The Hacker's Cache
The show that decrypts the secrets of offensive cybersecurity, one byte at a time. Every week I invite you into the world of ethical hacking by interviewing leading offensive security practitioners. If you are a penetration tester, bug bounty hunter, red teamer, or blue teamer who wants to better understand the modern hacker mindset, whether you are new or experienced, this show is for you.
The Hacker's Cache
#85 Q&A: I Chose Higher Pay Over Stability... Here’s What It Cost Me
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Is higher pay worth sacrificing stability, purpose, and peace of mind? In this cybersecurity Q&A episode, I share why leaving the Air Force for higher-paying private-sector cybersecurity work came with tradeoffs I did not fully appreciate at the time. I also answer whether government and public-sector cybersecurity jobs offer better job satisfaction, explain how to ethically tailor your LinkedIn job title to match the work you actually perform, discuss my updated cloud certification plan as a Cloud Security Engineer, and lay out a practical beginner penetration testing roadmap using TryHackMe, CompTIA PenTest+, TCM Security certifications, and more. Whether you are choosing between public vs. private sector cybersecurity, trying to break into penetration testing, or planning your next cybersecurity certification, this episode gives you a realistic perspective on building a career that fits your goals.
Connect
---------------------------------------------------
https://www.KyserClark.com
https://www.KyserClark.com/Newsletter
https://youtube.com/KyserClark
https://www.linkedin.com/in/KyserClark
https://www.twitter.com/KyserClark
https://www.instagram/KyserClark
https://facebook.com/CyberKyser
https://twitch.tv/KyserClark_Cybersecurity
https://www.tiktok.com/@kyserclark
https://discord.gg/ZPQYdBV9YY
Music by Karl Casey @ White Bat Audio
Attention Listeners: This content is strictly for educational purposes, emphasizing ETHICAL and LEGAL hacking only. I do not, and will NEVER, condone the act of illegally hacking into computer systems and networks for any reason. My goal is to foster cybersecurity awareness and responsible digital behavior. Please behave responsibly and adhere to legal and ethical standards in your use of this information.
Opinions are my own and may not represent the positions of my employer.
Welcome to the Hacker's Cache, the show that decrypts the secrets of cybersecurity one byte at a time. I'm your host, Kyser Clark. And in this episode, I have another Q&A episode for you, where you, the viewer slash listener, ask questions and I answer them here on the Hacker's Cache podcast.
To submit questions, literally just drop a comment on any video. And if it's a good question, or if it's one of the better questions, I will feature it here on the podcast on one of my Q&A episodes, which happen roughly once a month, is what I'm aiming for. So without further ado, let's go ahead and dive into the first question.
So the first question is very simple. Someone had asked, so no cloud search? And this to give you some context, this is a question that was put on the last episode, where I was talking about how certifications doesn't automatically evolve your cybersecurity career, especially if you're someone like me with like 19 certifications later in your career, more certifications doesn't necessarily help you as much as they do in your early career and early career, they definitely absolutely help you out mid career for sure. And I'm still in my mid career.
But like, like I said, in that podcast episode, you know, I have 19 certification, what's one more going to do for me? So this person asked, so no cloud search? With like five question marks, actually. And then someone else on a different video on the one I talked about securing my new cloud security engineer position. So I asked, are you going to start hitting cloud search now? If so, what's the game plan? So here's my game plan when it comes to cloud certifications.
And I did say in that last episode, certifications later in your career, like at my point, eight years in 19 certifications deep now, doesn't automatically give me more raises or better opportunities, and doesn't involve my career as fast as it used to. But that doesn't mean I'm stopping getting certifications. I'm just slowing down.
I had mentioned that I am still interested in getting more certifications, but I'm not trying to crank them out as fast. And as frequent as I used to, I have less motivation to do it for reasons stated in the previous episode. And I'm really trying to enjoy my personal life more because to get these certifications, guys, you do need to spend a lot of time in your free time to obtain them, which is absolutely necessary if you're trying to break in, or even trying to get to level up.
But I had a point in my career where it's like, like I said, you know, going from 19 to 20 certifications, going from 20 to 25 certifications really isn't going to do a whole lot for me. And because of that, I'm just slowing down. However, I do want more certifications.
There are other certifications on my radar. I've talked about getting more AI certifications. That is interesting to me.
And now that I'm in a cloud role, cloud certifications are now interesting to me, especially since there are a lot of job openings that are cloud security minded. And having cloud certifications will absolutely help your career. And as someone who is a cloud security engineer, it's going to help me level up my current role, and maybe even other roles.
In fact, my next cloud certification, or yeah, because I have one cloud certification, I have the CompTIA Cloud Plus currently, which is vendor neutral, and kind of basic. I mean, it's not an easy certification by any means, but my company is going to be paying for some more certifications for me. In fact, my company gives a little bit of a bonus to acquire Microsoft certifications and Azure certifications.
So that's kind of where I'm going to be focusing because my company that I currently work for is not only encouraging me to get them, but also actively paying me to get them. Like I said, there's a bonus associated with those certifications if I attain them. So that motivates me a little bit, but the bonus isn't large enough for me to be like, let me nail this out.
In my opinion, it's a small bonus. I mean, maybe a medium-sized bonus, but it's not going to be a huge increase in my bank account, if you will. To me, it's a small bonus, which is nice.
I mean, a company that gets to give you a bonus, that's great. I'm not knocking it because that's great for people who want to go out and get the certifications. And like I said, it's going to make me go and get them, but I'm just going at a much slower rate than I used to.
I'm not trying to crank out a certification every other month now, or try to get five in one year. My goal used to be four in one year. Once at one a quarter, I think that's a pretty fair thing.
Now, maybe one a quarter, maybe just a couple a year at this point. If I can get a couple a year, I think that'd be pretty good rather than four, five, six a year. So there are clusters I want to get, and I'm going to focus on the Microsoft certs and the Azure certs because I work in an Azure environment.
And that's kind of where my thought process is. And because my company is actively giving me bonuses and encouraging me to get Microsoft and Azure certifications. And I'm pretty sure I only get bonuses if it's Microsoft certification.
So if I go get a different vendor certification, I'm pretty sure there's no bonus associated with that. I could be wrong on that. I haven't done into policy too much, but I'm pretty sure it's Microsoft only.
So that's kind of where I'm pointing my eyes at in terms of cloud certifications. I've talked about this several times in my videos, CCSP, the certified cloud security professional from ISE too. So that's one that's always been on my radar and it's even more on my radar now that I'm in a cloud role.
And I feel like cloud roles are very prominent in the industry right now in the job market. So having cloud skills, as I used to consider something that's nice to have, but it seems like over time, it's more of a need to have because cloud is everywhere and everyone wants a cloud. Engineer, cloud security engineer.
So cloud certs are very valuable these days. And I used to sleep on them, as you can tell, because I only have one CompTIA cloud certification and no other cloud certifications. But as I learn more about the industry, as things evolve, my plan and my certification that I want to get involved as well.
So there you go. So I'm going to give some context before I put in the next question here. So I was talking about you can change your titles on your resume in the last episode.
You can go back and watch the last episode to get the full context. But moral of the story is, if you accept a position at a company and it has a title associated with it, which you will always have a title associated with it, you don't have to put that title on your resume. And this person says, or they ask, what about the titles in LinkedIn? Let's say you've worked as an IT security administrator for a company, but have mainly done tasks like incident response, compliance policies, and tool security reviews.
Is it okay to change the title in LinkedIn to InfoSec Analyst to pursue such positions? That's a good question and absolutely 100%. Yes, you can do that. When I say you can change your title on your resume, you can also change your title on LinkedIn.
And I give the example of my current role. I had accepted a position as an Azure, I think Azure Administrator, Azure Security Administrator or something like that. And I just put Cloud Security Engineer.
That's what I changed it to on both LinkedIn and my resume. So you can absolutely do that. And I have no problem with you doing that.
That's not lying, because if you are doing those things, if you truly are doing those things in that role, then absolutely InfoSec Analyst lines up with what you're doing. So 100%, if you're trying to go from that system IT Security Administrator to some other cybersecurity position, if you want to put InfoSec Analyst, or you might even want to put Cybersecurity Analyst, because Cybersecurity Analyst is probably going to hit more jobs, then you can absolutely do that. But you can also do this, which is what I recommend, is just change the title to whatever position you're applying for.
So if you're applying for Instant Response role, just put Instant Responder. If you're applying to a compliance position, put Cybersecurity Compliance Professional or something, just whatever, whatever the title is, as long as you did it, then you can do that, if that makes sense. So I gave this example in the last episode.
I'm not going to harp on it too much, because I did have it, I did it on the last episode. But for people who didn't watch or listen to that one, let's say you are a Penetration Tester, and you're trying to get a new pen test position. And the new pen test position says Cybersecurity Consultant.
You can change Penetration Tester to Cybersecurity Consultant on your resume and on LinkedIn to match that job that you're applying for. Or because there's a lot of pen test positions that go Cybersecurity Consultant, that's the title. If you are a Cybersecurity Consultant, and you're applying for a Penetration Testing position, absolutely change that title to a Penetration Testing position, assuming you actually did real pen testing.
Don't lie, but if you actually did pen testing activities, then you can do that. Another example is, let's say you're a Penetration Tester, and you're applying to a Red Team Engineer position, you can change it to Red Team Engineer, because there's a lot of crossover in skills, and I would find that perfectly acceptable. However, what's not acceptable is if you are a Blue Teamer, let's say you're Cybersecurity Stock Analyst, and you've never done pen testing in a day in your life, changing Stock Analyst to Penetration Tester to apply for a pen testing position, that is a big no-no, is what I would say.
But if you are a Blue Teamer applying for other Blue Team positions, you can pretty much change that title interchangeably, because all Blue Teams positions have a lot of overlap. Same thing for Red Team and Offense Security, have a lot of overlap. So if you're going from Red to Blue or Defensive to Offensive, don't do that.
But if you're going from Blue to Blue, Defensive to Defensive, Red to Red, Offense to Offensive, totally fine. So that's my stance on it. And then there's obviously some nuanced areas where you can probably finagle the titles as well.
The titles really don't matter. Titles are all made up. That's literally it.
Titles are all made up. That's why you can just change whatever you want. And the bullet points, make sure they're factual things you've actually done.
Next question. Do you think working in the public sector, mill slash gov, would have better job satisfaction because of the profit margin not really being a factor? The dilemma is that it doesn't pay as much, but it's more stable. You bypass a lot of the saturated roles if you have clearance.
And the longer you're in there, it seems like the pay isn't too bad, question mark. It's an excellent question. And you're right.
The pay is a little worse. And there is more stability. It's also slower pace.
And there's also better benefits. So that's the pros and cons of the public sector, government jobs compared to private sector, non-government jobs. Now, I've never worked in a public sector job, government job, military job, with the exception of me being active duty military, but that's completely different because your pay is really bad then, which is the primary reason why I chose to get out of the military, actually.
I love the military. And I might make a full episode about this, but honestly, I kind of regret getting out of the military because I got out just to make more money. And I'm finding that I have less purpose in life because of that, because I took a lot of pride in wearing the Air Force uniform and actually going to work and doing a very good job because what I did felt like it mattered.
And I got a lot of praise, a lot of acknowledgement, and I got a lot of respect in the military. The military is notorious for awarding people for doing good things. And I had my fair share of military awards and decorations.
And when you get those, it's like, wow, I'm doing something really good here. And I missed that. So I do regret getting out of the military to a certain extent, and I miss it a lot.
To the fact that when I was on my... So people who've been watching and following me, they know that I took a six-month break off of making videos and just being out of the field, basically. I almost went back in the military, and I would have gone back in the military, back in the Air Force active duty if they had slots, but they had all the slots filled up, so I didn't go. So I was forced to find a new position.
And I could, I guess, go back in now, but at this point, I'm kind of liking my position enough to not go back in. But it's not because I like the job more, it's just because it pays significantly more. So that's the pros and cons between active duty and being civilian again.
In the public sector, when you're a civilian working for the government or the military, same thing. You're going to get more pay than active duty service member, but you're not going to get as paid as much, generally speaking, as a private or a non-government type position. And the stability is there because it's very, very hard to get fired from a government position.
I mean, it's very, very hard. You essentially can't get fired for poor performance. You got to be doing something like really malicious and fraudulent, or maybe you're getting in trouble outside of work, criminal activity type stuff to get kicked out of those types of positions.
Now, maybe you can get fired from performance issues, but I mean, you got to have a lot of performance issues to get fired. It's very hard to get fired from a government slash military position. But on the same token, if the government shuts down, as you know, the whole Doge thing happened a couple of years ago, I think at this point, they do try to thin out the government where they can sometimes.
So you also got to take that into consideration, because if the government shuts down, which it can and it does, then you're not going to be working during that time, which is not a big deal, because I mean, if you save your money, then you're not going to get paid, but at least you get a little vacation out of it until the government spins back up. So there's pros and cons for sure. You work in the civilian sector, or sorry, the private sector, then, you know, your performance, you got to be you got to be high, you got to be on top of your a game, you can't, like if you mess up once or twice, you're out.
That's just how it kind of how it works. There's a lot less leniency, there's a lot less stability. But the pay is much higher.
So and you kind of have to bet on yourself, because while you as a professional might be really good at your job, you know, a company can go out of business at any time, company can sell itself to a bigger corporation at any time. And then when that corporation buys a smaller company, then the corporation can just say, hey, you're laid off. Even in big corporations, people that worked at Google for 20 plus years, and they just got laid off.
So it's there's a lot less stability in private sector jobs, but pay is a lot higher. And like I said, you have to bet on yourself, because if you get laid off, then you got to go out and find a new job, which it's not too hard if you have the skill set people are looking for, and you are the real deal. But even if you are qualified and credentialed, it's still going to be a painful experience because search for a job just sucks.
It just flat out sucks. It's not a it's not a fun experience. And someone like me, you know, for example, me, I have eight years experience, 19 certifications, bachelor's, master's in cybersecurity, tons of try hackneyed rooms, like 200 plus try hackneyed rooms, 125 hacked the box machines, hacked active presence in the community.
And it took me just under two months to find a job, which is very quick, by the way, very, very quick. The average job search, I think right now is like six months for the average person. But for me, those two months was very painful, because you go through so many interviews.
And yet it's just annoying, man, it really is. So that stability can add to your mental mental health, even though you're not getting paid as much. And for me, personally, I kind of miss that stability.
And that's kind of why I miss the military, because there was a lot of stability with that. And like I said, I took a lot of the uniform and all that. I took a lot of pride in wearing it.
But yeah, it's the lack of stability in my current private sector jobs. Because like I said, I haven't worked. Ever since I got back to duty, I haven't worked in military and government, which I could because I do have a clearance.
But I just chose not to because I wanted my pay. I chose I chose to take the higher pay compared to the stability. And you can make that choice yourself.
Everybody's different. But good question. And glad I got to explain that a little bit.
If you if you have any questions further on that, then feel free to ask comments. Last question here. How would you rate the try hack me pre security plus track me junior pen tester plus EJPT plus PT1 plus Conti Appendix plus roadmap for a beginner that wishes to secure a job as a penetration tester? Great question.
I do have a video talking about how to become a penetration tester. And it's one of my most watched videos. So if you sort by most watched videos on my YouTube channel, then you're going to find it pretty easily.
And my advice in that video still applies. I don't. There's a reason why I haven't made another one, because I don't think it's my advice is too much different.
But we'll take your specific question here. And I'll tell you, I highly recommend watching that video because you're going to get my opinion from like a couple of years ago. And then you can mix it in with what I'm about to say now.
But absolutely get started tracking. You should make a try hacking account right off the rip if you want to be a pen tester. Do that.
And you should be doing your try hack me for an hour a day while simultaneously pursuing pen testing certifications. So the try hack me pre-security path. Perfect.
Try hack me junior pen test path. Perfect. And then there's even a middle of a pen tester path, which you'd want to do as well.
And you might even want to do some of the other. I think there's like cyber security beginner. I forget all the past, but there's there's a few a handful of beginner try hack me.
Pathways that are applicable to both offensive and defensive cyber security. You want to do all of those, especially if you're starting from scratch. If you're not starting from scratch and you kind of pick and choose.
But I'm assuming you're starting from scratch. You want to do all that beginner level stuff. And there's going to be a lot of overlap between some of the terminologies.
But that's OK, because the more reps you do, the more it's going to become second nature. And you're going to understand the back of your hand. I have learned about the TCP three way handshake probably 100 times now from 100 different courses.
And every time I just watch it because it's so critical to what we do. And that's why I have the foundations like back my hand, because I went over the foundational information so many times. And I highly recommend doing that.
Don't skip stuff just because you've seen it once, because you're going to see it again and again and again. And you're going to get a different instructor, a different writer, a different author. Teaching you this stuff, and then you're going to learn a little bit more because they're going to explain a slightly different.
And it's going to there's going to be a different type of light bulb that clicks in your head when you watch it again. But at a certain point, you needed you do. OK, you can go ahead and skip this.
At this point, like if I went to a course, I saw three way handshake. I put it on like three X speed as fast as the video would go just to get through it and then not really pay attention. But that's because I've already seen a hundred times.
But when it comes to trying to pass, yeah, you definitely would do all the beginner level. Pathways that apply to both offensive and defensive cyber, because I think having both skill sets is good. Don't do the defensive cyber like the defensive specific stuff, then focus on the offensive stuff once you get over the.
The ones that apply to both the general ones. And then, like I said, yeah, the pathway you got here is good, but I think the certifications you have are in the wrong order. So you're saying EJPT PT once that's the pen testing one for drag.
You don't know. And then the Comte appendix plus I would recommend. I would recommend.
The Comte appendix plus first. I would also recommend. Swapping out the EJPT for the TCM security junior penetration tester.
The PGPT practical junior penetrate tester from TCM security, because I think TCM security has better certifications than I need security, which is the ones that do the EJPT, the E-Learn security junior penetration tester. It used to be E-Learn security. Now it's I need security junior penetration tester.
And I have the EJPT. Actually, I don't have it. I actually let it expire.
But I did the EJPT. And the only reason why I chose the EJPT is because it was really the only junior pen junior pen tester on the market at the time, which was 2022, right? No, beginning of 2023. Which would have been three years ago, over three years ago at this point.
There was no PT one option at the time. There was no TCM security. Practical junior penetration tester.
So that's I was kind of forced to do the EJPT, but knowing what I do now, I do have one TCM security certification. I also have one TriHackMe certification. So I can, I don't have the practical junior pen tester and I don't have the TriHackMe PT one, but because I have certifications from those vendors, different certification from those vendors, I can say this with confidence that I do like, I do advise getting the TCM security, practical junior pen tester and not pursue the INE security junior penetration tester.
And my main reason is this is because the TCM security junior penetration tester does not expire. Whereas INE security EJPT does expire, which is why I let it expire because I don't really like certs that expire because when you have a lot of them, it costs you an arm and a leg to renew them. So that's a big reason.
And also because the TCM security junior penetration tester is going to be a much more practical and much more real world. But the EJPT had some really, really great training, by the way, can't knock it. And it was a fairly difficult exam.
It's just not as realistic as you might want it to be. I'm not, you can get the EJPT, but I think given the choice, I respect the TCM security junior penetration tester over the EJPT. When it comes to the TriHackMe PT1, you know, I kind of have a video kind of knocking a little bit, but TriHackMe certifications actually are pretty difficult.
They're not, they're not easy. They are junior-ish, but don't let that, that doesn't make it easy. Okay.
Like I did fail the TriHackMe SAL1. I did fail that. Granted, I wasn't a security analyst.
That's a security analyst level one. Never been a security analyst. So that's the primary reason why I failed the first time.
But even with someone at the time, I think I had like six and a half, maybe seven years experience and like 15 certifications or so, maybe 16 or 17 at the time. And I failed it. So do not sleep on this TriHackMe certifications either.
Between the TriHackMe, you don't, you don't need, so I did mention this in a TriHackMe PT1 video, but I'll reiterate it here since you're already here. You don't need multiple junior pen testing certs. I would just pick one and then just go with that.
Now, now which one's the best? That's the question. I think EJPT is automatically out the window. So it really, so, so it really is between the TriHackMe PT1 and the TCM Security Practical Junior Penetration Tester, PJPT.
So which one's better, TriHackMe or TCM Security for the junior certs? I, if you want to pursue all types of pen testing, let me specify if you want to pursue web app pen testing and network pen testing simultaneously, which is a fair and fine route. That's the route I went. I'm a network pen tester, or I was a network pen tester, and I was a web app pen tester.
That's what I did when I was a full-time pen tester. I did network and web apps. Not everybody can do both.
They are two separate skill sets. There's some overlapping skills and knowledge for sure, but pretty drastic in terms of the skill sets that you're going to learn and the tools you're going to use and the methodologies that you're going to be doing. So if you want to pursue that, if you want to be multi-faceted and you want to be a web app pen tester and a network pen tester, I would go with TriHackMe because TriHackMe does cover both of them in one certification.
And you can do that. When you do the Practical Junior Penetration Tester, that is all network, not really web app. Maybe there's some web app stuff in there.
I'm not sure. I haven't done an exam. I haven't done a training.
But there's probably going to be some smaller amounts of web app stuff. And it's mostly network based. And I can say with confidence because they also have a web app certification, a junior web app.
Well, they don't call it junior. They call it associate. So associate and junior is the same thing in terms of TCM security.
So actually they used to call it the Practical Junior Web Pen Tester or something like that. And they change it to the PWPA, the Practical Web Pen Test Associate. And I have that certification, by the way.
I failed it the first time, by the way, as well. Not an easy cert, by the way. Not easy.
Very, pretty hard to do. But I got that one and I learned a lot of web app skills from getting that certification. So you can do.
If you want to do just web app pen testing, then get that the PWPA, the Practical Web Pen Test Associate. If you just want to do just web app, if you want to do just network, then get the Practical Junior Penetration Tester. If you want to do both and you only want one junior cert, then get the PT1.
If you want to be really good at both and you're not trying to take shortcuts, then I would actually get this kind of goes against advice earlier where I said only get one junior. But if you get the TCM Security Junior Penetration Tester and TCM Security Practical Web Pen Test Associate, there's two junior associate level. I'm doing air quotes for the listeners, junior, because they're not really easy.
They're not easy at all. That's two, but it's in two different skill sets. So if you want to master both skill sets and I would get two, I would double up on TCM.
So I would get both their associate slash junior pen testing certs and then move on to something harder like the OSCP or the CPTS or the, and you can also pursue TCM Security as well. They have, so they have a network practical, the PMPT, the Practical Network Penetration Tester, and they have the PWPP, which is a Practical Web Pen Test Professional, which is the next level up. So you can pursue any of those ones for the mid-levels if you're trying to master this.
But if you're trying to like speed up the process and kind of get over that junior level quicker, quicker, then the PT one is just fine because they're going to, because you're going to want to get those mid-level certifications. And those junior level certifications aren't really well respected, unfortunately. So you're going to need those certifications anyways, like I said, OSCP, CPTS, TCM Securities, Professional Certifications.
And if you have junior certs, once you get those mid-level certs, those junior certs are pretty much become obsolete and they kind of just get shoved under the rug if they're on your resume because you have high level certs. So it don't really matter what your resume says when it comes to like, oh, do I got PT one or do I have TCM Security, PWPA or TCM Security, PJPT. It doesn't really matter because that's not what they're looking for.
They're looking for a mid-level professional. And like I said, once you get those mid-level certs, then your junior ones kind of become obsolete, which is one of the main reasons why I let my EJPT expire because I have mid-level certs in both web app and network. But it just depends on the person.
So if you're a quick learner, then you can probably learn all the stuff you need, all the foundational stuff you need in the PT one, especially if you're on a budget. PT one is one certification. You're going to learn a bit of both.
And if you go to the TCM Security route and you get both of the junior and their associate certifications in web app and network, like it's going to be a slower process. You're probably going to be a little bit harder and you're going to go into that intermediate level with a lot more knowledge, which is going to set you up for success down the road. You're going to struggle.
You're going to struggle less on those intermediate certifications than if you just got the PT one and then moved on to the service. Hopefully that makes sense. If you have any questions, feel free to ask them in the comments, but it really just depends on like how much challenge you want at the next level.
Right. If you want it to be easier than I would recommend getting to TCM Security certifications, if you want to be a network pentester and a web pentester, which is totally fine to do, but you can, and you are allowed, it's perfectly reasonable to say, Hey, I just want to be a web pentester. Hey, I just want to be a network pentester.
And there's advantages and disadvantages to that as well. So if, because if you, if you split your focus on two different skill sets, then you're not going to master either one of them, if that makes sense. So like, I can, I can confidently say like, yeah, I didn't master network pentesting.
I didn't master web pentesting. I was just pretty good at both. You know what I mean? Whereas someone who just doesn't only web app pentesting, like they really understand web app pentesting a lot more than I, than I did, or in the same thing for network, they understand network pentesting a lot more than I did because I have two different skill sets where they're focused on the one.
So you there's pros and cons of both of those. And the opportunities you're going to get vary based off of what path you choose. You basically have three paths as a pentester, web app network, or both.
You can do either one, any one of those three, and that's totally fine. And you got to make that choice for yourself. And I think if you start going through trying to hack new stuff, yeah, go ahead and learn a lot of stuff.
You don't need to make a decision now and go through the network stuff. And you're going to learn, Hey, what do I like? What do I like web apps? Do I like networks? Do I like both? Some people don't like web apps. Some people don't like networks.
Some people really like web apps. So it just, it just varies on the person. And that's why there's so many different types of professionals out there that can, you know, either do either or, or both.
I'm the type of person that wanted to do both. And that's what I pursued. And I really am glad I did that because I was able to have two different skill sets, which is nice.
But like I said, I wasn't as advanced as I wanted to be in either one. So that's the con to learning both because you can't learn everything about everything. Unfortunately, your time is limited.
Anyways, hopefully that set you up on a path for success for your pen tester career. If you have any questions, leave, leave a comment and I will get back to you and maybe feature on the next Q and a episode next month. So there you go.
Hopefully you enjoyed this episode, hit the five-star review. If you're on audio, if you enjoyed this episode, and if you're on video, if you're on YouTube, hit the like button, subscribe for more hacking and cybersecurity content. Hopefully I see you in the next episode.
Until then, this is Kyser signing off.