Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests and 2 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
Is CEH really useful?
EH-Net
May 25, 2013, 08:44:42 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
Is CEH really useful?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Is CEH really useful? (Read 8254 times)
0 Members and 1 Guest are viewing this topic.
shakuni
Jr. Member
Offline
Posts: 80
Is CEH really useful?
«
on:
August 25, 2008, 12:23:12 AM »
I am active in infosec arena for some time now and I beleive that I know all the moves of the game. Recently I just got a book on CEH preparation and I found that the exam is really easy and doesn't cover much material there is. So is CEH really worth it?
I think I can clear it easily within a week, should I do it?
Logged
There is no rule, law or tradition that apply universally... including this one.
dalepearson
Sr. Member
Offline
Posts: 357
Re: Is CEH really useful?
«
Reply #1 on:
August 25, 2008, 02:25:21 AM »
This is just my personal opinion, but all certs are the same thing.
A certification is an official way of proving you have studied a subject, and retained the knowledge, allowing you to answer questions and carry out tasks. As a reward you get the certificate to prove this, should anyone want to see it.
Personally (and maybe its because I end up paying for all the courses I do) I am much more concerned with obtaining as much knowledge as I can, and not really to fussed with getting the piece of paper. I have interviewed so many people who have certifications for all sorts, but they dont really seem to know what they are doing, they just dont know how to apply the knowledge they claim to have I guess.
So personally if you have had no issues proving yourself in the past, then just having the knowledge should be enough. However many organisations like people to have the Certs, as it helps with the marketing.
Sorry if this has been of no help, but I dont think there is a right answer, just the one you feel most suitable to your needs.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Is CEH really useful?
«
Reply #2 on:
August 25, 2008, 03:00:25 AM »
Shakuni,
think I'm somewhere in the middle here. The key to any training is, as Dale says, getting as much knowledge as you can. Certifications are secondary. However I still intend to get as many certifications as I can get my hands on.
Having the cert may get you the interview, while lack of knowledge gets you the door. But in some cases lack of the certs means you won't get the interview to prove you know your stuff.
Bottom line is (AFAIK, not C|EH qualified yet) the exam is relatively cheap compared to other certs. If you believe that you already have all the required knowledge making it a simple and quick process for you to gain the cert then I'd recommend going for it.
Granted, you may find that having the cert provides no benefit due to your exhisting experience/skillset, but having it should have a detrimental effect either. Plus it never hurts to flex you little grey-cells every now and then
Just my £0.02...
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Simon
Newbie
Offline
Posts: 18
Re: Is CEH really useful?
«
Reply #3 on:
August 25, 2008, 07:00:09 AM »
Note: I'm somewhat biased in this answer
I think that a cert is just a means to opening up doors that may otherwise be closed to you. Same as a college degree -- they don't mean that you are an expert in the field, but they're at least an indication that you have the knowledge and capability to learn. A C|EH doesn't mean you're a hacker....but it is an indication that you can learn the skills needed and gain the experience.
I've found the C|EH to be one of the more technical certs out there for hacking (more decidedly in the "gray" range than others). For a beginner, it's very tough....one of the harder exams some of the rookies at my office have had to take. For someone with experience, it's really not so bad (as you surmised). To me, that's a sign of a good test in that it means the test checks for knowledge that you actually apply.
There's a number of things that I don't like about the exam, but the good outweigh the bad for me.
Logged
C|EH, ECSA, C|EI
http://www.halock.com
Ketchup
Hero Member
Offline
Posts: 1021
Re: Is CEH really useful?
«
Reply #4 on:
August 25, 2008, 07:15:28 AM »
I think that this cert is is meant to get your started in the pen testing world. I don't believe that after you pass the exam you are necessarily ready to become a "hacker." Still, I think it has a good foundation and the rest is up to you.
Logged
~~~~~~~~~~~~~~
Ketchup
mad_irish
Newbie
Offline
Posts: 17
Re: Is CEH really useful?
«
Reply #5 on:
August 25, 2008, 07:57:38 AM »
Certification, in the end, stands as independent verification that you passed a test. The test criteria and the respectability of the certifying body determine the value of the test to others.
Personally, when I interview someone I don't give a second look at the certifications they have. I look for experience that proves the assertions the certifications make. Proving you can apply knowledge that a certification tests is much more difficult than just getting a certification.
I have to applaud the CEPT because it has a practical portion that is unstructured, that forces you to apply your knowledge. If all certifications had this sort of component fewer people would be certified but certification would be worth a lot more.
That said, in the end I think demonstrable knowledge and skill are much more important than a certification, but then again I'm not working in a big box corporation. For large organizations, the HR departments will insist on some sort of rubber stamp they can use to weed out candidates. So if that sort of job is your goal, certifications are great.
