CertForums


Go Back   CertForums > Certification Forums > Other IT certifications


Certification Advice

Reply
 
Thread Tools Display Modes
  #1  
Old 05-Jan-2010, 02:25 PM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Question Certification Advice

Hi

A complete newbie here.. So please be gentle with me

This has probably been asked a million times before, but I think my case is slightly different. Hence the reason for my post. I have read the guide here for beginner's entry into Security, but I also needed your valuable opinion on the below certifications.

I was looking to move into IT Security area and was wondering if any of the experts here could give me any advice on choosing the right certification.

Let me start with a little bit of my background.. I have been in the IT industry for the past 8 years on and off, but not with much commercial experience. I have completed my MCSE 2003 few years back, but not had a chance to work much in a commercial environment. I had worked as an IT Support Engineer (for 1 year) for a small firm few years back. The firm got closed down and I was forced to take up a sales job (which involved very few IT skills). I set up my own IT Support business last year, supporting few of my clients on Microsoft platform, both server and clients. I have got experience in Windows 7/XP/Vista/2003, Office 2003/2007, Active Directory, Exchange Server, Backup, Firewalls, VPN, DNS, TCP/IP, WLAN, Antivirus, AntiSpyware, etc.

As my business is not doing very well, I was looking to move into IT security, which I believe is very much in demand these days. Would you be able to recommend any certifications that the employers are looking for these days? I was looking to complete the certification and take up a suitable position is some company. If you can recommend any such certification for someone with my background, that would give me an entry into IT security, that would be very much appreciated. To start off with, I would think a generic rather than a vendor-specific certification would be more appropriate. What do you think? I am aware that certifications like CISSP, CISM, CISA are very much in demand these days, but these wouldn’t suit someone with my background. I was thinking of doing the CEH, but I was told that it was a bit advanced. The EC-Council’s Network Security Administrator (ENSA) looked quite interesting. Any ideas on this? The other options I have been given are Comptia Security+, CISMP, ECSA, a combination of CISMP, CEH and ECSA, etc. If you can give me any recommendations, I would be very much obliged.

I have been doing a lot of research on this and struggling to make up my mind. I hope I can find a favorable answer here.

Sorry for the long detailed mail. I thought it was essential for you to know my background to guide me to the 'right track'.

Thanks for your time and patience.

 
Reply With Quote
  #2  
Old 05-Jan-2010, 03:27 PM
Bri1981 Bri1981 is offline
Valued Member
Posts: 124
 
Reputation
Points: 861 Bri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 points
Power: 11
Awards
None
Profile
Join Date: 07 Oct 2009
Location: Brussels
Age: 29
Certifications: See signature
WIP: ITIL expert,MCITP EA, CISM
Rep Power: 11
Bri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 pointsBri1981 has over 500 points
I think the Security+ would be a good place to start, with the experience you have the material should be relatively straightforward. Once this is out of the way (depending on what exams you completed for the MCSE) you may only need one more for the MCSE Security cert.


PMP, Prince2 Practitioner, Project+, MCTS MS Project 2007, ITIL v2 & v3 foundation, CISSP, MCSE Security, Security+, CCNA Security, CCNA, MCTS Vista
 
Reply With Quote
  #3  
Old 05-Jan-2010, 03:46 PM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Thanks for your reply and suggestion..

I compared the Security+ with ENSA and the ENSA seems to cover a wide range of topics.

The following modules are covered in ENSA program:

Module: Fundamentals of Network
Module: Wireless Network Security
Module: Web Security
Module: Virtual Private Networks
Module: Troubleshooting Network
Module: Security Standards Organizations
Module: Security Standards
Module: Security Policy
Module: Securing Modems
Module: Protocol Analysis
Module: Patch Management
Module: Packet Filtering and Proxy Servers
Module: Network Vulnerability Assessment
Module: Network Security Threats
Module: Network Security
Module: Network Protocols
Module: Log Analysis
Module: Intrusion Detection System (IDS) and Intrusion Prevention Systems (IPS) Module: Incident Response
Module: IEEE standards
Module: Hardening Routers
Module: Hardening Physical Security
Module: Hardening Operating Systems
Module: Firewalls
Module: E-mail Security
Module: Disaster Recovery and Planning
Module: Creating Fault Tolerance
Module: Bastion Host and Honeypots
Module: Authentication: Encryption, Cryptography and Digital Signatures
Module: Application Security

whereas Security+ seems to cover the following:

Day 1: Introduction to General Security Concepts
InfoSec Overview and History
Access Control
Authentication
Non-Essential Services/Systems/Protocols
Attacks
Malicious Code
Social Engineering
Auditing
Remote Access
Email
Web
Directory
File Transfer
Wireless
Devices
Media
Security Topologies
Intrusion Detection
Security Baselines
Day 2: Cryptography/Operational/Organizational Security
Algorithms
Concepts of Using Cryptography
PKI
Standards and Protocols
Key Management/Certificate Lifecycle
Suspension
Recovery
Renewal
Destruction
Key Usage
Physical Security
Disaster Recovery
Business Continuity
Policy and Procedures
Privilege Management
Forensics
Risk Identification
Education
Documentation

More information on the ENSA course and its contents are available on the EC-Council website:

http://www.eccouncil.org/training/co...e_outline.aspx

Any good?

Thanks!


Last edited by Shajin; 05-Jan-2010 at 10:56 PM.
 
Reply With Quote
  #4  
Old 06-Jan-2010, 06:27 PM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Seems like nobody is interested in helping me..

 
Reply With Quote
  #5  
Old 06-Jan-2010, 07:35 PM
GiddyG's Avatar
GiddyG GiddyG is offline
Friendly taxman...
Posts: 2,387
 
Reputation
Points: 2763 GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Power: 56
Awards
None
Profile
Join Date: 16 Aug 2007
Location: Born and bred in Birkenhead
WIP: CCENT, CCNA, CWSP, 70-680
Rep Power: 56
GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Quote:
Originally Posted by Shajin View Post
Seems like nobody is interested in helping me..
Not so.

I would suggest that Bri1981 is correct that Sec+ is a valid certificate to go for. It is certainly a certificate that can be used, or it certainly used to be, as an elective for the MS route. There is a book written by Darril Gibson which is very good. Its ISBN number is: ISBN-10: 1439236364.

Following on from that, you could look at the likes of the CEH as appropriate certs where you hold the requisite knowledge.

You may also wish to consider the likes of the CCNA, where you can work towards the CCNA Security certification, if you are working in a Cisco networking environment.

Best of luck.

John

 
Reply With Quote
  #6  
Old 06-Jan-2010, 11:42 PM
Trogdor's Avatar
Trogdor Trogdor is offline
The Burninator
Posts: 199
 
Reputation
Points: 759 Trogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 points
Power: 18
Awards
None
Profile
Join Date: 05 Jun 2005
Location: St Albans, Hertfordshire
Certifications: A+, Network+, MCDST
WIP: MCSA, IT Diploma
Rep Power: 18
Trogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 pointsTrogdor has over 500 points
I think the Security + exam is a good place to start. It also counts to adding a security specialisation to your MCSE, which is an added bonus. Realistically, I think you need some substantial commercial experience to get a position in security. What kind of experience do you have? What are you doing at the moment?


"If you think education is expensive, try ignorance."
-Derek Bok
 
Reply With Quote
  #7  
Old 07-Jan-2010, 01:59 AM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Thanks for all your suggestions...

The reason why I was considering ENSA over Security+ was that ENSA seemed more "hands-on" and seemed to cover a wide range of topics. I am not sure whether Security+ or ENSA is more in demand in the job market.

@GiddyG
As a starter to security, I thought a more generic certification would be more appropriate rather than going for a vendor-specific certification. I could look into that later on as I progress. What say?

@ Trogdor
My entire life history has been stated in the first post I am self-employed at the moment, supporting few of my clients mainly on Microsoft platform.

