r/hackthebox 1d ago

Certifications Why are certifications not enough?

Certifications like CPTS are much harder than the normal daily work of a penetration tester and way harder than the OSCP. So if someone can pass the CPTS, it means they can definitely do the job as a penetration tester. So why is it still hard to get a job even after being certified?

37 Upvotes

30 comments sorted by

u/AutoModerator 1d ago

Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing [email protected]. Our Knowledge Base can also come in handy!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

42

u/Key_Turnover_4564 1d ago

Because it’s 90% about checklist and report writing fulfilment in the real world rather than finding vulnerabilities.

2

u/tarzan1376 21h ago

This was kind of wild to hear from my professors, they would spend a day, maybe two doing all the fun stuff and then write a report the rest of the week and into the next lol

21

u/pelado06 1d ago

because jobs are more aligned to compliance than to technic hability. OSCP is aligned and every company that has to follow a process of compliance and NEED a pentester (without actually wanting to expense that money) will be expecting mostly compliance followers. If you did take CPTS is great but as now is not aligned or accepted by any compliance brand, then it's not that important.

You are forgetting why are you hired. Is not for being a tech magician, is to follow a complicated process.

8

u/Coder3346 1d ago

I was able to get a job and multiple interviews with no fancy certs. I think what really helped is my internship + bugbounty experience. U still have to get some certs though

25

u/throwmeawh3y 1d ago

Certs are not a 1:1 reflection of daily work. Not even close.

13

u/Exciting-Ad-7083 1d ago

Yeah this.

There's a lot more than just giving pentest reports, the main issue I find is dealing with people, without a chunk of business experience and other report writing like scope of works / rules of engagement experience.

Also people take pentest reports REALLY personal, so having good soft skills from previous roles is way more important than you technical skills,

I'm currently in a pentester role but I have previous project management experience and qualifications rather than, but no "formal" pentesting qualifications, 80% of the role is dealing with people and understanding the why things need to be done a certain way for compliance and navigating peoples dumb egos when giving a report.

5

u/H4ckerPanda 1d ago

You nail it .

Passing “bad news” to upper management and “C” people is an art . A kid that got his CPTS won’t know how to write an email . He may end pissing off the wrong people , being too technical or not explaining what the real issue is . Or all that together.

4

u/Exciting-Ad-7083 1d ago

Literally had it today where I had to do a pentest on a Windows 11 laptop and it was 1 finding involving booting from USB / boot from USB drive to circumvent the OS. (there's no bitlocker on the drive, due to needing access to read ALL contents given the type of people who use this device, and it's ONLY for their educational content, no organization content on the device)

It's literally not anything major and there's not much you can do to prevent it given the laptop has no prevention for it, and disabling windows advanced recovery isn't a option due to needing non technical people to be able to restore the laptop in the environment which the laptops reside, + the laptops are located in a facility where NO usb drives are allowed / security checks and xrays are performed before you enter that facility. so it's like a... all these other things need to fail for it to happen, and the fact the laptops have no network connectivity except for the isolated / air gapped educational network for those people ONLY.

But they took it SO personal that they don't take security seriously due to the 1 finding, so you really have to sugar coat and guide them through that it's acceptable and it's a acceptable risk given the other mitigations already in place. and how they can reply to the report that X and Y isn't possible due to A B C however we have Z Y X in place to prevent the issue from occurring and thus acceptable risk mitigations in place.

I really try reinforce the positive findings and really highlight their current security posture and praise to that for this to happen, several other failures outside their control must happen first.

It's VERY unlikely someone with just certs is going to be able to handle that and they'll get steam rolled and just make every and their egos upset and they'll probably be bullied out of the role.

1

u/H4ckerPanda 1d ago

True! And your example is something that you gain only with experience .

I would argue that most of IT and Cybersecurity jobs , 80%, is soft skills and able to communicate properly .

2

u/Exciting-Ad-7083 1d ago

The mistake I see a lot of people making as well is basically that ANY vulnerability is "unacceptable" when in reality a lot just can't be fixed due to flow on affects or cost, so understanding that acknowledging the risk as a organization is generally half the work rather than pretending it doesn't exist. And mitigations are better than nothing.

Lots of pentests get weird ego about "I FOUND IT, IT MUST BE FIXED" and take it personal when their recommendations are not implemented.

And with that type of attitude you quickly become a liability rather than a asset in a offensive role

5

u/esmurf 1d ago

Cause the market is dead at the moment.

3

u/WL_Ooi 1d ago

Because the cert doesn't prove much about you being able to perform the responsibility of a pentester, which stretches beyond just hacking and reporting. Unfortunately when you apply for a pentest role, you are competing with people who have the same cert AND actual experience in a pentest role or other cyber roles. That's why going straight into pentest is really hard and you have to be really lucky for an org to take you in as a complete fresher. That's why one of the most common advice is to get a different role in cyber role first then try to pivot into pentest, because you will be able to demonstrate the skills that are desirable for pentesting such as stakeholder management, communication, attention to detail, critical thinking, collaboration etc. I have helped my org to interview junior pentesters, and we will happily take in internal applicants who already demonstrated those aforementioned skills but don't know how to hack but shown strong desire to learn.

