Cybersecurity Certificate Tier List (2024)

Mad Hat
4 Jun 202416:53

Summary

TLDRThis video ranks ethical hacking cybersecurity certifications from S-tier to F-tier, focusing on the specialized field of penetration testing, or 'red teaming'. The ranking is based on the Mad Hat metrics, which include reputation, difficulty, HR clout, and price. The script humorously critiques various certifications, highlighting the importance of practical skills over mere titles and emphasizing that the field is highly technical and demanding, not for the faint-hearted.

Takeaways

  • πŸ“š The video ranks ethical hacking and cybersecurity certifications from S-tier to F-tier, focusing on specialization for roles like penetration testing and red teaming.
  • πŸ” The speaker emphasizes the difference between penetration testing and ethical hacking, noting that all penetration testing is ethical hacking, but not all ethical hacking is penetration testing.
  • πŸ‘¨β€πŸ« The script discusses the importance of not just obtaining certifications, but also the practical knowledge gained from the courses and labs associated with them.
  • πŸ’Ό The video warns about the potential confusion between job titles and responsibilities, advising viewers to check job descriptions carefully to avoid being misled into unrelated positions.
  • πŸ”Ž The rankings are based on an analysis of 100 job descriptions and 100 random job listings for penetration testers, ethical hackers, and red teamers.
  • πŸ’° The 'Mad Hat metrics' are introduced as the criteria for ranking, including reputation, difficulty, HR clout, and price.
  • πŸ“‰ CompTIA certifications, while basic and broadly recognized, are considered too elementary for specialized ethical hacking roles and may not significantly enhance a resume in this niche.
  • πŸ†• TCM (The Cyber Mentor) certifications are highlighted as relatively new and positively received in the cybersecurity community, despite some pricing concerns.
  • πŸ“ˆ The script points out that the Offensive Security Certified Professional (OSCP) is the most recognized and sought-after certification in the field, despite its cost and difficulty.
  • 🚫 The Certified Ethical Hacker (CEH) certification is criticized for its lack of practicality and is ranked low due to its perceived lack of value in the ethical hacking community.
  • πŸ›‘ The video concludes with advice on the importance of continuous learning and practical experience beyond certifications for those pursuing a career in ethical hacking.

Q & A

  • What is the main focus of the video?

    -The video focuses on ranking various ethical hacking and cybersecurity certifications from S-tier to F-tier, specifically for roles in penetration testing, red teaming, and ethical hacking.

  • Why is specialization important for getting into ethical hacking?

    -Specialization is important because ethical hacking requires substantial technical knowledge and skills that go beyond general cybersecurity principles and concepts.

  • What is the difference between penetration testing and ethical hacking according to the video?

    -All penetration testing is considered ethical hacking, but not all ethical hacking is penetration testing. Ethical hacking is a broader term that includes red teaming, while penetration testing is a specific type of ethical hacking.

  • Why might someone be confused about job roles in ethical hacking?

    -Confusion can arise due to the use of various titles such as penetration tester, ethical hacker, and red teamer, which are often used interchangeably but may have different job responsibilities.

  • What does the video suggest about the CompTIA trifecta and Security Plus certifications in the context of ethical hacking?

    -The video suggests that while CompTIA trifecta and Security Plus are foundational, they are too basic for ethical hacking roles and may not be visible on resumes when applying for such jobs.

  • What is the general consensus on the Pentest+ certification from CompTIA according to the video?

    -The Pentest+ certification is considered not very useful for red teaming, as it is a high-level multiple-choice exam without much hands-on aspect, making it less practical for the job.

  • What are the key differences between TCM Security's PJPT and PNPT certifications?

    -PJPT (Practical Junior Penetration Tester) is an entry-level certification, while PNPT (Practical Network Penetration Tester) is a more advanced certification for those with more experience in the field.

  • Why does the video suggest that the eLearn Security certificates may not be the best choice currently?

    -The video suggests that eLearn Security certificates have become outdated and less practical since the acquisition by INE, with exams not being updated regularly and a lack of continued educational units.

  • What is the main issue with the SANS Institute's red teaming certificates according to the video?

    -The main issue is the high cost of the SANS Institute's red teaming certificates, which can be over $10,000 when including training and materials, and the exams being largely multiple choice with limited hands-on components.

  • What does the video suggest about the value of the Offensive Security Certified Professional (OSCP) certification?

    -The video suggests that while the OSCP is a well-recognized and respected certification, it may not be necessary to skip the basics and go directly for the more advanced certifications like the OSCP.

Outlines

00:00

πŸ˜€ Ethical Hacking Certifications Overview

The video script introduces a ranking system for ethical hacking and cybersecurity certifications, ranging from S to F-tier. It clarifies the distinction between general cybersecurity certificates and specialized ethical hacking ones. The focus is on penetration testing, often known as red teaming, which is a sought-after role in cybersecurity. The speaker emphasizes the importance of understanding job descriptions to ensure the right path is chosen, and mentions the Mad Hat metrics for evaluating certifications based on reputation, difficulty, HR clout, and price. The script also highlights the difference between penetration testing and ethical hacking, and the common misconceptions surrounding these terms.

05:01

πŸ“š New and Established Ethical Hacking Certifications

This paragraph delves into specific certifications, starting with the CompTIA Pentest+, which is considered basic for ethical hacking roles. It then introduces newer certifications like TCM Security's PJPT and PNPPT, and compares them with e-learnsecurity's EJPT and ECPPT, which are more established but have seen a decline in quality and reputation. The discussion includes the importance of hands-on experience in these technical roles, the pricing of the certifications, and their recognition in the job market. The paragraph also touches on the issue of certificate expirations and the need for continued education.

10:03

πŸ’° High-Cost Certifications and Their Value

The script moves on to discuss high-cost certifications from SANS Institute, such as the GPEN and GXPN, which are expensive and have a significant reputation in the cybersecurity community but are criticized for their pricing and lack of hands-on components. It also mentions lesser-known certifications like Zero Point Security's Red Team Ops and Altered Security's CRTP and CRTE, which are more reasonably priced and cover both penetration testing and red teaming concepts. The paragraph emphasizes the importance of practical skills over certifications alone.

15:06

πŸ† Top-tier Certifications and the Importance of Practical Knowledge

The final paragraph focuses on the most recognized certifications in the ethical hacking community, particularly Offensive Security's OSCP and the lesser-known but highly respected CPTS from Hack The Box. It discusses the difficulty and comprehensiveness of these exams, the recognition they receive in the cybersecurity community, and their impact on job prospects. The script concludes with a warning about the Certified Ethical Hacker (CEH) certification, advising against it due to its lack of practical value and high cost. The importance of continuous learning and practical application of skills beyond certifications is stressed.

Mindmap

Keywords

πŸ’‘Ethical Hacking

Ethical hacking refers to the practice of testing computer systems and networks to identify vulnerabilities that a malicious hacker could exploit. In the video, it is the main theme, with the speaker discussing certifications that can help one specialize in this field. Ethical hacking is often misunderstood and is distinguished from general cybersecurity roles.

πŸ’‘Certifications

Certifications in the context of the video are credentials awarded upon completing a course or exam that validates a person's skills and knowledge in ethical hacking and cybersecurity. The speaker ranks various certifications from S-tier to F-tier based on their value and relevance to the ethical hacking field.

πŸ’‘Penetration Testing

Penetration testing is the practice of simulating a cyber attack on a system to evaluate the security of that system. In the video, it is mentioned as a sought-after role in cybersecurity and is often synonymous with ethical hacking and red teaming. The speaker emphasizes that not all ethical hacking is penetration testing, but all penetration testing is considered ethical hacking.

πŸ’‘Red Teaming

Red teaming is a methodology where a group of security professionals simulate a cyber attack on an organization to test its defenses. In the video, the speaker clarifies that while all ethical hacking can be considered red teaming, not all red teaming is penetration testing, indicating the diverse skill sets required for these roles.

πŸ’‘CompTIA

CompTIA is a non-profit trade association that certifies professionals in the IT industry. In the video, CompTIA's Security Plus certification is mentioned as a basic requirement for cybersecurity roles but is considered too basic for specialized ethical hacking positions.

πŸ’‘TCM Security

TCM Security, founded by Heath Adams, offers certifications like the PJPT and PNPT. The speaker discusses these certifications as relatively new but reputable options for those looking to specialize in ethical hacking, positioning them in the B-tier ranking.

πŸ’‘GIAC

GIAC, or Global Information Assurance Certification, offers advanced certifications for cybersecurity professionals. The speaker mentions GIAC's GPEN and GXPN certifications as expensive and not as practical as they could be for preparing someone for a penetration tester role, ranking them in the C-tier.

πŸ’‘Zero Point Security

Zero Point Security offers certifications like the Red Team Ops and Red Team Ops 2. The speaker highlights these as lesser-known but high-quality certifications that cover both penetration testing and red teaming concepts, ranking them in the A-tier.

πŸ’‘Offensive Security

Offensive Security is known for its OSCP (Offensive Security Certified Professional) certification, which is highly respected in the cybersecurity community. The speaker discusses the OSCP and its more advanced counterpart, the OSWE (Offensive Security Web Expert), as top-tier certifications due to their practical exams and industry recognition.

πŸ’‘Certified Ethical Hacker (CEH)

The Certified Ethical Hacker certification is offered by the EC-Council. The speaker criticizes the CEH as being less practical and more of a checkbox for government requirements, ranking it in the F-tier due to its lack of hands-on value and high cost.

πŸ’‘CISSP

The Certified Information Systems Security Professional (CISSP) is a certification for experienced security practitioners. The speaker humorously mentions the CISSP as showing up in job listings but does not recommend it for ethical hacking roles, considering it baggage due to its high cost and less practical focus for the niche.

Highlights

The video ranks ethical hacking and cybersecurity certifications from S-tier to F-tier.

Specialization is necessary for those wanting to enter ethical hacking.

Penetration testing is often confused with ethical hacking, but they are not the same.

Ethical hacking is a misunderstood niche in cybersecurity.

Job descriptions are analyzed to determine the value of specific certificates.

CompTIA Security Plus is not sufficient for ethical hacking roles.

Pentest+ is considered basic and not highly regarded in the ethical hacking field.

TCM Security offers the PJPT and PNPT certifications for ethical hacking.

E-learn Security's certificates are criticized for being outdated and expensive.

GIAC offers GPEN and GXPN certifications, but they are costly and impractical.

Zero Point Security and Altered Security offer lesser-known but valuable certifications.

Offensive Security's OSCP is the most recognized but not necessarily the best for job listings.

Hack The Box's CPTS is highly regarded within the cybersecurity community.

The Certified Ethical Hacker (CEH) certification is not recommended for serious ethical hackers.

The importance of continuing education and practical experience beyond certifications.

Certifications are meant to enhance resumes, but the real value lies in the knowledge gained.

The difficulty of breaking into the ethical hacking job market is highlighted.

