Awae

Содержание:

COURSE PRICING

All prices in US dollars. Register for AWAE.

AWAE + 30 days lab access + OSWE exam certification fee $1400
AWAE + 60 days lab access + OSWE exam certification fee $1600
AWAE + 90 days lab access + OSWE exam certification fee $1800
OSWE certification exam retake fee $200
AWAE lab access – 30-day extension $500
AWAE lab access – 60-day extension $700
AWAE lab access – 90-day extension $900
Upgrade AWAE course materials to the latest version + 30 days lab time $99
Upgrade AWAE course materials to the latest version + 60 days lab time $299
Upgrade AWAE course materials to the latest version + 90 days lab time $499

1C

Отечественный 1С попал в этот список вовсе не по ошибке. Все же, мы живем в России и далеко не каждый IT-шник непременно стремится найти работу за рубежом. А у нас, как это ни странно, 1С используется повсеместно, и спецы в этой области, вполне предсказуемо, востребованы.

Ну и, разнообразия ради, этому списку не помешает хотя бы один российский вендор :). Сертификат «1С:Профессионал» будет являться официальным подтверждением того, что его владелец может эффективно использовать в своей работе весь спектр возможностей «1С:Бухгалтерия».

Сертификация на данный момент проводится по системам «1С:Предприятие 8» и «1С:Предприятие 7.7».
Официальная информация: www.1c.ru/prof/prof.htm

Information Systems Security Engineering Professional

The CISSP-ISSEP is an ideal credential for proving you know how to incorporate security into all facets of business operations.

This security engineering certification recognizes your keen ability to practically apply systems engineering principles and processes to develop secure systems. You have the knowledge and skills to incorporate security into projects, applications, business processes and all information systems.

The CISSP-ISSEP was developed in conjunction with the U.S. National Security Agency (NSA). It offers an invaluable tool for any systems security engineering professional.

Please Note: Effective November 13, 2020, the CISSP-ISSEP exam will be based on a new exam outline. The domains and their weights have changed. Please refer to our FAQs for details.

CISSP — стандарт профессионального мастерства

Сертификация CISSP, Certified Information Systems Security Professional, — это независимая и объективная мера профессионального опыта и знаний в профессии специалиста по информационной безопасности. Если Вы собираетесь строить карьеру в информационной безопасности, одной из наиболее видимых сегодня профессий, и если Вы имеете, по крайней мере, три года опыта работы в качестве специалиста по информационной безопасности, то диплом CISSP должен быть вашей следующей целью в профессиональной карьере.

Сегодня наличие диплома CISSP — ключевой критерий в процессе выбора специалистов для позиций, связанных с информационной безопасностью, новых назначений и продвижений. Сертификация CISSP дает Вам много преимуществ как специалисту. Достигнув звания CISSP:

  • Вы показываете, что отвечаете глобально принятому профессиональному и этическому стандарту
  • Вы признаны как профессионал, строящий карьеру в области информационной защиты
  • Вы значительно увеличиваете возможности для Вашей карьеры
  • Вы продемонстрировали знание и компетентность в 10 областях (доменах) «Общепринятого объема знаний» (Common Body of Knowledge, CBK)
  • Вы обладаете всемирно признанным дипломом

Вашей организации также очень выгодна сертификация своих специалистов как CISSP. Организации, укомплектованные CISSP, получают преимущество перед конкурентами. Т.к

специалисты, защищающие их данные — лучшие в своей области, то эти организации демонстрируют клиентам, поставщикам и своим служащим важность и значение, которые они придают безопасности. Также, квалификация CISSP означает, что штат по информационным технологиям должным образом и согласованно профессионально обучен и подготовлен

Требования к претендентам на звание CISSP строги. Чтобы стать CISSP, Вы должны иметь не менее пяти полных лет работы непосредственно в качестве специалиста по информационной безопасности систем в двух или более из 10 областей CBK:

  • Управление доступом
  • Безопасность приложений
  • Планирование непрерывности бизнеса и восстановления в случае чрезвычайной ситуации
  • Криптография
  • Управление рисками и безопасностью информационных систем
  • Законодательство, регулирование, соответствие и расследования
  • Безопасность операций
  • Физическая защита от воздействий окружающей среды
  • Архитектура и построение безопасности
  • Безопасность телекоммуникаций и сетей

