Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 67 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
GPEN - GIAC Certified Penetration Tester
GSEC and GPEN Down
EH-Net
May 18, 2013, 02:27:15 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
GPEN - GIAC Certified Penetration Tester
(Moderator:
don
) >
GSEC and GPEN Down
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: GSEC and GPEN Down (Read 10824 times)
0 Members and 1 Guest are viewing this topic.
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
GSEC and GPEN Down
«
on:
April 01, 2010, 05:04:38 PM »
I just challenged these since I didn't feel like I'd get much out of paying $3500/course for these. You don't get the official resources, but I figure at $900/exam and $150/retake, I'd still come out ahead even if a stumbled once or twice. I'm definitely glad I went this route.
I did the GSEC first. It is 180 questions, and you are given five hours. I got 170 correct and finished in an hour. Then I moved on to the serious one. The GPEN is 150 questions and you're given four hours. I got 136 in that one, and again finished in an hour. I actually only had ten wrong, but the java-based connection to a virtual machine was so slow that I just guessed on those because I had clearly already passed.
I do like that they tell you whether or not you got the previous question right or not, so you always know where you stand. I'd gladly give up the ability to review for that. I do find it humorous that they end the exam immediately if you ever get to the point where it's no longer possible to pass. Plus, I imagine it helps maintain the integrity of exams.
The questions were probably more straight-forward than any other exam I've ever taken. I wouldn't recommend challenging these unless you're well versed with the material. I've already done MCSE:S, Linux+, CCNA, CWNA, CWSP, etc. I've also gone through everything for the OSCP and CISSP, and regularly do pen testing, IT audits, risk assessments, vulnerability assessments, social engineering, etc. Needless to say, this was basically all review.
I might challenge the GWAPT next since I've been dabbling with web development since I was 13 and am familiar with all the common attacks. I might have to get the courses for GCIH and GCIA since those are further outside my realm of expertise. I'll see how I feel after I get through Counterhack Reloaded (supposedly close to the IH material) and the new Wireshark book. A quality Snort resource or two should put me in pretty good shape. I'm hoping to make a GSE attempt in the fall of 2011, and getting all those under my belt will make me eligible.
I'll worry about that later though. I only have a couple weeks to prepare for the CISSP, and I'm not even through the AIO book yet...
I didn't really get to prepare for these since I was so busy with work, so I never got around to taking the practice exams. I've already given one of the GSEC exams away, but I have one more of those and both for GPEN. My expiration for taking the GPEN was April 3th, and I'm not sure if the practice exams expire then or not. You must be an active/contributing member to apply. Sorry, no lurkers
Edit: GPEN practice exams are good until 6/2/2010, and GSEC exams are good until 9/22/2010.
«
Last Edit: April 02, 2010, 02:07:49 AM by dynamik
»
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
kriscamaro68
Jr. Member
Offline
Posts: 61
Re: GSEC and GPEN Down
«
Reply #1 on:
April 01, 2010, 05:13:42 PM »
Nice job on passing both. As for the GSEC what made you decide on that and not go for something else a little higher up? What was your take on the GPEN in comparison to the CEH? I am very interested in the GSEC practice exam. Like I said in the other post I made I am willing to trade or get you an o'reily book if interested.
Congrats and good luck on the CISSP.
Logged
A+, Net+, Server+, Security+, MCP/XP
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: GSEC and GPEN Down
«
Reply #2 on:
April 01, 2010, 06:08:17 PM »
Actually, I had allocated that first GSEC practice exam to you since we discussed it in that other thread, so there's still one more for someone else
PM me your email address.
GSEC is a prereq for the GSE, and I had a good feeling I could get through it easily, having already done the other certs I have. You can substitute GCUX and GCWN for the GSEC, but I don't know if I could get through those without the course materials. It was simply the cheapest and easiest way to fulfill that requirement.
Honestly, I thought the GPEN was a lot easier CEH. I hated the wording in the CEH, and it was ridiculously broad (there are no questions about terrorists and GPS on the GPEN). Keep in mind, I also do GPEN-level work every day, so that factors into the equation as well. I wouldn't lump it in with the A+ or anything
If the powers that be can forgive a link to another forum, my CEH experience is
here
.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
What90
Full Member
Offline
Posts: 120
Re: GSEC and GPEN Down
«
Reply #3 on:
April 02, 2010, 06:48:48 PM »
Nicely done dynamik!
That a pretty impressive showing on both exams.
As to the 504 I'd imagine you'd do pretty well, as 560 and 504 have significant cross overs on the tools. The mindset and approach to incident response as the key differentiators.
503 is a very different world and a more intense packet beast :-) If you get the chance, or work to pick up the tab, I'd take the SANS class as there's a lot of information and skill sets in the the class and material.
If you are manic enough to challenge the 503 exam, the wireshark book would be a great starting point (waiting for mine to turn up) and get yourself up to speed on packets on the wire.
Then I'd head over to honeynet challenges
http://www.honeynet.org/
and work your way through them.
Good luck with your progress to attempt on the GSE in 2011. Perhaps you should see if you can get some fellow EthicalHackers on this board to sign up with you and take the exam :-)
Logged
http://www.chris-mohan.com
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: GSEC and GPEN Down
«
Reply #4 on:
April 02, 2010, 09:30:30 PM »
Quote from: What90 on April 02, 2010, 06:48:48 PM
Nicely done dynamik!
That a pretty impressive showing on both exams.
As to the 504 I'd imagine you'd do pretty well, as 560 and 504 have significant cross overs on the tools. The mindset and approach to incident response as the key differentiators.
503 is a very different world and a more intense packet beast :-) If you get the chance, or work to pick up the tab, I'd take the SANS class as there's a lot of information and skill sets in the the class and material.
If you are manic enough to challenge the 503 exam, the wireshark book would be a great starting point (waiting for mine to turn up) and get yourself up to speed on packets on the wire.
Then I'd head over to honeynet challenges
http://www.honeynet.org/
and work your way through them.
Thanks! I appreciate the advice.
Some of us at the office made the "mistake" of getting it signed. The non-signed copies showed up awhile ago while we're still waiting
Quote from: What90 on April 02, 2010, 06:48:48 PM
Good luck with your progress to attempt on the GSE in 2011. Perhaps you should see if you can get some fellow EthicalHackers on this board to sign up with you and take the exam :-)
So, are you volunteering?
A coworker of mine is also going to give it a shot. We're probably going to do terribly since it's not what we do day-to-day. I think we're each just going to setup a lab and take turns attacking each other's stuff and see what we come up with. Oh well, it's a challenge and something to work towards. I'd definitely like to move more into the IA/IH/forensics side of things sooner or later.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
veritas_libertas
Newbie
Offline
Posts: 13
Audentis Fortuna Iuvat
Re: GSEC and GPEN Down
«
Reply #5 on:
April 03, 2010, 12:27:10 AM »
Congratz man! So do you think GSEC can comfortably be challenged without taking a class? Also, do you get study material when you sign up to challenge a GIAC certification?
Logged
CCENT | Network+ | Security+ | MCTS
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: GSEC and GPEN Down
«
Reply #6 on:
April 03, 2010, 08:32:06 AM »
Quote from: veritas_libertas on April 03, 2010, 12:27:10 AM
Congratz man! So do you think GSEC can comfortably be challenged without taking a class?
That totally depends on your experience. I know someone that actually took the course, and the way the course goes is that they dedicate one day to Windows, one to Linux, one to Networking, and so on (I don't remember the designations for the others).
Here are the exam objectives:
http://www.giac.org/certbulletin/gsec.php
I've already done MCSE:S, CCNA, CEH, CWSP, Linux+, etc., so hardly any of that was new to me. I think the majority of the ones I got wrong were related to VOIP since I have no experience with that.
I wouldn't say the exam is significantly harder than the Security+. It just covers a lot more material, and making sure you have all your bases covered is going to be the most problematic aspect of going the self-study route. The Network Security Bible (2nd) will be a great resource to get you started. It was actually written by one of the GSEC authors. After that, I suppose you could just see how you do on the practice test questions, take notes about what you need to research further, and repeat.
Quote from: veritas_libertas on April 03, 2010, 12:27:10 AM
Also, do you get study material when you sign up to challenge a GIAC certification?