Transcripts

play00:00

in this video I'm going to be ranking

play00:01

the best ethical hacking cyber security

play00:03

certifications from s tier all the way

play00:06

down to f-tier if you see my first tier

play00:08

list video you'll already know about

play00:10

General cyber security certificates but

play00:11

as some of you might know if you've seen

play00:13

any of my other videos If you want to

play00:14

get into ethical hacking you're going to

play00:16

need to specialize I'm learnning and

play00:20

some of these certificates might help

play00:21

you do just that this isn't for GRC or

play00:24

blue team security operations this is

play00:26

for arguably the most sought-after role

play00:28

in cyber security penetration testing

play00:31

often referred to as red teaming

play00:33

otherwise known as ethical hacking

play00:35

otherwise known as one of the most

play00:37

misunderstood cyber security niches of

play00:39

all now let's get real semantical right

play00:40

now all penetration testing is ethical

play00:43

hacking but not all ethical hacking is

play00:45

penetration testing what but all ethical

play00:47

hacking is red teaming bro what are you

play00:50

talking about man same thing really

play00:51

synonyms in this back assword language

play00:53

we call English but HR has us all

play00:55

confused with titles so check the job

play00:57

description to make sure that you're not

play00:59

getting lured into a Help Desk position

play01:02

I think I'm going into penetration

play01:03

testing I didn't know you liked writing

play01:05

that much what do you mean it's just

play01:07

writing reports all day it's hacking

play01:09

into computers all day no it's hacking

play01:12

into computers one day and then writing

play01:13

reports the other four days you serious

play01:17

yeah if you can't already tell I'm mad

play01:20

hat a six-time security analyst as in

play01:22

I've been offered six security

play01:24

operations positions in my lifetime now

play01:26

much like my previous rankings these

play01:28

have been created using the Advanced job

play01:31

description analysis I analyzed a 100

play01:33

job descriptions in my previous tier

play01:35

list but now we're checking everything

play01:37

everything everything what I've

play01:40

discovered through advanced query syntax

play01:42

we can actually get a reliable list that

play01:44

contain any one specific

play01:47

certificate wait a minute but I also

play01:49

pulled 100 perfectly random job listings

play01:52

for penetration tester ethical hacker

play01:54

and red teaming also so we can finally

play01:56

answer the question on everyone's mind

play01:58

who the fck is this guy how do I get

play02:00

into this cyber Niche now I'll explain

play02:03

my reasoning using The Mad Hat metrics

play02:05

reputation difficulty HR clout and of

play02:07

course price cuz this economy has us

play02:09

living paycheck to credit card debt at

play02:11

the end I'll summarize my thoughts on

play02:13

this field and what you need to consider

play02:15

when trying to get into this field very

play02:17

important that you get to the end cuz

play02:18

this field is not for the weak-minded

play02:20

and the mini mad hats need some new

play02:22

shoes let's get started and a lot of

play02:24

ways the needs of ethical hacking are so

play02:26

Technical and so in the weeds that

play02:27

you're going to be digging through the

play02:28

roots h get it

play02:31

Roots whereas blue teaming security

play02:34

analyst work requires more of a high

play02:35

level knowledge or a more broad

play02:38

understanding of basic cyber security

play02:39

principles and Concepts to start working

play02:41

in that Niche check out this video here

play02:42

if you want to know what those are

play02:44

getting a start in ethical hacking

play02:45

require substantially more technical

play02:47

knowledge because finding a

play02:49

vulnerability in say a very hyp specific

play02:51

process or subprocess to gain access and

play02:54

then continue down the line to do things

play02:56

like account privilege escalation to

play02:57

lateral movement is hard all of this is

play03:00

very difficult so for that reason the

play03:02

CompTIA trifecta in our previously

play03:05

goated Security Plus is not a part of

play03:08

this

play03:08

[Music]

