Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
CEH or GPEN more attractive to employers?
EH-Net
May 21, 2013, 06:50:28 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
CEH or GPEN more attractive to employers?
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: CEH or GPEN more attractive to employers? (Read 20361 times)
0 Members and 1 Guest are viewing this topic.
T_Bone
Full Member
Offline
Posts: 199
CEH or GPEN more attractive to employers?
«
on:
January 07, 2010, 12:11:21 PM »
Hi Again guys
Yet again, i have another question on certification comparisons i need some advice on
I am based in the UK and would eventually like to become either CHECK, CREST or TIGERSCHEME Senior certified as these are
the most highly rated security testing certifications in the UK but unfortunately I am unable to do one of them because I dont
have the experience or the money at £1600-£1700 (2500USD) per exam. I am therefore looking for an alternative
certification to help me get into the security testing industry and would like some advice on which to choose next.
I currently hold the Comptia Security+ and GIAC GCIH certification as of last year and am thinking of going after either the CEH
or GPEN next. Unfortunately I cannot afford to attend either course and will therefore have to prepare using self study.
The GPEN exam cost £560 (900USD) and the CEH cost £150 (250USD) which is quite a difference in price but would like to know
which of the certifications would be more attractive to employers?
Any comments appreciated
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: CEH or GPEN more attractive to employers?
«
Reply #1 on:
January 07, 2010, 01:49:25 PM »
Hey T_bone,
It really depends... Ill try and outline the pros and cons of each below:
CEH:
+ The CEH name has more recognizably right now as the GPEN is still relatively new. HR screening personnel know what a CEH is, some might not have heard of the GPEN.
- Anyone who is a real security person i know laughs about the CEH cert based on its old format. It used to be a half hazard, loosely jointed, outdated tools test. The new versions of the test are greatly improved but unfortunately it left a bad taste in some peoples mouths.
- CEH is a non-hands on test.
GPEN:
+ Hands on test. Recently SANS added some practical/hands-on portions back into their tests. Which is good in my opinion.
+ GPEN is a more technical and in depth test. Anyone who knows about SANS/GIAC knows the test curriculum and program are the best right now for a Penetration Testing specific course.
- Still relatively new and might not be recognized by HR handlers.
Hope that helps.
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
T_Bone
Full Member
Offline
Posts: 199
Re: CEH or GPEN more attractive to employers?
«
Reply #2 on:
January 07, 2010, 02:34:03 PM »
Hey Jhaddix
Thanks for the quick reply.
Yeah I understand what you mean about how the CEH is felt by real security folk. I have a friend in the industry and he told me that every security consultant he knows laughs about the CEH, which is why i am reluctant to take it, but when viewing job posts here in the UK for security roles the majority ask for CHECK or CREST (which is what he is) and you sometimes find the odd one that asks for CEH but never SANS( I think i have only ever seen one posting).
I quite like the sounds of the OSCP and the E-Learnsecurity course set to be released early this year also but as most HR personel dont know SANS i very much doubt they would know either of these.
Its difficult cause of my lack of experience i am trying to get certs to show my enthusiasm and understanding but the cost is so extreme and do not have a company that can pay for it as i work as a contractor in sys admin.
Logged
grinderman
Newbie
Offline
Posts: 2
Re: CEH or GPEN more attractive to employers?
«
Reply #3 on:
January 07, 2010, 03:11:03 PM »
Hi,
I'm currently both CEH & GPEN (as well as GCIH) and currently progressing towards Check Team Leader so feel that I might have quite a good perspective on this
CEH is a bit of a joke really - I only took it because I had some training funding which paid for the exam. I did a bit of self study and used the various practice exams and questions scattered across the net. The actual exam took me about 30 minutes point'n'click. People tend to view it as giving you a lot of info on viruses and snort and not much else. However it is very widely recognised and everyone in HR (or an OCR programme) knows it.
GPEN was a great course, it sounds like your thinking of just doing the exam challenge without the course - not something I would recommend!! Although the SANS exams are open book as you know from your GCIH, you still need the books to give you the info! I created an index of my notes and this was totally invaluable in passing - I would have still passed having done the course, a week of revision and 2 practice exams, but it would have been more difficult.
It may be worth looking at the Tiger website
http://www.tigerscheme.org/
as they have a tiered approach which would allow you to progress through to CTL. The last comment I'd make is that you cant actually be Check/CREST/Tiger unless your working for a company which is tied to those organisations, so most people get so far on their own then their company puts them through Check equivalence after relevant experience.
Regards,
Rob
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: CEH or GPEN more attractive to employers?
«
Reply #4 on:
January 07, 2010, 03:19:02 PM »
grinderman: thanks for the awesome perspective!
A side note, which is interesting, the OSCP actually is gaining some name space. I've had it on on my resume and gotten questions as to how the training and test was. It was very surprising. Real sec people know Muts and the OS people and have much respect for their program.
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
T_Bone
Full Member
Offline
Posts: 199
Re: CEH or GPEN more attractive to employers?
