How I Would Learn Cyber Security If I Was To Start Over in 2024 (Beginner Roadmap In Cybersecurity)

InfoSec Pat
15 Sept 202410:00

Summary

TLDRIn this video, the speaker shares insights on how they would approach starting a career in cybersecurity in 2024. They emphasize mastering the basics, such as networking and system administration, and gaining hands-on experience. The speaker advises choosing a specialization, such as pentesting or cloud security, and getting certified to prove practical knowledge. They also stress the importance of building a professional network and staying updated with industry trends through continuous learning.

Takeaways

  • 😀 Start with mastering the basics of cybersecurity, including networking, computer setups, and system administration.
  • 🔧 Gain practical experience by setting up networks and computers for friends, local charities, or churches.
  • 💡 Understand the fundamentals of networking, such as IP addresses, protocols, and how data traverses networks.
  • 📚 Utilize resources like CompTIA IT Fundamentals, Network+, and A+ to build a strong foundation in cybersecurity.
  • 🎯 Choose a specialization within cybersecurity, such as system administration, network engineering, or cloud engineering.
  • 🛠️ Develop expertise in specific areas like Windows Server, DNS, Active Directory, or firewalls, based on your chosen specialization.
  • 🔬 Get hands-on practice with platforms like Hack The Box, TryHackMe, or by creating your own home lab for real-world experience.
  • 📝 Consider getting certified in your area of specialization, such as OSCP, PTP, or EJPT for practical knowledge and recognition.
  • 🤝 Build a professional network by participating in cybersecurity forums, Discord servers, and local meetups to share knowledge and insights.
  • 📈 Stay updated with the latest trends and advancements in cybersecurity through blogs, trainings, podcasts, and industry events.

Q & A

  • What was the speaker's experience at St Pete?

    -The speaker had a really good time at St Pete, enjoying meeting every single person in their workshop and conference.

  • What is the first step the speaker suggests for mastering cybersecurity?

    -The first step is to master the basics of cybersecurity, such as networking, computer setups, and system administration.

  • Why is it important to understand what happens when you hit the power button on a computer?

    -Understanding what happens when the power button is hit helps in grasping the fundamentals of system administration, which is critical in cybersecurity.

  • What resources are recommended for learning the basics of networking and computer systems?

    -Resources like CompTIA's IT Fundamentals, Network+, and A+ are recommended for mastering the basics.

  • Why is choosing a specialization important in cybersecurity?

    -Choosing a specialization allows one to focus on a specific area of cybersecurity, such as pentesting or cloud security, and become highly proficient in it.

  • What does the speaker suggest for getting hands-on practice in cybersecurity?

    -The speaker suggests creating a home lab, using platforms like Hack The Box and TryHackMe, and participating in workshops for hands-on experience.

  • What is the significance of getting hands-on experience in cybersecurity?

    -Hands-on experience is critical for understanding real-world scenarios and for troubleshooting and solving problems in a legal and controlled environment.

  • Which certifications does the speaker recommend pursuing in cybersecurity?

    -The speaker recommends certifications from CompTIA, Offensive Security, and other practical certifications like PTP, OSCP, and CTPS.

  • Why is it important to build a network in the cybersecurity field?

    -Building a network helps in sharing ideas, getting guidance, and finding job opportunities within the cybersecurity community.

  • How can one stay updated in the fast-paced cybersecurity industry?

    -One can stay updated by following blogs, participating in trainings, listening to podcasts, and attending events to keep abreast of the latest trends and developments.

  • What is the speaker's advice for those starting over in cybersecurity in 2024?

    -The speaker advises starting with the basics, choosing a specialization, getting hands-on experience, getting certified, building a network, and staying updated.

Outlines

00:00

🔄 Starting Over in Cybersecurity

The speaker begins by expressing gratitude for a recent event at St Pete and then dives into a discussion about how they would approach starting a career in cybersecurity in 2024. The first step emphasized is mastering the basics, such as networking, computer setups, and system administration. The speaker suggests gaining practical experience by offering to help friends or local organizations with their IT needs. They also highlight the importance of understanding what happens when a computer boots up and the fundamentals of networking, including IP addresses and data transmission. The speaker recommends using resources like CompTIA's IT Fundamentals, Network+, and A+ to build a strong foundation in these areas.

05:03

🛠️ Hands-On Experience and Certifications

In the second paragraph, the speaker continues with advice on gaining hands-on experience, which they consider critical for anyone entering the cybersecurity field. They recommend setting up home labs and transitioning to online platforms like Hack The Box and TryHackMe for practical learning. The speaker also stresses the importance of certifications, suggesting that practical certifications from organizations like Offensive Security, CompTIA, and others are more beneficial than multiple-choice exams. They also encourage building a professional network through platforms like LinkedIn, Discord, and local meetups, which can be invaluable for job seekers and those looking to grow in the field. The speaker concludes by urging viewers to stay curious, hands-on, and continuously learning, emphasizing the fast-paced nature of the cybersecurity industry.

