Cyber Security Certificate Tier List – UPDATED (2023)

UnixGuy | Cyber Security
10 Sept 202322:33

Summary

TLDRThe video offers an insightful evaluation of various cybersecurity certifications, highlighting their usefulness in landing jobs and the importance of practical knowledge over theoretical memorization. It emphasizes the value of CompTIA Security Plus and SANS training, the practicality of ethical hacking certifications like OSCP, and the limitations of vendor-specific and GRC-focused certificates. The speaker shares personal experiences and industry insights to guide viewers on their cybersecurity career path.

Takeaways

  • 📚 The speaker's personal journey with cybersecurity certifications highlights the struggle of finding relevant and practical training early in their career.
  • 🚀 CompTIA certificates are popular for beginners, offering vendor-neutral, foundational knowledge, but may involve memorization over practical skill development.
  • 🔒 CompTIA Security Plus is considered a good introduction to cybersecurity, providing a broad understanding of the field.
  • 📈 CompTIA Cybersecurity Analyst (SECA+) is more challenging and covers useful concepts for cybersecurity analysts, despite being theoretical.
  • 🤔 The speaker questions the value of CompTIA PenTest+, comparing it to learning to drive by reading a book, and suggests it may not be worthwhile.
  • 🌟 SANS Institute training is highly regarded in the cybersecurity industry, offering practical, up-to-date training from experienced professionals.
  • 💡 ISAO certificates focus on governance, risk, and compliance (GRC), but may not provide practical training, and require significant experience.
  • 🔥 Ethical hacking certificates like OSCP are favored for their practical approach, testing real-world ethical hacking skills rather than theoretical knowledge.
  • 🛠️ Vendor-specific cybersecurity analyst certificates from Google, IBM, Microsoft, and Splunk aim to introduce cybersecurity basics to those without IT experience.
  • ☁️ Cloud security certifications are in high demand, with specialized vendor certificates from AWS, Azure, and Google Cloud being particularly valuable.
  • 🔑 The effectiveness of a single certification in securing a job depends on experience and the job market, but certifications can serve as a starting point for a learning journey in cybersecurity.

Q & A

  • What is the speaker's main goal in creating this video?

    -The speaker's main goal is to provide an honest, no-nonsense rating of cybersecurity certifications and help viewers understand which certifications are useful for both learning and landing a job in the cybersecurity industry.

  • What was the speaker's experience with CompTIA A+ and CCNA certifications?

    -The speaker found the process of learning for CompTIA A+ and CCNA certifications extremely boring and felt that the knowledge gained was irrelevant to ethical hacking and web application servers.

  • What does the speaker think about the CompTIA Security Plus certification?

    -The speaker believes that CompTIA Security Plus is a good introductory certificate that teaches the general foundations of cybersecurity, making it a valuable starting point for beginners.

  • Why does the speaker criticize multiple-choice exams for cybersecurity certifications?

    -The speaker criticizes multiple-choice exams because they believe that they encourage memorization and cramming of concepts rather than a deep understanding and practical application of cybersecurity topics.

  • What is the speaker's opinion on the CompTIA PenTest+ certification?

    -The speaker does not believe that the CompTIA PenTest+ certification serves any practical purpose, as it is based on theoretical knowledge from a multiple-choice exam, which is insufficient for learning ethical hacking skills.

  • What are the advantages of SANS Institute training and certifications?

    -The advantages of SANS Institute training and certifications include high-quality, up-to-date material, experienced instructors, practical components, and broad coverage of cybersecurity topics. They are also well-respected within the cybersecurity industry.

  • What is the main disadvantage of SANS training?

    -The main disadvantage of SANS training is its high cost, which is typically around eight thousand dollars, targeting companies to pay for their employees' training.

  • What does the speaker think about the OSCP certification?

    -The speaker highly regards the OSCP certification as it is fully practical and tests the candidate's ability to perform ethical hacking, rather than just passing multiple-choice exams.

  • Why does the speaker rate CISSP certification as a B?

    -The speaker rates CISSP as a B because, while it is a well-known certification, it is more suited for cybersecurity managers and does not deeply cover specific domains. It also requires memorization of concepts, which may not reflect practical cybersecurity skills.

  • What is the speaker's view on vendor-specific cybersecurity analyst certificates like Google, IBM, Microsoft, and Splunk?

    -The speaker views these vendor-specific certificates positively, especially for beginners with no IT experience. They provide a good introduction to cybersecurity and come with hands-on labs, which are beneficial for learning and confidence building.

  • How does the speaker feel about cloud security certificates?

    -The speaker sees cloud security certificates, particularly those from major cloud providers like AWS, Azure, and Google Cloud, as highly valuable due to the increasing demand for cybersecurity professionals with cloud security knowledge.

Outlines

00:00

🔍 Introduction to Cybersecurity Certifications

The speaker shares their personal journey and experiences in the cybersecurity industry, highlighting the importance of understanding the value of different cybersecurity certifications. They discuss their initial steps with CompTIA A+ and CCNA, and their realization that these certifications were not as relevant to their desired ethical hacking path. The speaker also notes the surprising fact that some friends secured cybersecurity jobs without any certifications, prompting a reevaluation of the certification process.