«
Reply #5 on:
January 07, 2010, 03:55:06 PM »
Thanks for the reply grinderman, that is indeed helpful
So realistically i should probably go for the CEH as it is the cheaper option to add an extra cert to my CV which i hope will work in my favour. I have checked out the Tigerscheme and the Qualified course and exam is £1590 plus VAT so once again very expensive.
I think at the moment i am just looking for the cheaper and easier way of getting a foundation to enter the security arena, what qualifications did you guys have when you first started off? Or did you just get a break?
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: CEH or GPEN more attractive to employers?
«
Reply #6 on:
January 07, 2010, 04:50:00 PM »
I had a Cisco background in a past life. I took the GSEC 1st GPEN 2nd to break into security.
Really, if you get to a real interview person, try show them you are passionate about current security issues. Let them hear you talk about SQLi, XSS, Newer kernel exploits, etc. They will hire passion over certs in my opinion. Their gonna have to train you for their process/infrastructure when you get hired anyways
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
Ketchup
Hero Member
Offline
Posts: 1021
Re: CEH or GPEN more attractive to employers?
«
Reply #7 on:
January 07, 2010, 09:22:16 PM »
Jason, would you go with GPEN or OSCP if you had to chose?
Logged
~~~~~~~~~~~~~~
Ketchup
Jhaddix
Sr. Member
Offline
Posts: 317
Re: CEH or GPEN more attractive to employers?
«
Reply #8 on:
January 08, 2010, 12:12:11 AM »
I'd say GPEN first then OSCP later =)
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
T_Bone
Full Member
Offline
Posts: 199
Re: CEH or GPEN more attractive to employers?
«
Reply #9 on:
January 08, 2010, 02:07:15 AM »
See this is so frustrating because my first choice would be to do the GPEN, but would have to do it without attending the course as it is expensive (unless i manage to get the facilitator role as i did with GCIH again, but feel it was a lucky break). I believe that if i could afford the materials that SANS offer as Self study (which i believe includes books and audio) that would be fine or actually just the books i believe would be sufficient, but this is still too expensive!
I have to admit i am not getting a lot of love for CEH so far and to be honest am not surprised cause its not really the option i wanted to take either...
Decisions.................
I just wish i won the lotto right now
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: CEH or GPEN more attractive to employers?
«
Reply #10 on:
January 08, 2010, 02:54:44 AM »
T_Bone,
The only tests i think SANS could offer that you couldn't pass without the physical classes is the GSEC, GCIA, GCFA, GREM, and GAWN.
GPEN is totally do-able self study. All the answers are in the books. Study hard and create a spectacular index you will pass.
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
UNIX
Hero Member
Offline
Posts: 1235
Re: CEH or GPEN more attractive to employers?
«
Reply #11 on:
January 08, 2010, 05:15:55 AM »
I can only speak about CEH as I have done the course, will soon go for the exam and recently had a job interview where I was able to bring it up as well.
I thought that it was only little known by the interviewer, probably because it is more known in the USA - however, it helped to demonstrate that I am interested in security and do more than 'necessary'.
The exam itself (without any course) seems to be quite cheap compared to some of the other certs, therefore I would go for it, if money is short but you want something to do.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: CEH or GPEN more attractive to employers?
«
Reply #12 on:
January 08, 2010, 06:45:50 AM »
I also hold both CEH and GPEN. In my interview for my current position, neither was mentioned or brought up specifically - likely because neither qualify for 8570 currently - but they did say that my security certification were what really stood out, and that probably helped give me an edge on the other candidates.
In my interview yesterday, the manager was familiar with SANS/GIAC but had not heard of GPEN. He also had not heard of CEH or EC-Council.
I agree with Jason, you can surely do GPEN self-study, just make sure you become very familiar with the tools/topics that are listed in the bulletin.
It's certainly a tough decision to make. As you've mentioned the CEH has shown up on job postings (and it is probably more widely known), plus it's cheaper, I would probably go that route.
Logged
T_Bone
Full Member
Offline
Posts: 199
Re: CEH or GPEN more attractive to employers?
«
Reply #13 on:
January 09, 2010, 03:44:12 AM »
I have made a decision to do the CEH now and hopefully fingers crossed will be accepted to be a facilitator at the same SANS conference I did last year!
Thanks for your input guys, i am sure this will not be the last question i ask
Logged
KamiCrazy
Jr. Member
Offline
Posts: 78
Re: CEH or GPEN more attractive to employers?
«
Reply #14 on:
January 10, 2010, 03:09:19 PM »
I decided to do the CEH/ECSA/LPT route as it was vastly more affordable than GIAC certs.
I think I could probably do the GPEN without attending the course as long as I had access to the study books. Once I am done with CEPT I think I might give that a go.
(Shameless plug, if anyone would like to sell me their recent GIAC study materials, please send me a PM.)
However the GIAC GWAPT course looks interesting. Not many options out there which focuses on web apps.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GAWN - GIAC Assessing Wireless Networks
: Karen Millen Dresses Things did improve as the decade gone on
(0) by
dtree70fx
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.