Activity
Mon
Wed
Fri
Sun
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
What is this?
Less
More

Memberships

CISSP Study Group

Public • 469 • Free

CISSP Study Group+

Private • 22 • $20/m

83 contributions to CISSP Study Group
Provisionally passed last night at ~110
I'm not sure of the exact number. At 107, I had about an hour left, and I thought, okay, I have time. My god, that test was brutal. My undergrad was in math & computer science. I took very serious advanced math exams. Next to this beast, they were a kindergarten trip to the park. Other than maybe 5 "gimmes," the questions were nothing like the practice exams. The "50 hard CISSP questions" YouTube video came the closest to emulating them, but these questions were on steroids. I had no earthly idea if I was answering them correctly. I made educated guesses and hoped I guessed right. Then there were 3-5 questions that I literally had no idea how to answer, so I just blindly guessed. Hey, a 25% chance of being right >> a definite 0. I was certain I had failed. Imagine my joy when the proctor handed me that paper. I wanted to shoot off fireworks. Studying for this exam took over my life for the past 2 months, particularly the last 4-6 weeks. My study materials: - The OSG. I couldn't get through that droll thing, but I used the online test banks. - Destination CISSP book. Didn't read the whole thing because of time constraints. If I had, it probably would've helped. - 50 Hard CISSP questions. This helped A LOT. https://youtu.be/qbVY0Cg8Ntw?si=I9bpKBzhPQVtqEhq - CISSP exam cram. This helped a lot, too, especially the downloadable PowerPoints. https://youtu.be/_nyZhYnCNLA?si=ZKcYH45vFssJAX4Q - Why You Will Pass the CISSP. Not just a cheerleading video! Great accompaniment to the 50 Hard Questions video. https://youtu.be/v2Y6Zog8h2A?si=nGBn-euPo7diJ7Cc - The LearnZapp app. I got to 74% preparedness yesterday. They very recently updated it for the new exam. Well worth the $35. I have an MBA, which helped with the whole "think like a manager" thing. That whole degree was about that. As others have mentioned, the practice questions drill you on the WHAT. The exam asks you WHY ... in painful detail.
15
11
New comment 3d ago
Provisionally passed last night at ~110
0 likes • 3d
Congrats Teresa!
0 likes • 3d
LOL, I had more then 5 I had little or no idea how to answer. Your summary quantified in much better detail what I witnessed as well, the questions were no joke, mine were about 80% managerial, 2 gimmies maybe, and I was sure I failed too. Welcome to the Cissp club : )
Interview time for a ISA gig
Hey everyone, I landed a first level interview for a ISA gig with my old company, the same one who downsized me during merger, lol. Information Security Advisor function provides a single point of contact for all security-related activities for designated customer accounts. Part of the requirement is a understanding of SentinelOne. I located the videos Ill link to below. If anyone has any better ones, please link them. Another part of the requirement is firewall knowledge. I only know Sonicwall, if anyone else can link any free training to any of the firewalls below, please do, and thanks! Firewall technologies (Palo Alto, Fortinet, Cisco, Check Point, Juniper, etc)
2
4
New comment 4d ago
Interview time for a ISA gig
0 likes • 4d
Looking for training, pref free on any and all of these types: (Palo Alto, Fortinet, Cisco, Check Point, Juniper, etc)
1 like • 4d
Of course they did, thanks Vince! Thing is to pivot into this role I need luck, and a bit more experience with configuring rules on the other types of firewalls not just Sonicwall. I pent the day looking at Sentinel, 12 videos in all, every single menu, I linked to it. Next I'm going to find a Palo Alto tutorial just as detailed.
Practice Question
Gary was recently hired as the first chief information security officer (CISO) for a local government agency. The agency recently suffered a security breach and is attempting to build a new information security program. Gary would like to apply some best practices for security operations as he is designing this program. Gary is preparing to develop controls around access to root encryption keys and would like to apply a principle of security designed specifically for very sensitive operations. Which principle should he apply?
Poll
16 members have voted
1
7
New comment 2d ago
2 likes • 4d
this question is worded very closely to whats on the exam
BCP vs DRP
Good morning fellow studier's. It's 3 AM here and I just read something that honestly, felt like a huge pit of nothingness and misunderstanding opened up. I read someone's quick notes and it presented information that was completely opposite of my understanding. I just emailed them to see if it is errata and if not if they might explain. Below are some situations, are they BCP or DRP? 1) A vulnerability has been discovered by a hacker? 2) A firewall has failed? 3) Data center was destroyed by a Tsunami? 4) BIA is a part of? 5) Stakeholders should be involved in? 6) Dealing with a more immediate or specific emergency?
2
3
New comment 4d ago
0 likes • 4d
A business continuity plan (BCP) describes what steps must be taken in case of an outage or disruption, whereas a BIA identifies the risk that could prompt the outage as well as the critical business functions that could be impacted by the outage and prioritizes these for recovery. A BIA lays the foundation for a solid business continuity plan and prepares an organization for the inevitable effort required to recover from a business disruption. BCPs not only focus on technical operations (hardware/software issues) but also take into account the personnel and other resources associated with business continuity. https://shorturl.at/BsYJB
0 likes • 4d
RE: A vulnerability has been discovered by a hacker? OR A firewall has failed. I would say this would be address with a BC/DR RE: Data center was destroyed by a Tsunami. Would fall under BC then DR. BIA is a part of BCP In my opinion. Stakeholders should be involved in...all the above, they authorize pulling the trigger on implementing the DR plan in a scenario where you fail over to another site so they have to be involved early on in the plans to understand the gravity of doing that. As far as "Dealing with a more immediate or specific emergency". Depends on the depth of the emergency, if it doesnt disrupt the business operation, so DR is not triggered, then you just take care of it using the established recovery procedure you have, for the firewall for example, maybe your already mirroring it using HA : )
Cissp study questions
New Cissp study web site I just found which provides questions perhaps more aligned with what I witnessed, I posed three questions today. Take the 10 question quiz, cost is 24$ per yer which isnt bad. https://cissprep.net/
3
0
1-10 of 83
Peter Kuczynski
5
275points to level up
@peter-kuczynski-1942
CISSP(Provisional), VCP, A+,N+,Security+ DevOps Engineer

Active 3d ago
Joined May 24, 2024
Chicago
powered by