Certifications are also good if you're freelance or doing consulting. Having certifications stand in good stead for references (which are probably better). However, having lots of certifications will make your client feel more confident about you, and allows them to justify their investment in your services to their superiors. Like the saying goes, nobody ever got fired for choosing the Gartner pick.
Outside of consulting and big corporations though, in that other murky realm inhabited by your peers, a certification is going to be worth the paper it's printed on. Other security professionals, especially those who are familiar with certifications, view certifications with quite a bit of skepticism. Proving to this audience that you know your stuff will require quite a bit more. In this arena I would say a published article is worth a lot more than a certification. Working on an open source project, producing white papers, publishing exploits and the like will go a lot farther to prove your credibility than producing a certification that shows you memorized the answers to a hundred multiple choice questions.
Of course, going to a hiring officer at a large company and saying "I published the remote root compromise of servers running foobar 1.2" will probably just get you a blank look. On the flip side, if you do something like that, someone might just come looking for you with a job offer. I never heard of anyone trolling the CISSP registrations looking to hire their next rock star though...
Logged
oleDB
Recruiters
Full Member
Offline
Posts: 236
Re: Is CEH really useful?
«
Reply #6 on:
August 25, 2008, 09:32:05 AM »
In its current form, I do not believe the CEH provides any value. I studied for a week and passed it easily. My complaints about it, are that it is too much focused on tools and options of said tools. Knowing that a tool exists and how to use it, is nothing special IMHO. I wouldn't call the CEH a pen testing cert either. Its more like hacking tools 101.
Logged
Simon
Newbie
Offline
Posts: 18
Re: Is CEH really useful?
«
Reply #7 on:
August 25, 2008, 09:37:13 AM »
One thing to keep in mind on the C|EH is the nature of the exam: it's a random draw of questions from an increasingly large pool.
In the exams that I've proctored, I've seen some very bright guys get a rough draw of questions and have a hard time with the exam. I've also seen some "not so bright" guys (to put it lightly) get an easy draw on questions and coast right on through.
In the last round of proctoring, one guy failed the exam and decided to re-sit it immediately (it's a 4 hour exam). He passed on the second try, saying that the questions he got on the second round were a LOT easier than the first.
It's all about the draw.
I tend to think of it as: the exam does a decent job of eliminating false positives (you need to know the subject matter to pass)....not so good at eliminating false negatives.
Logged
C|EH, ECSA, C|EI
http://www.halock.com
Kev
Sr. Member
Offline
Posts: 428
Re: Is CEH really useful?
«
Reply #8 on:
August 25, 2008, 01:50:39 PM »
Is the CEH useful? Yes and no. I believe it depends on how you present it and yourself. Is nmap useful? Same answer. It depends on how you apply it. In one persons hands it can be useless and in another it can be a good tool. The CEH is not like having a Havard degree where most people will just automatically assume you have your act together. But if you know how to sell yourself and present it in a certain way, it can open some doors. All in all I would say having it is a plus as I would say with any certification. Just don't expect the world to coming breaking down your doors because you have it.
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Is CEH really useful?
«
Reply #9 on:
August 25, 2008, 02:43:00 PM »
I'll echo Kev's words. The cert got me the interview and it showed that I wanted to get into the field and wasn't afraid to spend my own money to do so. After getting the interview, the rest was up to me. Yes certs have value, but they are just a step in getting the job, the rest is up to you.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
shakuni
Jr. Member
Offline
Posts: 80
Re: Is CEH really useful?
«
Reply #10 on:
August 25, 2008, 11:25:18 PM »
Thanks a lot guys.
One more question,
If certs are only good for HR filtering then I don't need it cause I am already in(just because of my skill). So should I get it now?
@mad_irish, this one was great!
Quote
I never heard of anyone trolling the CISSP registrations looking to hire their next rock star though...
Logged
There is no rule, law or tradition that apply universally... including this one.
don
Editor-In-Chief
Administrator
Hero Member
Online
Posts: 4169
Editor-In-Chief
Re: Is CEH really useful?
«
Reply #11 on:
August 26, 2008, 09:52:33 AM »
Couple things:
1. You may not be working where you just got hired for the rest of your life. In fact, chances are you will not. You should always look at your resume as a work in progress.
2. Your new employer may pay for the training & exam whether that be CEH, CISSP or any other cert. So then why not?
$.02
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
dalepearson
Sr. Member
Offline
Posts: 357
Re: Is CEH really useful?
«
Reply #12 on:
August 26, 2008, 01:44:59 PM »
If there is someone else paying, and there isnt to much of a catch, and you have the time and they support you, its probably worth a shot.
With all things though, its easier if you
actually
want to do it.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.