CISSP PRACTICE QUESTIONS – 20200427

Effective CISSP Questions

You have engaged in a double-blind pentest contract and get started to conduct testing. To effectively assess vulnerabilities and keep the testing in secret, which of the following should be conducted first?
A. Enumerate services on hosts to discover potential attack vectors
B. Conduct passive testing against the target
C. Exploit vulnerabilities by sending passive payloads
D. Cloak a port scan with decoys to hide your IP address


Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.

Continue reading

CISSP PRACTICE QUESTIONS – 20200425

Effective CISSP Questions

You are managing a software development project and considering implementing DevOps. After doing some research, you realized that ISO/IEC TS 23167:2020 defines DevOps as the “methodology which combines together software development and IT operations in order to shorten the development and operations lifecycle.” Which of the following statements about DevOps is not true?
A. DevOps relies heavily on tools for automation and streamlining the processes.
B. Agile addresses communication gaps between customers and developers, while DevOps addresses gaps between developers and IT operations.
C. DevOps relieves the burden of security professionals by central management.
D. In addition to developers and system administrators, DevOps also engages QA staff.

Continue reading

My Book is Available on Kindle Store Now!

TheEffectiveCISSP_SRM_Amazon
I’m pleased to let you know, my book, The Effective CISSP: Security and Risk Management, has been published to the Kindle store. A 72-hour countdown deal promotion will start from May 24, 12:00 AM (PDT), 08:00 AM in London, 03:00 PM in Taiwan. (May 24 is the earliest date imposed by Amazon to start promotions)

This copy is a so-called “Print Replica,” which is a fixed-format, PDF-like, ready for printing ebook, so the navigation experience may not meet your expectations. However, it’s still worthy of your time reading it.

This book is an introductory-level tutorial with a focus on fundamental concepts of security and risk and GRC. In addition to tutorial materials, chapters that introduce risk management can be used as a reference. It not only helps you prepare for CISSP but also CISM.

As an experienced IT veteran, I’ve successfully passed CISSP, ISSMP, ISSAP, ISSEP, CCSP, CSSLP, CISM, CISA, CGEIT, CRISC, CEH, ECSA, CBAP, ACP, PBA, RMP, and many more certifications with astonishing speed.
This book presents what I believe crucial in preparing for CISSP, CISM, and many other management-based certification tests. This book is definitely a stepping stone to guide you right on the way to success!

GO GET ONE RIGHT NOW!

The Effective CISSP - SRM_Cover


Improvement

Thanks go to Mr. Grewal for reporting some images rendered poor quality in Kindle. The following is an improved image.

CISSP PRACTICE QUESTIONS – 20200424

Effective CISSP Questions

You are the project manager of a software development team following a generic software development life cycle. Meeting the requirements of stakeholders is crucial to the success of the project. Which of the following should be completed right before your team gets started to design the solution?
A. Requirement verification
B. Requirement certification
C. Requirement validation
D. Requirement analysis

Continue reading

CISSP PRACTICE QUESTIONS – 20200423

Effective CISSP Questions

The Secure Software Development Lifecycle (SSDLC) is curial to information security. The Agile mindset, which comprises a set of values, principles, and practices, is prevalent in software development. Scrum is one of the most well-known Agile practices nowadays. Which of the following statements about Scrum is not true?
A. Scrum is a methodology that incorporates eXtreme Programming (XP) and Kanban.
B. The Product Owner is responsible for maximizing the value of the product.
C. The Development Team is self-organizing, so no one should tell them how to create values.
D. The Scrum Master is a servant-leader and helps everyone understand Scrum.

Continue reading

CISSP PRACTICE QUESTIONS – 20200422

Effective CISSP Questions

An Integrated Product Team (IPT) is a multidisciplinary group of people who are collectively responsible for delivering a defined product or process. Which of the following statements about the IPT is true?
A. The structure of IPTs solely relies on the Work Breakdown Structure (WBS).
B. The composition of IPTs is favorable to the formation of Agile teams.
C. IPTs are system engineering teams, not responsible for acquisitions.
D. IPTs emphasize team diversity and don’t fit classified military-based projects.

Continue reading

CISSP PRACTICE QUESTIONS – 20200421

Effective CISSP Questions

Your organization decides to purchase new firewalls to replace the legacy ones. Two brand vendors are competing for the bid. Which of the following is the best evidence of your organizational capability that assures the procurement decision of firewalls renders the best outcome?
A. Common Criteria (CC)
B. Service Organization Controls (SOC) 2 Type 2 Report
C. Capability Maturity Model Integration (CMMI)
D. Evaluation Assurance Level (EAL)

Continue reading