Mindmap

Keywords

💡Cyber Security

Cyber Security refers to the practice of protecting systems, networks, and data from digital attacks. In the context of the video, it is the main theme and the field the speaker is discussing. The speaker talks about starting over in cyber security, emphasizing the importance of mastering the basics and getting hands-on experience.

💡Pen Testing

Pen Testing, short for penetration testing, is the process of testing a computer system, network, or web application to find vulnerabilities that an attacker could exploit. The video discusses starting over in this field, suggesting that one should learn the basics, specialize, and get hands-on practice.

💡System Administration

System Administration involves managing and maintaining an organization's computer systems. The speaker mentions it as a fundamental skill to master, suggesting that understanding how systems work is crucial for anyone starting in cyber security.

💡Networking

Networking refers to the practice of setting up and maintaining the communication links between computers. The video emphasizes the importance of understanding networking basics, such as IP addresses and protocols, for anyone looking to start a career in cyber security.

💡Specialization

Specialization in this context means focusing on a particular area within a broader field. The speaker advises choosing a specialization, such as system administration, network engineering, or pen testing, to gain in-depth knowledge and skills in that area.

💡Hands-On Practice

Hands-On Practice implies engaging in practical, real-world activities to gain experience and skills. The speaker stresses the importance of setting up home labs and using platforms like Hack The Box for hands-on experience in cyber security.

💡Certifications

Certifications are credentials that prove one's knowledge and skills in a particular field. The video mentions certifications like CompTIA, Offensive Security, and others as a way to validate one's expertise in cyber security.

💡Home Lab

A Home Lab is a personal setup of equipment and software used for learning and experimentation. The speaker recommends creating a home lab for hands-on experience, which is essential for understanding and practicing cyber security concepts.

💡Active Directory

Active Directory is a directory service by Microsoft that allows administrators to manage user and computer accounts. The speaker uses Active Directory as an example of a system one should understand when specializing in pen testing or system administration.

💡Social Engineering

Social Engineering involves manipulating people to perform actions or divulge confidential information. The speaker mentions social engineering as part of their specialization, highlighting its importance in the field of cyber security.

💡Stay Updated

Staying Updated means keeping abreast of the latest developments and trends in a field. The video emphasizes the importance of staying current with cyber security news, blogs, trainings, and events to remain effective in the industry.

Highlights

Master the basics of cyber security, including networking, computer setups, and system administration.

Offer to help local charities or churches with networking and computer setups to gain practical experience.

Understand the fundamentals of networking, such as IP addresses and data transmission across networks.

Learn how to build computers, install operating systems, and administer systems.

Choose a specialization within cyber security, such as system administration, network engineering, or cloud engineering.

Transition from system administration to network engineering and specialize in areas like firewalls and threat defense.

Specialize in pentesting and social engineering, focusing on both internal and external assessments.

Get hands-on practice with platforms like Hack The Box and Try Hack Me, and create your own home lab.

Set up your own home lab to gain real-world experience and learn to troubleshoot systems legally.

Get certified in your chosen specialization, such as TCM, Offensive Security, or other practical certifications.

Build a network by participating in cyber security forums, attending local meetups, and engaging with the community.

Stay updated with industry changes through blogs, trainings, podcasts, and events.

Stay curious and keep pushing your learning boundaries in cyber security.

Engage in workshops and hands-on labs to gain practical experience and improve your skills.

Understand the importance of DNS settings and how they affect system connectivity in a network.

Transcripts

play00:00

hey what's up everyone welcome back to

play00:01

another video I just want to say thank

play00:03

you to everyone first of all at St Pete

play00:06

bides this weekend I had a really really

play00:09

good time I really enjoyed meeting every

play00:11

single person in my workshop and in the

play00:14

conference so thank you so much for that

play00:16

if you guys are ready today we're going

play00:18

to be talking about if I had to start

play00:20

over in 2024 in cyber security pen

play00:23

testing or whatever you want to call it

play00:24

what would I do so I was getting that

play00:27

question a lot this weekend if you can

play00:29

start over how would you approach it so

play00:32

we're going to go over some steps and

play00:33

let's get into the

play00:37

[Music]

