Let's Talk About Cyber Security Certificates
Interview
[Hakin9 Magazine]: Hello! Thank you so much for agreeing to the interview! Please, tell us something about yourself.
[Felipe Martins]: I’m an ex-musician and current security engineer by trade, specialized in penetration testing, and other cyber security testing. I love music, martial arts, puzzles and technology.
[H9]: To begin with, what cybersecurity certificates did you obtain?
[FM]: I’ve obtained several EC-Council, Offensive Security, eLearnSecurity, (ISC)2 certificates such as CISSP, CEH, OSWP etc.
[H9]: Why did you decide to pursue those certificates?
[FM]: Most of the certifications were basically market requirements, but I also pursued them due to two things, their value in my resume and also for the knowledge they would give me.
[H9]: From all of them, which one do you value the most?
[FM]: Not sure exactly if there is one I value above all. Any certification that you can get, where you can learn something, is a good certification. No matter if it is a multiple choice or hands-on one.
[H9]: From the current perspective, which one was the most difficult to achieve?
[FM]: All certifications can be doable when you study correctly, so I don’t find them difficult, but the one that really got me a hard time, more due to the nature of the certification itself, rather than its difficulty was (ISC)2 CISSP. The process of getting certified can be a bit tedious in this one.
[H9]: Which one do you consider the most useful?
[FM]: None specifically, all of them complete each other. But for pentesters I would say, any from Offensive Security or eLearnSecurity.
[H9]: In what situations did the certificates prove most useful? How did they influence your career? Did anyone ever require any of them?
[FM]: Most of the certifications I got were market requirements, but now I’m in a position to choose the ones I want.
[H9]: We’re curious what your position on the ‘certificates vs. skills’ debate is. Do certifications always imply real knowledge and competences?
[FM]: There are good points to both fronts, certifications are the way the market can pinpoint you among thousands of professionals, but it doesn’t mean a highly certified professional has appropriate experience. At the same time, I know hundreds of highly experienced professionals with no, or just a few certifications. It all depends on the goal. If the goal is to learn something new and put it to practice, I would totally go for any certifications you can put your hands on.
[H9]: How long does it take to prepare to take an exam for such certificates?
[FM]: That is a very wide open question, it could vary due to the specific certification, personal time at the candidates disposal and also the experience of the candidate. I would say in general terms, for multiple choice exams it could take 1-3 months. For hands-on ones, it could take between 3 months to a year, depending on the difficulty of the subject and how experienced you are at that.
[H9]: What is the most challenging part of preparing for such certificates from your point of view?
[FM]: First of all the high prices some certifications are rated. SANS for example are too expensive (course and exams) for most of us to pay. Second would be finding time to continuously study. I would say time is always the biggest problem.
[H9]: Are there any certificates that you now consider a waste of time?
[FM]: I wouldn’t say a waste of time, but I wouldn’t take certifications where my current certifications would overlap or supersede them in terms of knowledge. I personally prefer to do hands-on exams rather than multiple choice ones.
[H9]: Let’s now assume that our reader is at the beginning of his security path. What steps does he have to follow to prepare for and pass the exam for such certificates? Do you have any advice? What ‘certificate roadmap’ would you suggest?
[FM]: First would be choosing the field he wants to work and study deeper. Once that is chosen, he would start from scratch. I would first start by learning TCP/IP (networks in general) and also at least 1-2 Operating systems, so you are prepared for your studies in security I would then start to get some 101 security knowledge, for that CompTIA and (ISC)2 exams can help, or any other course that can grab you by the hand and give you a bit of perspective and one inch deep knowledge of security. I would then, if intrusive security is the path you chose, I would go for an INE subscription, it would give you access to all eLearnSecurity courses, they will prepare you from scratch. If you are a bit more advanced, you could take Offensive Security right away.