CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingThe roles a CEH certification realistically opens — SOC analyst, penetration tester, consultant — and the logical next certifications at each fork.

A common mistake with the Certified Ethical Hacker (CEH) is treating it as a destination. It is a junction. Nobody's job title is "certified ethical hacker"; the credential's real function is to move you from adjacent IT work — or from study — onto one of several distinct security tracks, each with its own day-to-day reality and its own logical next certification. Plan the track before you sit the exam, and the certification does far more for you.
This article maps those tracks: the roles CEH plausibly opens, what each actually involves, and what to earn next at each fork. It deliberately avoids two neighbouring questions with their own dedicated answers: whether the credential justifies its price (is CEH worth it in 2026?) and what CEH holders earn (the CEH salary guide).
EC-Council's CEH — currently v13, with AI-driven techniques woven through the curriculum — is a broad, vendor-neutral knowledge credential: 125 multiple-choice questions covering attack techniques, tools and methodology across the whole offensive landscape. Eligibility itself hints at its career position: candidates need either official EC-Council training or two years of information-security work experience plus a $100 application. In other words, EC-Council positions CEH as an early-to-mid-career credential — a bridge out of general IT or junior security work, not an entry ticket for complete beginners and not a specialist's capstone.
That breadth is exactly why it forks. A survey of every attack category qualifies you to start in several directions at once; it makes you a finished specialist in none. Three tracks absorb most CEH holders.
The least advertised and most common landing spot for new CEH holders is blue-team work. Security operations centres (SOCs) hire people who understand how attacks unfold, because you cannot triage an alert well without recognising the technique behind it. CEH's catalogue of attack methods maps directly onto that need.
Typical roles on this track: SOC analyst, security analyst, threat detection analyst, incident responder. The work is monitoring, triage, investigation and escalation — reading logs and alerts through an attacker-literate lens. For candidates coming from helpdesk, networking or system administration, this is usually the most accessible first security job, because SOC teams hire at volume and value exactly the broad recognition-level knowledge CEH certifies.
Next steps on this track. Within EC-Council's own catalogue, the Certified SOC Analyst credential targets this role directly, and the Certified Incident Handler (212-89) formalises the escalation side of the job; ExamPractice hosts practice questions for both the Certified SOC Analyst exam and the Certified Incident Handler exam. Deeper along the defensive line, EC-Council's Certified Network Defender (CND) covers network protection, and its Computer Hacking Forensic Investigator (CHFI) turns incident response into a forensics specialism. A realistic progression: SOC analyst for eighteen months to two years, then a fork of your own between detection engineering, incident response and forensics.
This is the track most people picture. Penetration testers are paid to attack systems with permission: scoping engagements, enumerating targets, exploiting weaknesses and writing reports clients can act on. Consultancies and in-house red teams both hire for it.
Be clear-eyed about CEH's role here: it gets you the vocabulary, the methodology and — importantly — past HR screening into interviews, but offensive hiring managers want demonstrated hands-on skill. On this track, CEH is the opener, not the argument.
Next steps on this track. Three moves, roughly in order:
A scenario makes the sequencing concrete. A systems administrator with three years' experience passes CEH, spends six months on lab platforms while applying for junior consultancy roles, lands one on the strength of CEH-plus-lab-evidence, then pursues OSCP in the first year on the job — often at the employer's expense. That order (credential → evidence → job → OSCP) is usually faster than trying to stack every certification before applying.
Not every CEH holder wants to live in a terminal or a SOC queue. A third population uses CEH's breadth where breadth is itself the job: security consultants who advise rather than exploit, vulnerability assessment analysts, security auditors, and IT professionals folding security into architecture or management responsibilities. In these roles, CEH's value is credibility across the whole attack surface — being conversant with every category of threat when talking to clients, auditors or boards.
Next steps on this track. Depth here means governance and scale rather than exploitation. EC-Council's own ceiling for this line is the Certified CISO programme for security leadership — Certified CISO practice questions are available on ExamPractice — while broader management credentials from other bodies also sit naturally after CEH for candidates heading toward strategy and leadership rather than hands-on work.
If the fork itself is the hard part, these three questions usually settle it.
Note what is not on the list: salary. Pay differs by track, region and seniority in ways that deserve sourced figures rather than folklore — that evidence lives in the CEH salary guide.
Whichever track you choose, CEH travels with you on a maintenance schedule. The certification is valid for three years under EC-Council's Continuing Education (ECE) scheme; holders log continuing-education credits (widely reported as 120 per three-year cycle, alongside an annual membership fee — confirm current terms with EC-Council, as these details come from secondary guides). The practical career implication: activities you should be doing anyway — training, conferences, further certifications — count toward renewal, so a well-planned track keeps CEH current as a side effect. Letting it lapse mid-career mostly costs you the HR-recognition value you originally paid for.
One more maintenance note for the exam itself: if you are still at the preparation stage, timed practice questions that expose weak domains beat re-reading notes — see how to prepare for the CEH exam for the full plan.
Realistically: SOC analyst, junior security analyst, vulnerability assessment analyst and similar entry-level defensive roles — especially if you have adjacent IT experience (helpdesk, networking, sysadmin) to pair with it. Direct entry to penetration testing with no experience and no lab evidence is uncommon; treat CEH as the interview-getter and hands-on proof as the interview-winner.
Only on the offensive track. Defensive and consulting careers progress perfectly well through detection, incident-response, forensics or governance credentials. OSCP is the standard next rung specifically for penetration-testing ambitions.
It keeps existing roles current rather than creating new titles. AI-assisted reconnaissance, vulnerability assessment and malware analysis now appear across SOC, testing and consulting work alike, so the v13 curriculum's AI thread is relevant on all three tracks — but employers advertise the same role names as before.
If you are moving within the defensive or breadth tracks, usually not — the knowledge credential plus role experience carries you. If you are pivoting to the offensive track without other hands-on evidence, CEH Master's practical exam is one of the cheapest credibility upgrades available to you, though EC-Council does not publish a standalone Practical price, so confirm costs directly.
Pick the track before the next purchase. If you are pre-exam, that choice shapes how you study — defensive candidates should linger on detection-relevant domains, offensive candidates on exploitation chains. If you already hold CEH, the fork decides your next credential: SOC and incident-handling certifications on the defensive line, hands-on labs and OSCP on the offensive line, governance and leadership programmes on the breadth line. The certification bought you the junction; the direction is yours to choose.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading