• About Me
    • Bios
  • Professional
    • Resumes
      • Data Security Resume
      • Full Consulting Resume
      • Skills List
    • Certifications
      • Certified Information Systems Security Professional (CISSP)
      • GIAC Certified Incident Handler (GCIH)
      • GIAC Security Leadership (GSLC-Gold)
      • Novell Certified Linux Professional (NCLP)
      • Red Hat Certified Engineer (RHCE)
    • Communities
      • A Ticket, A Task Kit
      • Infragard
      • Central Iowa Area Linux Users Group
      • SANS Community
    • HOWTOs
      • How To Configure Firefox – 2005 Version
      • How To Configure FreeBSD
      • How To Configure Mediawiki
      • How To Configure NetBSD – 2004
      • How To Configure Palm Treos
      • How To Migrate Red Hat 6.1 server to VMWare
  • Fun Stuff
    • Allergies
    • Book Reviews
    • Coyote Signs – The Inspiration
    • How to make s’mores
    • How to ship a tiger to Canada
    • Photography
    • Strained Geometries
  • Categories
    • Business Security
    • Coyote Signs
    • Mythology
    • Natural History
    • Psychology
    • Sprint
  • Contact
Menu

Certification – Test Types

  • At July 24, 2008
  • By Josh More
  • In Business Security
  • 0

There are generally two types of tests. Those which you can go back and look at questions once you’ve answered them (generally paper-based) and those where you cannot (generally practica or “live” tests). Each of these have different strategies to win.

Paper-based
If you are taking a paper test, go through it as fast as you can and answer everything that you KNOW. If you don’t know, skip it. You should be done very quickly. Then, go back through the test and look at the ones that you didn’t know right away. If it’s multiple choice or true/false, find the answers that you KNOW are wrong, and cross those out. You’re not actually answering questions at this point, you’re just eliminating possibilities. Then, go back through and see if you KNOW any of them now that you’ve eliminated the ones that were obviously wrong. This also should not take much time.

By this point, most of the test should be answered, and the good news is that these answers are things that you know are correct, and with absolute certainty. Now you get to actually start thinking about the remaining questions. This will be hard, but you have to keep in mind that you have already answered most of the questions right. It’s OK if the hard questions are hard, just do the best you can. If you’re stuck, try to think of a real-life scenario involving the question and ask what you would do. You can also flip the question around and see what you would do if the situation were reversed. This may make the correct answer more obvious.

If there is an essay component to the test, do NOT just start writing. First, take notes of what you want to say. Then, categorize the notes by putting a letter in front of each key item. Then, within each category, prioritize the importance by putting a number in front of the letter. Then, write an introduction and segue into point 1A. Once you’ve addressed that, go to 2A, to 3A and all the way until you’re done with the As. Then start with 1B. At this point, your essay has become a game of connect the dots, and you can just write until you’re done. Don’t worry about style, the examiner is looking for correct information, not a brilliant expression of ideas.

Live Tests
As computers advance, these tests are becoming more popular. They allow the test to adjust itself to your level. Sometimes this is used to give you challenging questions, sometimes it’s used to drive you into an area that you do not know so well. On tests like this, you have to know the scoring. Keep a mental tally on how you are doing and how much of a penalty you may get by skipping questions. Then, allocate time based on what you need to do the best. It’s often better to take more time on each question than on the paper tests, because of how wrong answers can impact the questions that you get later.

Practicum
When taking a practicum, you cannot use strategy to manipulate the test system to your advantage. You either solve the problem or you do not. Luckily, there are often multiple problems to solve, so start with the ones that you know best. However, do NOT assume anything. Do not make any changes that you cannot test. Test before a change and then test after, to make sure that your change did what you think. If you have to restart a service, test after the restart, to make sure that your changes persisted. On many systems, it is easy to forget that some changes only affect the running system and are lost on a reboot. (Cisco is tricky this way.)

Also, use proper diagnostics. Test at the boundaries or interface layers. On modern systems, this is often the TCPIP stack, so use tools like netcat and telnet to ensure that the interfaces are responding properly.

Most systems also come with built-in reference documentation. Whether it is a commented configuration file, the documentation that came with the package, or a man/help page, know where to find the information and verify that you understand what you think you do.

Lastly, at the end of a test or scenario, RETEST everything that you’ve done. Make SURE that the problem is solved. It’s much too easy to break one thing when you’re fixing another.

Certification – How to test

  • At July 22, 2008
  • By Josh More
  • In Business Security
  • 0

Once you’ve prepared, you will do well on the test… unless you do something stupid. Luckily, by this point, you will know that you know enough to pass. You can let the worry go and instead of trying to succeed, you can simply focus on not screwing up. It is much easier just not to screw up. So, let’s talk a bit on how to do that:

Dealing With Panic
If you panic, you’re likely to do stupid things like skip questions, forget directions and so forth. So, don’t panic.

Yeah, like that’s going to help.

If you find yourself panicking, take a break and count to 10, slowly. Then, write down on a spare piece of paper what you’re panicking about. Odds are that your brain is stuck in a loop, and by getting things down on paper, you can see the loop. Then, find where your thinking is illogical and cross that item out. Go through the loop and eliminate the stupid thoughts. This entire process will feel like it’s taking an hour. It’s likely taking less than five minutes, so don’t worry about the time lost.

If you were panicking, those five minutes wouldn’t have been productive anyway.

Protein
If you run out of energy, you’ll know. Your thoughts will start to drift and you’ll be distracted. You may feel tired. Odds are that you will NOT feel hungry. This is because your body is stupid and doesn’t tell you what’s going on. Bring protein with you. Peanuts are good, energy bars are good. Candy is BAD. Coffee is BAD. If you start to drift, have a small bite of protein. Keep this up throughout the test. Have a bottle of water to drink too. Keep the cap on (so you don’t spill) and take small sips.

After the test, you’ll feel weird. That’s a sort of protein high, and it’ll wear off. The important thing is to keep giving your brain the food and hydration it needs. Your body can be confused for a bit, it’s OK.

By the way, the reason to avoid candy (sugar) and coffee (caffeine) is because these give you easy energy. Once the easy energy is used up, your system will crash. Some people try to “ride the high” through a test. However, since crashing affects your thinking, it will impact both the results of the test and your perception as to where you are on the “high”. An exam is the wrong time to try to reprogram your brain. Use the protein, it’s more stable.

Set Milestones
Every certification test that I know uses time to control the test. Therefore, the clock is your enemy. To win, you must control the clock by figuring out how long you have, and setting milestones. Do not worry about how much time you have until the end of the test, worry about how much time you have for each question, each page, or each task. Then, if you beat time, take a short break (1 minute) to regroup and continue. If you do not beat time, at least you are aware of where you stand.

The milestones that you set will vary by test type.

Certification – Costs of Maintaining a Certification

  • At July 15, 2008
  • By Josh More
  • In Business Security
  • 0

The act of maintain a certification also has associated costs.

Re-testing
Some certifications require you to re-test every so many years (often four). That means that you have to budget for both the test itself and either the time to prepare to take the test or a refresh course. Keep in mind that the more technical the certification, the more things will change between tests. This will affect your prep time estimate or drive the need to go to a prep course. In either case, understand that the value of a second test to maintain your certification ensures that you still know and understand the subject sufficiently to be certified in it. Thus, certifications that require re-testing often maintain their value better than the ones that do not.

Dues
Some certifications require yearly dues to maintain your certified status. This practice helps to maintain the financial solvency of the certifying body. However, it does put you in the position to yearly decide whether the certification is giving you a value equivalent to the cost of the dues. If all the organization is doing for you is taking your money, I would suggest that may not be worth it. Consider any other opportunities that may come your way because of your certified status. Some “member” programs that go with the dues will give you discounts on programs or access to a group of experts. If you are availing yourself of such resources, by all means, pay the dues. However, be sure to think about WHY you’re paying the dues instead of just paying them.

Continuing Education
Many certifications have a continuing education requirement. In other words, in order to maintain your certified status, you need to dedicate time and money to continuously educating yourself in your field. This can be a pain, as you must, at the end of every cycle (usually one year) demonstrate that you have been learning. If you are not good with time management, it can produce a rush to complete education before you lose your certification.

You can get around this problem by treating the process like the running of a marathon. Every week, you just make a small step towards your CPE goal, and by the end of the cycle, you should be well ahead of where you need to be. This not only fulfills the requirements, but continuously reinforces the thinking that the initial certification helped you to achieve. Of course, it is important to account for this accurately, but like all habits, this will improve with practice.

The costs of continuing education is governed by you. There are usually options for a variety of budgets, ranging from $10,000 training classes to free podcasts and webinars. Just keep your eye on the prize, and you should be fine.

Certification – Costs of Attaining a Certification

  • At July 10, 2008
  • By Josh More
  • In Business Security
  • 0

When pursuing any form of higher education, the subject of money often comes up. It is common for people to question what a certification is “worth”, and just as common as people to respond in terms of salary increases compared to the cost of getting the certification. This is erroneous thinking. As you have (hopefully) already read, the true value of a certification is the learning that it brings you and the new ways it gives you to think about problems. Comparably, these are the terms in which you have to account for the costs of a certification.

There are many ways to attain a certification, the common ones are listed below with a short breakdown of that they actually mean

Boot-camp
In a boot-camp situation, you generally go somewhere and do nothing but focus on the certification for about a week. This is often very expensive, as you (or your company) must foot the bill for tuition, meals, lodging, travel, and any other incidentals that may arise. Additionally, during this week, you are not able to make money for your company, so the company often gets a double-whammy on the financial side.

That said, this method tends to be highly successful in filling your brain with the knowledge needed to pass the certification exam. This is good if the primary goal is getting certified. However, if you want the learning to become permanent, you have to ask yourself if you learn best in one shot or slowly and over a period of time. If you can actually absorb information that quickly, and you are willing to talk with your fellow classmates and learn from them, this could be a very cost effective way for you to learn. If not, consider a different method.

Mentor
Some certifications offer a mentor program. As a mentor, the “instructor” is available to help you understand specific topics, but the learning is expected to be mostly on your own. As such, it tends to be somewhat cheaper than the boot-camp scenarios. However, the financial cost is offset by increasing the time cost. Simply put, it takes more time for you to gain the certification. Depending on your learning style, this could be a good thing. If the extra time is needed to get the new patterns imprinted on your brain, then this method is definitely worth the time cost.

If, however, you approach this program from a perspective where you only think about it during the mentor sessions, it is unlikely to be effective for you. This method takes more work on your part than the boot-camp does. If you have the passion, go for it. If not, it’s best to give it a pass.

Study Group
Some people prefer to learn from their peers, and to that end, will form a study group for the purpose of helping one another learn enough to pass the test. This tends to be very inexpensive from a financial standpoint, but extremely expensive in terms of time. In addition to the learning that you have to do on your own, you have to carve even more time out of your week to attend the study group. Moreover, everyone in the group has to do this to be successful.

Often, these groups dissolve into chatter, which is socially enjoyable, but a waste of resources compared to the ultimate goal. If you have a group of people that you KNOW can stay on task, and you ALL are interested in actually learning about the topic, go ahead and try this method. However, only go into it with your eyes wide open.

Books / Self Study
This is probably the least expensive in terms of dollars and you have complete control over the time cost. However, studying on your own often only works well if you have the passion and drive needed to learn on your own. This method is not for the passive learner. If you pursue this path, I strongly recommend that you develop a schedule for yourself and stick to it. You have to be brutally honest with yourself and constantly test your knowledge. It also helps to commit to a specific testing date, as this puts pressure on you to keep to your training schedule.

If you pursue this method, you will lose the learning opportunity of bouncing ideas off of others, but if you are dedicated to your path, it may not matter so much. However, your success will also be linked to the quality of the book you choose. This is why I recommend picking up multiple certification prep guides (raising the costs). That makes it more likely that you will learn the material and not just the way that author chooses to present the material.

Testing
There is almost always a financial cost to taking a certification test. There is another one for re-taking a certification test, so be sure that you can pass before you sign up for one. The hidden costs here include travel, hotel, meals, and time lost to taking the test. Also, anticipate being exhausted after an exam and do not plan to be productive during the trip back. Odds are that you will just want to sit and fret about how you did. Depending on the exam, you may or may not know for days. Remember that this stress has a cost as well.

Other Sites: Business, Photos/Conservation
Search

Get the feed (RSS):



Josh More - Entropologist
Expert in removing chaos from
I.T. and business systems.

Recent Posts

  • Thinking about enterprises
  • New Book: Breaking In to Information Security
  • Security Metaphors
  • Book Review: All Yesterdays
  • Book Review – Blackhatonomics
  • Three Stories about Growing Up
  • Internet Theft and the Holidays
  • Sophos: Pushing the Boundaries
  • Controlling the Security Story
  • Video – OWASP – July 16th, 2012

Archives

Categories

  • Business Security
  • Coyote Signs
  • Mythology
  • Natural History
  • Psychology
  • Sprint
  • Uncategorized
Copyright © 2013 by Josh More