05:01

📚 CompTIA Certifications: Pros and Cons

The speaker delves into the advantages and disadvantages of CompTIA certifications, emphasizing their vendor-neutral approach and the foundational knowledge they provide, especially for beginners. They appreciate CompTIA Security+ for its introductory nature but criticize the memorization-based learning style of multiple-choice exams. The speaker also discusses other CompTIA certifications like Cybersecurity Analyst (SECA+), CASB+, and PenTest+, with a critical view on the latter's theoretical approach.

10:02

🎓 SANS Institute and ISACA Certifications

The speaker highly recommends SANS Institute training and certifications, noting their industry recognition and the practical, up-to-date content provided by experienced instructors. They mention the extensive range of topics covered by SANS and the respect it commands in the cybersecurity field. However, the high cost of training is a significant drawback. ISACA certifications, focusing on governance, risk, and compliance, are also discussed, with the speaker appreciating their community events but criticizing the experience requirement and lack of practical teaching.

15:04

💻 Ethical Hacking and Vendor-Specific Certificates

The speaker expresses a strong preference for ethical hacking certificates, particularly the OSCP, for their practical approach to testing real-world ethical hacking skills. They also mention other entry-level ethical hacking certifications like EJPT and PJPT, praising their focus on practical training. The speaker is less enthusiastic about the CISSP, viewing it as more suitable for cybersecurity management roles and criticizing it for its focus on memorization rather than practical skills. They also touch on the value of vendor-specific cybersecurity analyst certificates from companies like Google, IBM, Microsoft, and Splunk.

20:05

☁️ Cloud Security and the Role of Certifications

The speaker discusses the growing importance of cloud security certifications, particularly from major cloud providers like AWS, Azure, and Google Cloud. They highlight the AWS Security Specialty and Microsoft Azure Cloud Engineer Associate as highly valuable certifications, while noting the lesser demand for Google Cloud certifications. The speaker also critiques vendor-neutral cloud security certifications like CCSP and CCSK for their theoretical nature and lack of practical application, suggesting they do not fully prepare individuals for cloud security roles.

🚀 Beyond Certifications: Practical Experience and Projects

The speaker acknowledges that while certifications can be a starting point, they are not a guarantee for landing a job in cybersecurity. They emphasize the importance of practical experience and suggest a list of progressive projects that can help build confidence and skills. The speaker offers a roadmap for those who have completed some cybersecurity certificates and are seeking the next steps in their learning journey, promising more details in the video to come.

Mindmap

Keywords

💡Cyber Security

Cyber Security refers to the practice of protecting systems, networks, and data from digital attacks. It is the main theme of the video, which discusses the importance of certifications in the field and their relevance to landing jobs in cyber security. The video provides an overview of various certifications and their utility in building a career in this domain.

💡Certifications

Certifications are formal qualifications or credentials that individuals earn to demonstrate their skills and knowledge in a specific area, such as cyber security. In the context of the video, certifications like CompTIA, CISSP, and OSCP are evaluated for their usefulness in the job market and their role in advancing one's career in the field.

💡CompTIA

CompTIA is a non-profit trade association that offers a range of IT certifications, including those related to cyber security. In the video, CompTIA certifications like Security Plus and Cyber Security Analyst (CySA) are discussed as foundational and introductory qualifications for those new to the field.

💡Vendor Neutral

Vendor neutral certifications teach general principles and practices that are applicable across multiple systems and technologies, rather than being specific to a single vendor's products. The video highlights the advantage of vendor neutral certifications like CompTIA, which can be beneficial for individuals new to cyber security as they cover a wide range of topics without focusing on a particular brand or system.

💡Penetration Testing

Penetration Testing, often referred to as ethical hacking, is the practice of testing a computer system, network, or web application to find vulnerabilities that an attacker could exploit. The video discusses certifications related to penetration testing, such as CompTIA PenTest+, and critiques the effectiveness of theoretical certifications in practical scenarios.

💡SANS Institute

The SANS Institute is a well-known organization in the cyber security field that offers intensive training courses and certifications. The video praises SANS for its high-quality training, experienced instructors, and comprehensive coverage of cyber security topics. The SANS trainings are highly respected and can be a significant boost to a professional's credibility in the industry.

💡Experience

In the context of the video, experience refers to the hands-on, real-world application of skills and knowledge in the field of cyber security. The speaker emphasizes the importance of practical experience over certifications alone, suggesting that actual work in the field is more valuable to employers than theoretical knowledge gained from certifications.

💡Cloud Security

Cloud Security involves the protection of data, applications, and infrastructure in cloud computing environments. The video discusses the growing demand for cloud security professionals and the importance of certifications from major cloud providers like AWS, Microsoft Azure, and Google Cloud Platform.

💡Vendor Specific Certificates

Vendor specific certificates are qualifications that focus on the products and services of a particular vendor. In the context of the video, this refers to certifications offered by companies like Google, IBM, Microsoft, and Splunk, which aim to educate individuals on the security aspects of their respective platforms.

💡Practical Projects

Practical projects are hands-on assignments or tasks that allow individuals to apply the knowledge and skills they have learned. The video suggests that completing practical projects is a valuable way to gain real-world experience and enhance one's cyber security skills beyond what is learned from certifications alone.

Highlights

The speaker shares their personal journey in the cybersecurity industry and offers an honest rating of cybersecurity certifications.

CompTIA A+ and CCNA were found to be boring and irrelevant for ethical hacking by the speaker.

Some individuals managed to land cybersecurity jobs without any certifications, questioning the necessity of these certificates.

CompTIA Security Plus is considered a good introduction to cybersecurity, delivering foundational concepts.

CompTIA Cybersecurity Analyst (SECA+) is appreciated for its harder content and practical concepts for cybersecurity analysts.

CompTIA PenTest+ is criticized for being theoretical and not effectively teaching ethical hacking skills.

SANS Institute is recognized for its high-quality, up-to-date, and practical cybersecurity training.

SANS training courses cover a vast range of topics and are well-respected in the cybersecurity industry.

ISAO focuses on governance, risk, and compliance (GRC) with limited practical teaching, requiring five years of experience.

Ethical hacking certificates, such as OSCP, are favored for their practical approach to testing cybersecurity skills.

CISSP is seen as less valuable among cybersecurity professionals, often being a target for those outside the field.

Vendor-specific cybersecurity analyst certificates from Google, IBM, Microsoft, and Splunk aim to introduce cybersecurity basics to beginners.

Amazon AWS, Microsoft Azure, and Google Cloud platform certificates are in high demand for securing respective cloud environments.

Vendor-neutral cloud security certificates like CCSP and CCSK are considered less practical and less valuable in the job market.

The speaker provides a tiered list for different cybersecurity certifications, with 'S' being the best and 'F' being the worst.

Practical projects and intermediate cybersecurity certificates are recommended for those starting their learning journey.

The video aims to save time and money for individuals looking to enter the cybersecurity field by providing an informed perspective on certifications.

