Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 54 guests online
You are here:
Home
Resources
Career Central
CISSP/Career Advice Needed
EH-Net
May 22, 2013, 08:31:14 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
CISSP/Career Advice Needed
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: CISSP/Career Advice Needed (Read 11516 times)
0 Members and 1 Guest are viewing this topic.
xcircusmusician
Newbie
Offline
Posts: 7
CISSP/Career Advice Needed
«
on:
August 21, 2011, 02:48:10 PM »
Hello all:
I’m considering obtaining the CISSP Cert, and I'm trying to get ‘realistic’ advice concerning the opportunities/options that the CISSP would provide me.
I’m 48 years old, and I’m asking for any (brutally honest) advice concerning the realistic options that I have for securing a career in I.T. Security. (Probably Entry-Level)
(I’ve been with Comcast for eight years/Four of those on the Senior-Help Desk)
I currently have: Associates (IT) /Network +/Security +/Certified Ethical Hacker (CEH) and some experience with the OSCP. I found the OSCP to be very challenging.
Any thoughts/insight on the difficulty of CISSP compared to the OSCP or CEH?
I’m experiencing a sense of ‘urgency’ in securing a career, and am open to any/all options.
I’m willing to relocate/travel 100%/Contract/etc.
I’m looking into options such as: Incident Handler/Loss Prevention/Management/
I’m willing to spend a year (self-study) to obtain a CERT that will put me in the 50K to 70k range
If you have any advice/resources/etc., I would certainly appreciate it.
Thanks in advance,
Michael
And yes, I really am an Ex-Circus Musician (Bass Guitar)
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: CISSP/Career Advice Needed
«
Reply #1 on:
August 21, 2011, 03:12:05 PM »
CISSP is a totally different animal than CEH or OSCP. CISSP has a management spin and is less technical, however you're expected to know technical details in some areas.
I actually just took the CISSP exam 2 days ago. Do NOT underestimate this cert. I always looked at it as a "read a book and pass the exam" type of cert. The reality is that there is a lot of information to remember for that exam. Quite frankly, if you don't have a decent amount of practical work experience in more than a few of the domains, its going to be even harder. Dedicate serious time to CISSP if you're going to do it because you really have to understand all the concepts and how they fit together. That test was a bitch. Then again.....our buddy H1t M0nkey cranked out CISSP in 17 days which is pretty amazing.
CISSP is beloved by HR and hiring people. I just did a quick search on dice.com and there were 1361 jobs across the country. This is a valuable cert for your career. In comparison, there were 6 jobs for OSCP and 92 for CEH
I wont get into the debate on which is more valuable for your brain....we'll leave that for another thread.
Look at the 10 common bodies of knowledge for CISSP, do you have at least 5 years experience in at least 2 of them? Another CISSP will have to vouch for that experience. If you don't have that, you'll be put into CISSP purgatory until you satisfy the practical work experience. If you do, I would say go for it because as you can see by the job numbers, there are plenty of them.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: CISSP/Career Advice Needed
«
Reply #2 on:
August 22, 2011, 07:48:17 AM »
Quote
Then again.....our buddy H1t M0nkey cranked out CISSP in 17 days which is pretty amazing.
Yes, but I did GSEC a year before CISSP and they both cover similar material. I didn't have any life in this 17 days: Waking up at 4:30am to study before work then studying again on every single evenings until 11:00pm (so about 5 hours a day, more on weekends). It took me a full month to recover from this crazy pace.
Oh, I forgot to mention I have 2 daughters...
So don't do that! Take 2-3 months to study this beast...
Good luck cd1zz!!!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
WCNA
Full Member
Offline
Posts: 187
Re: CISSP/Career Advice Needed
«
Reply #3 on:
August 22, 2011, 03:48:26 PM »
Quote
Take 2-3 months
Yes, at least. The test is a bear. If you don't have the FULL time experience required, at least you'll have the ISC2 Associate and that is....well, it's something.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
maxpeck
Newbie
Offline
Posts: 21
Re: CISSP/Career Advice Needed
«
Reply #4 on:
August 22, 2011, 08:47:34 PM »
I'm in a similar situation to the OP. Mid 40's, multiple certs and a good bit of computer experience just not in the domains I want to work in.
I decided to go for the CISSP now because almost every juicy position I see has that same 5 letter certification either required or recommended. I would MUCH rather work on my OSCP or take Joe McCrays Advanced CAST class but the CISSP looks to open more doors for me than almost anything else right now.
To give you perspective on my current study habits - I read a domain in both Kurtz/Vines and Conrads newest 11th hour guide to get a general feel for the topics. Then hit the AIOv5 and OSG2 to fill in the gaps, then take a 250 question quiz on just that domain on cccure to see what I didn't pick up.
So far so good - been doing this since late June for maybe 10-15 hours a week. Its really opened my eyes to what I didn't know existed in the security realm.
I'm going to try and take the test in either October or November depending on how much of my time has to go to projects at work.
BTW - any advice on tweaks to my study habits from you CISSP'ers would be great!
