Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 61 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow GPEN - GIAC Certified Penetration Testerarrow Passed GPEN - My Experience
EH-Net
May 25, 2012, 09:24:20 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Passed GPEN - My Experience  (Read 5902 times)
0 Members and 1 Guest are viewing this topic.
ngriffin
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: June 01, 2010, 04:16:47 AM »

I just passed (89%) the GPEN exam and I wanted to detail my experience so that others may benefit.

Just to give you some background, I have been working in security for about 12 years. I have experience in Vulnerability Assessments, Web Application Security testing and Penetration testing. 

My journey to the GPEN certification started last year when I studied for the CEH and ECSA exams. A lot of the material is the same although the CEH/ECSA exams themselves require more memorization. I did not take the SANS 560 course or have a copy of the material.

Last month, I purchased a SANS practice test to help gauge my study progress. I wanted to see how I was doing before I paid out the $900 for the exam. I figured losing a $100 was not that drastic. I passed the first exam with an 84% and had to use the full four hours. I was happy with my progress.

I then purchased the exam, scheduled it for two weeks out and started tightening up on my skills. I also worked on my indexing of material.

What I used.

I have taken a couple of other SANS courses such as Command Line Kung Fu and PCI which did contain relevant material and hands on exercises. I wrote both STAR exams for those courses which gave me some experience with the SANS exam format.  I also completed the CEH, ECSA exams last year as mentioned.

I read books such as Professional Penetration Testing, Live Hacking, Google hacking, the NMAP guide and many others.

I have a lab configured at home with VMware workstation and windows and Linux clients.

I also work with some of the tools which helped immensely.

The Exam

I brought a backpack full of material to the exam. I indexed everything. Actually going through the two practice exams (87% and 95%) helped me focus on the material I needed with me.

I found the exam to be similar to the practice tests but harder. The practice exams only scraped the surface for the different topics and the real exam dug into the finer details. Fortunately for me, I took the queue from the practice exam to actually do the digging.

Overall I enjoyed the experience as it allowed me practice with tools that I don’t get to use all the time.

I hope this helps.
 
Cheers,
Norbert Griffin
CISSP, CISA, GPEN, CEH, ECSA, LPT, MCSE
« Last Edit: June 01, 2010, 05:58:56 AM by ngriffin » Logged
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #1 on: June 01, 2010, 04:52:19 AM »

It certainly does, thanks for sharing!
Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
Manu Zacharia (-M-)
Sr. Member
****
Offline Offline

Posts: 393


c0c0n Hacking Conference - where hackers unite


View Profile WWW
« Reply #2 on: June 01, 2010, 04:56:55 AM »

First of all congragulations.

The experience was pretty comprehensive and useful. Thank you so much. And also welcome on-board EH-Net. I see this is your first post. Smiley
Logged

Manu Zacharia
MVP (Enterprise Security), ISLA-2010 (ISC)², C|EH, C|HFI, CCNA, MCP,
Certified ISO 27001:2005 Lead Auditor

There are 3 roads to spoil; women, gambling & hacking. The most pleasant with women, the quickest with gambling, but the surest is hacking - c0c0n
Equix3n-
Sr. Member
****
Offline Offline

Posts: 379



View Profile
« Reply #3 on: June 01, 2010, 05:39:45 AM »

Congrats!
Thanks for sharing your experience and welcome to the forum Smiley
Logged
SecMan
Newbie
*
Offline Offline

Posts: 17


View Profile
« Reply #4 on: June 01, 2010, 12:46:31 PM »

Sweet.  Way to go ngriffin
Logged
secureseven
Jr. Member
**
Offline Offline

Posts: 79



View Profile
« Reply #5 on: June 01, 2010, 12:51:51 PM »

Congrats! Good insight. I am looking to go down a similar path since I personally do not have the funds to take the whole course. Still in college, I do not have the backing of a company either lol.
Logged

http://twitter.com/mikesantillana
eLearnSecurity Team Member.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #6 on: June 01, 2010, 03:03:11 PM »

Thanks for the feedback, and congrats!

The GPEN is definitely on my radar, after I complete: 1.) OSCP and 2.) eCPPT (eLearn's cert)

So it's nice to get some solid feedback from folks who've 'been there, done that.'

Again, congrats!
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
impelse
Sr. Member
****
Offline Offline

Posts: 493


View Profile
« Reply #7 on: June 01, 2010, 07:28:20 PM »

Congrats
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security, Working Windows 7 70-680
BillV
Hero Member
*****
Offline Offline

Posts: 1830


View Profile WWW
« Reply #8 on: June 01, 2010, 08:17:45 PM »

Welcome to the community and congrats!

I agree 100% with your assessment that the practice exams are a little bit easier than the actual exam. I thought the same thing when I did the GPEN. Did you take an ECSA/LPT course from any of the EC-Council master instructors? I felt that most of the material in GPEN was quite similar to that of ECSA/LPT.

BillV
Logged
ngriffin
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #9 on: June 02, 2010, 06:10:54 AM »

No I have been doing this all on my own. It’s hard to fit in courses with work and life. There is also so much material out there like books, videos and sites like this. I also really enjoy figuring things out myself. It takes a bit longer but it’s worth it for me. 

I have not decided on my next certification. I’m considering the Offensive Security cert but I’m also looking at the SANS GWAPT because of some projects I’m currently working on. Any suggestion?

Cheers,
Norbert
Logged
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 660



View Profile
« Reply #10 on: June 02, 2010, 08:48:03 AM »

ngriffin, I followed the same path as you for my GSEC certification last winter: bought a practice exam, put all my notes and materials together and took the test.

Since I pay everything from my own pocket, it also made sense to me...

I will be looking at GPEN in fall!
Logged

GPEN, GSEC, CEH, CISSP, PMP
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #11 on: June 18, 2010, 06:51:27 AM »

Congrats on passing and thanks for sharing your experience. Also, welcome to the community.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.323 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.