All suggestions welcome.. Thanks!

 
Reply With Quote
  #8  
Old 07-Jan-2010, 10:48 AM
GiddyG's Avatar
GiddyG GiddyG is offline
Friendly taxman...
Posts: 2,387
 
Reputation
Points: 2763 GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Power: 56
Awards
None
Profile
Join Date: 16 Aug 2007
Location: Born and bred in Birkenhead
WIP: CCENT, CCNA, CWSP, 70-680
Rep Power: 56
GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Quote:
Originally Posted by Shajin View Post
@GiddyG
As a starter to security, I thought a more generic certification would be more appropriate rather than going for a vendor-specific certification. I could look into that later on as I progress. What say?

Well, the Security+ is vendor-neutral, hence it's always a good one to go for. There are a few books about Sec+ out as well. Personally, I think it would give you a very good grounding in security, over and above what you already know. Mind you, I find that with all of the subjects I read books about, even those I think I know quite well.

Best of luck with your studies!

 
Reply With Quote
  #9  
Old 07-Jan-2010, 05:10 PM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Thanks for your reply GiddyG.

I understand that Security+ is a vendor-neutral certification. And so is ENSA. I wanted your opinions on which one to go for out of the two. I believe ENSA is a fairly new course which is why not many people have heard about this. The course curriculum looks very interesting. But how are EC-Council certifications generally? Do they have any upper hand over CompTia?

Thanks!

 
Reply With Quote
  #10  
Old 07-Jan-2010, 08:01 PM
GiddyG's Avatar
GiddyG GiddyG is offline
Friendly taxman...
Posts: 2,387
 
Reputation
Points: 2763 GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Power: 56
Awards
None
Profile
Join Date: 16 Aug 2007
Location: Born and bred in Birkenhead
WIP: CCENT, CCNA, CWSP, 70-680
Rep Power: 56
GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
I do not believe that the ENSA certification would hold sway, certianly not at the moment. As has already been mentioned by me and others, the Sec+ can also be used as an elective against the MCSE. This, to my mind, makes it the certification of choice as a starter for ten.

Someone like WagnerK (Ken) will no doubt have his own valid views on the matter.

 
Reply With Quote
  #11  
Old 07-Jan-2010, 08:24 PM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Sorry if I sound dumb.. But who is WagnerK???

 
Reply With Quote
  #12  
Old 07-Jan-2010, 08:28 PM
greenbrucelee's Avatar
greenbrucelee greenbrucelee is offline
Lifetime Member
Posts: 12,860
 
Reputation
Points: 5721 greenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 points
Power: 192
Awards
None
Profile
Join Date: 21 Mar 2007
Location: Carlisle Cumbria
Age: 33
Certifications: A+, N+, MCDST, S+
WIP: N+ 2009 for some stupid reason
Rep Power: 192
greenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 pointsgreenbrucelee has over 4000 points
Quote:
Originally Posted by Shajin View Post
Sorry if I sound dumb.. But who is WagnerK???
He is another member here who knows lots about certifications and what will be best for you, why not PM him and ask him.

I would also agree with above posts about that Sec+ would be better for you to do than the other one.


S+,MCDST,N+,A+,HND Business Computing, GNVQ Level 3 IT, NVQ Level 1 & 2 IT

Mobo: Asus Rampage Formula x48
CPU: Intel C2D E8400 @ 4GHz
HSF: Tuniq Tower
GPU: BFG GTX 260 OC2 Maxcore Edition
RAM: 4GB Geil Black Dragon 1066Mhz
CASE: Antec 1200
PSU: 700W Seasonic M12
DVDRW: LG 20x DVD Rewriter
HD1: 250GB Samsung Spinpoint
HD2: Samsung external backup drive 160GB
Display: 22" Samsung SyncMaster 2253BW

RIP UCM, your were always willing to help & will not be forgotten
 
Reply With Quote
  #13  
Old 07-Jan-2010, 10:19 PM
wagnerk's Avatar
wagnerk wagnerk is offline CertForums News Posting Member
aka kitkatninja
Posts: 9,292
 
Reputation
Points: 8777 wagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 points
Power: 189
Awards
None
Profile
Join Date: 13 May 2005
Location: Northants, UK
Age: 32
Certifications: 2nd Degree Black Belt
WIP: NVQ3 Management
Rep Power: 189
wagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 pointswagnerk has over 4000 points
Sorry for the late reply, been very busy at work

I agree with what's already been said, if you're trying to gain entry into the IT Security field, the bare minimum that I (as an IT manager) would like to see in a candiate (certification/knowledge wise) is the Comptia Security+.

I would recommend doing your Security+, then using that whatever other MS exam(s) you need to top up your MCSE to the MCSE: Security.

To tell you the truth, the only cert that is widely known is the CEH from the EC-Council. They are more US based, and while they are gaining more popularity (mainly really only due to the CEH). I would recommend looking into the ICS2 instead, nothing against the EC-Council, just that ICS2 already has a foot-hold in the UK/EC in fact global market and industry. Hence they are more recognised and accepted in the UK. Their entry level credential is the "Associate of (ISC)˛".

One thing that I would like to point out that you can gain all these certs/credentials, but you should also be getting the experience to back it up, otherwise (imo) it'd all be almost useless. Start implementing what you're learning/learnt on your clients networks, etc - with their permission first to get basic experience. If you're going to be looking for employment with a organisation then you may only get the entry level (possibly one level about that) IT Security post.

Along with gaining membership into the ICS2, I would also recommend looking into Professional Membership of the BCS - if only to show that you're guided by the BCS Code of Conduct. I joined in support of the IT field and to gain my CITP, so I am pro them. Some find them useful, some don't.

Hope this helps

-Ken


No matter how much you think you know, there's always someone who knows more...
IT Manager, IT Writer/Columist & Part-time IT Lecturer
 
Reply With Quote
  #14  
Old 09-Jan-2010, 01:22 AM
GiddyG's Avatar
GiddyG GiddyG is offline
Friendly taxman...
Posts: 2,387
 
Reputation
Points: 2763 GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Power: 56
Awards
None
Profile
Join Date: 16 Aug 2007
Location: Born and bred in Birkenhead
WIP: CCENT, CCNA, CWSP, 70-680
Rep Power: 56
GiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 pointsGiddyG has over 2500 points
Thanks Ken. I knew you could add a bit of meat to the sandwich.

 
Reply With Quote
  #15  
Old 11-Jan-2010, 03:23 AM
Shajin Shajin is offline
New Member
Posts: 16
 
Reputation
Points: 0 Shajin has no points
Power: 2
Awards
None
Profile
Join Date: 05 Jan 2010
Rep Power: 2
Shajin has no points
Thank you very much for all your help and advice.

I think I will go with Security+ like all the experts here suggested.

As I am spending the time and money for Security+ anyway, I wouldn't mind doing another course with it. What would go well with Security+? CEH? Network+? Server+ or any others that you can recommend?

Also, does it add value if the certification is obtained from the UK? I was planning of getting it done outside the UK (may be India) as it is much cheaper.

Thanks!

 
Reply With Quote
Reply

Go Back   CertForums > Certification Forums > Other IT certifications

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Seeking Advice on .net certification Please Sohail09 MCAD /MCSD / MCTS / MCPD 0 06-Aug-2009 03:25 PM
Certification advice sought. London_exile Training & Development 3 23-Mar-2009 11:36 AM
The industry's 10 best IT certifications kevicho Training & Development 12 18-Dec-2008 12:46 AM
A Threat to Your Career: Combating Certification Fraud wagnerk News 15 31-Aug-2008 03:23 AM
Want some advice regarding Microsoft certification pallavid MCAD /MCSD / MCTS / MCPD 1 03-Sep-2007 09:34 AM


All times are GMT +1. The time now is 12:47 AM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2009 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Lunarpages.com Web Hosting