installing Kali Linux
-
How to Hack Wi-Fi: Stealing Wi-Fi Passwords with an Evil Twin Attack
-
How To: Target Bluetooth Devices with Bettercap
-
How To: The Hacks Behind Cracking, Part 1: How to Bypass Software Registration
-
How To: Build a Beginner Hacking Kit with the Raspberry Pi 3 Model B+
-
How To: Exploit EternalBlue on Windows Server with Metasploit
-
How To: Gain SSH Access to Servers by Brute-Forcing Credentials
-
How to Hack Wi-Fi: Cracking WPA2-PSK Passwords Using Aircrack-Ng
-
How To: Perform Advanced Man-in-the-Middle Attacks with Xerosploit
-
How To: Crack SSH Private Key Passwords with John the Ripper
-
How To: Use Hash-Identifier to Determine Hash Types for Password Cracking
-
How To: Use an ESP8266 Beacon Spammer to Track Smartphone Users
-
The Hacks of Mr. Robot: How to Spy on Anyone's Smartphone Activity
-
How To: Manually Exploit EternalBlue on Windows Server Using MS17-010 Python Exploit
22 Responses
You will definitely need the comptia A+ course certification. However, all in all, just get as many certifications as you can. The more certs you have, the better your chances are of being hired. To put this in a real world from, If you and some other person apply for an IT/Hacking job, and you have one more certification than said person, odds are, you will get the job.
In all honesty, an awful lot of people in this industry have no certifications. If you want to pursue the certification route in IT security, I suggest;
A+
Net+
Sec+
Linux+
Then.
CASP
CEH
CISSP.
OTW: I was wondering which one of these I should take. Thanks for a good list :)
Jeremiah:
It depends upon your background and aspirations.
I am hoping to get into the security or pen tester field. I already have A+ and Net+
Then get the security + next.
Will do! Thank you again.
Thanks for this list
thanks so much for your insight OTW! I appreciate the advice!!
to OTW: i just finished CCNA certification can you tell me what certification should i take? thanks
The whole certification thing is a slippery slope. Some expect them, some don't. Some respect them, and others don't. Best advice I can offer is learn the craft. Hone your skills. All a certification will do is possibly get you through the door. I can share this tip that I was not able to take advantage of myself, but could possibly be a fit for you. I got in touch with a guy via this site (http://h.foofus.net/?p=821) who had a posting looking for n00b hackers for paid internships. That's right paid. They basically train you as a Penetration Tester and then offer you a job with their company (a sub-division of CDW).
Good luck.
I do have a question: is there an age requirement? I'm 14, and I am very serious about going into IT. And also, OTW, what certifications do uou have?
I'm pretty sure you have to be 18 years of age. You can check out OTW's profile page to see his certs.
My two cents: Offensive Security and eLearnSecurity certifications are great. I'm an OSCP certified and I loved its "hands on" approach... the 24-hour exam was cruel :D These are certifications you earn applying what you study during the course, not by just memorizing some notions :)
Super jealous......I would love to go through those but they're so damn expensive, unfortunately. If money weren't an issue, I'd be doing everything through offsec.
I really can understand you :)
Consider however that given the cost of other certifications, OffSec ones are also a little cheapier!
As a 15+ year experienced hiring manager, it can give you an advantage, but not always. Some certs are baseline just to be considered. For example, to be a security contractor for the US Government, you need at least a Security+ just to be considered for an average position (DoD 8570).
If I'm hiring for a mid-level Network Engineer in a Cisco shop (for example), I'll most likely only look at CCNPs. Depending on the composition of my current team, I may go with a CCNA or an expired CCNP and look at how well your personality integrates with the team, skill set, experience, and how hungry you are to learn. I will, however, look very closely at your reason for not having a CCNP. If you let it expire, what life events got in the way? If you only have a CCNA, are you working on a CCNP? I wouldn't hire the worse of two candidates if it came down to having a cert/degree or not.
I am granular enough with my interviewing process that of the 100 or 200 employees I've hired directly or been involved with hiring, it has never came down to certifications between two candidates being the deciding factor. It's super cliche to say that it happens, but generally you have to have the cert just to be considered. There's always many other factors to decide on.
Certs and degrees will generally get you eliminated at the first or second gate in the hiring process, especially at larger organizations, because the hiring manager doesn't have a lot of time and will say "They must have a CCNP" (as an example). Someone that's not technical looks at your resume, sees you don't have a CCNP, and discards your application.
So, just like most things in life, "it depends". Of course, every hiring manager is different so YMMV (Your mileage may vary).
thank you so much for your insight!
I'm currently employed as a security consultant/pen-tester. I studied for the CEH, but like yourself I read mixed reviews.
Instead I took the knowledge from the CEH book plus a years worth of home study and then took week intensive course called Cyber Security Team Member which is CHECK equivalent.
I have been to a few interviews in London because of my CSTM qualification and they told me that they didn't even bother with people with CEH as it focuses too much on tools and not much skill/free thinking.
I hope that shows how much the CEH is worth as an actual qualification, its more of a stepping stone into the industry.
Thanks so much for your insight. I'm like you. Everything I know is self study. I come from a completely different background. I have my master's degree in healthcare administration and management. My problem is it took me sooooooooooooooooooooo longggggggggggggggg to find what I wanted to do with my life. I went into healthcare because my dad is a doctor. I never had that one career I was like "I want to do this" until I stumbled into hacking about 2 years ago. I hate working in healthcare...HATE it. It's just not at all interesting and it doesn't hold my attention. I went to work everyday frickin miserable. Now I'm much, much more happy. I landed a pentesting job with a local sec company but it's contract work only and I need something more stable. I also applied to some other local sec companies who told me to come back once I had a solid foundation of knowledge. With that advice I began studying and using skillset.org to track my progress towards the CEH. I think for me, a cert is important because I don't have an IT background. I'd love to go through one of the programs offered at offsec, ect but they're so expensive and money is not exactly growing off my trees right now. Thanks so much for the feedback. It's appreciated!
Guys i need some advice, im thinking about getting into IT.
I would love to hear your opinions/point of view
Keep the things you do on your computer separate. At work I use my laptop for studying, researching and practising. When I get home from work I use it for entertainment and gaming :) .
Share Your Thoughts