+ Reply to Thread
Results 1 to 10 of 10
  1. Junior Member Registered Member
    Join Date
    Jun 2017
    Posts
    2
    #1

    Default Certification path advice - CISSP to C|EH / OCSP

    I've recently got back on the certification track after taking and passing my CISSP yesterday, and am keen to keep the momentum as far as keeping learning and working on my certifications (getting back to the technical ones), and am looking for some advice on where to go next, ideally from the people who have both a C|EH and OSCP.

    I've worked as a Firewall and Network administrator now for 10+ years and would like to learn some skills from the other side of firewall, and I have my eye on the OSCP, a cert that seems to carry a bit of respect, and offers a learning track thats really going to give you some real world skills. Ive started to take some small steps (very small steps, Cybrary course) into learning to code in Python, with an eye on the long term.

    The question I have, is it worth me studying for and taking the C|EH to get the basic knowledge, or is this just a waste of time and effort because the OSCP will teach me everything I will learn in the C|EH and more? Appreciate there is the HR department being the 1st line of defence angle as far as the C|EH is concerned, so I'm guessing it should be on the list. But for now, I am keen on personal development. Any advice on this path would be appreciated.

    Cheers
    Reply With Quote Quote  

  2. SS -->
  3. Are we having fun yet? UnixGuy's Avatar
    Join Date
    Mar 2008
    Posts
    3,363

    Certifications
    GCFA, eJPT, RHCE, Solaris 10, SNIA SCSP, Security+, Server+, ITILv3, CCNA (Expired)
    #2
    Skip CEH and anything EC-Council. Try eLearnSecurity and SANS (if your employer pays for it)
    Goal: GCFA (DONE), GPEN
    Reply With Quote Quote  

  4. Senior Member shoey's Avatar
    Join Date
    Jun 2016
    Location
    Knowhere
    Posts
    105

    Certifications
    Life
    #3
    I agree with UnixGuy. You will be kicking yourself when you get to the OSCP and realize what the C|EH didn't do for you...

    If you search through the OSCP threads on here you'll find plenty of free resources to study that will better prepare you then speding time/money on the C|EH...
    "I have missed more than 9,000 shots in my career. I have lost almost 300 games. 26 times, I've been trusted to take the game winning shot and missed. I've failed over and over and over again in my life. And that is why I succeed." - Michael Jordan
    Reply With Quote Quote  

  5. Junior Member
    Join Date
    Oct 2017
    Posts
    27

    Certifications
    Security+
    #4
    CEH is definitely better for you HR wise. I would have actually recommended you get it before CISSP since I heard CEH can help prepare you for some of the PENtester material on CISSP but since you've already gotten CISSP CEH doesn't really do much for you outside of HR. I agree with the rest, go for an ELearn cert first to prep for OSCP if you're just interested in the skill.
    Reply With Quote Quote  

  6. Senior Member
    Join Date
    Jun 2011
    Location
    Maryland
    Posts
    190

    Certifications
    GWAPT, CISSP, eJPT, CEH, Sec+, ITIL-F, BS:IS
    #5
    Quote Originally Posted by HCPS123 View Post
    CEH is definitely better for you HR wise. I would have actually recommended you get it before CISSP since I heard CEH can help prepare you for some of the PENtester material on CISSP but since you've already gotten CISSP CEH doesn't really do much for you outside of HR. I agree with the rest, go for an ELearn cert first to prep for OSCP if you're just interested in the skill.
    If OP does not plan to work for US Gov't then no point at all to do CEH since he already has CISSP. I also suggest what UnixGuy advices. ELearnSecurity such as eJPT or eCPPT.
    Reply With Quote Quote  

  7. Member
    Join Date
    Oct 2017
    Posts
    37

    Certifications
    CISA, CRISC, CASP
    #6
    Congrats to you sir!

    Once I pass the CISSP (on or before 12/31/18 ), I wish to learn pentesting as well. Will the eLearnSecurity course(s) be helpful for a total newbie like me?
    Last edited by Info_Sec_Wannabe; Yesterday at 01:38 AM.
    Reply With Quote Quote  

  8. Senior Member
    Join Date
    May 2017
    Posts
    124
    #7
    taking CISSP for me is not newbie

    for pentest i think you can take a look ejpt first

    Quote Originally Posted by Info_Sec_Wannabe View Post
    Congrats to you sir!

    Once I pass the CISSP (on or before 12/31/18 ), I wish to learn pentesting as well. Will the eLearnSecurity course(s) be helpful for a total newbie like me?
    Reply With Quote Quote  

  9. Senior Member E Double U's Avatar
    Join Date
    Apr 2014
    Location
    The Netherlands
    Posts
    1,173

    Certifications
    CISSP, CISM, GCIA, GCIH, C|EH, and more.
    #8
    I would take advantage of whatever my employer pays for. If you can get into a SANS course I would say take SEC560/GPEN before going for OSCP. But if that route is too pricey then CEH before OSCP wouldn't hurt if you want to learn basics (and I do mean basics). Regardless of how lots of us feel about CEH, it is a nice to have when employers are scanning resumes.
    "You tried your best and you failed miserably. The lesson is, never try." - Homer Simpson
    Reply With Quote Quote  

  10. Senior Member shoey's Avatar
    Join Date
    Jun 2016
    Location
    Knowhere
    Posts
    105

    Certifications
    Life
    #9
    Quote Originally Posted by HCPS123 View Post
    CEH is definitely better for you HR wise. I would have actually recommended you get it before CISSP since I heard CEH can help prepare you for some of the PENtester material on CISSP but since you've already gotten CISSP CEH doesn't really do much for you outside of HR. I agree with the rest, go for an ELearn cert first to prep for OSCP if you're just interested in the skill.
    Not true... A couple of years back several of my compliance buddies switched back to the technical side (i.e. PenTesting), and the companies now mandate you get your OSCP within the first six months. Sure HR still looks for C|EH, but many of those jobs (where I live) also list OSCP... Additionally, any real PenTesting company is very aware of the OSCP (as well as how little the C|EH actually teaches).

    I definitely agree with E Double U that if a cert is free, might as well knock it out...
    Last edited by shoey; Yesterday at 07:55 AM.
    "I have missed more than 9,000 shots in my career. I have lost almost 300 games. 26 times, I've been trusted to take the game winning shot and missed. I've failed over and over and over again in my life. And that is why I succeed." - Michael Jordan
    Reply With Quote Quote  

  11. Member
    Join Date
    Oct 2017
    Posts
    37

    Certifications
    CISA, CRISC, CASP
    #10
    Quote Originally Posted by vynx View Post
    taking CISSP for me is not newbie
    Hmm... I'm looking at it from this perspective, CISSP will allow me to understand about how a bunch of stuff works although it is not enough for me to really know the nitty gritty (e.g., what command to use, how to interpret stuff like logs, etc.) or getting my hands dirty so to speak.

    Quote Originally Posted by E Double U View Post
    I would take advantage of whatever my employer pays for. If you can get into a SANS course I would say take SEC560/GPEN before going for OSCP. But if that route is too pricey then CEH before OSCP wouldn't hurt if you want to learn basics (and I do mean basics). Regardless of how lots of us feel about CEH, it is a nice to have when employers are scanning resumes.
    I would like to go for that route as well, but unfortunately, the SANS courses are only limited for the Red Team peeps (I'm currently in our GRC block).
    Reply With Quote Quote  

+ Reply to Thread

Social Networking & Bookmarks