Transcripts

play00:00

this video might be controversial but my

play00:02

goal is to help you understand the cyber

play00:04

security industry better so in this

play00:06

video I will give you my honest no BS

play00:09

rating of cyber security certifications

play00:11

in terms of which ones are useful for

play00:13

you so you can man a subject but also

play00:15

land the job this is from my own Journey

play00:17

when I was trying to break into cyber

play00:18

security 20 years ago but also from what

play00:21

I see in the market both as a hiring

play00:23

manager but also as a cyber security

play00:25

consultant where I help organizations

play00:27

run the cyber security division when I

play00:29

was trying to land my first cyber

play00:31

security role I thought I had it all

play00:32

figured out people gave me the advice

play00:34

that I needed to do CompTIA a plus and

play00:36

CCNA to build that Foundation before I

play00:40

can begin to learn how to do some

play00:41

ethical hacking activities but as I was

play00:44

going through these certificates I

play00:46

noticed that I was getting extremely

play00:48

bored learning both the a plus and the

play00:50

Cisco CCNA but not only that I noticed

play00:52

that the things that I was learning were

play00:54

completely irrelevant I didn't know how

play00:56

learning The Cisco command line will

play00:58

help me out in doing ethical hacking for

play01:00

web application servers it just made no

play01:02

sense but then things got worse I

play01:05

started noticing that some of my friends

play01:06

got their first cyber security job

play01:08

without even doing any of those

play01:10

certificates in fact I've even met fresh

play01:12

University graduate who got their first

play01:14

cyber security role without having any

play01:16

certifications or experience whatsoever

play01:18

so I started questioning the part that I

play01:21

was on which turned out to be a blessing

play01:23

in disguise because it led me to a

play01:25

journey of doing so many cyber security

play01:27

trainings and certifications which gave

play01:30

me exposure to so many cyber security

play01:32

certification programs and if this video

play01:34

manages to save time and money for one

play01:37

person then I consider my goal

play01:38

accomplished let's get into it CompTIA

play01:40

certificates are extremely popular among

play01:43

people who don't work in cyber security

play01:45

and among people who are extremely

play01:47

Junior and early in their cyber security

play01:49

Journey the main advantage of the

play01:51

CompTIA certificates is that it's vendor

play01:53

neutral which means instead of teaching

play01:55

you how to configure Palo Alto firewalls

play01:58

they teach you in general what firewalls

play01:59

are and what they do but they don't

play02:01

teach you how to configure a specific

play02:03

vendor firewall which can be useful for

play02:06

someone who's new to the field so you

play02:07

get to learn the generic concepts of how

play02:09

things are supposed to work the other

play02:11

big advantage that I personally like

play02:13

about CompTIA is the CompTIA Security

play02:15

Plus is a beginner introductory

play02:17

certificate that will teach you the

play02:18

general foundations of what cyber

play02:20

security is this was quite revolutionary

play02:22

because in the past we didn't have many

play02:24

cyber security certifications that will

play02:27

introduce you to the field so Security

play02:28

Plus was and still is a good

play02:30

introduction to cyber security now there

play02:32

are many problems with CompTIA

play02:34

certificates the biggest disadvantage of

play02:36

CompTIA certificates is that the exams

play02:38

are multiple choice exams which means

play02:40

when people study for these certificates

play02:42

they end up memorizing and cramming a

play02:44

bunch of Concepts so they can pass the

play02:46

exam which is not the best way to learn

play02:48

a topic in my opinion we will use this

play02:50

popular tiering system so the S tier is

play02:52

the super tier and then comes the a b c

play02:55

d and then the f is the worst tier in

play02:57

the list so the company certificates

play02:59

that I will look at is Security Plus I

play03:01

think it does a good job introducing

play03:03

people to the field of cyber security it

play03:05

delivers on the promise that it will

play03:07

teach you the foundational concepts of

play03:08

cyber security it's not going to make

play03:10

you an expert it's not going to make you

play03:11

an all knowledgeable hacker man but it's

play03:14

definitely a good introduction to cyber

play03:15

security then we have the seza plus

play03:17

which is the CompTIA cyber security

play03:19

analyst certificate I actually really

play03:21

like this one because it's a lot harder

play03:23

than the Security Plus and it introduces

play03:25

you to an extremely useful Concepts that

play03:27

you will use if you work as a cyber

play03:29

analyst it will teach you about security

play03:31

operations incident response

play03:33

vulnerability management and even

play03:34

reporting unfortunately the same

play03:36

disadvantage that apply to all companies

play03:38

certificates apply here it's extremely

play03:40

theoretical so you will end up

play03:42

memorizing and cramming a bunch of

play03:44

Concepts to pass a multiple choice exam

play03:46

but nonetheless I still think the

play03:47

information in there is valuable the

play03:49

next one is the cast B plus this is

play03:51

meant to be a tier above the sizzle plus

play03:53

it's a little bit harder it touches on

play03:55

Concepts such as architecture and

play03:58

operations again GRC engineering and

play04:01

cryptography and then we have the

play04:02

CompTIA pen test plus this is the

play04:04

penetration testing certificate I

play04:06

honestly don't think this certificates

play04:07

serve any purpose because trying to

play04:09

learn ethical hacking from a theoretical

play04:11

multiple choice based exam is like

play04:13

channeling to drive a car by reading a

play04:14

book yes you can learn all about the

play04:16

traffic Rules by reading a book but you

play04:18

still have to actually try and drive the

play04:20

car to learn driving so in my opinion

play04:22

pen Test Plus doesn't serve any purpose

play04:24

to put them in our tiering list I will

play04:26

put all of the company certificates as

play04:28

tier B because they have good

play04:30

theoretical information but

play04:32

unfortunately they have the practicality

play04:34

that we need in cyber security except

play04:36

the pen test plus I think it's rated as

play04:38

