Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow Have GCIH taking CEH
EH-Net
May 24, 2013, 12:09:34 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Have GCIH taking CEH  (Read 9889 times)
0 Members and 1 Guest are viewing this topic.
bigwhiff
Newbie
*
Offline Offline

Posts: 14


View Profile
« on: January 28, 2008, 01:31:40 AM »

Hi All,

This is my first post on here and I am getting ready to schedule the CEH exam.  I have my GCIH from SANS and I was wondering if anyone could compare the two exams for me and how much more I might need to study for the CEH?

Cheers,
Jack
Logged

Jack Campbell
CCNP CCDP GCIH GHTQ C|EH
http://secauditor.wordpress.com
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #1 on: January 28, 2008, 12:10:19 PM »

Off the top of my head, the main reason you would want to study more for the CEH is the fact that the GIAC stuff is open book over the web and your only tested on material directly from the books. Whereas the CEH covers a lot of tool specific stuff, like switches or flags, that if you don't know it right away your not gonna guess it.
Logged
bigwhiff
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #2 on: January 29, 2008, 01:46:38 AM »

Thanks alot for the post.  I have the NMAP flags down, I am having a hard time memorizing all the freakin' ports associated with the various trojans and DOS tools.

I have to say I really enjoy the way that SANS lays their testing out.  If you don't know the material you won't make it through the exams cold with just the books.  Very similar to a real world event happening.  I am constantly going back to other resources that I know about to help during an incident.

Thanks Again,
Jack
Logged

Jack Campbell
CCNP CCDP GCIH GHTQ C|EH
http://secauditor.wordpress.com
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #3 on: January 29, 2008, 02:06:37 PM »

When I took the exam a month ago, I was surprised by the number of questions dealing with:

-Snort Signatures (what does the following sig detect? which of the following sigs would you use to detect x? etc.)
-Packet Analysis
-What programs are used to do what (Loki is use for what?)
-Poor interpretation of the English language

G'luck!
Logged

Poking at security since 1986.  +++ATH
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #4 on: February 04, 2008, 05:27:25 PM »

Several years ago the CEH examine was also filled with snort signatures and what tool does what kind of thing.  Make sure you know what all the most common tools do.  The more common tools like nmap and netcat you should know  the options. As far as packet read out, make sure you can read some hex. What they will do is blank out some of the letter equivalents and then you need to make sense of it. If you haven't memorized your hex that still is not a biggy because there is usually enough info available to put it together. That is, if you see what letter repeats you can figure out what the hex value is and then hopefully translate the appropriate hex line with the missing ascii into something readable and then pick the correct answer.
« Last Edit: February 04, 2008, 05:31:11 PM by Kev » Logged
bigwhiff
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #5 on: February 05, 2008, 12:23:28 AM »

Hi All,

Well I passed the CEH exam with an 82% not great but I spent about 8 hours studying for the test after passing my GCIH.  It is funny though the previous write up on the forum with the CEH study guide made it sound like I had the same exam.  THOUGHTS:

About 1/4 of the test was log reviews. Snort/tcpdump/etc.
NMAP and all the associated switches was huge maybe 15 questions
I used the CEH exam study guide (condensed book) and Testking practice tests and about 25 questions were exact duplicates on the test.

Over all I felt cheated some what by the test.  It has a sense of almost being something valuable, it has a good breadth of knowledge but it is such a patchwork that it doesn't really seem to accomplish anything.  Pretty much what most have said here on the forum.  Since I had already scheduled the test before finding this forum, I didn't put much effort into studying for the test.

Now onto completing my paper for the GCIH gold and trying to run through the GCFA material.

Cheers,
Jack

Logged

Jack Campbell
CCNP CCDP GCIH GHTQ C|EH
http://secauditor.wordpress.com
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« Reply #6 on: February 05, 2008, 01:09:01 AM »

Well good job!
Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #7 on: February 05, 2008, 01:19:28 AM »

Congrats bigwhiff, 82% isnt bad at all.
Logged

eCPPT, GCIH, OSCP, OSWP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4168


Editor-In-Chief


View Profile WWW
« Reply #8 on: February 05, 2008, 10:56:08 AM »

Congrats and good write up. It's these kind of posts that really help people in determining what and how to study.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.