CAT Exam
Computerized Adaptive Testing; adjusts question difficulty based on answers.
Getting Started: CISSP Exam Essentials
Free knowledge base
Everything from the course in one searchable place: 391 entries. Use it to review before a practice test or look up a word you forgot.
391 results · showing first 300, refine your search
Computerized Adaptive Testing; adjusts question difficulty based on answers.
Getting Started: CISSP Exam Essentials
Percentage of exam questions allocated to a specific knowledge area.
Getting Started: CISSP Exam Essentials
Fixed set of questions, allows review, used for non-English CISSP.
Getting Started: CISSP Exam Essentials
Unscored questions used to evaluate for future exams.
Getting Started: CISSP Exam Essentials
Minimum 700 out of 1000 points required to pass CISSP.
Getting Started: CISSP Exam Essentials
International Information System Security Certification Consortium.
Getting Started: CISSP Exam Essentials
Remember the 8 domains with 'SAM Can't See All Secure Software Dev'. (Security & Risk, Asset, Comm & Net, Security Arch & Eng, Identity & Access, Security Assess & Test, Security Ops, Software Dev Security)
Getting Started: CISSP Exam Essentials
The CISSP exam for English candidates is 100-150 questions, 3 hours, and uses CAT. For non-English candidates, it is 250 questions, 6 hours, and is linear. The passing score is 700/1000 for all versions.
Getting Started: CISSP Exam Essentials
Assuming all questions count towards your score; some are pre-test items.
Getting Started: CISSP Exam Essentials
Trying to guess the difficulty of questions to determine if you are doing well; focus on each question individually.
Getting Started: CISSP Exam Essentials
Not allocating study time according to domain weighting; this can lead to under-preparation in critical areas.
Getting Started: CISSP Exam Essentials
Common Body of Knowledge; the comprehensive framework of topics for the CISSP exam.
Getting Started: CISSP Exam Essentials
A major functional area of information security within the CISSP CBK.
Getting Started: CISSP Exam Essentials
The primary textbook published by ISC2 for CISSP exam preparation.
Getting Started: CISSP Exam Essentials
Simulated exam questions used to assess knowledge and familiarize with format.
Getting Started: CISSP Exam Essentials
A structured schedule outlining topics, resources, and timelines for exam preparation.
Getting Started: CISSP Exam Essentials
An approach to exam questions prioritizing risk, business impact, and policy over technical details.
Getting Started: CISSP Exam Essentials
To remember key study steps: 'Assess, Plan, Resource, Practice, Review' – APRPR. Like 'April's Pretty Radiant, Right?'
Getting Started: CISSP Exam Essentials
The exam often tests your ability to apply concepts, not just recall facts. Look for keywords like 'MOST effective,' 'BEST course of action,' or 'FIRST step.' These indicate a need for critical thinking and often a managerial perspective, prioritizing business objectives and risk management.
Getting Started: CISSP Exam Essentials
Focusing too heavily on technical details without understanding the managerial and risk-based implications.
Getting Started: CISSP Exam Essentials
Relying on only one study resource, missing out on diverse perspectives and question styles.
Getting Started: CISSP Exam Essentials
Neglecting weaker domains, assuming strong areas will compensate for deficiencies.
Getting Started: CISSP Exam Essentials
Protecting information from unauthorized disclosure.
Foundations of Security & Risk Management
Ensuring information is accurate, complete, and unaltered.
Foundations of Security & Risk Management
Ensuring authorized access to information and systems when needed.
Foundations of Security & Risk Management
Framework for strategic security direction and oversight.
Foundations of Security & Risk Management
Moral principles guiding professional conduct in security.
Foundations of Security & Risk Management
Assurance that an action or event cannot be denied later.
Foundations of Security & Risk Management
Verifying the identity of a user or the origin of data.
Foundations of Security & Risk Management
Remember 'CIA' for 'Confidentiality, Integrity, Availability' – the core 'C'omponents 'I'n 'A'ny security system.
Foundations of Security & Risk Management
The exam often tests your ability to identify which part of the CIA triad is violated in a given scenario. For example, a DDoS attack impacts Availability, while unauthorized data viewing impacts Confidentiality.
Foundations of Security & Risk Management
Confusing Integrity with Confidentiality: Integrity is about data accuracy and completeness, not just secrecy.
Foundations of Security & Risk Management
Underestimating the importance of Availability: Downtime can be as damaging as a data breach.
