Certified Ethical Hacker

Certified Ethical Hacker

The Certified Ethical Hacker (C|EH) is a professional certification provided by the International Council of E-Commerce Consultants (EC-Council.)

An Ethical Hacker is one name given to a Penetration Tester. An ethical hacker is usually employed by an organization who trusts him or her to attempt to penetrate networks and/or computer systems, using the same methods as a hacker, for the purpose of finding and fixing computer security vulnerabilities. Unauthorized hacking (i.e., gaining access to computer systems without prior authorization from the owner) is a crime in most countries, but penetration testing done by request of the owner of the targeted system(s) or network(s) is not.

A Certified Ethical Hacker has obtained a certification in how to look for the weaknesses and vulnerabilities in target systems and uses the same knowledge and tools as a hacker.

The exam code for C|EH is 312-50. The certification is in Version 7.1 as of 14 June 2011.

The EC-Council offers another certification, known as Certified Network Defense Architect (C|NDA). This certification is designed for United States Government Agencies, and is available only to members of selected agencies. Other than the name, the content of the course is exactly the same. The exam code for C|NDA is 312-99.[1]

To get a more detailed understanding of this process, see the Ethical Hack page.

Contents

Certification coursework

The coursework of version 7 contains 19 modules, which consists of instructor-led training and self-study. Some training centers, Western Governors University (http://www.wgu.edu/) in the US, and universities in Asia, and Europe include EC Council's C|EH program as part of their course modules.

Examination

Certification is achieved by taking the CEH examination after having either attended training at an ATC (Accredited Training Center) or done self-study. If a candidate opts for self-study, an application must be filled out and proof submitted of 2 years of relevant information security work experience. In case you do not have two years of information security related work experience, you can send them a request detailing your educational background and request for consideration on a case basis.[2] The current version of the C|EH is V6 uses EC-Council's exam 312-50, as did v5. Although the new version V7 has recently been launched.[3] This exam has 150 multiple-choice questions, a 4 hour time limit, and requires at least a score of 70% to pass.[4] The earlier v4 had 125 multiple-choice questions and a three hour time limit. The version 7 exam costs US$500 and the version 6 exam costs $250 (both with an additional $100 eligibility fee) in the United States (prices in other countries may differ),[2] and is administered via computer at an EC-Council Accredited Training Center, Pearson VUE, or Prometric testing center (in the United States).

Recertification

EC-Council Continuing Education (ECE) points serve to ensure that all certified professionals maintain and further their knowledge. Professionals must meet ECE requirements to avoid revocation of certification. Members holding the C|EH/C|NDA designation (as well as other EC-Council certifications) must recertify under this program every three years for a minimum of 120 credits (40 credits per year).

Controversy

Certain computer security professionals, such as Marcus J. Ranum, have objected to the term ethical hacker: "There's no such thing as an 'ethical hacker' - that's like saying 'ethical rapist' - it's a contradiction in terms."[5] Part of the controversy may arise from the older, less stigmatized, definition of hacker, which has since become synonymous with computer criminal.

On the other hand, some companies do not seem to mind the association. According to EC-Council, there has been an increase of careers where C|EH and other ethical hacking certifications are preferred or required.[6][7][8] Even the US government accepts this association and requires C|EH accreditation for some jobs per 8570 guidelines.[9]

Further reading

  • Graves, Kimberly; CEH Certified Ethical Hacker Study Guide, Wiley, John & Sons, Incorporated, 2010. ISBN 978-0470525203
  • Graves, Kimberly; Official Certified Ethical Hacker Review Guide, Sybex Publishing, 2006. ISBN 978-0782144376
  • Gregg, Michael; Certified Ethical Hacker Exam Prep, Que Publishing, 2006. ISBN 978-0789735317

References

External links


Wikimedia Foundation. 2010.

Игры ⚽ Нужна курсовая?

Look at other dictionaries:

  • Certified Ethical Hacker — es una certificación profesional promovida por el Consorcio Internacional de Consultas de Comercio Electrónico. Un hacker ético es el nombre adoptado para la realización de pruebas de penetración o intrusión a redes informáticas. Un hacker ético… …   Wikipedia Español

  • Hacker (desambiguación) — Hacker puede hacer referencia a alguno de estos artículos: Informática Hacker (informática), una descripción general de los diferentes tipos de hackers en la informática y las relaciones entre estos. Hacker (seguridad informática), una persona… …   Wikipedia Español

  • Hacker (seguridad informática) — Un wikipedista está trabajando actualmente en este artículo o sección. Es posible que a causa de ello haya lagunas de contenido o deficiencias de formato. Si quieres, puedes ayudar y editar, pero por favor: antes de realizar correcciones mayores… …   Wikipedia Español

  • Council of Registered Ethical Security Testers Certified Consultant — The CREST Certified Consultant certification is a professional certification provided by the [http://www.crest approved.org Council of Registered Ethical Security Testers (CREST)] .OverviewCREST Certified Consultants are highly skilled… …   Wikipedia

  • CEH — Certified Ethical Hacker (Computing » Security) * Continuing Education Hours (Community » Educational) * Comisión para el Esclaracimiento Histórico (International » Guatemalan) …   Abbreviations dictionary

  • CPTS — The Certified Penetration Testing Specialist (CPTS) is a professional certification provided by the Mile2 Organization.A Penetration Tester is one name given to an Ethical Hacker. A penetration tester is usually employed by an organization who… …   Wikipedia

  • International Council of Electronic Commerce Consultants — The International Council of Electronic Commerce Consultants (EC Council) is a member supported professional organization. The EC Council is headquartered in New York, NY.The EC Council is known primarily as a professional certification body. Its …   Wikipedia

  • Licensed Penetration Tester — The EC Council Licensed Penetration Tester (ELPT) is a professional certification provided by the International Council of Electronic Commerce Consultants.The Network Security Administrator is a secondary certification for the EC Council CEH and… …   Wikipedia

  • Seguridad de la información — Este artículo o sección necesita ser wikificado con un formato acorde a las convenciones de estilo. Por favor, edítalo para que las cumpla. Mientras tanto, no elimines este aviso. También puedes ayudar wikificando otros artículos o cambiando este …   Wikipedia Español

  • Information security professionalism — is the set of knowledge that people working in Information security and similar fields (Information Assurance and Computer security) should have and eventually demonstrate through certifications from well respected organizations. It also… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”