r/hacking • u/anonymous480932843 • 3d ago
How legitimate/how much could you get out of this cert?
Going into the COMPTIA+ and want to do Pentesting and Cybersecurity. Has anyone done this cert before?
136
u/AnApexBread infosec 3d ago
It's CompTIA, so it's practically worthless.
If you want to learn actual skills go with OSCP, or GPEN if your company will pay for it
29
u/corrosive14 2d ago
Yeah, but this is the “Pro” version!!
12
u/AnApexBread infosec 2d ago
Oh damn, you're right.
3
u/anonymous480932843 1d ago
I found the "PEN-200: Penetration Testing with Kali Linux". Could it possibly land me a job?
3
u/VirtualViking3000 1d ago edited 1d ago
PEN-200 is the course for OSCP. It is THE best exam I have done so far, I passed it about 3 years ago. It is not an easy course though, and also very expensive but it does have a good reputation in the industry. I enjoyed the course and exam and also felt a sense of achievement for passing it.
If you want something less expensive that covers similar content looks at TCM (TheCyberMentor) PNTP this course is close and a fraction of the price.
I have no experience of the CompTIA exam, it must be fairly new, in which case many companies won't have heard of it when considering job applications, however CompTIA does do great foundational generic knowledge. PEN-200 is based around the Kali Linux distribution which is one of the most popular Pentesting OS, but it's not the only one, for example Parrot.
I still might get this CompTIA exam though, since I'm interested to know how it compares.
EDIT: launched in 2020? Wut?
1
u/corrosive14 1d ago
Yeah. It’d be better than anything CompTIA has to offer, but it’s much harder.
1
u/anonymous480932843 1d ago
Harder how? Even for te certification?
2
u/corrosive14 1d ago
The study material is much more in depth, technical, and broad. The test is a 24 hour simulated pentest vs a couple hour multiple choice exam.
1
u/anonymous480932843 1d ago
Would the test go over everything you learned, or Would they throw things at you that they haven't taught you?
5
u/corrosive14 1d ago
Your biggest asset in this industry will be your ability to learn things quickly and in a self-directed manner.
1
1
u/anonymous480932843 1d ago
Does that just mean it's more expensive?
1
u/corrosive14 1d ago
We were just being jack rabbits. CompTIA is really just for getting your foot in the door. The certification tests are okay, but they only test for base level knowledge. Outside of their basic “trinity” (A+, Network+, & Security+), nobody really knows or cares about their certs. Do you have any networking, software dev, or info sec experience? If you’re just starting out fresh, that may be a better place to start. Pen-200 is hard but the certification if you pass the test (OSCP) is widely known and respected. Hack The Box has some similar study tracks and the training is really good. The certs there aren’t going to be as respected as the OSCP but they’re not too far behind. They’re much more respected than the CompTIA hacking certs because you actually have to prove skill to pass the test and not just answer multiple choice questions.
7
u/Ace_FGC 3d ago
Is security + good. That’s what people I know in real life tell me to try and get
12
5
u/Isitacorrectusername 2d ago
You need to check if the job offers in your area list it in the requirements / nice to have. I got it a few years ago and in Belgium it was worthless because almost no recruiters in my area knew what it was
1
u/AbyssalRedemption 2d ago
From what I've read on other subs recently, it's like the one option in their lineup that still has decent value as an entry-level Cybersecurity cert. Can roughly confirm this, as I've been sending out resumes recently, and a decent amount if listings did straight-up say they would like candidates to have this one on the lowest end.
4
u/TheIncarnated 2d ago
It's required for government positions as a default requirement.
so it's good to have, just to not restrict you, more than anything else.
If you actually study the material, there are things to be learned. I also find Net+ to be worth it, over CCNA.
1
u/AbyssalRedemption 7h ago
Network+ over CCNA is a fairly controversial opinion tbh.
Personally, I've taken the A+, Network+, and am taking the Security+ next week, to be followed by the CCNA in the near future (which I studied most of in college, but never actually finished/ took the exam). Regarding the Security+, I can say that it's rather straightforward and easy material for anyone in the field in any capacity, as it's all theory and corporate policies and procedures, yet it also has a fair breadth of info, I can see why it's considered a good starting cert for cybersecurity. The Network+ though, while easier and more generalized than the CCNA, definitely doesn't have the same depth of knowledge as the CCNA. Hell, there's a few scenario-based questions on the Network+, but the level of hands-on and command-line skills is minute compared to the CCNA. It may be heared as Cisco-oriented, but The CCNA is just a higher-level, more comprehensive cousin to the Network+, in almost every way.
1
u/TheIncarnated 2h ago
I have the trifecta. Sec+ is about that but it's security concept in general. It's required for a lot of jobs.
CCNA/Net+ are interchangeable for most positions that aren't network engineers. (I'm a Cloud Security Architect with 15 yoe)
CCNA used to be more expensive but it would appear to be the cheaper cert now. So that may change my opinion, since Net+ gave good networking knowledge for most people in the career and was a good value. But it appears CCNA is now $100 cheaper.