Foundations of Security & Risk Management
Ignoring the role of ethics: Technical skills alone are insufficient without strong moral principles.
Foundations of Security & Risk Management
Adherence to rules, laws, regulations, or standards.
Foundations of Security & Risk Management
High-level, mandatory statements of management's intent.
Foundations of Security & Risk Management
Mandatory, specific technical or configuration requirements.
Foundations of Security & Risk Management
Detailed, step-by-step instructions for performing a task.
Foundations of Security & Risk Management
Recommendations or best practices; not mandatory.
Foundations of Security & Risk Management
EU regulation for data protection and privacy.
Foundations of Security & Risk Management
US law protecting health information privacy and security.
Foundations of Security & Risk Management
Rules established by regulatory bodies in an industry.
Foundations of Security & Risk Management
P.S.P.G. - Policies Set Procedures and Guidelines. (Remember Standards fit in between Policies and Procedures in detail level).
Foundations of Security & Risk Management
Memorize the hierarchy: Laws/Regulations > Policies > Standards > Procedures > Guidelines. The exam often tests your ability to distinguish between these levels of documentation and their mandatory nature.
Foundations of Security & Risk Management
Confusing a guideline (recommendation) with a standard (mandatory specification).
Foundations of Security & Risk Management
Underestimating the importance of legal counsel in incident response and policy development.
Foundations of Security & Risk Management
Failing to regularly review and update policies, making them obsolete or ineffective.
Foundations of Security & Risk Management
The potential for loss, damage, or destruction of an asset.
Foundations of Security & Risk Management
A potential danger that might exploit a vulnerability.
Foundations of Security & Risk Management
A weakness that can be exploited by a threat.
Foundations of Security & Risk Management
The amount of risk an organization is willing to accept.
Foundations of Security & Risk Management
Reducing the likelihood or impact of a risk.
Foundations of Security & Risk Management
Structured approach to identify and address security risks.
Foundations of Security & Risk Management
Risks introduced by third-party vendors or partners.
Foundations of Security & Risk Management
To remember the four risk treatment strategies, think of 'A.A.M.T.' - Alligators Always Make Trouble!
Foundations of Security & Risk Management
The CISSP exam frequently tests your understanding of risk treatment strategies. Remember the four main strategies: Accept, Avoid, Mitigate, and Transfer. Be able to differentiate between them and provide examples of each.
Foundations of Security & Risk Management
Confusing a threat with a vulnerability (a threat exploits a vulnerability).
Foundations of Security & Risk Management
Believing all risks must be eliminated (risk management aims for acceptable risk levels).
Foundations of Security & Risk Management
Neglecting supply chain risks, assuming third-party security is always adequate.
Foundations of Security & Risk Management
Maintaining critical business functions during disruptions.
Foundations of Security & Risk Management
Restoring IT systems after a major incident.
Foundations of Security & Risk Management
Max tolerable time for system downtime.
Foundations of Security & Risk Management
Max tolerable data loss period.
Foundations of Security & Risk Management
Fully equipped, ready-to-use recovery facility.
Foundations of Security & Risk Management
Partially equipped recovery facility, needs setup.
Foundations of Security & Risk Management
Basic infrastructure recovery facility, needs significant setup.
Foundations of Security & Risk Management
Managing human risk throughout employment lifecycle.
Foundations of Security & Risk Management
BC/DR: Business Continues, Disasters Recover. Think of BC as the CEO's concern, DR as the CIO's concern.
Foundations of Security & Risk Management
On the CISSP exam, distinguish BC from DR by their scope: BC is business-focused, DR is IT-focused. Memorize RTO (time) and RPO (data loss) definitions and their implications for recovery strategies. Understand the phases of personnel security (pre-employment, employment, termination).
Foundations of Security & Risk Management
Confusing RTO and RPO: RTO is about time, RPO is about data loss. Don't mix them up!
Foundations of Security & Risk Management
Treating BC and DR as interchangeable: They are distinct plans with different objectives, though related.
Foundations of Security & Risk Management
Neglecting personnel security after hiring: It's an ongoing process, not just a one-time check.
Foundations of Security & Risk Management
Categorizing data by sensitivity, value, and criticality.
Protecting Information Assets
Senior manager accountable for data protection and classification.
Protecting Information Assets
Implements and maintains security controls as directed by owner.
Protecting Information Assets
Individual who accesses data to perform their job duties.