Допуск к сертификации CISSP осуществляется на основании Вашего опыта работы. Далее, для того, чтобы получить Ваш диплом CISSP, Вы должны подписать кодекс этики ISC2, и сдать экзамен разработанный для проверки Ваших знаний в 10 доменах CBK. Уровень знаний, требуемых для успешной сдачи экзамена, весьма высок. Экзамен проходит в течение шести часов, и состоит из 250 вопросов, на каждый из которых возможны четыре варианта ответа (правильным является только один из вариантов). Впоследствии Вы должны поддерживать вашу квалификацию CISSP, получая не менее 120 единиц продолжающегося профессионального обучения (Continued Professional Education, CPE) в течение каждых последующих трех лет.

Для подготовки к экзамену CISSP Вам стоит принять участие в специальном подготовительном учебно-консультационном семинаре. Подробнее о семинаре Вы можете прочитать здесь.

Стоит ли становиться сертифицированным специалистом?

Предложение/спрос

В сети Linkedin, к которой сейчас довольно ограниченный доступ, можно найти 50 аккаунтов российских пользователей с сертификатами CISA, 31 — c CISSP и 9 — c CISM.

Пролистывая профили пользователей, указавших данные сертификаты, можно увидеть, что их обладатели, как правило, занимают руководящие должности в крупных компаниях, многие задействованы в консалтинговой сфере (BIG4, ИТ-интеграторы и т.п.)

CISSP

CISA

CISM

Количество открытых вакансий

41

47

26

Распределение

по регионам

Россия 33

Москва 29

Украина 4

Киев 4

Беларусь 2

Минск 2

Санкт-Петербург 2

Казахстан 1

Астана 1

Республика Алтай 1

Самарская область 1

Другие страны 1

США 1

Россия 34

Москва 33

Украина 8

Киев 8

Беларусь 3

Минск 3

Казахстан 2

Астана 1

Алматы 1

Республика Алтай 1

Россия 16

Москва 15

Украина 5

Киев 5

Беларусь 3

Минск 3

Казахстан 2

Астана 1

Алматы 1

Республика Алтай 1

Уровни заработной платы

Указана 8

от 195 000 руб — 3

от 310 000 руб.- 2

от 370 000 руб.- 1

Указана 4

от 195 000 руб. – 1

Указана 2

от 125 000 руб. 1

Очевидно, что в основном такие специалисты востребованы в крупных городах и в особенности в столицах. Уровень зарплат достойный, но, конечно, же зарплату платят не за наличие сертификата, а за работу.

Анализируя эти данные нужно также помнить, что руководящие должности в крупных организациях часто замещаются без публикации вакансий. Поэтому реальный спрос на таких специалистов несколько выше.

Вопросы для оценки необходимости стать сертифицированным специалистом

Давайте сведем в один список вопросы, ответы на которые позволят специалистам в области ИБ решить насколько им необходима сертификация.

У меня получился такой «аудиторский» чеклист:

  1. Обладаете высшим техническим образованием в ИТ-сфере и средний балл не ниже 4?
  2. На работе занимаетесь проектами по большинству тем экзамена?
  3. Без словаря читаете английские статьи на профессиональные темы?
  4. Есть желание двигаться по карьерной лестнице вверх?
  5. Будет время готовиться вечерами и сможете взять несколько дней отгула перед экзаменом?
  6. Хоть немного ощущаете себя настоящим менеджером?
  7. Готовы к тому, чтобы жить и работать в столице?

Если на большинство вопросов у вас положительный ответ, то определенно стоит ввязаться в это дело, подготовиться, сдать экзамен(ы), а затем постоянно поддерживать свои знания на достойном уровне.

Certification Process

Once you’ve completed PWK and practiced your skills in the labs, you’re ready to take the certification exam. OSCP is a foundational penetration testing certification, intended for those seeking a step up in their skills and career.

The OSCP exam has a 24-hour time limit and consists of a hands-on penetration test in our isolated VPN network. You’ll receive the exam and connectivity instructions for an isolated network for which you have no prior knowledge or exposure. Points are awarded for each compromised host, based on their difficulty and level of access obtained.

You must submit a comprehensive penetration test report as part of your exam. Reports should contain in-depth notes and screenshots detailing your findings. This exam is proctored.

Real-world Benefits

A passing exam grade will declare you an Offensive Security Certified Professional (OSCP). The OSCP certification is well-known, respected, and required for many top cybersecurity positions.

Certified OSCPs are able to identify existing vulnerabilities and execute organized attacks in a controlled and focused manner. They can leverage or modify existing exploit code to their advantage, perform network pivoting and data exfiltration, and compromise systems due to poor configurations.

Preparing for PWK

The best way to prepare for the OSCP exam is to take PWK, with time in the labs to tackle as many of the machines as possible. To prepare for and get the most out of PWK, start by getting comfortable with Kali Linux. We offer a free Kali training course, Kali Linux Revealed, for those who are new to the platform. 

Other prerequisites include a solid understanding of TCP/IP networking and reasonable Windows and Linux administration experience. Familiarity of Bash scripting with basic Python or Perl a plus.

Labs

The PWK labs are a standalone network environment. You may safely and legally practice your skills within the labs. Students using the new version of PWK should use the VM recommended here: https://support.offensive-security.com/kali-vm/

Students on the previous version of PWK should use the VM recommended here: https://support.offensive-security.com/pwk-kali-vm/

Lab time begins on your course starting date, at the same time you receive your course materials. Lab time is counted in consecutive days and is measured by the number of days you have purchased.

OSCP course

The course leading up to the OSCP certification was first offered in 2006 under the name «Offensive Security 101». Students expecting a 101 course were not prepared for the level of effort the course requires, so the name was changed to «Pentesting With BackTrack» in December 2008, and again to «Penetration Testing With Kali Linux» when the BackTrack distribution was rebuilt as Kali.

The course covers common attack vectors used during penetration tests and audit. The course is offered in two formats, either online or live «instructor led» classes. The online course is a package consisting of videos, a PDF, lab assignments and lab access. The instructor led course is intensive live training covering the same material, also with lab access. The labs are accessible via a high speed internet connection, and contain a variety of operating systems and network devices where the students perform their assignments.

What about students who purchased prior to the update?

Both versions of the PWK course prepare you for the exam. The change in course material will not make the exam any harder than it already was, so you will have just as much of a chance to pass as you did before the update.

Students who want to access the new course material have two choices:

  1. Purchase an upgrade to receive the new PWK materials and lab access (paying the upgrade price, not the full course price).
  2. Continue with the previous version of the course materials and labs.

If you choose to upgrade, you can do so at any time. Please visit our for more details.

Vouchers: Students who redeem a voucher after the update is live will receive access to the updated PWK course material and the new lab environment.

Extensions: As noted above, lab extensions no longer come with an exam attempt. If you have already purchased the course and 30, 60, or 90 days of lab time, you will have one exam attempt. Further attempts will require you to purchase a retake.

Please note that this applies to all courses, not just PWK.

But What About My Privacy?

We are really excited about this new safeguard being deployed. We firmly believe that there is no point in having a tough exam you have to sweat over if the integrity of the exam is not such that it can’t prevent cheaters. This new online proctoring solution will go a long way in helping to maintain that integrity.

We encourage anyone who has questions or concerns about this new proctoring initiative to contact us and ask questions regarding this matter. Our updated privacy policy covers more details about the proctors, the proctoring data collected, and our data retention policy and is up to date with the latest concerns following the rollout of GDPR.

Offensive Security Certified Professional (OSCP)

The flagship OSCP certification could be considered one of the most valuable bullet points a penetration tester could put on their resume. To be recognized as an Offensive Security Certified Professional, the student must complete a 24 hour lab exam which will put their understanding of pen test methodology to the ultimate test. The journey is very rewarding even for experienced penetration testers, but it is only the beginning!

Penetration Testing With Kali

The PWK course is the prerequisite training for the OSCP certification. While anyone can sign up for this course, a solid understanding of TCP/IP, networking, and reasonable Linux skills are definitely required. Experience with Bash scripting and python will help greatly as well. During this course you will be given access to a student lab network to hone your enumeration and exploitation skills. Take advantage of this lab time as much as you can. I personally recommend purchasing 90 days of lab time right off the bat when signing up for this course. It might seem like a lot, but it is worth every penny. The lab is very well thought out, and designed to challenge you at all levels on your journey to OSCP. Not to mention it’s actually pretty fun. The adrenaline rush of finally getting root on a machine you’ve been stuck on for days is something you will eventually miss once you’ve completed the course. No matter how frustrated you get in the lab, you will appreciate every moment of it once you’ve completed the journey! The PWK course also includes several hours of video training, as well as a PDF document. You will learn the very basic fundamentals expected of a successful penetration tester such as:

  • Passive/Active Information Gathering
  • Vulnerability Scanning
  • Buffer Overflow Basics
  • Working with Exploits
  • Data Exfiltration Fundamentals
  • Privilege Escalation
  • Client Side Attacks
  • Web Application Attacks
  • Password Attacks
  • Pivoting
  • Metasploit Framework

The OSCP Exam

The OSCP exam is a 24 hour lab based exam which will test your technical skills as well as your time management skills. The student is expected to exploit a number of machines and obtain proof files from the targets in order to gain points. There are 100 possible points on the exam, 70 are required to pass. None of the machines on the exam are unreasonably difficult, but you must avoid falling into rabbit holes. If something seems overly complicated, you may want to step back for a moment and enumerate the target again. The real challenge in this exam is managing your time effectively. Ensure you plan to take breaks for meals, and to clear your head when you feel stuck.

One critical skill I will emphasize is note taking. You will be expected to document your path to success in the form of a professional penetration test report. You are given an additional 24 hours after the exam to prepare and submit the report. This will be much easier if you take good notes during the exam. I suggest reviewing the exam guide in advance to ensure you understand what is expected. Offensive Security also provides a template that you can use for your report, I suggest using this. During my exam I used a note taking application (CherryTree). I would create a page for each exam machine, and sub pages under that for each of the sections in the exam report template. I also added sub pages for my scan results, and any console output I wanted to save. Doing this for each machine will help ensure you don’t forget anything while writing the report. Find a note structure that works best for you, and stay organized.

This exam can get frustrating if you don’t manage your time well. My advice would be to practice multitasking. For example, when looking closely at one machine, try to have scans running in the background against other machines. Combine this with good note taking skills and you’ve got a solid foundation to manage this exam!

Helpful OSCP Links

Below are some links to articles I found helpful during my OSCP journey:

  • Penetration Testing with Kali Linux Reporting
  • OSCP Certification Exam Guide
  • Offensive Security Forums
  • Windows Privilege Escalation Fundamentals
  • SQL Injection Cheat Sheet
  • Reverse Shell Cheat Sheet
  • Spawning a TTY Shell
  • Basic Linux Privilege Escalation

Как подготовиться?

Шаг 1. Где я?

Выяснить в чем хорошо разбираетесь, а в чем не очень. Просмотреть вопросы по всем доменам или пройти пробные тесты. Определить какие домены для вас легкие, а по каким нужно «прокачаться».

Шаг 2. Что с английским?

Оцените, хватает ли ваших знаний английского для понимания вопросов и предлагаемых ответов, если нет, включите в свой план подготовки английский язык.

Шаг 3. Добывание и изучение учебных материалов

Базы вопросов

Можно легко найти и приобрести базы вопросов для подготовки к экзаменам, как официальные от ISC2 и ISACA, так и от сторонних вендоров. Базы вопросов могут быть как в виде программ для тестирования, так в виде учебников. Очень полезный материал, позволяющий постоянно оценивать свою готовность к экзамену. Только не рассчитывайте увидеть точно такие же вопросы на самих экзаменах, поэтому заучивать вопросы и ответы наизусть – бесполезная трата времени.

Курсы подготовки

Стоит ли идти на специализированные курсы? Стоит, если хотите сразу за пару дней погрузиться в тематику экзамена и увидеть всю картину в целом. Нужно понимать, что никакой курс не заменит самостоятельное чтение книг и решение пробных тестов.

Длительность этой фазы подготовки, если ни одного подобного экзамена ранее не сдавали, 3-4 месяца (в среднем по часу в день), если опыт успешной сдачи есть и уровень знаний высок, то срок может быть сокращен и до недели (разумеется, в режиме полного погружения).

Как правило, подготовка к экзамену растягивается на длительный срок и в конце можно немножко подзабыть, что изучали вначале. Поэтому целесообразно взять несколько дней отгула перед экзаменом, чтобы пролистать целиком свои материалы. В любом случае, в конце подготовки придется уделить пару дней для зубрежки отдельных технических параметров.

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *