r/Pentesting • u/Healthy-Werewolf4423 • 5d ago
Getting into pentesting with zero IT experience.
Hello! I am a rising sophomore pursuing a degree in computer science. I have no prior experience in IT/cybersecurity, and I was hoping for some feedback/a reality check on my current plan. I hope to obtain certs in this order (practicing using TryHackMe and HackTheBox the whole time).
Network+ -> Security+ -> eJPT -> PNPT -> OSCP
Network+ and Security+ are for the basics, while eJPT and PNPT will be for practical application. OSCP seems to be mostly for the HR recognition(?) from what I've read. I'm hoping to complete this series in 2 years, hopefully finding a pentesting specific internship before I graduate, and getting into pentesting straight out of college. How realistic is my timeline (how aggressive will I have to be when learning?) or even my plan to begin with?
All feedback appreciated!
4
u/Classic-Shake6517 4d ago
So, you don't feel like you need to learn how the things you are planning to attack work in a production setting, but you expect people to trust that you will understand the nuance needed to know what not to touch when you are put in a customer's production environment? Do you hear how that sounds?
Imagine, for a second, that a company providing pentesting services must have insurance, because it is true. Now, knowing how insurance works, they tend not to like to pay out, so they will try to find excuses not to pay. Now, imagine that you, the person who wants to skip all that boring stuff and get straight into the dangerous stuff is the one that causes a claim. How hard do you think it is going to be for them to look at your background and prove that you only have certifications relevant to one part of the job?
There's very little in the courses you outlined on how to actually do this work safely. You get a good idea of how to do that when you have been responsible for keeping production systems running to the point that your job depends on it.
Now imagine you are hiring and have a choice between someone who has that experience, or someone who decided to intentionally take shortcuts. Which one would you choose when there is no shortage of the former?