Ethical Hacker or Security+ as training course

Techknowledge

Member
Jul 15, 2013
36
0
0
Does anyone know the difference of the two training security courses and which is better and why? How long does it take and could I take an online course or download books to go over them?

Thank you
 

SecurityTheatre

Senior member
Aug 14, 2011
672
0
0
Security+ is a very entry-level broad security exam. It covers a whole scope of security, ranging from severs and networks to firewalls and data classification, but it does it from orbit (very shallow depth).

CEH is a somewhat picky, specific test on a variety of network audit and penetration testing tools and techniques, some of which will make absolutely no sense to you if you don't have a broad security background.

Asking how long it takes... depends a lot on your background.

I passed both cold, without studying. :) So my answer is zero.

Then again, I had been working in IT for years when I took the Security+ (this was 10 years ago too), and I had been doing penetration testing for several years already when I took the CEH.

Realistically, you could learn most of the Security+ in under a week, but only if you have *some* background in IT and/or networking. You will be answering questions about the OSI model and a bit about port/protocol security and some about routing and a bit about firewalls (the difference between deep-packet and traditional stateful, etc). If you don't know the difference between TCP and UDP and their relative advantages, or the purpose and benefits of Active Directory (as two vague examples of general knowledge), you are probably in over your head considering security training at all at this point.

To be honest, neither exam is valued very highly, although the CEH at least has some merit with the HR types for a small set of jobs (security audit & penetration testing). However, this job description almost never has the word "entry level" at the beginning of it.
 
Last edited:

Savatar

Senior member
Apr 21, 2009
230
1
76
Security+ is a broad introduction to security in general... whereas CEH is an introduction into practical security testing and penetration.

For teaching real-world security practices, I feel that CEH is much, much better than the Security+ course... but it's by no means perfect (I hate that they make you memorize some specific command parameters, for example - in real life people just read the documentation unless you use it every day). Most people with a passing interest in security should be familiar with most of what is presented in the Security+ course to begin with.
 

lif_andi

Member
Apr 15, 2013
173
0
0
Am currently reading for Security+ and as other have said, it's very broad. Depending on your knowledge and experience, this is either good or bad. For me, as I'm just starting, passed CCNA last month, and want to get more into security, Security+ is a good start. Borrowed 'Network Security Fundementals´ from 2005 from my work today, and having read 2 chapters I now understand more about the subject than after the entire Security+ book. As I said, its broad, but doesn't go into detail about anything really.

But its a good starting point.
 

Mushkins

Golden Member
Feb 11, 2013
1,631
0
0
Does anyone know the difference of the two training security courses and which is better and why? How long does it take and could I take an online course or download books to go over them?

Thank you

As has been stated before, they're both very different exams on very different focuses. Sec+ is pretty much the A+/Net+ of the security world, any "real" job in the security field is going to expect you to have a whole lot more experience and expertise than just a Sec+ cert. It's a good stepping stone to other certifications, but practically worthless on its own unless you're just checking it off the list for a boss that's a stickler about certs.

Ethical Hacking in general is a much higher level skillset than a Sec+. It's not a specialization you start in by any means. If you couldn't already pass the Sec+ and have considerably security experience I wouldn't even consider focusing on this specialization in any serious capacity until you've done your time.

From your other recent posts and topics lately, you seem to be just getting your feet wet in the networking field in general. The best advice anyone can give would be to focus on the networking first, build a solid core understanding of the theory, technologies, and practical implementations of networks, and *then* if you want to focus on a security specialization you'll be ready. You can't learn how to secure a network if you don't understand the intimate details of how a network works :)
 

JBT

Lifer
Nov 28, 2001
12,094
1
81
If you are new to Security go for the Security+ is lays the ground work. I doubt its going to help land and job out there. I wouldn't pay for a course or anything though. Just pick up a book or maybe CBT Nuggets?
CEH now a days I'm pretty sure you have to go to a 5 day training for. I could be wrong. I haven't looked into that one in a LONG time.