CEH or GIAC - Which one should I pursue?

If you are focusing on Security Testing, the CEH does seem to be a useful entry level certificate. See the answers on this question on professional certifications. It will get you an understanding of the common tools used in the industry and it is recognised by recruitment agencies.

It doesn't give you the broader view of security, as to where it fits in with real world business needs, but to be honest, that will be further down the road for you and when you want to start looking along those lines, studying CISSP (links to free resources here) gives you a wider perspective and it is a very well respected cert.

GIAC is more in depth, and requires more knowledge and experience, but is valued higher than CEH. It is not an entry level cert.


In the comments and on chat I ran across some great underlying career advice and I just want to be sure it gets at least "answer" status (if Avid or Rakkhi want to expand on them, I'd be happy to delete this answer)

There is an important career-planning aspect to your question, and deciding what direction you really want to head in is the first, most important step. Here are some great resources:

  • What are the career paths in the computer security field? - IT Security

  • What Aren’t They Thinking? - an article from the Overcoming Bias blog on why folks should be out there shadowing folks in jobs that interest them, studying the job market, getting internships, etc. Look before you leap!


GIAC offers many certifications in many areas of security. So it actually gets worse than deciding what type of security testing you're interested in--you may not even be interested in testing!

See the GIAC certification list to see what I mean. If you have any more specific career aspirations than "security" we can help more. Otherwise, the GSEC is a decent entry-level security certification for IT practitioners and security folk alike. Another option you may have available is the SSCP, which requires as little as one year of experience. Also note, that both the SSCP and CISSP grant some credit for college degrees.