Protecting Information Assets
Classification for highly sensitive business or personal data.
Protecting Information Assets
Classification often used for personally identifiable information (PII).
Protecting Information Assets
Classification for data intended for general public consumption.
Protecting Information Assets
Ensures data quality, defines data elements, and implements policies.
Protecting Information Assets
O.C.U.S.T. - Owners Classify, Users Store, Custodians Take care. (Okay, the 'U' is a stretch, but it helps remember the roles!)
Protecting Information Assets
The CISSP exam frequently tests your understanding of roles. Remember: the Data Owner is ultimately ACCOUNTABLE for the data, while the Data Custodian is RESPONSIBLE for its technical protection. Look for questions distinguishing between these accountabilities.
Protecting Information Assets
Confusing the Data Owner's accountability with the Data Custodian's responsibility. The owner is the decider, the custodian is the doer.
Protecting Information Assets
Applying a 'one-size-fits-all' security approach without proper classification, leading to either over-spending or under-protecting.
Protecting Information Assets
Failing to regularly review and update data classifications as data value or regulatory requirements change.
Protecting Information Assets
California Consumer Privacy Act/California Privacy Rights Act.
Protecting Information Assets
Embedding privacy into systems from the start.
Protecting Information Assets
Highest privacy settings applied automatically.
Protecting Information Assets
Collecting only necessary personal data.
Protecting Information Assets
Policy for how long data is kept.
Protecting Information Assets
Irreversible removal of data from media.
Protecting Information Assets
To remember the core privacy principles: T-P-D-A-S-I-A (Transparency, Purpose, Data Minimization, Accuracy, Storage, Integrity, Accountability). Think 'The Privacy Data Act Saves Individual Assets'!
Protecting Information Assets
The CISSP exam frequently tests on the core principles of GDPR and CCPA/CPRA. Memorize the seven principles of Privacy by Design and understand the difference between 'by design' (proactive integration) and 'by default' (automatic highest privacy settings).
Protecting Information Assets
Confusing privacy (individual's rights over data) with security (protecting data from threats). They are related but distinct.
Protecting Information Assets
Assuming one privacy regulation (e.g., GDPR) applies everywhere; global organizations must comply with multiple, sometimes conflicting, laws.
Protecting Information Assets
Failing to regularly review and update data retention policies, leading to unnecessary data accumulation and increased risk.
Protecting Information Assets
Policy-based safeguards like policies, procedures, and training.
Protecting Information Assets
Hardware or software mechanisms for data and system protection.
Protecting Information Assets
Tangible measures protecting physical assets and environments.
Protecting Information Assets
Data stored on media, requiring encryption and access controls.
Protecting Information Assets
Data moving across networks, secured by protocols like TLS.
Protecting Information Assets
Data actively processed by a CPU or in RAM, challenging to secure.
Protecting Information Assets
Day-to-day security procedures, like backups and logging.
Protecting Information Assets
Remember 'ATP' for the main control types: Administrative, Technical, Physical. Then add 'O' for Operational to cover the day-to-day.
Protecting Information Assets
The exam frequently tests your ability to categorize controls. Be ready to identify whether a given control is administrative, technical, or physical. Keywords like 'policy', 'encryption', 'fence' are strong indicators.
Protecting Information Assets
Confusing administrative controls with operational controls; administrative defines 'what to do', operational defines 'how to do it' daily.
Protecting Information Assets
Underestimating the importance of physical controls; a strong firewall is useless if someone can walk away with the server.
Protecting Information Assets
Forgetting to consider data in use; many focus on data at rest and in transit, but data in memory is also vulnerable.
Protecting Information Assets
Data actively being used by a system, application, or user.
Protecting Information Assets
Policy-based approach to managing data from creation to destruction.
Protecting Information Assets
Systems preventing unauthorized transmission of sensitive data.
Protecting Information Assets
Transforming data to protect confidentiality and integrity.
Protecting Information Assets
Secure, irreversible removal of data from storage media.
Protecting Information Assets
Remember the three states of data with 'R.I.P.': Rest, In Transit, Processing.
Protecting Information Assets
The exam expects you to differentiate between data states and apply appropriate security controls for each. Keywords to spot include 'encryption at rest,' 'TLS/SSL,' 'access controls,' and 'secure destruction.' Remember that data in processing is often protected by OS and application controls.
Protecting Information Assets
Confusing data states with data lifecycle phases; they are related but distinct concepts.