play00:41

video all right everyone so the first

play00:44

step into mastering cyber security or

play00:47

what I would do if I was starting all

play00:48

over in 2024 is master the basics of it

play00:53

right what is this actually mean maybe

play00:55

some basic networking computer setups

play00:59

system Administration what you can do is

play01:02

do basic Network setups for your friends

play01:04

go to a local charity go to a local

play01:06

church and say hey do you guys need any

play01:08

networking or computer setups just to

play01:10

plug it in understanding when you hit

play01:12

the power button on a computer when it

play01:14

boots up what exactly is happening right

play01:17

so that's definitely the first step

play01:19

right because in cyber security

play01:20

fundamentals and understanding the solid

play01:23

system administration maybe some light

play01:25

programming is super super critical

play01:27

right I'd learn how to Network computers

play01:31

build computers install operating

play01:33

systems this is what I would do if I had

play01:36

to start all over right and

play01:38

understanding first of all understanding

play01:40

the fundamentals of networking such as

play01:42

IP addresses protocols how data

play01:45

traverses across your basic Network or

play01:47

your local network and across the web

play01:50

right when you send out a packet when

play01:52

you go to google.com or facebook.com or

play01:55

youtube.com what exactly is happening so

play01:59

and obviously some resources that you

play02:01

can use to get this knowledge is stuff

play02:05

like from compt or you can do the it

play02:07

fundamentals plus they have a basic

play02:09

basic one network plus A+ all of this

play02:13

will help you master the basics that's

play02:16

number one okay so the second thing that

play02:20

I have when I wrote down on the way home

play02:23

is choose a specialization what does

play02:25

this really mean so for example me when

play02:28

I got into it want to specialize in

play02:31

system administration right I got really

play02:33

good with Windows Server I got really

play02:35

good with all the stuff DNS active

play02:37

directory Windows clients all that good

play02:40

Jazzy Jazz right so then I trans I

play02:43

transitioned into Network Administration

play02:46

network engineering Cloud engineering

play02:48

and building out like VMware

play02:50

understanding Cisco routing switching

play02:52

firewalls and all that stuff and then

play02:55

that was my specialization right I was

play02:57

really really good with firewalls that

play02:58

was my specialization I was really good

play03:00

with ASAS and fire power threat defense

play03:03

or ftds and all that stuff so that's

play03:05

where my specialty was before I got into

play03:07

the world of pen testing and offensive

play03:10

security and cyber security right so

play03:14

choose a specialization and I think that

play03:15

will be awesome awesome for you like my

play03:18

specialization now is a little all over

play03:20

the place right for me personally I like

play03:22

to do the Blue Team aspect and I like to

play03:24

do the offensive right so but my

play03:27

specialization is probably pentesting

play03:29

and in all honesty social engineering

play03:32

internals externals Wi-Fi pen testing

play03:34

that's what I specialize in right can I

play03:36

dabble in some other stuff absolutely

play03:38

but I have my specialization and I know

play03:41

what I'm good at right

play03:44

so and now what you can do is choose a

play03:47

path right do you want to focus on pen

play03:49

testing you want to focus on sock

play03:52

analyst you want to do Cloud security

play03:54

and once you actually choose whatever

play03:56

you want to dabble in and get better at

play03:59

what you can do is specialize in that

play04:01

and start training in those areas right

play04:04

for an example if you wanted to become a

play04:05

pentester you can start learning you

play04:08

know burp Suite Cali Linux you know

play04:10

active directory depending on what you

play04:11

want to you know what Avenue what

play04:14

specialty you want to do in pen testing

play04:16

for example web app testing you'll

play04:18

understand fuzzing you have to

play04:20

understand burp Suite proxies code maybe

play04:24

code review and all the stuff that you

play04:25

know web pen testers do if you want to

play04:27

be an internal assessor and you want

play04:29

want to learn about active directory pen

play04:31

testing you have to learn what active

play04:33

directory really is and understand the

play04:35

ins and outs of it because if you don't

play04:37

know how to build it you don't know how

play04:38

to administer it how can you attack it

play04:40

right just think about that for a second

play04:42

and the next step that I would say this

play04:45

is probably one of the critical if

play04:47

you're getting into pen testing and even

play04:49

defensive stuff and sock analyst is get

play04:51

Hands-On practice right so practice

play04:54

practice practice I got an itch on my

play04:56

nose you can do this with my my course I

play04:59

do a lot of uh practice Hands-On for pen

play05:03

testing you can use hack the box you can

play05:05

use try hack me but I I believe home

play05:07

Labs is where it's at create your own

play05:09

home lab and then transition to an

play05:11

online platform just because you can

play05:13

have an understanding of those

play05:15