F because in my opinion it doesn't serve

play04:40

any purpose it will just waste your time

play04:42

and money now before we move on to the

play04:44

next section I didn't forget the popular

play04:46

CompTIA a plus and network plus and even

play04:48

things like CCNA in my opinion these are

play04:51

not cyber security certificates these

play04:53

are General it certificates and for

play04:55

cyber Security Professionals I don't

play04:57

think it's a great idea to do them now

play04:59

if you've already done them that's great

play05:01

but if you haven't done them then there

play05:02

are so many options that are cheaper and

play05:04

faster that will teach you the same

play05:06

Concepts and I talked about all of them

play05:07

in this video so please check it out the

play05:09

next one is the GX certificates the DX

play05:12

certificates have an Associated Sands

play05:14

training the sense training institute is

play05:16

the most popular cyber security training

play05:18

institute in the cyber security industry

play05:21

sure your it manager or network admin or

play05:24

even your Hotshot Junior cyber analyst

play05:26

may not have heard about the Sans

play05:28

Institute but those of us who work in

play05:30

cyber security are extremely familiar

play05:31

with the Sans Institute they are not

play05:33

only a training provider but they've

play05:35

actually set some industry standards

play05:36

that we use in our day-to-day cyber

play05:38

security jobs the way it works is you do

play05:41

a sense training that is four to six

play05:43

days of training depends on the course

play05:44

and then you study and pass the

play05:46

associated Jac exam the Sans Institute

play05:49

has world-class cyber security training

play05:51

for a number of reasons they are

play05:53

extremely selective on who the

play05:54

instructors are so a stand instructor is

play05:56

usually someone who have a lot of

play05:58

experience in cyber security they are

play06:00

actively working in cyber security so

play06:02

they are not a full-time instructor and

play06:04

they are not an academic so they have

play06:06

the hands-on experience and to become a

play06:08

sense instructor it's a very very

play06:10

demanding process so they maintained

play06:12

this high quality of instructors

play06:13

throughout their use now compare that to

play06:15

your PhD University Professor who have

play06:17

never worked a day in their life and

play06:19

they're trying to teach you how to

play06:20

become a cyber security professional

play06:21

there is a huge difference the other

play06:23

good Advantage about Sans is the

play06:25

material is so high quality it's always

play06:27

up to date their courses reflect

play06:29

problems that we face today in cyber

play06:31

security other great thing about sense

play06:33

training is usually most of their

play06:35

courses have a practical component that

play06:37

you will do in the training the other

play06:39

underrated advantage of sense training

play06:41

is that they cover every topic Under the

play06:43

Sun they've got a training course for

play06:45

every topic you can imagine even obscure

play06:47

things like they'll have a course

play06:49

dedicated to operational technology they

play06:51

have courses dedicated to mobile device

play06:53

forensics they have courses for cloud

play06:55

forensics so whichever topic you want to

play06:57

learn chances are there is a sense

play06:59

training and you know know that the

play07:00

quality is super high and the final

play07:02

advantage of sense training is that it's

play07:04

well respected within the cyber security

play07:05

industry when people see that you've

play07:07

done a sense training or a GX

play07:09

certification they know that you know

play07:10

something that goes beyond memorizing

play07:12

and cramming and passing a multiple

play07:14

choice exam now the biggest disadvantage

play07:16

of sense training is the price the cost

play07:18

of the training is about eight thousand

play07:20

dollars and the reason behind that is

play07:22

the sense training usually Target

play07:23

companies so they want your company to

play07:25

pay for the trading so the employees can

play07:27

attend the training now bonus tip if you

play07:29

want to do sales training cheaper go to

play07:31

the work study program within sense

play07:33

apply there and you might get a chance

play07:34

to be an assistant in a sense training

play07:36

program or you get to do the training

play07:38

for much much cheaper I've done a few of

play07:40

those myself I highly recommend it now

play07:42

there are so many Jax certificates so

play07:44

it's nearly impossible to rate all of

play07:46

them but if I was to group them all

play07:48

together and rate GI can even the sense

play07:49

training institute all at the same time

play07:51

they will definitely in the istio anyone

play07:54

who works in the industry knows that and

play07:55

they've maintained their quality

play07:57

throughout the years the next one is

play07:58

isaka isaka certificates focuses on the

play08:01

area of governance risk and compliance

play08:03

or GRC the main advantage of isaka is

play08:05

that kind of the only GRC certificate

play08:08

providers so if you want to do an I.T

play08:10

audit certificate then isaka is pretty

play08:13

much all you have at the moment the

play08:14

other thing that I like about iseka is

play08:16

they earn a lot of free events for the

play08:18

community so if you go to Google and you

play08:20

type isaka chapter in your own City then

play08:22

chances are you'll find a really nice

play08:24

Meetup that you can attend and you can

play08:25

network with other cyber Security

play08:27

Professionals I highly recommend

play08:28

attending those now unfortunately there

play08:30

are many disadvantages with isaka

play08:32

certificates the first one is that to do

play08:34

isaka certificates you need five years

play08:36

of experience and I'm talking here about

play08:38

the popular one Caesar series can see

play08:40

ISM in my opinion this experience

play08:43

requirement is not warranted the topics

play08:45

in season even C risk and cism to a

play08:48

certain extent are not exactly Advanced

play08:50

so any Junior IT Auditor should be able

play08:52

to do and pass this at least the Caesar

play08:55

certificate so to me they created an

play08:57

unnecessary hurdle but the main biggest

play08:59

disadvantage that I personally don't

play09:01

like about isaka is that the training

play09:03

itself doesn't teach you anything so

play09:05

think of Isaac as after you get GRC

play09:08

experience then you do isaka

play09:10

certificates to kind of validate your

play09:12

experience but if you do the isaka

play09:14

certificate they're not going to teach

play09:15

you how to do GRC which is a huge

play09:17

problem in my opinion and because of all

play09:20

of that my tearing is C I still think

play09:22

they hold some value but unfortunately

play09:24

they don't teach you anything the next

play09:26

ones are ethical hacking certificates

play09:28

those are my absolute favorite

play09:30

certificates I wish that the rest of the

play09:32

cyber security domains have good

play09:34

training materials similar to ethical

play09:35

hacking the most popular ethical hacking

play09:37

certificate is the oscp and it's fully

play09:40

practical and it's popular for a reason

play09:42

because it will test that you can

play09:43

actually perform ethical hacking as

play09:45

opposed to testing you on how you're

play09:47

gonna pass a bunch of multiple choice

play09:48

exams but fortunately we have other

play09:50

ethical hacking certificates so we have

play09:52

the ejpt and the pjpt both are

play09:56

entry-level ethical hacking certificates

play09:58

that are meant to introduce you to the

play10:00

field of ethical hacking using fully

play10:02

practical training and practical exams

play10:04

which I'm a huge fan of even if you

play10:06

don't want to be an ethical hacker in my

play10:08

opinion doing these certificates is

play10:09

extremely helpful for you as a cyber

play10:11

security professional so if I was to

play10:13

tier the ejpt and the pjpt they are

play10:16

definitely tra now we talked about oscp

play10:18

but there is ecppt and there is tntp all

play10:22

are extremely valuable practical ethical

play10:24

hacking certificates in my opinion they

play10:26

are tier s because if you do them you

play10:28

will learn so so much but doing the exam

play10:31

you will also prove that you have the

play10:33

skill of ethical hacking I personally

play10:35

know so many cyber security

play10:36

professionals who started studying for

play10:38

the oscp but they never managed to

play10:40

finish it because it's just hard and

play10:42

finishing it also communicate to me that

play10:44

you are passionate about cyber security

play10:45

as a hiring manager I see so many

play10:47

candidates who tell me I'm very

play10:49

passionate about cyber security but to

play10:51

me this is meaningless instead of

play10:52

telling me you're passionate about cyber

play10:54

security show me what work you've done

play10:56

in the field show me the difficult

play10:57

projects that you've done because this

play10:59

will prove that you're passionate it's

play11:01

really really hard to pass the oscp

play11:03

without being passionate about cyber

play11:04

security now there is easy Council and

play11:06

the certified ethical hacker certificate

play11:08

this is a multiple choice exam based

play11:10

certificate in my opinion it's not the

play11:12

best way to learn ethical hacking it's

play11:14

extremely similar to the pen Test Plus

play11:16

so in my opinion I would personally rate

play11:18

it as F because doing it will not make

play11:20

you an ethical hacker so it doesn't

play11:21

deliver on the promise and for these

play11:23

Reasons I'm tearing it as if the next

play11:25

one is the ifc2 certificates the cissp

play11:28

is definitely the most popular

play11:30

certificate for people who have no idea

play11:32

how cyber security works so for example

play11:34

I'll get network Engineers who come and

play11:36

ask me or should I do cisp to become a

play11:39

cyber security professional or I will

play11:40

meet someone who is a university student

play11:42

who would like to work in cyber security

play11:44

and the first thing they ask me is oh

play11:45

should I do cissp the truth is among

play11:48

people who actually work in cyber

play11:49

security we don't care about cissp and

play11:52

there are so many reasons for this the

play11:54

first thing is the cissp is actually

play11:56

intended to make you a cyber security

play11:57

manager this is the goal of the system

play11:59

ticket so it's meant to be a mile wide

play12:01

and an inch deep so it touches on so

play12:03

many domains but it doesn't go deep in

play12:05

any of those domains so an isc2 came up

play12:08

with this certificates they thought this

play12:09

is what cyber security managers need now

play12:11

the other reason that we don't really

play12:13

care about cissp is because the vast

play12:15

majority of server security managers do

play12:17

not have CI SSP and they don't even care

play12:19

about it because to be a really good

play12:21

cyber security manager you need to have

play12:23

a lot of depth in so many topics but you

play12:25

also need management skills which the

play12:27

CIS SP definitely don't teach you other

play12:29

huge disadvantage of cissp is that if

play12:32

you can't see issp I know for sure that

play12:35

you've just crammed a bunch of Concepts

play12:36

it's all about memorizing the whole heap

play12:38

of junk in my opinion trust me

play12:40

memorizing the types of fire alarms have

play12:42

nothing to do with cyber security no one

play12:44

cares now is the CIS SP all that bad no

play12:48

there are few things going on for the

play12:49

cissp they actually have a group of

play12:51

cyber security professionals who

play12:53

contribute to the exams so the multiple

play12:55

choice questions that you get in the

play12:56

exam have actually come from some really

play12:58

good cyber security profession so they

play13:00

try to emulate real world as much as

play13:02

possible in a multiple choice exam in

play13:04

fact one of my close friends sit in that

play13:06

committee the other good slash bad thing

play13:08

about the cisp is that people who don't

play13:10

work in cyber security seem to somehow

play13:12

know about it so when they do a job

play13:14

search cyber security they see the ciss

play13:16

be thrown here and therefore jobs that

play13:18

Frankly Speaking have nothing to do with

play13:20

cicssp I have no idea why a security

play13:22

analyst would ever need a cissp

play13:24

nonetheless people still copy paste the

play13:26

CI SSP and they put it there more often

play13:29

than not this is just a wish list so

play13:31

they'll put the issb and they'll put a

play13:33

bunch of certificates that doesn't mean

play13:35

they absolutely want you to have it it

play13:36

just means if you have it yep nice to

play13:38

have whatever what you really need is

play13:40

the skill of being a cyber security

play13:41

professional the other advantage of cisp

play13:44

is that it's a little bit harder than

play13:45

Security Plus it's not a lot harder I

play13:47

personally know people who passed it in

play13:49

two weeks those are professionals who

play13:51

work in the field who have the

play13:52

experience so all they did was they just

play13:53

read the book quickly and went and took

play13:55

the exam so yes it is harder than

play13:57

Security Plus but it's not that hard in

play13:59

fact it's a lot easier than something

play14:01

like the oscp so don't be fooled by

play14:03

shiny objects just because I see issb

play14:06

show up on a job search doesn't mean

play14:08

it's as valuable as some beginners on

play14:10

the Internet seem to think in the real

play14:11

world no one cares so my personal rating

play14:14

of it is B and that's mainly from what I

play14:17

see in the industry most people who have

play14:19

CIS SP usually don't have that much

play14:21

experience I'm aware that the CI SSP

play14:23

asks you for five years of experience

play14:25

but usually what happens is a helpless

play14:27

experience for example can qualify for

play14:29

you to meet that experience requirement

play14:31

even if your experience of help desk had

play14:33

nothing to do with the security domains

play14:35

it's it's good it's a level above the

play14:36

Security Plus but I wouldn't exactly

play14:38

call it an advanced certificate there

play14:40

are also two popular certificates from

play14:42

isc2 which is the sscp that was meant to

play14:45

be a stepping stone for the cisp in my

play14:47

opinion it absolutely serves no purpose

play14:49

so I would rate it as F but then there

play14:52

is a new one called certified cyber

play14:54

security this is aimed at beginners who

play14:56

have no cyber security experience or

play14:58

skills in my opinion this is useful

play15:00

because it introduces people to the

play15:01

field of cyber security although I

play15:03

personally think it's a little bit

play15:05

watered down so I would rate it as C

play15:07

just because there are other alternative

play15:09

beginner cyber security certificates

play15:11

that will teach you a little bit more

play15:12

next up is cyber security analyst

play15:14

certificates from vendors like Google

play15:16

IBM Microsoft Splunk and Cisco these are

play15:19

certificates from Big vendors like

play15:20

Google and Microsoft they are aimed at

play15:22

people who have no I.T experience no

play15:25

technical knowledge and no degree and

play15:26

they teach you the basics of cyber

play15:28

security this is fantastic news because

play15:30

even as far as two years ago we did not

play15:32

have anything like this in the market so

play15:34

kudos for these companies for creating a

play15:36

good quality training that's aimed to

play15:38

get more people to work in cyber

play15:40

security now you may be wondering which

play15:42

one is better the Google cyber security

play15:43

certificate or the IBM or Microsoft or

play15:46

Splunk or Cisco in my opinion I wouldn't

play15:48

be splitting hairs on which one is

play15:50

better I've explored all of them I think

play15:52

they're all pretty good there are minor

play15:54

differences and I will tier them a

play15:55

little bit different but in my opinion

play15:57

you can't go wrong with any of them and

play15:58

they're all quite cheap to be honest so

play16:01

if you do one or two or even all of them

play16:02

it's not going to take you a lot of time

play16:04

but it will also not cost you a lot of

play16:06

money now some of the advantages of

play16:08

these certificates is that a few of them

play16:10

come with Hands-On Labs like the Google

play16:11

certificate and even the IBM and

play16:13

Microsoft certificates they definitely

play16:15

have Hands-On lab where you get to

play16:16

practice what you learn which is a huge

play16:18

thing especially for someone who's

play16:20

completely new to it or cyber security

play16:22

it gives you a chance to practice but it

play16:24

also improves your confidence and it

play16:26

helps you retain the information you

play16:27

learned so you're not just cramming a

play16:29

bunch of Concepts to pass a multiple

play16:31

choice exam now if I look at the

play16:32

differences between them I think the

play16:34

Google is a great option because it

play16:36

teaches you MySQL Linux and python which

play16:39

are extremely popular tools that you

play16:40

will use as a cyber security

play16:42

professional the Microsoft certificates

play16:44

it teaches you a little bit about Office

play16:45

365 and Microsoft Azure Cloud platforms

play16:48

which are extremely useful the IBM

play16:50

certificate will show you how to use

play16:52

things like GitHub and snake and the IBM

play16:54

x4s which are popular tools in the

play16:56

industry then we have the Splunk

play16:58

certificate I think is the odd one out

play17:00

because this certificate will not

play17:01

introduce you to cyber security as a

play17:03

field but more so it will introduce you

play17:05

into how to use Splunk as a tool but

play17:07

Splunk is an extremely popular tool so

play17:10

it's definitely useful and then we have

play17:11

the Cisco certified support technician

play17:13

again it gives you an introduction to

play17:15

cyber security as a field which is

play17:17

extremely useful so in my opinion if I

play17:19

was to tier these certificates they

play17:21

definitely deliver on the promise that

play17:22

they will introduce you to cyber

play17:24

security as a field so to me that's

play17:26

definitely a tier a and this goes for

play17:27

the Google certificate IBM certificate

play17:30

the Microsoft certificate and the Cisco

play17:32

certificate Splunk unfortunately it does

play17:34

not really introduce you to cyber

play17:35

security it also introduces you to

play17:37

Splunk as a tool so to me that's

play17:39

definitely a tier C yes it's useful but

play17:42

it doesn't deliver on the promise that's

play17:44

an introduction to cyber security next

play17:46

up is cloud certificates this is

play17:48

definitely a hot area in the market

play17:49

there is a huge demand for cyber

play17:51

security professionals who understand

play17:53

and know how to use that cloud the three

play17:55

biggest cloud providers are Amazon AWS

play17:57

Microsoft Azure and the Google Cloud

play17:59

platform Amazon AWS is still the market

play18:02

leader in Cloud so if you work in cyber

play18:05

security or even if you work in it

play18:06

chances are you will run into Amazon AWS

play18:09

they are still by far the most widely

play18:11

used and adopted Cloud platform in fact

play18:13

as a consultant every time I go to help

play18:15

a company with their cyber security

play18:16

Journey they always complain about how

play18:18

they have a huge Amazon AWS setup they

play18:21

don't have many people who understand

play18:22

how to secure the AWS Cloud so it's an

play18:25

extremely useful skill so to explore

play18:27

Cloud security certificates we have

play18:29

vendor certificates so certificates from

play18:31

Amazon Microsoft and Google we also have

play18:33

vendor neutral certificates as well so

play18:35

starting with the most popular and most

play18:37

useful one in my opinion which is the

play18:39

Amazon AWS security specialty you're

play18:41

meant to do that after you do something

play18:43

like the Amazon AWS Cloud practitioner

play18:45

and the Amazon AWS architect and then

play18:48

you can do the AWS security specialty

play18:50

it's extremely useful the information

play18:51

and knowledge in there will definitely

play18:53

help you land the role securing the

play18:55

Amazon AWS Cloud there is an equivalent

play18:57

to this certificate and from Microsoft

play18:59

soft which is the Microsoft Azure Cloud

play19:01

engineer associate again extremely

play19:03

useful yes in the market there is more

play19:05

AWS than Azure but Azure is still widely

play19:07

used chances are you will run into

play19:09

companies earning at least something

play19:10

like Office 365 and maybe SharePoint so

play19:13

it's really useful to know about Azure

play19:14

security Technologies and less known one

play19:16

is from Google which is the Google Cloud

play19:18

security engineer Google has a much

play19:20

smaller market share however doing it is

play19:22

still useful because believe it or not

play19:24

all the cloud platforms are extremely

play19:26

similar so once you learn and get good

play19:28

at one of the cloud platforms the same

play19:30

skills are transferable to other Cloud

play19:32

platforms you will just find some

play19:33

differences in the names of the tools

play19:35

that's all so if I was to tear them in

play19:37

my opinion both the AWS and the

play19:39

Microsoft Azure certificates both are

play19:41

too old because the skills are

play19:42

definitely highly sought after the

play19:44

Google Cloud security engineer I would

play19:46

teach it as serious because it's not as

play19:48

popular and you're less likely to be

play19:49

dealing with Google Cloud security

play19:51

issues at least in the present moment

play19:53

now looking at vendor neutral Cloud

play19:55

security certificate from ist2 we have

play19:58

the ccsp this is meant to teach you

play20:00

General Cloud security Concepts so the

play20:02

claim that this certificate will enable

play20:04

you to become a cloud security

play20:05

professional unfortunately I haven't

play20:07

seen this happen in the real world no

play20:09

one will hire you just because you have

play20:11

the ccsp as hiring manager we're looking

play20:13

for someone who knows how to configure

play20:15

security groups within Amazon AWS or how

play20:18

to configure identity and access

play20:19

management in the cloud we don't want

play20:21

someone who knows generic concept about

play20:23

how Cloud security should be so in my

play20:25

opinion this certificate doesn't really

play20:27

deliver on the promise of making you a

play20:29

cloud security professional the same

play20:31

thing goes for the cloud Alliance ccsk

play20:33

again another theoretical certificate

play20:35

that claims to make you a cloud security

play20:37

professional by teaching you a bunch of

play20:39

Concepts now the cloud security Alliance

play20:41

have actually used for checklists that

play20:42

I've seen in the industry where people

play20:44

use the CSK checklist on how to secure

play20:46

clouds this can be useful but just

play20:49

because these spreadsheets and these

play20:50

checklists are around doesn't mean that

play20:52

the certificate itself is useful that

play20:54

security is one of those extremely

play20:56

practical things so I'd rather you know

play20:58

how to configure security ability in

play20:59

Office 365 as opposed to memorizing

play21:02

concepts of how the cloud need to be

play21:04

secured so if I was to tier them both

play21:06

the ccsp and the ccsk are trf because I

play21:09

would never recommend anyone doing them

play21:10

now a common question I constantly get

play21:13

asked is is the Google cyber certificate

play21:15

enough for me to land the job as the

play21:17

Security Plus enough for me to land the

play21:18

job is the cissp enough for me to land

play21:21

the job is this training sufficient is

play21:22

this boot camp sufficient and to be

play21:24

honest the answer is always it depends

play21:26

on how much experience you have but

play21:28

assuming you have zero experience and

play21:30

zero knowledge and all you did was one

play21:31

certificate or two certificates the

play21:33

answer is maybe you might get lucky and

play21:35

get hired with one certificate in fact

play21:37

I've seen people get hired with zero

play21:39

certificates it definitely happened but

play21:41

chances are you will probably need more

play21:43

the certificates are meant to be used as

play21:45

a structured way for you to learn a

play21:47

subject but especially those beginner

play21:49

level certificates are meant to be the

play21:50

beginning of your journey they are meant

play21:52

to introduce you to the field and to get

play21:54

you started in your Learning Journey but

play21:56

what ends up happening is after you

play21:58

finish one or two two certificates

play21:59

you'll find that you have to memorize

play22:01

and cram a bunch of Concepts and maybe

play22:03

you start to forget this concept but

play22:05

also you may not have so much confidence

play22:07

in applying to jobs or in landing your

play22:09

first job so to solve this I curated a

play22:12

list of practical projects that you can

play22:13

do progressively so you can go from one

play22:15

project to the other you start from

play22:17

beginner level projects all the way to

play22:19

intermediate projects and then you do

play22:20

practical intermediate cyber security

play22:22

certificates I created this roadmap

play22:24

specifically for people who've done some

play22:26

cyber security certificates and are

play22:28

looking for this next step on what to do

play22:30

all of this is detailed in this video

play22:32

and I'll see you then

Rate This

5.0 / 5 (0 votes)

Etiquetas Relacionadas
Cybersecurity CertificationsCareer GuidanceIndustry ExpertiseJob MarketCertification TiersLearning JourneyPractical ProjectsProfessional DevelopmentCyber AnalystVendor Certifications
¿Necesitas un resumen en inglés?