play03:13

list you got to know everything they

play03:15

cover but sadly these might as well be

play03:18

invisible on your resume when applying

play03:20

to ethical hacking jobs so while it does

play03:22

come up a handful of times in our sample

play03:24

and an insurmountable amount of times in

play03:27

other cyber security niches it is two

play03:29

basic for this ntion now as the elephant

play03:31

in the cyber security space ptia does

play03:33

have an option for a red teaming

play03:35

certificate the pentest plus which if

play03:37

you ask our local Discord Legend it's as

play03:39

useful as a poop sack poop sack and

play03:41

unfortunately I have to agree with that

play03:43

sentiment as it's purely a highlevel

play03:45

multiple choice exam and at $44 it sits

play03:49

as the D tier for doggy doooo no

play03:51

Hands-On aspect which is crucial to test

play03:54

on when having such a highly technical

play03:56

job honestly this is designed to just

play03:58

nudge you in the direction of red

play04:00

teaming and red teaming

play04:02

Concepts but largely unnecessary if

play04:05

you're serious about getting into this

play04:06

Niche now would have been an F tier

play04:08

however it does appear a surprisingly

play04:09

high amount of times in our sample and F

play04:11

tier is saved for the especially heinous

play04:14

of certificates coming up so consider

play04:16

yourself lucky pentest Plus Moving On we

play04:19

have the New Kids on the Block TCM

play04:21

security founded in 2019 by Heath Adams

play04:24

himself creator of the YouTube channel

play04:26

the Cyber Mentor we have the PJ PT at

play04:28

$249 the Practical Junior penetration

play04:31

tester and its more advanced older

play04:33

sibling riddled with fresh teenage angst

play04:36

the PNP the Practical Network

play04:38

penetration tester now these two

play04:40

certificates somewhat similarly compare

play04:42

to in security ejpt and E cptx which is

play04:46

formerly known as e-learn Securities

play04:48

Junior penetration tester which is

play04:50

currently also $249 and e-learn

play04:53

securities Advanced penetration testing

play04:55

which was retired on October 1st of last

play04:58

year bastards why so the closest thing

play05:01

to the pnppt would be the ecpp PT the

play05:04

certified professional penetration

play05:05

tester at $399 currently they're having

play05:08

a special where if you purchase the

play05:09

voucher you get 3 months of Premium

play05:12

access which by the way is required to

play05:14

purchase this exam voucher outside of

play05:16

any promos going on you would need to

play05:19

normally purchase the $700 premium

play05:21

subscription before you're even allowed

play05:23

to purchase this exam voucher but as it

play05:25

currently stands it is a little bit

play05:26

cheaper than the pmpt but usually it's

play05:28

way more now would be a good time to

play05:30

mention certificate expirations I expire

play05:33

after 3 years PCMS do not although we do

play05:36

see a history of potentially bringing in

play05:38

expirations to tcm's certificates to

play05:40

comply with reputable accreditation

play05:42

boards but currently they don't expire

play05:43

and you also notice that TCM was

play05:45

mentioning cus or continued educational

play05:48

units you know educational credits that

play05:50

renew your certificates yeah INE doesn't

play05:53

have that you just straight up have to

play05:54

retake the exam you took and Fork over

play05:57

that hard-earned coin now this wouldn't

play05:58

make sense if the exam was updated

play06:00

regularly as technology changes but uh

play06:04

yeah they're struggling to update

play06:06

anything over there now as far as

play06:07

reputation goes TCM has in beat by a

play06:10

long shot when in acquired e-learn

play06:12

security things went downhill fast labs

play06:15

are breaking exams were getting outdated

play06:17

fast lots of fans were hitting the shits

play06:19

whereas TCM security is consistently

play06:22

making improvements and adding content

play06:24

to their courses and exams their

play06:26

reputation is mostly positive in the

play06:28

cyber security Community even when the

play06:29

recent adjustments to their pricing with

play06:32

P&P going up to

play06:34

$499 but they still don't have any

play06:36

premium money grabbing gatekeeping like

play06:38

IE has neither of them really show up in

play06:41

job listings yet just a few hits for any

play06:43

one of them with all the complaints

play06:44

covered lack of HR clout and highly

play06:46

suspect pricing model IE you're going in

play06:48

C tier or can't believe you tarnished

play06:51

e-learn security certificates you suck

play06:53

TCM good job you've earned a spot in the

play06:56

B tier way to be better than INE walk

play07:00

we meet again I've been far too generous

play07:02

for guac CTS in the past and the last

play07:04

thing guac and Sans Institute needs is

play07:06

my generosity my money Sans of course

play07:09

being the people who offer courses that

play07:11

are essentially required to pass any one

play07:13

of the guerts these expensive ass

play07:16

courses now I won't get into another

play07:17

rant about spending $10,000 on one

play07:20

certificate but they do provide two red

play07:22

teaming certificates worth mentioning

play07:24

the guac penetration tester

play07:25

certification and the gxpn the guac

play07:28

exploit researcher and advanced

play07:30

penetration tester both cost $979 for

play07:33

the exam voucher but with the

play07:34

essentially mandatory Sans training and

play07:37

materials needed to pass this open book

play07:39

exam it's more like $110,000 a piece

play07:41

nuh-uh nope ain't paying that mm- if

play07:43

your job can pay for it by all means but

play07:45

I'm sure most of you are watching are

play07:46

still trying to get into your first

play07:47

cyber security job and don't have a job

play07:50

that's willing to pay an arm and a

play07:51

kidney for one certificate do get you

play07:55

certified and also these are largely

play07:58

multiple choice exams

play08:00

with six quote unquote lab questions

play08:02

which is how they address the Hands-On

play08:04

side of things making these exams very

play08:06

impractical as far as preparing someone

play08:08

to be a penetration tester or an ethical

play08:10

hacker sure the gpen appears the second

play08:12

most often in our sample with the gxpn

play08:14

appearing in roughly 10% of them but for

play08:16

all the reasons outlined walk y'all shat

play08:19

the beted on this one either make your

play08:21

exam more Hands-On or reduce your

play08:23

pricing for the sand courses now I know

play08:25

what some of you might be thinking Mad

play08:26

Hat these shirts are to prove that you

play08:28

went through the sand course which are

play08:29

highly respected in the Cyber SEC

play08:34

Community eh you I say go watch my Mr be

play08:36

Style video to see why that's not the

play08:38

case C tier for gpen and since gxpn is

play08:41

more complicated and proves you know a

play08:43

little bit more about what you're doing

play08:44

B tier but below TCM Sears through my

play08:47

sweaty late night research I've

play08:49

discovered some certificates that I've

play08:50

never heard of that apparently appear in

play08:52

some of these job listings I pulled zero

play08:54

point Securities red team Ops and Red

play08:56

Team Ops too this company is kind of

play08:58

like the security blue team as it seems

play09:00

as far as quality but for red teaming

play09:02

similar in that they're both British boy

play09:04

the general consensus on these CTS is

play09:06

that they're harder than more wellknown

play09:07

Sears coming up on this list While most

play09:09

certificates focus on penetration

play09:11

testing these exams cover that and red

play09:14

teaming Concepts including an emphasis

play09:16

on OPC which is keeping sensitive data

play09:18

from the bad guys a concept that is

play09:20

neglected in a lot of the searchs on

play09:21

this tier list now the red team Ops 2

play09:23

simply Builds on the knowledge gained

play09:25

from the first exam the labs and exams

play09:26

heavily utilize Cobalt strike beaconing

play09:29

which which is neat basically they cover

play09:30

more than what's covered on most of the

play09:32

certificates on this tier list and at

play09:35

$462 and $55 plus potential additional

play09:38

lab costs these are pretty decently

play09:40

priced certificates for what you're

play09:42

getting a tier hey good job mate you're

play09:44

a winner similar to zero point security

play09:46

Sears we have another underground

play09:48

company altered Securities crtp the

play09:51

certified red team professional at only

play09:54

$249 and the more advanced crte the

play09:57

experts sir at $299

play09:59

now these might seem cheap but the

play10:01

30-day lab access for the cheapest

play10:03

option might not be enough for folks and

play10:05

the prices shoot up pretty quick if

play10:06

you're not a fast learner now these

play10:07

shirts are more or less Unknown by HR

play10:10

and these were formerly certificates

play10:11

provided under in Securities website but

play10:13

the cour maker left shocking I know but

play10:16

they were able to pull the rights back

play10:17

to the materials in the exam from in's

play10:19

hold now these are pretty extensive

play10:21

exams but they're not quite as difficult

play10:23

as Zero Point Security exam but they do

play10:25

still cover similar material utilizing

play10:27

Powershell instead of cobalt strike

play10:28

these are of course B tier wedged

play10:30

accordingly in between the TCM CTS but

play10:33

above this doooo face now for the moment

play10:35

I'm sure all of you have been waiting

play10:38

[Music]

