Certified Ethical Hacker
The Certified Ethical Hacker (C|EH) is a professional certification provided by the International Council of E-Commerce Consultants (EC-Council.)
An Ethical Hacker is one name given to a Penetration Tester. An ethical hacker is usually employed by an organization who trusts him to attempt to penetrate networks and/or computer systems, using the same methods as a hacker, for the purpose of finding and fixing computer security vulnerabilities. Illegal hacking (i.e.; gaining unauthorized access to computer systems) is a crime in most countries, but penetration testing done by request of the owner of the targeted system(s) or network(s) is not, except in Germany.
A Certified Ethical Hacker has obtained a certification in how to look for the weaknesses and vulnerabilities in target systems and uses the same knowledge and tools as a hacker.
The certification is in Version 6 as of August 2008.
The EC-Council offers another certification, known as Certified Network Defense Architect (C|NDA). This certification is designed for United States Government Agencies, and is available only to members of selected agencies. Other than the name, the content of the course is exactly the same. The exam code for CNDA is 312-99.[1]
To get a more detailed understanding of this process see the Ethical Hack page.
•
Certification coursework
The coursework consists of 67 modules, which range from 30 minutes to five hours or more, depending on the depth of the information provided.
Some training centers and universities in Asia and Europe include EC Council's CEH program in one of their course modules.
Examination
Certification is achieved by taking the C|EH examination after having either attended training at an ATC (Accredited Training Center) or done self-study. If a candidate opts for self-study, an application must be filled out and proof submitted of 2 years of relevant information security work experience. In case you do not have two years of information security related work experience you can send them a request detailing your educational background and request for consideration on a case basis.[2] The current version of the CEH, v6, uses EC-Council's exam 312-50, as did v5. This exam has 150 multiple-choice questions and a 4 hour time limit. The earlier v4 had 125 multiple-choice questions and a three hour time limit. The exam costs US$250 in the United States (prices in other countries may differ)[3], and is administered via computer at an EC-Council Accredited Training Center, Pearson VUE, or Prometric testing center (in the United States).
Recertification
EC-Council Continuing Education (ECE) points serve to ensure that all certified professionals maintain and further their knowledge. Professionals must meet ECE requirements to avoid revocation of certification. Members holding the C|EH/CNDA designation (as well as other EC-Council certifications) must recertify under this program every three years for a minimum of 120 credits (20 credits per year).
Controversy
Certain computer security professionals, such as Marcus J. Ranum, have objected to the term ethical hacker: "There's no such thing as an 'ethical hacker' - that's like saying 'ethical rapist' - it's a contradiction in terms."[4] Part of the controversy may arise from the older, less stigmatized, definition of hacker, which has become synonymous with computer criminal.
On the other hand, some companies do not seem to mind the association. According to EC-Council, there has been an increase of careers where CEH and other ethical hacking certifications are preferred or required.[5][6][7]
Further reading
• Graves, Kimberly; CEH Certified Ethical Hacker Study Guide, Wiley, John & Sons, Incorporated, 2010. ISBN 978-0470525207
• Graves, Kimberly; Official Certified Ethical Hacker Review Guide, Sybex Publishing, 2006. ISBN 978-0782144376
• Gregg, Michael; Certified Ethical Hacker Exam Prep, Que Publishing, 2006.
Wednesday, May 19, 2010
MCITP Success - Pursuing Microsoft Certifications
Microsoft has released some news on SQL Server 2008 certifications. In short, they'll be releasing three MCTS certifications this year based on three roles. Each role will require one exam to earn the MCTS certification.
• Database Administrator
• Database Developer
• Business Intelligence Developer
There will also be three MCITP tracks geared to the same three roles. The SQL 2008 MCITP tracks arent' decided yet and probably won't come out until about six months after SQL Server 2008 goes live (Q3 2008).
The three MCTS Certifications will be:
1. 70-432
MCTS: SQL Server 2008, Implementation and Maintenance
Role: Database Administrator
Expected go live date: August 2008
Beta target: June 2008
Focused on Database Admin role, unlike the 70-431 exam which covers multiple roles
Test topics ():
- Installing and configuring
- Maintaining SQL Instances
- Managing Security
- Maintaining a database
- Data Management Tasks
- Monitoring and Troubleshooting
- Optimizing
- Implementing High Availability
2. 70-433
MCTS: SQL Server 2008, Database Development
Role: Database Developer
Expected go live date: September 2008
Beta target: July 2008
Test topics (not complete yet):
- T-SQL (triggers, stored procedures, views)
- Connecting to Datasources
3. 70-448
MCTS: SQL Server 2008, Business Intelligence Development and Maintenance
Role: Business Intelligence Developer
Expected go live date: August 2008
Beta target: June 2008
Test topics (not complete yet, similar to 70-445):
- Configuring, deploying, maintaining, and implementing
- SSIS
- SSRS
- SSAS
• Database Administrator
• Database Developer
• Business Intelligence Developer
There will also be three MCITP tracks geared to the same three roles. The SQL 2008 MCITP tracks arent' decided yet and probably won't come out until about six months after SQL Server 2008 goes live (Q3 2008).
The three MCTS Certifications will be:
1. 70-432
MCTS: SQL Server 2008, Implementation and Maintenance
Role: Database Administrator
Expected go live date: August 2008
Beta target: June 2008
Focused on Database Admin role, unlike the 70-431 exam which covers multiple roles
Test topics ():
- Installing and configuring
- Maintaining SQL Instances
- Managing Security
- Maintaining a database
- Data Management Tasks
- Monitoring and Troubleshooting
- Optimizing
- Implementing High Availability
2. 70-433
MCTS: SQL Server 2008, Database Development
Role: Database Developer
Expected go live date: September 2008
Beta target: July 2008
Test topics (not complete yet):
- T-SQL (triggers, stored procedures, views)
- Connecting to Datasources
3. 70-448
MCTS: SQL Server 2008, Business Intelligence Development and Maintenance
Role: Business Intelligence Developer
Expected go live date: August 2008
Beta target: June 2008
Test topics (not complete yet, similar to 70-445):
- Configuring, deploying, maintaining, and implementing
- SSIS
- SSRS
- SSAS
Subscribe to:
Posts (Atom)