CISSP PRACTICE QUESTIONS – 20210210

Effective CISSP Questions

After a periodic security assessment, you are reviewing the plan of action and milestones (POA&M) to correct non-compliance issues and mitigate risk. As a CISO, which of the following is your most concern?
A. Tasks not assigned an owner
B. Tasks underestimated on purpose
C. Tasks marked for further evaluation
D. Tasks solved and inherited from the previous report

Continue reading

CISSP PRACTICE QUESTIONS – 20210209

Effective CISSP Questions

The software testing team is testing a web-based E-Commerce system. The back-end API receives an HTTP request, GET /customer/delete?country=all, with an empty HTTP message body. Which of the following is the most likely test undergoing?
A. Fuzz testing
B. Stress testing
C. Synthetic transaction
D. Misuse/Abuse testing

Continue reading

CISSP PRACTICE QUESTIONS – 20210206

Effective CISSP Questions

Which of the following block cipher modes of operation in which a block cipher doesn’t use plaintext as the direct input but operates on its output and the plaintext to produce the ciphertext?
A. Cipher Block Chaining (CBC)
B. Cipher feedback (CFB)
C. Electronic codebook (ECB)
D. Initialization Vector (IV)

Continue reading

The Effective CISSP: Security and Risk Management

The Effective CISSP: Security and Risk Management
The Effective CISSP: Security and Risk Management

The Effective CISSP: Security and Risk Management

“This book should be part of your study plan for the CISSP.” -J. Stapp

As the author, I wrote this book to help you build a solid conceptual foundation that applies to both the CISSP and CISM exam. If you come from the IT or technical field, this book is for you!

Purchase right away on Amazon: https://www.amazon.com/dp/9574376478
Both Kindle eBook and paperback are available.

NIST Infrastructure-related Guidelines

  1. NIST SP 800-41 R1 (Firewalls)
  2. NIST SP 800-92 (Log Management)
  3. NIST SP 800-94 (IDS & IPS)
  4. NIST SP 800-95 (Web Service)
  5. NIST SP 800-125 (Virtualization)
  6. NIST SP 800-125A R1 (Hypervisor)
  7. NIST SP 800-125B (Virtual Network)
  8. NIST SP 800-153 (Wireless)
  9. NIST SP 800-177 R1 (Trustworthy Email)
  10. NIST SP 800-190 (Container)
  11. NIST SP 800-207 (Zero Trust)

CISSP PRACTICE QUESTIONS – 20210205

Effective CISSP Questions

You are learning cryptography. Which of the following is correct?
A. Secret-key encryption uses a shorter key than public-key encryption to achieve a lower work factor.
B. The CBC mode of public-key encryption hides ciphertext patterns, while ECB doesn’t.
C. Block ciphers have better performance than stream ciphers on constrained hardware.
D. Stream ciphers are more vulnerable to cryptanalytic attacks than block ciphers.

Continue reading