Protecting Information Assets
Assuming encryption alone is sufficient for all data states; access controls and other measures are also vital.
Protecting Information Assets
Neglecting the secure destruction phase, leading to potential data leakage from discarded media.
Protecting Information Assets
A secure cryptoprocessor that stores cryptographic keys and measures system integrity.
Designing Secure Systems
An immutable, inherently trusted hardware component that forms the basis of a secure system.
Designing Secure Systems
Registers within a TPM that store cryptographic hashes of system components for integrity checks.
Designing Secure Systems
A security model focused on confidentiality, preventing unauthorized information flow downwards.
Designing Secure Systems
A security model focused on integrity, preventing unauthorized information flow upwards.
Designing Secure Systems
A security feature that encrypts all data on a hard drive, protecting it from unauthorized access.
Designing Secure Systems
A process that ensures only trusted software (firmware, OS) can load during system startup.
Designing Secure Systems
To remember Bell-LaPadula's rules: 'Bell's Confidentiality: No Reading Up, No Writing Down.' Think of a 'bell' ringing to keep secrets contained.
Designing Secure Systems
The CISSP exam frequently tests the core functions of the TPM, especially its role in providing a hardware root of trust, secure key storage, and integrity measurement using PCRs. Be ready to distinguish between confidentiality (Bell-LaPadula) and integrity (Biba) models.
Designing Secure Systems
Confusing the Bell-LaPadula (confidentiality) and Biba (integrity) models; remember their primary goals.
Designing Secure Systems
Underestimating the importance of a hardware root of trust; it's the foundation, not just an add-on.
Designing Secure Systems
Believing software-only encryption provides the same level of protection as hardware-backed encryption with a TPM.
Designing Secure Systems
A standard awareness document for web application security.
Designing Secure Systems
Attack inserting malicious SQL queries into input fields.
Designing Secure Systems
Injecting malicious scripts into web pages viewed by others.
Designing Secure Systems
Exploiting deserialization of untrusted data to execute code.
Designing Secure Systems
Bypassing mobile OS restrictions to gain elevated access.
Designing Secure Systems
Low-level software embedded in hardware devices.
Designing Secure Systems
Application Programming Interface; defines interactions between software.
Designing Secure Systems
For OWASP Top 10, think 'I BROKE SADLY, X-RAYING INSECURE COMPONENTS.' (Injection, Broken Auth, Sensitive Data, XML External Entities, Broken Access, Security Misconfiguration, Cross-Site Scripting, Insecure Deserialization, Using Components with Known Vulnerabilities, Insufficient Logging & Monitoring)
Designing Secure Systems
The CISSP exam frequently tests your knowledge of the OWASP Top 10. Memorize the categories and understand the general nature of each vulnerability, not just the names. Also, understand the unique security challenges presented by mobile and IoT devices due to their resource constraints and deployment environments.
Designing Secure Systems
Underestimating the impact of architectural flaws, which are often the hardest to remediate.
Designing Secure Systems
Focusing solely on code-level vulnerabilities and neglecting configuration or deployment issues.
Designing Secure Systems
Assuming mobile or IoT devices are inherently secure due to their small size or limited functionality.
Designing Secure Systems
Single secret key used for both encryption and decryption.
Designing Secure Systems
Public/private key pair; one encrypts, the other decrypts.
Designing Secure Systems
Freely shared key in an asymmetric pair, used for encryption or signature verification.
Designing Secure Systems
Secret key in an asymmetric pair, used for decryption or digital signing.
Designing Secure Systems
Advanced Encryption Standard, a widely used symmetric encryption algorithm.
Designing Secure Systems
Rivest-Shamir-Adleman, a common asymmetric encryption algorithm.
Designing Secure Systems
Combines symmetric and asymmetric methods for efficiency and security.
Designing Secure Systems
Symmetric is for SPEED (Single key), Asymmetric is for SECURE EXCHANGE (Two keys).
Designing Secure Systems
The CISSP exam frequently tests the *purpose* and *use cases* of symmetric vs. asymmetric cryptography. Remember that asymmetric solves the key distribution problem, while symmetric is faster for bulk data. Keywords to spot: 'bulk encryption' often points to symmetric; 'key exchange' or 'digital signatures' often points to asymmetric.
Designing Secure Systems
Confusing the speed and efficiency of symmetric vs. asymmetric algorithms.
Designing Secure Systems
Misunderstanding that asymmetric encryption is primarily for key exchange and digital signatures, not bulk data encryption.
Designing Secure Systems
Neglecting the importance of key management for both types of cryptography.
Designing Secure Systems
Approach embedding privacy into system design and operations.
Designing Secure Systems
Protecting physical assets from unauthorized access, damage, or theft.
Designing Secure Systems
Reusable solution to a common security problem in architecture.
Designing Secure Systems
Common design mistake leading to vulnerabilities.
Designing Secure Systems
Layering multiple security controls to protect assets.
Designing Secure Systems
Two-door entry system preventing tailgating.
Designing Secure Systems
For PbD: 'Proactive Privacy Embedded Fully, End-to-End, Visible, Respectful.'
Designing Secure Systems
Memorize the 7 Foundational Principles of Privacy by Design (PbD) and be able to distinguish them from other security principles. Also, understand that the OWASP Top 10 is a list of common risks, not a comprehensive standard.
Designing Secure Systems
Assuming physical security is 'someone else's job' and not integrating it into overall security planning.
Designing Secure Systems
Treating OWASP Top 10 as a checklist to 'pass' rather than a guide for continuous secure development.
Designing Secure Systems
Implementing privacy features as an afterthought or only to meet minimum compliance, rather than embedding them by design.
Designing Secure Systems
Suite of protocols securing IP communications.
Securing Networks and Communications
IPsec protocol for integrity and authentication.
Securing Networks and Communications
IPsec protocol for confidentiality, integrity, authentication.
Securing Networks and Communications
IPsec mode encrypting entire original IP packet.
Securing Networks and Communications
Separates network control from data plane.
Securing Networks and Communications
Defines parameters for secure IPsec communication.
Securing Networks and Communications
IPsec: I Protect Secure Encrypted Communications. Remember ESP for Everything (Encryption, Security, Protection) and AH for Authentication Only (no encryption).
Securing Networks and Communications
Memorize the core functions of AH (integrity, authentication) versus ESP (confidentiality, integrity, authentication) for IPsec. The exam often tests your understanding of which protocol provides which service. Also, distinguish between Tunnel and Transport modes.
Securing Networks and Communications
Confusing IPsec Transport mode with Tunnel mode applications.
Securing Networks and Communications
Believing AH provides confidentiality (it does not).
Securing Networks and Communications
Underestimating the security benefits of SDN's centralized control.
Securing Networks and Communications
Device that forwards data packets between computer networks.
Securing Networks and Communications
Device that connects devices within a local area network (LAN).
Securing Networks and Communications
Monitors and controls network traffic based on security rules.
Securing Networks and Communications
Detects (IDS) or prevents (IPS) malicious network activity.
Securing Networks and Communications
Wireless Access Point; connects wireless devices to a wired network.
Securing Networks and Communications
Dividing a network into smaller, isolated sub-networks.
Securing Networks and Communications
Process of securing a system by reducing its attack surface.
Securing Networks and Communications
IEEE standard for port-based network access control.
Securing Networks and Communications
R-S-F-I-W-S-H: **R**eally **S**ecure **F**irewalls **I**nside **W**ireless **S**egmented **H**omes. (Routers, Switches, Firewalls, IDS/IPS, WAPs, Segmentation, Hardening)
Securing Networks and Communications
The exam will test your understanding of the *purpose* and *placement* of devices like firewalls, IDS/IPS, and WAPs, as well as specific hardening techniques. Keywords to spot include 'least privilege' applied to device access, 'defense in depth' for layered security, and 'single point of failure' avoidance.
Securing Networks and Communications
Leaving default credentials on network devices, creating an easy entry point for attackers.
Securing Networks and Communications
Failing to update firmware and software regularly, leaving devices vulnerable to known exploits.
Securing Networks and Communications
Not segmenting networks, allowing a breach in one area to easily spread throughout the entire infrastructure.
Securing Networks and Communications
Cryptographic protocol for secure communication over a network.
Securing Networks and Communications
HTTP secured by TLS/SSL for encrypted web communication.
Securing Networks and Communications
Protocol for secure remote network services over an unsecured network.
Securing Networks and Communications
Standard for encrypting and signing email messages.
Securing Networks and Communications
Adds cryptographic security to the DNS protocol.
Securing Networks and Communications
Provides encryption and authentication for real-time audio/video.
Securing Networks and Communications
Digital document used to verify the ownership of a public key.