Nope, that's what I meant when I said you don't get the official resources. I'd challenge every one if they provided those to you. I'm not ragging on the courses; they sound awesome. I'm just having to pay for these out-of-pocket, and I have a difficult enough time coming up with $900 for an exam, let alone $3500 for a course.
Also, see if you can get in their work-study programs. You essentially help out during one of the courses and get to tag along. It's still $800 or $900, but that's a steal for training. I actually got accepted to do the GCIH in New Orleans last January, but my work schedule conflicted with it.
I've also heard you can sometimes pick up extra copies of the course material if you go to the conference and see if they have any they can spare. I remember the cost being something like $400. It's not cheap, but might be a viable option if you're on a budget.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
veritas_libertas
Newbie
Offline
Posts: 13
Audentis Fortuna Iuvat
Re: GSEC and GPEN Down
«
Reply #7 on:
April 03, 2010, 11:33:35 AM »
Thanks.
Part of my main reason for wanting to pursue the GSEC in the future is a search on Monster.com for security jobs. Really the only GIAC certification that you get when you search for GIAC is the GSEC. I figure for me, since I am not currently in a security role it would be best to hit the most commonly looked for security certifications, and then move into the more advanced ones when I have a job coincides with them.
Logged
CCENT | Network+ | Security+ | MCTS
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: GSEC and GPEN Down
«
Reply #8 on:
April 03, 2010, 03:56:11 PM »
Quote from: veritas_libertas on April 03, 2010, 11:33:35 AM
Thanks.
Part of my main reason for wanting to pursue the GSEC in the future is a search on Monster.com for security jobs. Really the only GIAC certification that you get when you search for GIAC is the GSEC.
No problem. No mention of the GCIH though? That's supposed to be extremely hot right now. I wouldn't expect to see a lot for the certs in more niche areas, like the GPEN, GWAPT, etc.
Quote from: veritas_libertas on April 03, 2010, 11:33:35 AM
I figure for me, since I am not currently in a security role it would be best to hit the most commonly looked for security certifications, and then move into the more advanced ones when I have a job coincides with them.
That's an excellent plan. You don't want your certs to vastly outpace your experience. You can always learn a programming language or something if you need to fill your free time
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
veritas_libertas
Newbie
Offline
Posts: 13
Audentis Fortuna Iuvat
Re: GSEC and GPEN Down
«
Reply #9 on:
April 03, 2010, 04:01:49 PM »
Ah yes, dreaded programming
I actually took a basic C programming course during my Associate degree studies. I could pickup where I finished off at. Would a web language be better to study, or software programming?
«
Last Edit: April 03, 2010, 04:04:45 PM by veritas_libertas
»
Logged
CCENT | Network+ | Security+ | MCTS
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: GSEC and GPEN Down
«
Reply #10 on:
April 03, 2010, 04:41:11 PM »
You really can't go wrong with starting out with C or Python. It totally depends on what you want to do though. If you're just going to do web app work, maybe PHP and Java would be better. However, once you get a good handle on one, others (save for something like assembly) aren't too bad to transition over into. I'd encourage you to work on something. It'll come in handy even if you just use it to parse log files or automate some other menial tasks. I haven't done any serious programming for awhile, but all the reverse engineering talk I've seen going on here has piqued my interests again.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
impelse
Hero Member
Offline
Posts: 563
Re: GSEC and GPEN Down
«
Reply #11 on:
April 03, 2010, 10:46:35 PM »
Congrats dynamik, good job.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
n1p
Jr. Member
Offline
Posts: 89
Re: GSEC and GPEN Down
«
Reply #12 on:
April 04, 2010, 07:12:17 AM »
Quote from: dynamik on April 03, 2010, 04:41:11 PM
I haven't done any serious programming for awhile, but all the reverse engineering talk I've seen going on here has piqued my interests again.
Any particular videos or tutorials on RE that you would like to see, just shout and I'm sure I could do something up. Get your interest back up again
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: GSEC and GPEN Down
«
Reply #13 on:
April 06, 2010, 04:33:59 AM »
Congratulations on passing both exams! thanks for the info!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(4) by
impelse
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
Web Applications
: Nessus and Nikto
(3) by
Cyber.spirit
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.