|
EH-Net
|
|
May 24, 2013, 03:31:35 AM
|
Show Posts
|
|
Pages: 1 ... 13 14 [15]
|
|
211
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: MAN DOWN
|
on: October 17, 2009, 12:30:14 AM
|
|
De-ice is the basic one, but it will be better for you if you'll gonna start reading some basic hacking books. Given that you are at least CCNA, you can start with one of the CEH books, in order to better understand the whole process. Then you are good to go with the tools (or better do both in the same time). Just my noob opinion.
|
|
|
|
|
215
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: Heorot.net Intermediate Penetration Testing Course Vs Offensive security
|
on: September 15, 2009, 12:56:37 AM
|
Hello guys, If I really well understand, according to Jhaddix and Kev, it is better to do Heorot training in order to be able to do a good job as pentester (I mean to be able to work as a consultant and to do a good job, and not to be some security guy on a company's payroll). This training seems to give the business knowledge of the job, besides the technical skills. I'd like to do both of their levels, but because I have to pay for them by myself it is a big problem.  Maybe I will wait to see what elearnsecurity will bring to the scene (a combination of both Heorot's levels wold be nice). In the mean time I am doing OSWP and starting to read Fyodor's book. Good luck to everybody.
|
|
|
|
|
217
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: CISSP Test
|
on: July 19, 2009, 02:14:53 AM
|
|
The best videos for the CISSP are the Shon Harris ones. Use them along with her book, and you'll be prepared. It is a difficile test to pass. Belive me, after finnishing the exam you'll pray God to pass it because you'll not want to study again for it. It is very broad, the questions are very smart, and you really have to understand the principles. There are some realtively easy questions but there are many of them very tricky.
Just to have an ideea you have here some questions from the internet:
1 (relatively easy one) Acceptable risk is achieved when: A. residual risk is minimized. B. transferred risk is minimized. C. control risk equals acceptable risk. D. residual risk equals transferred risk.
2 Which of the following is the MOST effective in preventing attacks that exploit weaknesses in operating systems? A. Patch management B. Change management C. Security baselines D. Acquisition management
3 (you'll see many "BEST" questions like these ones) Access to a sensitive intranet application by mobile users can BEST be accomplished through: A. data encryption. B. digital signatures. C. strong passwords. D. two-factor authentication.
4 (very probable one) The BEST way to determine if an anomaly-based intrusion detection system (IDS) is properly installed is to: A. simulate an attack and review IDS performance. B. use a honeypot to check for unusual activity. C. review the configuration of the IDS. D. benchmark the IDS against a peer site.
Anyway, the opinins about this examn differs according to the level of expertise and the level of education of peers. Study well, use cccure's questions, level pro and you'll pass.
Good luck!
|
|
|
|
|
224
|
Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Passed CEH
|
on: March 21, 2009, 01:29:46 AM
|
Congratulation for the Certification. Nice comment also. Can I ask why did you choose CEH and not OSCP? I am in a big dilemma. I want to do another certification, a technical one. I am about to graduate a Master in Infosec, I am Security+ and passed CISSP, but my experience is more managerial, BC and DR, and I want to go deeper in the technical field (I really like the adrenaline that comes with pentest). I really don't know which one to choose. I started to study for CEH, but on this forum I read a lot about OSCP and it seems very interesting. What advise do you give me? I am thinking about reading Michael Gregg's CEH prep guide and Build Your Own Security Lab A Field Guide for Network Testing. Also, I want to go and practice nmap, linux scripts, leo and then take OSCP and not CEH (the company I am working now don't want to pay for certifications so I'll have to choose only one). The problem is that if this would take more than 2 month I will have to reschedule it for the late fall, because I'm in Canada now and I want to spend the summer with my kids, and the 6 month of winter with the study  Do you think that I should go now for the CEH v5 and during the winter for the OSCP? Can CEH help me more to do vulnerability assessment and, maybe, for BIA? Thank's again. This forum became my daily journal.
|
|
|
|
|
Loading...
|