Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 33 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
Security
Next step
EH-Net
May 18, 2013, 04:40:29 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
>
Security
>
Next step
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Next step (Read 9892 times)
0 Members and 1 Guest are viewing this topic.
lorgmorgoth
Newbie
Offline
Posts: 7
Next step
«
on:
April 04, 2011, 08:04:31 AM »
Greetings,
A while ago I started to dive into the exciting and thrilling world of network security. I've been a network administrator for quite some time now, but I never had the opertunity to delve into the security aspect of network administration.
I'm currently certified as A+, Net+, Security+, MCSA, MCTIP:SA and JNCIA-FWV and I've enrolled in a 5 day EC-Council ENSA course starting the beginning of May.
Can you give me some advise on the next step?
I would like to focus more on the defensive part of network security (blue team), but I'm not sure which course/certification to pursue next.
The folks at the company where I'm taking the ENSA course, told me to go for CEH next, but that seems to focus more on the offensive aspect. On the other hand, there's more demand in the market for people with a CEH certification than there is for people with (the much lesser known) ENSA certification.
I've looked into SSCP but that one - as with ENSA, doesn't seem to be really valued in the market, due to the demand for CISSP certification.
Because I don't have the necessary work experience for CISSP, CISSP also fall from my shortlist.
Logged
hell_razor
Jr. Member
Offline
Posts: 90
Re: Next step
«
Reply #1 on:
April 04, 2011, 09:52:14 AM »
I would suggest SANS SEC504. It covers (or at least a few years ago) basics about offensive security, but concentrates far more on incident response and handling, some of the legal aspects, and whatnot.
Logged
A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Next step
«
Reply #2 on:
April 04, 2011, 08:39:52 PM »
Yea, 504 would be a good one. Depends on your specific area of interest. 503, 501, etc. might be more interesting for you. I think the SANS stuff is the right direction to go at this point:
http://www.sans.org/security-training/courses.php
Also, don't shy away from the CISSP just because you don't meet the experience requirements. You will be an associate until you meet them. You have six years to meet the requirements once you pass, and you'll only need four with your other certs. For better or worse, that one is practically a necessity, and it's nice to get it out of the way.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
lorgmorgoth
Newbie
Offline
Posts: 7
Re: Next step
«
Reply #3 on:
April 05, 2011, 05:05:31 AM »
I've also looked at the SANS courses, but they're outrageously expensive!
Also, I live in the Netherlands and the SANS certificates aren't really known down here, so I'm not sure if these certifications will justify the high price.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Next step
«
Reply #4 on:
April 05, 2011, 06:42:06 PM »
What do you ultimately want to be doing? We could probably recommend books, websites, etc. that could help you on your journey.
Are their any job sites for your region? Review the requirements for what you'd consider to be ideal jobs. That'll give you some direction for formal education, certifications, and other knowledge and skills.
Welcome to the forums, btw
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
tturner
Sr. Member
Offline
Posts: 432
Re: Next step
«
Reply #5 on:
April 05, 2011, 11:39:07 PM »
Quote from: lorgmorgoth on April 05, 2011, 05:05:31 AM
I've also looked at the SANS courses, but they're outrageously expensive!
Also, I live in the Netherlands and the SANS certificates aren't really known down here, so I'm not sure if these certifications will justify the high price.
800 (850 after June) for conference + 4 months ondemand + cert is really not bad if you are not afraid of a little work.
http://www.sans.org/security-training/volunteer.php
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
lorgmorgoth
Newbie
Offline
Posts: 7
Re: Next step
«
Reply #6 on:
April 09, 2011, 01:32:55 PM »
Quote from: dynamik on April 05, 2011, 06:42:06 PM
What do you ultimately want to be doing? We could probably recommend books, websites, etc. that could help you on your journey.
I haven't got a definitive careerpath laid out yet, I just want to get more involved with (network) security in general for now.
ATM i works as a senior network administrator at a small IT company (in which I hold a minor share) with 15 employees and somewhat under 50 customers ranging from 20 to 350 employees with serveral geographicly dispersed locations.
Our main focus is administering these networks. I spend half of my time designing and implementing the networks, whilst my collegues to the every day administering. Mainly due to the size of our company I spend the other half on petty end-user problems and documentation (one of the more evil parts of the job).
Ideally I would like to spend the majority of my time on the design aspect and balance that out with implementing the nessecary security polices, doing audits and going to security conventions (lol)
Quote
Are their any job sites for your region? Review the requirements for what you'd consider to be ideal jobs. That'll give you some direction for formal education, certifications, and other knowledge and skills.
There's where the short sightedness (is that a proper English verb?) of most HR departments comes in; they only demand the certifications they *know*, so almost any job that's got the 'security' description in it will demand CISSP and I haven't found a single job that mentions the SANS certifications...
Quote
Welcome to the forums, btw
Thank you very much indeed, glad to be here
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Next step
«
Reply #7 on:
April 09, 2011, 02:30:12 PM »
Quote from: lorgmorgoth on April 09, 2011, 01:32:55 PM
There's where the short sightedness (is that a proper English verb?
Yes, and you used it perfectly
Honestly, for what you want to do, the CISSP would actually be fairly relevant. You should also consider the CISA and CISM. Those would set you up really good for a management / auditing position.
Also consider the value of certifications even if they are not listed on HR's wishlist. Years ago, the Linux+ unexpectedly gave me a bump during a technical interview (after I got past the initial HR screening) simply because someone with some basic Linux experience could really help them out. SANS is a pretty well respected institution world wide, and if you get an opportunity to talk to someone more technical, being able to say, I've been trained and/or certified in <whatever> by SANS may give you an edge.
Training and certs are expensive though, so you need to pick-and-choose carefully to maximize your ROI. You'll waste your time and money if you just acquire them haphazardly (speaking from personal experience). You can often acquire a similar level of knowledge through self-study, so make sure you really need the letters before committing to anything.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
lorgmorgoth
Newbie
Offline
Posts: 7
Re: Next step
«
Reply #8 on:
April 10, 2011, 02:25:58 PM »
Quote from: dynamik on April 05, 2011, 06:42:06 PM
What do you ultimately want to be doing? We could probably recommend books, websites, etc. that could help you on your journey.
Recommendations for books, websites etc. are alway welcome!
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Next step
«
Reply #9 on:
April 10, 2011, 07:57:51 PM »
The CISSP AIO (5th) from Shon Harris would be a good start.
http://www.amazon.com/CISSP-All---One-Guide-Fifth/dp/0071602178/ref=sr_1_1?ie=UTF8&qid=1302483244&sr=8-1
For the CISA and CISM, you're pretty much stuck using the official guides. I really don't like the flow of either of them. I actually learned a lot more from going through their practice exam questions.
https://www.isaca.org/bookstore/Pages/Bookstore.aspx
Some others that may be of interest:
http://www.amazon.com/Security-Engineering-Building-Dependable-Distributed/dp/0470068523/ref=sr_1_1?s=books&ie=UTF8&qid=1302483318&sr=1-1
http://www.amazon.com/Myths-Security-Computer-Industry-Doesnt/dp/0596523025/ref=sr_1_2?s=books&ie=UTF8&qid=1302483411&sr=1-2
(kind of basic, but it has some interesting items)
http://www.amazon.com/New-School-Information-Security/dp/0321502787/ref=sr_1_1?s=books&ie=UTF8&qid=1302483427&sr=1-1
http://www.amazon.com/Beautiful-Security-Leading-Experts-Explain/dp/0596527489/ref=sr_1_1?s=books&ie=UTF8&qid=1302483411&sr=1-1
http://www.amazon.com/Security-Metrics-Replacing-Uncertainty-Doubt/dp/0321349989/ref=sr_1_1?s=books&ie=UTF8&qid=1302483419&sr=1-1
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
lorgmorgoth
Newbie
Offline
Posts: 7
Re: Next step
«
Reply #10 on:
May 22, 2011, 06:01:18 AM »
Well, I've nailed the ENSA exam from EC-Council, with a 940 out of 1000.
After careful deliberation on my part, I've deceided to start with SSCP after summer and then to go for CISSP.
Logged
thaper0007
Newbie
Offline
Posts: 4
Re: Next step
«
Reply #11 on:
June 11, 2011, 01:45:55 AM »
is it neccessary to do CCNA and RHCE before going for CEH?
Logged
hayabusa
Hero Member
Offline
Posts: 1630
Re: Next step
«
Reply #12 on:
June 11, 2011, 09:47:59 AM »
No...
Apologies for brevity, but I could swear I just saw someone post in the past day or so, regarding these certs being independent of one another. Will knowledge from one or the other 'help' you? Yeah, certainly. But the certs, themselves, are not 'required.'
«
Last Edit: June 11, 2011, 09:51:28 AM by hayabusa
»
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
tturner
Sr. Member
Offline
Posts: 432
Re: Next step
«
Reply #13 on:
June 11, 2011, 11:40:13 AM »
Quote from: thaper0007 on June 11, 2011, 01:45:55 AM
is it neccessary to do CCNA and RHCE before going for CEH?
I would say CEH is probably easier than either RHCE or CCNA, but if you had CCNA and RHCE under your belt you'd have a really strong base that would certainly be very useful for the kinds of jobs that are asking for CEH.
You don't want to be one of those folks that only focus on the security stuff and neglect their core skillsets. You will miss a ton of stuff.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Наконец то ра
(3) by
Georgydfea
Web Applications
: Nessus and Nikto
(4) by
Seen
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(4) by
impelse
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.