play10:41

for offset offensive security is by far

play10:44

the most commonly known certificate

play10:46

agency by the red teaming cyber SEC

play10:49

Community which was of course made

play10:50

famous by its Golden Child the ocp the

play10:54

offensive security certified

play10:56

professional now following along the two

play10:58

certificate per agent theme that we have

play11:00

going on they also have a more difficult

play11:02

exam the ep the offensive security

play11:05

experienced penetration tester now the O

play11:08

more or less just Builds on the

play11:09

knowledge that you learned in the ocp so

play11:11

not everything that's covered in the ocp

play11:13

is covered in the O exam which makes

play11:16

sense certificate agencies want you to

play11:18

buy all of their CTS building one off of

play11:20

the other it's a very logical and

play11:22

lucrative business model now both of

play11:24

these certificates cost the same to

play11:26

obtain at

play11:27

$1650 a pop unless you purchase is the

play11:29

learn one or learn unlimited option

play11:31

which does save you money if you plan on

play11:33

taking both or more of off sex

play11:35

Securities courses and certificates but

play11:37

it's not easy to find time and

play11:38

motivation to continuously study

play11:40

throughout the year while working 9 to5

play11:43

with 2 and A2 kids resisting the

play11:45

temptation to use any ounce of time you

play11:47

have remaining on Mindless yet so

play11:49

satisfying video games anyways the ocp

play11:52

is arguably less difficult and less

play11:55

comprehensive than the crtp or the cr1

play11:59

but but it is the de facto golden

play12:01

standard for the basics of penetration

play12:03

testing and it's the number one most

play12:04

commonly found certificate in our sample

play12:06

list W so of course the jacked older

play12:09

brother the O is s tier right wrong it

play12:13

doesn't come up in job listings I know I

play12:15

know the world doesn't make any sense

play12:18

I'm just trying to make sense of it the

play12:19

best that I can but it's a tier the

play12:22

immediate recognition of the ocp on a

play12:24

resume is the only reason that ocp is s

play12:28

tier and O is a tier I don't make the

play12:31

rules I just try not to break them and

play12:33

honestly I feel like skipping the ocp is

play12:35

a bit of a disservice to yourself I mean

play12:37

yeah the OSP is more difficult but in

play12:40

some ways that's like skipping the

play12:41

basics and if I recall in many many many

play12:44

many of my previous math classes that

play12:46

I've taken you're never taught the easy

play12:48

way to solve an equation first you have

play12:50

to learn the long ass complicated

play12:52

version first now the certificate that

play12:55

I've been waiting for p the Box

play12:56

Academy's certified penetration test

play12:59

specialist the

play13:03

cpts now hack the box is very well known

play13:06

in the cyers SEC Community but not the

play13:08

HR community so this is rarely seen on

play13:10

any job listings but this exam requires

play13:13

that you complete the penetration tester

play13:15

job roll path which is where the magic

play13:18

happens completing all these modules and

play13:20

boxes provides an invaluable amount of

play13:24

knowledge and insight into penetration

play13:26

testing all leading up to the exam which

play13:28

is just like the OSP in that it's also

play13:31

Hands-On entirely practical and it's

play13:33

almost entirely agreed upon online to be

play13:36

significantly harder than the OSP which

play13:39

is most likely due to it being a 10day

play13:41

exam whereas the OSP is only 24 hours

play13:44

pair that with the fact that you can't

play13:46

move on from one machine if you can't

play13:48

solve it whereas in the ocp you can

play13:50

bounce around and solve the easy ones

play13:52

first you can't get past one machine in

play13:54

the cpts exam you fail it's all or

play13:57

nothing so if you're weak in one aspect

play13:59

of penetration testing for you also it's

play14:02

been said that if you pass the cpts you

play14:04

can more or less immediately walk in and

play14:07

past the ocp so for that reason alone

play14:10

I've decided to take it upon myself to

play14:12

Grant the cpts the honor nay the

play14:15

privilege bestowed upon the greats and

play14:18

put it in s tier you've done what none

play14:20

of the other certificates could do

play14:22

you've become so powerful not even the

play14:24

HR Gates can stop you you're the

play14:27

underground goats of the red team space

play14:29

all because of the sheer amount of

play14:31

technical knowledge practical skills and

play14:33

sheer cyber security Community Clouts

play14:35

gained will actually show in your

play14:38

interviews now no list would be complete

play14:40

without another well-known quote unquote

play14:43

ethical hacking certificate the

play14:45

certified ethical hacker certificate the

play14:48

C if you're just looking to check a

play14:50

government requirement box just get the

play14:52

CSP it's cheaper at $750 has more HR

play14:57

clout and is just as easy watch this

play14:59

this video here and you'll pass in no

play15:01

time oddly enough the cissp actually

play15:02

shows up in 25% of our penetration

play15:05

testing job sample what can I

play15:08

say it's a popular certificate F tier my

play15:12

guy you don't want to be like this this

play15:15

is disgusting this is awful in every way

play15:18

if I could kill it I would but I legally

play15:22

can't but I've considered it you suck

play15:24

and I don't care if you show up in

play15:26

almost half the job listings in our

play15:28

sample you're baggage is not worth it in

play15:30

my masked opinion but hey I will throw

play15:32

EC count Sol a bone they do have the C

play15:34

Pence a certified penetration testing

play15:36

professional exam a 24-hour Hands-On

play15:38

exam similar to the OSP this is somewhat

play15:41

new not listed in any job descriptions

play15:43

but it seems to be an okay exam for

play15:45

learning again can't deal with the

play15:46

baggage but for learning's sake deter or

play15:49

quit [Β __Β ] around EC Council and fix

play15:51

your company's problems press shirts

play15:54

these exist and are very British and can

play15:56

be very expensive D tier sorry bro all

play15:59

right so what do you need to consider

play16:01

when going into ethical hacking consider

play16:03

joining the Army cuz good luck getting

play16:05

hired in this job

play16:07

[Music]

play16:10

market sorry I had to it's kind of

play16:13

become a tradition at this point but

play16:14

seriously certificates only serve one

play16:17

purpose and one purpose only making your

play16:19

resume look better now the courses

play16:20

around the certificates if they're even

play16:22

available are where you get your money's

play16:24

worth you know the more you get the more

play16:26

you feel your money worth from any of

play16:28

the certificates mentioned in this tier

play16:30

list Beyond completing all the courses

play16:32

labs and obtaining a certificate it's

play16:34

your responsibility to continue to build

play16:37

on what you learned cuz when it's time

play16:39

to interview if you just sound like a

play16:41

guy who memorized exploits to pass the

play16:43

exam it's going to show how does it

play16:48

feel treat me like you

play16:51

do when you play

Rate This
β˜…
β˜…
β˜…
β˜…
β˜…

5.0 / 5 (0 votes)

Related Tags
Ethical HackingCybersecurityCertificationsPenetration TestingRed TeamingCareer AdviceTechnical SkillsJob MarketSecurity AnalystCyber Niche