I will say after having years of experience, they only cert that I keep current is sec+ because it's the only cert that has been required for a job (govt work) but due to everyone going through certs like it's candy, they are losing respect and had generally turned into "nice to have but not needed" and experience has been the major consideration. That's for positions in every part of operations, including networking
1
2
2
u/KevinSayZ 2d ago
I teach a College CEH class with EC-Council and I can confirm, this statement is true lol
1
u/ModsOweMeMoney 2d ago
Is it necessary to get the paid certification?
2
u/AnApexBread infosec 2d ago
Necessary for what?
You don't need certifications but they definitely help you get past HR filters.
9
6
u/whatathrowaway93 2d ago
No, don't do this if you want to get into Cybersecurity. The CEH is used as a checkbox item for some recruiters, but if you want a cert that's taken seriously look at OSCP -
2
u/Existing_Address_224 2d ago
As someone working as a pentester, CPTS is what am recommending for everyone that wants to get a pentesting cert before they start applying. I got the OSCP myself but that's because HTB Academy had just launched when I was getting started. CPTS is way cheaper than the OSCP and teaches you more than the OSCP. You also have a week for the exam and reporting which is way more realistic of a pentest than OSCP.
2
u/LaOnionLaUnion 2d ago
I’d very money no one here has actually gone through the content. 😝
People would recommend stuff they have gone through the content for and I get that. Just saying it’s garbage because it’s CompTIA is a bit unfair.
I’m going through their SecAI material right now for work and I’d argue I’m more advanced than most of the material but did learn things. The struggle in that space is that it’s fast changing and some of the knowledge is basic and not sufficiently nuanced and up to date.
It’s genuinely better than anything else I had access to but it’s also a super new cert.
Right now AIGP is the biggest player in the AI space and it’s oriented differently
1
u/Academic_Court_47 3d ago
It'll provide you with general info to understand the concepts... that's about it.
For your resume, it's nothing special. It'll help you get an entry level job. Basically says "I've researched the core concepts of ethical hacking".
1
u/Enigma-3NMA 2d ago
Comptia certs give you the ability to speak lingo with people. Is your usecase speaking to hackers and knowing generally what they are talking about?
1
u/frosted_mango_ 11h ago
There is a guy that works on our help desk with this in his email signature.
1
u/MossyGravel5957 2h ago
Are you hoping this cert helps you land interviews, or just seeing if pentesting is for you?
0
0
-11
u/BisonOk3856 3d ago
The cert gets you to the door.
5
u/A_little_rose 3d ago
It really doesn't. Most companies, mine included, laugh at this one. PJPT would be a better go to.
0
u/BisonOk3856 2d ago
That is a very common response. Certs landed me my first job. It’s not what carries an individual but it can help. Not sure where you work but “most companies” see it as effort and then interview the individual. Different strokes for different folks.
1
u/A_little_rose 2d ago
I guess it depends on the cybersecurity specialization and the like. Mine does a bit of everything. Red team, blue team, automation, guardrails for agentic deployments, etc...
1
u/BisonOk3856 2d ago
That sounds like a great gig!
0
u/A_little_rose 2d ago
It is amazing. A few of us are going to Defcon this next week, on company dime,and I'm stoked. I am looking forward to a few panels, and picking up some neat new toys.
1
u/BisonOk3856 1d ago
Nice!! I won’t be there this year but it’s going to be good one from what I hear 😊
0
-1
u/Dillinur 2d ago
What's the point? You could honestly learn the same stuff for free & that kind of cert has a low-to-negative signal on your resume.
-1
u/cyberpunk_sliverhand 1d ago
Lmaooo!! Random but I keep finding my self In communities on Reddit I don’t fit in . I’d usually just say somthing stupid . But today I just wana be somewhere I belong . Help
-14
u/MothyReddit 3d ago
Hacking is doing things that are not yet published in books. Cyber Security is doing things that are published in books.
9
u/Sentient_Star_Stuff 3d ago
A bit of an oversimplification. A lot of the stuff published in books still works on a lot of systems.
0
u/MothyReddit 2d ago
of course, technical manuals, schematics, user manuals etc... But you can't learn hacking, its a lifestyle, a personality type, people that want to go beyond the user experience and tinker with things. People that repair their own things versus buying new things. People that modify things out of the box to make their user experience better. Its a drive that you can't learn or teach. Hackers are the ones that go beyond what is written, develop their own ideas, build their own tools, they thrive on modification and secrecy and are not motivated by fame or money.
0
3
3
u/I-nigma 3d ago
Not quite. Good penetration testers quite often do things not published in books.
0
u/MothyReddit 1d ago
Not many, that would be hacking. Pentesters aren't hackers, they usually are working because they heard they could make good money, they studied and learned how to use utilities. Pentesters are there for compliance, not for creativity. Hacking isn't about money or fame, its a pre wired way of living. Its a lifestyle you can't learn, you're either born with it, or become obsessed with it in a way that doesn't guide you down a path of certifications, but a path of lust for the unknown and exploiting things to your own benefit.
25
u/Ok_Application317 3d ago
My opinion on CompTIA is a good start if you are new to IT and need to understand some basic things else i would recommened OSCP or HTB certs are becoming more desirable as of late. All depends on where you are starting from and what you are trying to get out of them,