CISSP PRACTICE QUESTIONS – 20210816

Effective CISSP Questions

802.1X is an IEEE standard for network access control (NAC). Which of the following statements is correct? (Wentz QOTD)
A. Messages between the authenticator and authentication server are encapsulated by 802.1X.
B. Switch hubs and wireless access points are supplicants that use EAP-based authentication.
C. The security posture of the authenticator determines if a network access request is granted.
D. A supplicant doesn’t authenticate to the RADIUS server directly.

Continue reading →

CISSP PRACTICE QUESTIONS – 20210815

Effective CISSP Questions

Micro-segmentation is a security technique that isolates workloads using logical or virtual perimeter, provides granular security controls, and mediates east-west traffic to reduce the network attack surface. Which of the following is least related to micro-segmentation? (Wentz QOTD)
A. Software Defined Networks (SDN)
B. Software Defined Perimeter (SDP)
C. Virtual Local Area Network (VLAN)
D. Virtual eXtensible Local Area Network (VXLAN)

Continue reading →

CISSP PRACTICE QUESTIONS – 20210813

Effective CISSP Questions

The ISO OSI (open system interconnection) model and TCP/IP play a crucial role in the network and communication. Which of the following statements is correct? (Wentz QOTD)
A. TCP/IP is a protocol suite with inherent security designs.
B. Network protocols shall be designed per the ISO OSI model.
C. A network protocol belongs to only one layer of the ISO OSI model.
D. FCoE is a converged protocol that unifies fiber channels and Ethernet but is independent of TCP/IP.

Continue reading →

What Is Architecture?

Architectural and Design Principles
Architectural and Design Principles

As the foremost artifact of a solution, architecture is the conceptual, logical, and physical representation of an object (the solution) from various viewpoints or perspectives, which identifies its building blocks, relationships, interactions, boundaries, interfaces, environment, and context and guides the evolution of the solution across its life cycle.

~ Wentz Wu

Definitions

  • A set of related physical and logical representations (i.e., views) of a system or a solution. The architecture conveys information about system/solution elements, interconnections, relationships, and behavior at different levels of abstractions and with different scopes. (Source: NIST SP 800-160 Vol. 1)
  • that set of design artefacts or descriptive representations that are relevant for describing an object such that it can be produced to requirements (quality) as well as maintained over the period of its useful life (change) (Source: Zachman:1996, ISO/TR 20514:2005)
  • fundamental organization of a system embodied in its components, their relationships to each other, and to the environment, and the principles guiding its design and evolution (Source: ISO/IEC 15288:2008)
  • set of concepts and rules for a system that describes the inter-relationship between entities in the entire system, independent of the hardware and software environment
    Note 1 to entry: Architecture is described through a series of viewpoints that might be at varying levels of generality/specificity, abstraction/conception, totality/component, and so on. See also “communications viewpoint”, “functional viewpoint”, “organizational viewpoint” and “physical viewpoint” definitions below. (Source: ISO/TR 26999:2012)
  • fundamental concepts or properties of a system in its environment embodied in its elements, relationships, and in the principles of its design and evolution (ISO/IEC/IEEE 42010:2011)
  • representation of the structure of the item or element that allows identification of building blocks, their boundaries and interfaces, and includes the allocation of requirements to these building blocks (Source: ISO 26262-1:2018)
  • conceptual structure of a system
    Note 1 to entry: A system may consist of several interacting subsystems, each with its own architecture. (Source: ISO/IEC TR 29108:2013)
  • set of principles on which the logical structure and interrelationships to an organization and business context are based
    Note 1 to entry: Software architecture is the result of software design activity. (Source: ISO/TR 18307:2001)
  • specific configuration of hardware and software elements in a system (Source: IEC 61508-4)

EV Code Signing Token

Unknown Publisher Warning
Unknown Publisher Warning

To prevent security warning messages as shown above during the installation process of my CISSP test engine, WUSON Practice Field (WPF), I placed an EV Code Signing Certificate order to Sectigo on July 23 and received the EV Code Signing Token today, Aug. 12. It takes 20 days to fulfill the order. It may take longer if no complaints about their performance and services are made. The validation work, not including token delivery time, should be completed in one week as a normal situation.

Continue reading →

CISSP答題的思考重點

CISSP及其進階認證 - ISSAP, ISSEP, ISSMP
CISSP及其進階認證 – ISSAP, ISSEP, ISSMP
  1. 人員 > 流程 > 技術。人身安全永遠排在第一順位,是資安的黃金鐵則!
  2. 組織所有的活動都是由”目標“驅動;有目標就有風險,所以凡事都要考量風險。
  3. 組織的所有活動都必須符合經營階層的”政策“要求,以及相關的標準及程序。
  4. 風險處置或任何解決方案,都要考慮成本/效益及注意變更管理。
  5. 業務思維就是要知道如何善用技術來解決業務問題,以創造價值。
  6. 必須從組織、業務、技術的整體角度看事情,因此要注意到技術只是解決方案的要素之一。
  7. 須從主管的角度,了解如何選擇及善用技術來解決組織及業務的問題。
  8. 尋找通用的解決方案或答案,來解決眾多類似的問題。
  9. 具體的技術解決方案通常只能解決特定或一個問題,除非沒有其他更好的方案,否則盡量不要採用。
  10. 相信自己的專業,知道什麼答什麼就好!

全球唯一支援中、英文對照的CISSP題庫!

WUSON Practice Field (WPF) 是吳文智老師及教練群精心研發的CISSP考試引擎,以及全球唯一支援中、英文對照的CISSP題庫。主要的題庫內容由吳老師的CISSP每日一題(Wentz QOTD)組成。吳老師的CISSP每日一題歷經國內外考生實戰驗證,是最能訓練CISSP考生邏輯思考及整合觀念,且公認難度相當高的CISSP練習題與模擬題庫。經過WPF專業CISSP題庫的洗禮,讓您可以更從容地順利通過真實考試!

Information Security

Wentz’s book, The Effective CISSP: Security and Risk Management, helps CISSP and CISM aspirants build a solid conceptual security model. It is a tutorial for information security and a supplement to the official study guides for the CISSP and CISM exams and an informative reference for security professionals.

Information Security
Information Security

Security refers to the process of and the state reached by protecting something from danger or threat.

Information security is a discipline of protecting information assets from threats through security controls to achieve the security objectives of confidentiality, integrity, and availability, support business processes, and create value to fulfill the organizational mission and vision.

資訊安全

  • 安全是指保護某個東西免於受到危險或威脅的過程以及所達到的狀態。
  • 資訊安全是一門透過安全管制措施,保護資訊資產免於受到危害,以實現機密性、完整性和可用性的安全目標、進而支持組織的業務流程,並創造價值以實現使命和願景的學問。