OSCP / CEH / PNPT
Defensive view: industry certifications - what they are worth, what they signal, and how to pick.
Cert landscape
EXAMPLE
# Security certifications - a defender's map > Certifications are signal, not skill. Treat them like school grades - useful > evidence of effort and structured learning, but no substitute for hands-on > work. ## Foundations (entry-level) - CompTIA Security+ - good fundamentals, common HR filter - (ISC)2 CC - introductory cyber knowledge - Microsoft SC-900 / AWS Certified Cloud Practitioner - vendor basics ## Defensive operations - GIAC GSEC - broad security operations - GIAC GCIA - intrusion analysis - GIAC GCFA / GCIH - forensics and incident handling - Blue Team Level 1/2 (BTL1/BTL2) - hands-on blue team labs - SANS courses are pricey but deep ## Cloud - AWS Security Specialty - Microsoft SC-100 / SC-200 / AZ-500 - Google Professional Cloud Security Engineer - Wiz Certified Cloud Security Architect (newer) ## Application + DevSecOps - GIAC GWAPT - web app pen testing - AWAE / OSWE (Offensive Security) - hands-on advanced web - Kubernetes CKA + CKS for cluster security ## Offensive (defender knowledge) - OSCP (PWK) - hands-on practical - OSEP, OSED, OSWE for specialised paths - CRTO / CRTP for red-team operations - HackTheBox CPTS / CBBH ## Governance + risk - CISSP - leadership and breadth (8 domains) - CISM - management focus - CRISC - risk - ISO 27001 Lead Implementer/Auditor ## How to choose - Ask the question 'what role am I trying to win?' - Read 10 job descriptions for that role; pick certs that appear repeatedly - Pair certifications with portfolio work (GitHub, write-ups, talks) - Budget time and money; some certs cost thousands ## Anti-patterns - Cert collecting without applied projects - Skipping fundamentals for a niche cert - Believing OSCP makes you a senior engineer (it does not) - Letting certs replace continuous learning
Why it matters
Certifications are signal, not skill. Pair every cert with a portfolio project. The right cert for your next role is whichever appears most often in the job descriptions you are targeting.
Tip: Tweak the snippet with Try it Yourself », then sit the quiz at the bottom of the page.
Example
Example
# Common certs: # - OSCP (offsec) — hands-on, well-respected. # - PNPT (TCM Security) — modern + report-focused. # - CEH (EC-Council) — broad but theory-heavy. # - CRTP / CRTO / OSWE for niches (AD, red team, web). # Pick by your target role + employer's preferences.Try it Yourself »
Discussion
Loading…