CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingIs OSCP harder than CEH? A rigour-by-rigour comparison of exam formats, hands-on demand and where each sits on the penetration testing ladder.

A persistent myth puts the Certified Ethical Hacker (CEH) and the Offensive Security Certified Professional (OSCP) on the same rung of the certification ladder — two interchangeable "ethical hacking certs" that differ mainly in branding. They are not on the same rung. They are not even the same kind of ladder-climbing: one tests whether you can answer questions about attacks, the other tests whether you can execute them against live machines for 24 hours.
Short answer: OSCP is the more advanced credential, and it is not close. CEH's core exam is a four-hour, 125-question multiple-choice test of breadth; OSCP is a 24-hour proctored hands-on exam in which you must actually compromise three standalone machines and an Active Directory set, then write a professional report. In hands-on demand, preparation depth and the level of practitioner it certifies, OSCP sits one to two rungs above CEH. That does not make CEH pointless — it occupies a genuinely different, earlier position on the ladder, and this article maps exactly how far apart the two sit and what the gap means for your progression.
One boundary note: this piece measures the rigour gap. If your question is instead "which one should I buy first, given cost and employer recognition?", that buyer's decision has its own dedicated comparison in OSCP vs CEH.
| Factor | CEH (EC-Council) | OSCP (OffSec) |
|---|---|---|
| Exam format | 125 multiple-choice questions, 4 hours (ECC Exam Portal or Pearson VUE); optional 6-hour, 20-challenge CEH Practical for CEH Master | Hands-on 24-hour proctored exam in a private VPN, plus professional report |
| What passing proves | Recognition and recall of attack concepts, tools and scenarios across a broad syllabus | Demonstrated exploitation: initial access, privilege escalation and Active Directory compromise under time pressure |
| Passing mark | Banded cut score of 60%–85% depending on question form (no single fixed mark) | 70/100 points — 60 from three standalone machines, 40 from an AD set with partial credit; no bonus points since Nov 2024 |
| Prerequisites | Official training, or eligibility application ($100) with 2 years' infosec experience | None formal; OffSec recommends solid TCP/IP, Windows/Linux administration and basic Bash/Python |
| Cost (2026, USD) | Exam voucher $1,199 (Pearson VUE) or $950 (ECC portal); training bundles listed "starting at" $1,699–$3,499 | $1,749 Course & Cert bundle (90 days + 1 attempt); $2,749/yr Learn One (2 attempts); $1,699 exam-only |
| Difficulty character | Breadth and terminology under moderate time pressure | Depth, methodology and endurance under extreme time pressure |
| Renewal | 3-year ECE cycle (continuing-education credits and membership requirements apply) | Plain OSCP never expires; the OSCP+ designation lasts 3 years |
| Best for | Building and evidencing broad ethical-hacking knowledge early in a security career | Certifying job-ready practical penetration testing skill |
| Typical career stage | Entry to early-intermediate; HR-recognised generalist credential | Intermediate practitioner gate into hands-on offensive roles |
Every row above points the same direction on advancement. Now the substance behind the rows.
Start with the four hours versus twenty-four, because the formats are the honest measure of level.
CEH's knowledge exam (312-50, currently v13 — marketed as "CEH AI", with AI-driven techniques woven into the existing exam rather than a separate test) presents 125 multiple-choice questions in four hours. That is roughly two minutes a question to recognise the right tool, port, technique or countermeasure. The syllabus is wide — reconnaissance through web attacks, wireless, cloud and malware — but the cognitive act is selection among presented options. EC-Council scores it on a banded cut score of 60%–85% depending on the difficulty of the form you draw; the often-repeated "70% to pass" is simply wrong. EC-Council does offer a hands-on extension — the optional six-hour, 20-challenge CEH Practical on its iLabs Cyber Range, which combined with the knowledge exam earns CEH Master — and that variant narrows the format gap without closing it.
OSCP's exam gives you nothing to select from. You connect to a private VPN under webcam proctoring and face real machines: three standalone targets worth 60 points across initial access and privilege escalation, and an Active Directory set worth 40 points with partial credit. You need 70 of 100, and since 1 November 2024 there are no bonus points from coursework — the score is exam performance alone. When the 24 hours end, you still owe OffSec a professional penetration test report. A blank terminal for a full day is a categorically different examination of skill than a question bank for an afternoon.
The endurance dimension deserves its own sentence: managing energy, panic and time across 24 hours is itself an advanced professional skill, and OSCP examines it deliberately. The full anatomy of that ordeal is covered in how hard the OSCP exam is; CEH's difficulty profile — real, but of a different species — is dissected in how hard the CEH exam is.
Advancement level also shows in what it takes to arrive ready.
CEH preparation is fundamentally study: EC-Council's official training, or self-study backed by the $100 eligibility application and two years of information-security experience. The material rewards structured revision — learn the domains, drill terminology, practise question interpretation. A disciplined candidate with security fundamentals can prepare around a full-time job in a bounded, predictable way, and practice questions map naturally onto the exam's format. (A structured plan lives in our sibling guide on preparing for the CEH exam.)
OSCP preparation is fundamentally training, in the athletic sense. The PEN-200 course lists over 320 hours of content across 20+ modules — enumeration, exploitation, web attacks, privilege escalation, Active Directory — and the course is consumed by doing: labs, machines, notes, repetition until methodology becomes reflex. OffSec sets no formal prerequisites but recommends solid TCP/IP networking, Windows and Linux administration, and basic Bash or Python scripting before you start — a baseline that already approximates the level CEH certifies at. Neither vendor publishes official study-hour requirements and you should ignore anyone quoting guarantees, but the qualitative gap is stable across every honest account: CEH readiness is measured in revision weeks, OSCP readiness in lab months.
That asymmetry is the cleanest single statement of the level difference: the recommended starting point for OSCP looks a lot like the finishing point of CEH.
Advanced-ness is partly social: what does each credential license its holder to claim?
CEH's strength is institutional breadth. It is one of the most widely recognised security certification names among recruiters and HR systems, and it is commonly cited in US government-adjacent hiring contexts (specific DoD workforce-framework category mappings change, so verify current mappings on official channels rather than assuming). A CEH on a CV says: this person has covered the ethical-hacking landscape and cleared a formal, proctored bar. It functions best as a gateway and filter-passing credential.
OSCP's strength is practitioner credibility. Technical interviewers and offensive security teams treat it as evidence that the holder has actually done the work, because the exam cannot be passed any other way. Job adverts for penetration testing roles cite OSCP precisely where the hiring manager, not the HR system, wrote the requirements. An OSCP on a CV says: this person broke into machines under pressure and documented it professionally.
Those are different claims at different levels, which is why the certifications coexist rather than compete head-on. Whether either is worth its price for you personally is out of scope here — see is CEH worth it in 2026 and is OSCP worth it for those verdicts, and the OSCP career path and salary guide for what the more advanced credential opens up afterwards.
A fair calibration, kept deliberately qualitative because neither vendor publishes pass rates:
Net position: think of CEH as certifying the end of the beginner stage and OSCP as certifying the beginning of the practitioner stage, with roughly one full stage of skill-building between them for most people.
Taking CEH first suits people who need its specific strengths early: a recognised name for HR filters while job-hunting, a structured tour of the whole attack landscape before specialising, or an employer/government context that values EC-Council credentials. In that sequence CEH is the map and OSCP is the terrain: the conceptual breadth genuinely helps you know what exists before PEN-200 forces you to execute a subset of it deeply. The wasted-overlap cost is modest, because the two exams test such different faculties that little CEH revision is "spent" again on OSCP.
If you already hold security fundamentals from experience or other study, and your target is hands-on penetration testing, nothing in CEH is a prerequisite for PEN-200 — OffSec sets none. Candidates comfortable at a Linux command line, fluent in networking and able to script can treat OSCP as the direct route and let its preparation supply the depth. The trade-off is arriving at job applications without the HR-recognised generalist name; whether that matters depends on the employers you are targeting, which is the buyer's-decision territory of the OSCP vs CEH comparison.
Sequence-wise this looks backwards, and for skill development it is. It occurs in practice for institutional reasons — an employer or contract that names CEH specifically. Treat it as a compliance purchase, not advancement.
The gap between the rungs is exactly where candidates get hurt — buying OSCP lab time they cannot yet use. Before committing, you should be able to answer yes to most of these: comfortable administering both Windows and Linux; able to explain and use core protocols without notes; able to read and modify a Bash or Python script; already practising on deliberately vulnerable machines rather than only reading about them. If several answers are no, the honest move is a bridging period, not a bigger study plan for the same exam date. Structured self-testing helps you locate that line: working through timed question sets on security fundamentals exposes weak domains cheaply, and ExamPractice's EC-Council exam pages offer free sample questions per exam, with fuller sets and a timed simulation mode for subscribers. Use them to test understanding of objectives — memorising answers would defeat the entire purpose of climbing towards a hands-on exam.
OSCP is the more advanced certification by every rigour measure that matters — format, depth, preparation load and the level of professional it certifies — while CEH remains broader in syllabus and earlier in purpose. Placed correctly on one ladder: CEH certifies that you have surveyed offensive security and cleared a formal knowledge bar; OSCP certifies that you can practise it. Choose your next exam by the rung you are actually standing on: if you are still building fundamentals and breadth, CEH-level study (or equivalent) is the honest next step; if you can already operate at the command line and want to be hired for hands-on work, aim at OSCP and give it the months it demands. The ladder rewards climbers who do not skip rungs — and does not punish those who start on the first one.
Yes, though the gap narrows. CEH Master adds the six-hour, 20-challenge Practical to the knowledge exam, which introduces genuine hands-on pressure — but it remains challenge-based and a quarter of OSCP's duration, without the full compromise-and-report cycle.
No. OffSec sets no formal prerequisites for PEN-200; it recommends networking, Windows/Linux administration and basic scripting. CEH can supply useful conceptual breadth but is neither required nor assumed.
Almost certainly not without substantial additional lab practice. CEH certifies recognition of techniques; OSCP requires executing full attack chains. Plan a dedicated hands-on training period between the two.
Recognition systems differ from skill measures. CEH's long-standing name recognition and its citation in government-adjacent hiring frameworks make it the credential some HR templates specify, independent of technical depth.
OSCP, unambiguously — its exam is a simulated penetration test, scored on compromise and reporting. CEH covers penetration testing concepts within a broader ethical-hacking syllabus.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading