Career Guide · Ethical Hacking
How to Start a Career in Ethical Hacking from Scratch
Quick summary — how to start a career in ethical hacking
Ethical hacking is one of the most in-demand and rewarding careers in cybersecurity. This guide provides a step-by-step roadmap to start a career in ethical hacking from scratch — no prior experience required.
In this guide you will learn:
- Phase 1: Foundations — networking, Linux, and security basics (Weeks 1-4).
- Phase 2: Penetration Testing — tools, vulnerabilities, and hands-on practice (Weeks 5-8).
- Phase 3: Certification & Launch — CEH/OSCP, portfolio, and job search (Weeks 9-12).
- Career roadmaps for 6 backgrounds — B.Tech, BCA, Non-CS, Diploma, Freshers, Career Switchers.
- Interview Q&A — common ethical hacking questions.
SECTION 01Phase 1: Foundations (Weeks 1-4)
In this phase, you'll build a strong foundation in networking, Linux, and security fundamentals.
| Week | Focus | Daily Actions | Goal |
|---|---|---|---|
| Week 1 | Networking Basics | TCP/IP, DNS, OSI model, subnets | Understand networking |
| Week 2 | Linux Fundamentals | Command line, file system, permissions | Use Linux confidently |
| Week 3 | Security Basics | Threats, vulnerabilities, CIA triad | Understand security concepts |
| Week 4 | Lab Setup | Virtual machines, Kali Linux, Metasploitable | Set up practice lab |
Phase 1 — Weekly Plan:
Week 1: Networking Basics
- Learn: TCP/IP, DNS, HTTP, OSI model
- Practice: Wireshark for packet analysis
- Goal: Explain how data moves across networks
Week 2: Linux Fundamentals
- Learn: Command line (ls, cd, grep, awk)
- Practice: File permissions, user management
- Goal: Navigate Linux without GUI
Week 3: Security Basics
- Learn: Types of attacks, vulnerabilities, risk
- Practice: Read security blogs and news
- Goal: Understand the security landscape
Week 4: Lab Setup
- Install: VirtualBox/VMware
- Install: Kali Linux (attacker)
- Install: Metasploitable 2 (target)
Phase 1 Checkpoints:
✅ Can explain TCP/IP and DNS
✅ Can use Linux command line
✅ Understand common security threats
✅ Have a working lab environment
✅ Can ping and scan networks
SECTION 02Phase 2: Penetration Testing (Weeks 5-8)
In this phase, you'll learn penetration testing tools and techniques.
| Week | Focus | Daily Actions | Goal |
|---|---|---|---|
| Week 5 | Reconnaissance | Nmap, WHOIS, OSINT, Google dorks | Gather target information |
| Week 6 | Vulnerability Assessment | Nessus, OpenVAS, Nikto | Identify vulnerabilities |
| Week 7 | Exploitation | Metasploit, Burp Suite, SQL injection | Exploit vulnerabilities |
| Week 8 | Post-Exploitation | Persistence, privilege escalation | Maintain access |
Phase 2 — Weekly Plan:
Week 5: Reconnaissance
- Tools: Nmap, theHarvester, Shodan
- Practice: Scan a target, gather OSINT
- Goal: Map the attack surface
Week 6: Vulnerability Assessment
- Tools: Nessus, OpenVAS, Nikto
- Practice: Scan for vulnerabilities
- Goal: Identify weaknesses
Week 7: Exploitation
- Tools: Metasploit, Burp Suite, sqlmap
- Practice: Exploit a vulnerable machine
- Goal: Gain initial access
Week 8: Post-Exploitation
- Tools: Mimikatz, PowerShell Empire
- Practice: Privilege escalation
- Goal: Maintain persistent access
Phase 2 Checkpoints:
✅ Can use Nmap for network scanning
✅ Can identify vulnerabilities using Nessus
✅ Can exploit vulnerabilities with Metasploit
✅ Can perform privilege escalation
✅ Completed 3+ practice machines (HTB/CTF)
SECTION 03Phase 3: Certification & Launch (Weeks 9-12)
In this phase, you'll get certified, build your portfolio, and start applying for jobs.
| Week | Focus | Daily Actions | Goal |
|---|---|---|---|
| Week 9 | Certification Prep | CEH or CompTIA Security+ study | Pass certification exam |
| Week 10 | Portfolio Building | Write reports, GitHub, LinkedIn | Build professional presence |
| Week 11 | Interview Prep | Practice questions, mock interviews | Be interview-ready |
| Week 12 | Apply & Launch | Apply to jobs, network, follow up | Land interviews |
Phase 3 — Weekly Plan:
Week 9: Certification Prep
- Choose: CEH, CompTIA Security+, or OSCP
- Study: Official course materials
- Practice: Sample questions
Week 10: Portfolio Building
- Write: Penetration test reports
- Upload: CTF walkthroughs to GitHub
- Update: LinkedIn profile
Week 11: Interview Prep
- Practice: 20+ interview questions
- Mock: Technical and behavioral interviews
- Research: Companies and roles
Week 12: Apply & Launch
- Apply: 10+ quality applications
- Network: LinkedIn, cybersecurity forums
- Follow-up: Send follow-ups
Phase 3 Checkpoints:
✅ Certified (CEH/Security+/OSCP)
✅ Portfolio website or GitHub
✅ Practiced interview questions
✅ Sent applications
✅ Interview calls scheduled
SECTION 04Career Roadmaps for Every Background
Here are 6 detailed career roadmaps tailored to your specific background — choose the one that fits you best.
Career Roadmap: B.Tech / B.E. Graduates
Your Advantage: Strong engineering and networking background.
Your Challenge: Need to learn security tools and techniques.
Salary Range: ₹5 - 12 LPA
Focus Areas:
- Network security
- Penetration testing
- Security certifications (CEH, OSCP)
- Vulnerability assessment
Recommended Certifications:
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
Recommended Job Titles:
- Penetration Tester
- Security Analyst
- Ethical Hacker
- Security Engineer
Career Roadmap: BCA / MCA Graduates
Your Advantage: Strong programming and IT skills.
Your Challenge: Need to learn networking and security concepts.
Salary Range: ₹4 - 10 LPA
Focus Areas:
- Application security
- Web penetration testing
- Security tools
- Certifications
Recommended Certifications:
- CompTIA Security+
- CEH
Recommended Job Titles:
- Security Analyst
- Web Application Security Tester
- Ethical Hacker (Junior)
- SOC Analyst
Career Roadmap: Non-Technical & Non-CS Graduates
Your Advantage: Domain knowledge and communication skills.
Your Challenge: Need to build technical and security skills.
Salary Range: ₹3.5 - 7 LPA
Focus Areas:
- Security awareness
- GRC (Governance, Risk, Compliance)
- Security fundamentals
- Certifications
Recommended Certifications:
- CompTIA Security+
- CompTIA Network+
Recommended Job Titles:
- Security Analyst (Entry)
- GRC Analyst
- Security Awareness Specialist
- Junior Security Consultant
Career Roadmap: Diploma & Polytechnic Students
Your Advantage: Practical skills and hands-on experience.
Your Challenge: Need to build theoretical security knowledge.
Salary Range: ₹3 - 6 LPA
Focus Areas:
- Network security
- Vulnerability scanning
- Security tools
- Certifications
Recommended Certifications:
- CompTIA Security+
- CEH (after 1 year)
Recommended Job Titles:
- Security Technician
- Junior Security Analyst
- SOC Analyst (Entry)
- Network Security Administrator
Career Roadmap: Freshers & Recent Graduates
Your Advantage: Fresh perspective and adaptability.
Your Challenge: Need to build experience and certifications.
Salary Range: ₹4 - 8 LPA
Focus Areas:
- Security fundamentals
- Hands-on practice
- Certifications
- Portfolio building
Recommended Certifications:
- CompTIA Security+
- CEH
Recommended Job Titles:
- Security Intern
- Junior Security Analyst
- Ethical Hacker (Trainee)
- SOC Analyst
Career Roadmap: Career Switchers & Self-Taught
Your Advantage: Transferable skills and maturity.
Your Challenge: Need to build security expertise and credentials.
Salary Range: ₹4.5 - 9 LPA
Focus Areas:
- Security fundamentals
- Penetration testing
- Certifications
- Networking
Recommended Certifications:
- CompTIA Security+
- CEH or OSCP
Recommended Job Titles:
- Security Analyst
- Penetration Tester
- Security Consultant
- Ethical Hacker
SECTION 05Interview Q&A — Ethical Hacking
Q1Do I need a degree to become an ethical hacker?
No. Many ethical hackers are self-taught or have non-CS degrees. Certifications and practical skills matter more than a degree.
Q2Which certification should I get first?
CompTIA Security+ is a great starting point. Then move to CEH or OSCP depending on your career goals.
Q3What tools do ethical hackers use most?
Nmap, Metasploit, Burp Suite, Wireshark, Nessus, and Kali Linux are among the most commonly used tools.
Q4What's the salary for an ethical hacker in India?
Freshers can expect ₹4 - 8 LPA. With 2-3 years of experience, ₹8 - 15 LPA. Senior roles can go up to ₹20-30 LPA.
Q5How can I practice ethical hacking legally?
Use platforms like Hack The Box, TryHackMe, and VulnHub. Always practice in your own lab or authorized environments.
SECTION 06Test yourself — Ethical Hacking Career Quiz
Five questions. No sign-up.
0 / 5Pick an answer to see why it is right or wrong.
SECTION 07Frequently asked questions
How long does it take to become an ethical hacker?
With dedicated effort (4-6 hours daily), you can become job-ready in 3-6 months. The key is consistent practice.
Can I learn ethical hacking without coding?
Yes, but you'll need to learn some scripting (Python, Bash) for automation. Coding skills make you a better ethical hacker.
What are the best free resources for ethical hacking?
TryHackMe, Hack The Box (free tier), VulnHub, and YouTube channels like NetworkChuck and The Cyber Mentor.
Is ethical hacking a good career for 2026?
Yes. Cybersecurity is one of the fastest-growing fields with a massive skills gap. Ethical hacking is in high demand.
Do I need to know math for ethical hacking?
Basic math is sufficient. Advanced cryptography requires more math, but you can learn as you go.
SECTION 08Related reads
Classroom & online · Noida
Your ethical hacking career starts now
Our Ethical Hacking Training Course is designed to help you build the skills, certifications, and interview confidence needed to become an ethical hacker — even from scratch.
₹15,500 · full programme- Complete 12-week roadmap
- Hands-on lab practice
- CEH & OSCP preparation
- Placement support
- Weekday & weekend batches

