6 ms·
Don't waste your time and money on CompTIA certs or CISSP. They're basically worthless when it comes to pentesting. Pentesting is learned by doing. Get your ha
by bashwizard 7y ago
Don't waste your time and money on CompTIA certs or CISSP. They're basically worthless when it comes to pentesting.
Pentesting is learned by doing. Get your hands dirty and start learning basic methodologies by using Hack The Box, Virtual Hacking Lab or Vulnhub VM's. When you feel that you're getting a bit comfortable rooting boxes, sign up for the PWK and go for the OSCP. This is your ticket into pentesting if you're like me with no work experience whatsoever in IT.
I came from +10 years in finance and landed my first job as a junior pentester two months after I passed the OSCP.
- relaunched 7y agoOCSP is a hands on test that requires you to break into a system and write up your findings. It's all done in a controlled environment and time-boxed. It shows you have real abilities in a hands-on setting. It's also one of two certs that are respected. The other is SANS.