CISSP PRACTICE QUESTIONS – 20210831

Effective CISSP Questions

According to NIST, malware, also known as malicious code, refers to a program that is covertly inserted into another program with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise the confidentiality, integrity, or availability of the victim’s data, applications, or operating system. Which of the following statements about malware is correct? (Wentz QOTD)
A. A virus is not self-replicating; it can be loaded and executed by an operating system only.
B. A worm can either actively exploit network service vulnerabilities or passively use mass mailing to propagate itself.
C. Malicious mobile code, as the mobile app, traverses across mobile devices without the user’s explicit instruction.
D. A Trojan horse is a self-replicating and self-contained program that appears to be benign but actually has a hidden malicious purpose.

Continue reading

CISSP PRACTICE QUESTIONS – 20210830

Effective CISSP Questions

A microservices-based architecture in applications and service mesh application infrastructure that provides various security services through service proxies has emerged as the widespread application environment for cloud-native applications. Which of the following is not a common type of authorization policy used in service mesh? (Wentz QOTD)
A. Service-level authorization policies
B. End user-level authorization policies
C. Model-based authorization policies
D. Circuit-level authorization policies

Continue reading

CISSP PRACTICE QUESTIONS – 20210829

Effective CISSP Questions

The head of the sales department purchased a batch of new mobile devices for sales representatives to facilitate the selling process without the approval of the IT department. Which of the following is the best security control to prevent this from recurring? (Wentz QOTD)
A. Mobile Device Security Policies
B. User Education
C. OS & Application Isolation
D. Application Vetting

Continue reading

專案是實現使命、願景,及戰略的具體努力!

分享一些多年來專案管理及工作的心得:

專案是實現使命、願景,及戰略的具體努力。使命感、遠見與作夢的能力(visioning)、共享願景(“shared” vision),及深謀遠慮的戰略是重點。

這是一個講求結果、成敗論英雄的世界。專案成敗有客觀的定義,也有主觀的感受。客觀的範圍、時間、成本目標可量化,質化的專案目的(purpose) 及需要(needs) 難衡量。專案客觀達標,但主觀感受未被滿足,可能也會變成無效努力。專案分做事(management)跟作人(leadership) 二個部分,各有不同的方法(approach)及風格(style).

我多年來的工作心得:

  • 心存善意、與人為善
  • 誠實正直、追求成功
  • 重視結果、目標導向
  • 用對方法、講求紀律