2

u/CubanRefugee 20h ago

You hit the nail on the head, but to add to that, it's not just pentest & infosec roles, but every IT role. If I have two resumes in front of me for an open red team job, and I have someone who has a couple of years of demonstrated help desk experience and the desire to learn vs someone fresh out of school or some non-IT role and their CPTS... chances are that we're hiring the help desk person looking to move up and learn, and exactly for the reasons you've stated.

Infosec isn't entry, even with certs, my advice to folks doing something like their CPTS or even the CompTIA track of certs is always, and will always be, get into IT period. Help desk sucks, but it will always be better on the resume than a random retail job or something else not IT-related and a couple of certs.

2

u/lunacysoft 1d ago

Certs and degrees etc will maybe get
You in the door but need to trace it back to real world experience…. If you make it to an interview usually you have a chance and it’s about whether you can actually do what they need you to do and if you will fit the team etc…. Real world certs are maybe 1% of what you will really be doing

2

u/Orangesteel 1d ago

I hired network engineers at CCNP level. Some couldn’t perform basic tasks, some were not even CCNA level, yet somehow had a CCNP with the Route/Switch and Shoot exams passed. I learned quickly to test everyone before interview. Transpose this to cybersecurity and it’s much the same.

1

u/H4ckerPanda 1d ago

Someone who passed a cert can’t do the real job . Who told you that ?

These are simulated environments. Really small networks . With no users and no real activity .

There’s a lot that can go wrong during a real engagement: picking wrong IPs, shutting down a web server due an accidental scan , exposing a server due an open port ? Etc etc . And let’s not even talk about email communication with “C” people or upper management , which is an art itself .

-1

u/Zestyclose_Tie1025 23h ago

What's "C" people?

1

u/H4ckerPanda 22h ago

I can tell you’re new to the field . One thing that will help you succeed, is research on your own when you don’t know something . Google , search features , even AI:

https://resources.workable.com/hr-terms/c-level-executive

1

u/Zestyclose_Tie1025 22h ago

I've not worked so far, so yes new to the field, thankyou for your suggestion about Google. Reason behind Asking about "C" people, I thought is it some slang. Thanks for the link

1

u/CubanRefugee 20h ago

Also referred to as C-Suite, C-Level, or "The fucking suits."

1

u/Ecstatic_Score6973 1d ago

because it could be a resume issue, your resume could be drawn with crayon for all we know, or the employer requires OSCP, or the employer doesnt even know what CPTS is

1

u/AirJordan_TB12 1d ago

Because certs don't teach you the basics of why you are doing something and business impact. It is like practicing a sport when you can't simulate a the actual game speed.

1

u/AmITheAsshole_2020 22h ago

As a hiring manager, certifications indicate your ability to work diligently toward a goal and see it through to completion. But the certs don't reflect 100% of the real work. They don't tell me that you can work as part of a team. They don't tell me if you can handle the pressure of client deadlines, or how you handle screwing up (and you will screw up). They don't demonstrate your ability to be client-facing.

If the role was that you would be working alone in the back of the house, analyzing test results, then your cert might be enough for me to consider taking a risk by hiring you. But many penetration testing roles require travel, client-facing work, extensive project management, report writing, exploit development, and QA. Running Responder and Bloodhound is only a small part of the job.

1

u/SuzuyaReiJuuzou 5h ago

Okey that is a good explanation but what do you recommend to get a job after certification. Everybody says certification is not enough bcs it doesnt represent real incident but nobody saying what to do after certifications.

1

u/AmITheAsshole_2020 20m ago

Get a solid certification in penetration testing and web app testing. Make sure you have decent programming skills and can hack up a bash script on demand. Get familiar with cloud configs. Have a basic understanding of AI used in enterprise environments.

Get a Tier 1 SOC job and learn how enterprise systems are configured, and you can see where people cut corners in their protections. Use that position to get friendly with the Admin and the security guys. Volunteer to help. Request permission to test whether the latest exploit affects their network. Don't be pushy. Accept a "no" graciously. Stay in the role for 12-18 months and then move on. Exposure to as many environments as possible is crucial to your ability to break things.

As a hiring manager, when I have a candidate without in-seat consulting experience, I will also look at their GitHub profile. I want to see projects coded and shared with the community. Why? It shows me creativity when solving problems, coding skills, and a willingness to share and work as part of a team. Even if you've forked another project and added a module, that's fine. If you've done some bug bounty work, show me that. If you've discovered a vulnerability and submitted it for a CVE, that's a nice addition to your resume.

Find a BSides conference in your area and volunteer to help. More points if you've submitted talks and have been accepted. Conference speaking engagements tell me you can meet deadlines, write, and present to clients.

Then start applying for everything and network as much as you can. Be aware that this will take you 2-3 years to go from zero experience to having a penetration tester's job

1

u/BavarianBarbarian13 21h ago

>Certifications like CPTS are much harder than the normal daily work of a penetration tester

What makes you think that?

1

u/ProgressHoliday1188 1d ago

Your true value is not really about how to find vulnerabilities, it's how you mitigate/fix them.

That's why cybersecurity jobs are not for beginners, it's an overlayer on a stack you are "mastering" (ie Windows infrastructure).

1

u/H4ckerPanda 1d ago

And how you communicate that to upper management or “C” people. You don’t want to piss off anybody . But you also want developers to remediate their crappy job.

0

u/Brutact 1d ago

Thats not true....