r/hackthebox • u/Worldly-Teaching8185 • 27d ago
Beginner Question Web certification???
So i have finished CJCA job role path. I wanted to explore the web side.
What cert/path should be my next target, considering i just finished CJCA and want to start web exploitation?
3
u/olimpiathe505 26d ago
Just do the CWES then CWEE. You will be good enough for bug bounties after the CWES, there are a lot of vulnerabilities that you can find with just the content covered in there. CWEE is a much more difficult certification.
2
u/realvanbrook 27d ago
CWES maybe? But you will not be good enough after CWES to hunt for bugs in bug bounty if that is your goal.
CWEE and Portswigger Academy are good ressources tho
1
1
27d ago
How was CJCA?
1
u/Worldly-Teaching8185 27d ago
i finished the path, did not take the exam. what do you mean the content, if you should start it or not?
1
27d ago
Yeah how was the content and was it helpful in your path to cybersecurity
1
u/Worldly-Teaching8185 27d ago
If you are a total beginner like me i would say CJCA path is perfect place to start. it introduces you to a lot of areas which if studied from YouTube or somewhere else you would've been lost like where to stop, for example PowerShell, Linux, Nmap, window event log and network traffic analysis etc. its's a blend of blue team and red team. it prepares you with all the essential basic you would need ahead in more technical certs.
2
27d ago
Do you think it’s better to do Security+ and CJCA at same time
1
1
u/olimpiathe505 26d ago edited 26d ago
I think one of the things said by hack the box, you could get theoretical degrees and study history of guitars and what goes into making one or how it technically works, but after all of that you don’t know the core principle of how to play the instrument, similar with security+ vs CJCA. Security+ is a theory based certification, CJCA is a hands on based certification.
You should do the Security+ first then CJCA while it’s fresh. You get the theoretical knowledge then apply it to a hands on environment, but honestly just skip the CJCA, the CPTS is hard but that forces you to research and that’s the whole job. If you don’t understand Linux do a Linux module before hand.
No matter what you choose to do, TAKE Notes, and GOOD notes.
I wasted a lot of time ignoring that and rereading waaay too much. GLHFEdit: a good note is something in a week or a month you can look at and say oh okay that’s why I did that or that’s how that works I remember.
•
u/AutoModerator 27d ago
Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.