Episode 39: Pentesting Certifications Tier List Part 2
May 3, 2023
auto_awesome
Dive into the world of pentesting certifications as experts rank them from best to worst. Discover the significance of key credentials like OSCP, GPN, and the emerging PNPT. Explore personal experiences with the G-Pen and critiques of practical versus theoretical value in these certifications. Learn about the advantages of Pentest Plus and advanced red team tactics with CRTO. Get insights into accessible certification options and community support for beginners, igniting a lively debate on their real-world application!
01:06:29
AI Summary
AI Chapters
Episode notes
auto_awesome
Podcast summary created with Snipd AI
Quick takeaways
The podcast ranks penetration testing certifications using criteria like content relevance, job marketability, and community support for informed decision-making.
The OSCP certification is highlighted as a gold standard due to its rigorous assessment and strong community backing, despite being challenging for beginners.
Newer certifications like GCPN and GMOB are scrutinized for lacking practical exam components, affecting their tier rankings and overall industry recognition.
Deep dives
Overview of Pen Testing Certifications
The episode provides an in-depth ranking of penetration testing certifications within a tier system, ranging from S to D tiers. Key criteria for ranking include knowledge gained, job marketability, exam format, community support, and cost. The discussion highlights various certifications, emphasizing the relevance of their content and the recognition they hold in the industry. This structured approach aims to guide listeners in choosing the right certification based on their career goals and existing knowledge.
Insights on SANS Certifications
The SANS GIAC Penetration Tester (G-PEN) certification garners a mixed review, praised for its comprehensive course content but criticized for its high cost and outdated elements. While recognized in job listings, the community behind SANS adds significant value. Concerns were raised about the lack of notification for course updates that could render prior learning less relevant. Ultimately, it received a tentative A-tier ranking due to its marketability despite its steep price.
Emerging Certifications and Practical Considerations
The podcast discusses new certifications like the GCPN, which focuses on cloud penetration testing, although it lacks a practical exam component, resulting in a lower tier ranking. The panel emphasizes the importance of hands-on experience, expressing skepticism about certification value without practical assessments. Similarly, the GMOB certification, catering to mobile device penetration testing, faces scrutiny for its market recognition but is appreciated for its niche focus. Both certifications are placed in the C tier due to their limitations despite some useful content.
The Impact of Offensive Security Certifications
The OSCP from Offensive Security is deemed an S-tier certification, noted for its strong community, name recognition, and rigorous assessment format. It requires candidates to engage in a challenging 24-hour hacking format, which some feel might deter beginners. The discussion contrasts it with other certifications, such as the PNPT, which is acknowledged for its more practical approach and supportive structure. With fair comparisons across different credentials, the OSCP remains a gold standard despite critiques.
The Importance of Community and Learning Pathways
A consistent theme throughout the episode is the importance of community, hands-on training, and continuous learning in the cybersecurity landscape. The PNPT certification by TCM Security is commended for its structured approach, affordability, and lack of expiration, making it highly favorable for entry-level penetration testers. Its multi-faceted examination process combines external and internal testing, setting a new standard for certification in the field. Overall, certifications that emphasize practical knowledge, real-world applications, and community support are viewed as the most beneficial for aspiring pen testers.
This is part 2 of a 2 part series where Spencer, Darrius and Tyler talk about pentesting certifications and where they fall on a tier list. For those unfamiliar, we're ranking the popular pentesting certifications from best to worst. This is a must listen/watch episode, check it out and be sure to let us know in the comments what YOU think of these certifications and if we had any bad takes!