fundamental knowledge before you start

play05:17

going on to the internet and hacking and

play05:20

that's just my recommendation that's

play05:21

what I did and this this video is all

play05:24

about what I would do if I had a start

play05:26

over these are the things I would do

play05:28

right because cyber security is all

play05:31

about getting hands-on experience right

play05:34

so you have platforms like hack to box

play05:35

try hack me all this

play05:39

stuff and then setting up your own home

play05:42

lab is essential for getting real

play05:44

Hands-On and Real World Experience right

play05:47

learn how to solve break your system

play05:49

legally you can solve it maybe you join

play05:53

maybe this is real world right and this

play05:55

happened to me when I first started

play05:57

setting up my labs many many moons ago I

play06:00

would set up active directory for an

play06:01

example and when you set up active

play06:03

directory on your own if you do it with

play06:06

2019 2022 server you have a DNS server

play06:10

right so your DNS server should point to

play06:12

the DC IP address normally so if you

play06:16

don't reassign say for an example your

play06:19

DC is 19216811

play06:22

100.5 okay and your gateway is one and

play06:27

now sometimes like if you reboot you go

play06:30

back into your ipv4 settings your DNS is

play06:33

probably going to be the loop back

play06:35

12701 if you leave it as as so and you

play06:38

go to your Windows 10 machine and you

play06:40

try to join that computer it's not going

play06:42

to know where to find DNS so what you

play06:46

have to do is have a preferred DNS

play06:47

server and point it to five in this

play06:49

example and now on your unless you have

play06:52

a dhp server that's handing out DNS and

play06:54

all that stuff but that's something on a

play06:56

different level but if you want to get

play06:58

your windows 10 onto your onto your

play07:02

active directory you have to make sure

play07:03

Windows 10 is pointing to

play07:06

192.168.1 100.5 in that instance right

play07:09

for that example so just make sure and

play07:11

breaking it you know troubleshooting it

play07:13

it's real Hands-On so I always recommend

play07:16

that Hands-On that's why I do a lot of

play07:18

workshops Hands-On Labs setting it up

play07:21

because things things are really really

play07:23

critical when you have the real world

play07:26

experience and the next thing here I

play07:28

have on my screen that I written down

play07:30

was get

play07:35

certified so what does this mean so you

play07:37

can get uh prepared for uh for an

play07:40

example for certifications from like TCM

play07:43

security offensive security hack the box

play07:45

so many other things right pmpt PJP ejpt

play07:50

ocp cpts there's so many other

play07:53

certifications out there that you can

play07:55

prepare those are the ones that I would

play07:56

recommend because it's practical

play07:58

knowledge right it's not like going for

play08:00

your pentest Plus or C or any of those

play08:03

because those are like multiple choice

play08:05

yes you have the C practical but at you

play08:08

know unless you're going for a

play08:09

government position yeah C Security Plus

play08:12

those are mandatory they're not optional

play08:15

so I would always recommend that and

play08:18

remember if you get into a

play08:19

specialization for example like Cloud

play08:22

maybe you'll do like Azure security or

play08:24

AWS security or whatever your specialty

play08:27

remember have a specialty and I think

play08:29

that is always really critical okay and

play08:32

then the next thing I have here is build

play08:35

a network and stay updated what do I

play08:37

mean by that so if you want to have a

play08:41

network like on LinkedIn groups

play08:44

participate in different cyber security

play08:45

forms you can go on Discord servers you

play08:48

can go on local meetups like I just went

play08:50

to bide St Pete it's not local for me

play08:52

it's about 5 hours away but I went there

play08:55

I did a workshop I got to network with

play08:56

folks meet so many awesome people and

play08:59

it's always always good to network

play09:01

especially when you're looking for a job

play09:02

and you're getting into the field

play09:04

because now you're going to get together

play09:05

in a community with like-minded people

play09:07

and you can share your thoughts and what

play09:09

you want to do and maybe they can guide

play09:11

you to that path you know so the

play09:15

industry obviously changes really really

play09:17

fast really quickly and just stay up to

play09:19

date with like blogs trainings podcasts

play09:22

uh different kinds of events that's

play09:24

always always critical if you're getting

play09:26

into the field or if I wish to do this

play09:28

all over these are the things I would do

play09:30

right and that's pretty much it so

play09:33

that's my road map if I was to start

play09:35

again from scratch in 2024 so remember

play09:38

stay curious stay Hands-On keep pushing

play09:41

keep learning and obviously don't forget

play09:44

to like this video subscribe share it

play09:46

and for any other tips and tricks stay

play09:49

tuned

play09:54

[Music]

Rate This

5.0 / 5 (0 votes)

الوسوم ذات الصلة
Cyber SecuritySkill MasteryNetworking BasicsCertification PrepHands-On TrainingPenetration TestingSpecialization GuideCareer AdviceTech WorkshopProfessional Development
هل تحتاج إلى تلخيص باللغة الإنجليزية؟