Logged
Max
cd1zz
Hero Member
Offline
Posts: 561
Re: CISSP/Career Advice Needed
«
Reply #5 on:
August 22, 2011, 08:56:01 PM »
max
The only thing I would recommend is making sure that you don't rely on the cccure tests. This may seem obvious, but understand the CONCEPTS behind the questions because none of the practice tests you'll take are like the real exam. Those tests DO help to a certain degree, but by no means the end all be all. The exam requires you to understand concepts for the most part. Of course they sprinkle in some specific/granular stuff just to make you crazy.
I think you're being smart by reading multiple sources and being methodical and diligent. That is a recipe for success.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: CISSP/Career Advice Needed
«
Reply #6 on:
August 23, 2011, 06:45:33 AM »
cd1zz is right, no practice questions is like the real exam and that is a real shame. I bought practices questions from cccure.org, did the ones that came from Shon Harris book (even bought the extra questions from her), did more on another book and above all, I bought the expensive questions from ISC2! All in all, I did answered about 1600 practice questions from 4 different sources.
I was pissed to see the exam is different. Most questions (about 70%) are in the type: "Which answer is the BEST", "What would you do FIRST", etc. It means more than one answer is correct, you need to find the best one...
The other difference was that in the exam, they will sometime use different wording that you are use to. I think their goal is to see if you can talk to an executive who knows nothing about security and describe concepts in his own words. So for example, expect to see "pre-shared key" or "secret key" instead of "symmetric key". This drove my crazy in the exam...
Quote
I'm going to try and take the test in either October or November depending on how much of my time has to go to projects at work.
@maxpeck: Don't forget you cannot take the exam when you want like SANS. Where I leave, they only give it 3 times a year. That's why I did it quickly, I didn't want to wait an extra 6 months to write it...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
WCNA
Full Member
Offline
Posts: 187
Re: CISSP/Career Advice Needed
«
Reply #7 on:
August 23, 2011, 11:21:11 AM »
Benefits of becoming a CISSP
http://www.youtube.com/watch?v=8DZkpynFhak
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
cd1zz
Hero Member
Offline
Posts: 561
Re: CISSP/Career Advice Needed
«
Reply #8 on:
August 23, 2011, 02:44:34 PM »
AHAHAHAHAH that is effing awesome.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
lorddicranius
Sr. Member
Offline
Posts: 447
Re: CISSP/Career Advice Needed
«
Reply #9 on:
August 23, 2011, 03:22:39 PM »
Quote from: WCNA on August 23, 2011, 11:21:11 AM
Benefits of becoming a CISSP
http://www.youtube.com/watch?v=8DZkpynFhak
LOL!
Logged
GSEC, eCPPT, Sec+
hayabusa
Hero Member
Offline
Posts: 1632
Re: CISSP/Career Advice Needed
«
Reply #10 on:
August 23, 2011, 05:54:44 PM »
LOL ++1! Saw that one the other day!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
maxpeck
Newbie
Offline
Posts: 21
Re: CISSP/Career Advice Needed
«
Reply #11 on:
August 29, 2011, 09:00:06 PM »
LOL - nice video - funny thing is he looks like my lawn guy
Thanks for all the pointers guys! The biggest reason I'm not rushing to get this cert it to make bloody sure I get the concepts as well as I can. I know this isn't a Micro$oft exam...
I have 3 testing areas relatively close so I'm good on the test dates, the one available in November should work out well.
I'm using the various practice tests to help me round out the subject matter more than anything else. Taking the end of chapter test from each book is nice but they ask alot of specifics I know I won't be seeing in the same form on the big 6-hour hell-grind. That's one thing I'm dreading a lot - the LONG sit and sweat. I was uncomfortable when I took the CCNA for that very reason. After almost 3 hours sitting there and I so stressed I would have punched a nun in the face just to end it! Poor little nun...
Anyhow - thanks again for the help! Back to the joys of telcom...
Max
Logged
Max
l33t5h@rk
Guest
Re: CISSP/Career Advice Needed
«
Reply #12 on:
October 10, 2011, 01:38:42 PM »
A little late to the party but I think a couple items are illustrated that sum things up. I have been studying for the CISSP for about a year and the breadth is just unreal. I'd say most people, and this even means full time InfoSec types like us, only deal with 3-4 of the CISSP domains on a monthly basis. Even when you get roped in to random things, you may hit 5 or 6 of the domains. It's a bit odd to think that one exam contains a section on a question on how an s-box works in an encryption algorithm and then the next question is what type of fire prevention methods should be used in scenario A in a datacenter. The key point though as pointed out by cd1zz, if you want a resume booster, I can't think of much better than CISSP.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Gates
: Isabelle Marant if you're|a really wonderful|pc|whether you are having a lesson
(0) by
ddogs42zm
News Items and General Discussion About EH-Net
: 1000 страшно пол
(0) by
quohaphoday
GPEN - GIAC Certified Penetration Tester
: Karen Millen Outlet as an example SFTP
(0) by
dtree28yt
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.