Securing Networks and Communications
To remember key secure protocols: 'SSH-S-TLS-DNS' - Secure Shell, S/MIME, TLS, DNSSEC. Each protects a different communication aspect!
Securing Networks and Communications
The exam often tests the *purpose* of protocols. For example, if a question asks about securing web traffic, think HTTPS/TLS. If it's about secure remote access, think SSH. Know which layer (transport vs. application) each protocol generally operates at.
Securing Networks and Communications
Confusing the OSI layer where a protocol operates (e.g., thinking SSH is transport layer when it's application layer).
Securing Networks and Communications
Not understanding the difference between FTPS (FTP over SSL/TLS) and SFTP (SSH File Transfer Protocol).
Securing Networks and Communications
Assuming all secure protocols provide the same security services; each has specific strengths and weaknesses.
Securing Networks and Communications
An attack to make a machine or network resource unavailable to its intended users.
Securing Networks and Communications
A DoS attack launched from numerous compromised systems (botnet).
Securing Networks and Communications
An attacker intercepts and potentially alters communication between two parties.
Securing Networks and Communications
Secretly listening to private communication, often via network sniffing.
Securing Networks and Communications
A network of private computers infected with malicious software and controlled as a group.
Securing Networks and Communications
A tool used to capture and analyze network traffic.
Securing Networks and Communications
Monitors network traffic for malicious activity and takes action to prevent it.
Securing Networks and Communications
To remember attack types: 'DDoS' is 'Distributed' and 'Disruptive'. 'MitM' is 'Middle' and 'Malicious' interception.
Securing Networks and Communications
The CISSP exam frequently tests the distinction between DoS and DDoS (single vs. multiple sources), and the primary defense mechanisms for each. Pay attention to the 'intent' of the attack (e.g., disruption vs. data theft).
Securing Networks and Communications
Confusing DoS with DDoS: DoS is from a single source, DDoS from multiple.
Securing Networks and Communications
Underestimating the importance of encryption: Many attacks rely on unencrypted traffic.
Securing Networks and Communications
Believing a single security tool is sufficient: A layered defense is always necessary.
Securing Networks and Communications
Restricts entry to physical spaces and assets.
Managing Identities and Access
Restricts access to computer systems and data.
Managing Identities and Access
Users get minimum access needed for their job.
Managing Identities and Access
Prevents one person from completing critical tasks alone.
Managing Identities and Access
Requires two or more verification methods.
Managing Identities and Access
A list of permissions attached to an object.
Managing Identities and Access
Access based on user's role within an organization.
Managing Identities and Access
P-L-A-N: Physical, Logical, And Network. Remember you need to secure all three layers for complete protection.
Managing Identities and Access
The CISSP exam frequently tests the integration of physical and logical security. Look for questions that describe a scenario and ask for the *most comprehensive* or *most effective* control, which often implies a combined approach. Memorize that physical controls are 'something you can touch' and logical controls are 'something you can configure'.
Managing Identities and Access
Assuming strong logical controls compensate for weak physical security, or vice-versa.
Managing Identities and Access
Failing to regularly review and update both physical and logical access permissions.
Managing Identities and Access
Implementing controls in isolation without considering their interaction and potential gaps.
Managing Identities and Access
Claiming an identity to a system.
Managing Identities and Access
Verifying the claimed identity.
Managing Identities and Access
Determining what an authenticated user can do.
Managing Identities and Access
An authentication factor like a password or PIN.
Managing Identities and Access
An authentication factor like a token or smart card.
Managing Identities and Access
An authentication factor like a fingerprint or retina scan.
Managing Identities and Access
Remember 'IAA' as 'I Am Allowed' – first, I identify myself, then I prove I am who I say, then I'm allowed to do things.
Managing Identities and Access
The CISSP exam frequently tests the order and distinction of IAA. Remember: Identify, then Authenticate, then Authorize. Keywords to spot include 'verify identity' (authentication) vs. 'grant permissions' (authorization).
Managing Identities and Access
Confusing authentication with authorization: Authentication is *who* you are, authorization is *what* you can do.
Managing Identities and Access
Believing identification alone is sufficient for security: Identification must always be followed by authentication.
Managing Identities and Access
Underestimating the importance of multi-factor authentication: Single-factor authentication is easily compromised.
Managing Identities and Access
Cloud-based service offering identity and access management capabilities.
Managing Identities and Access
XML standard for exchanging authentication and authorization data.
Managing Identities and Access
Identity layer built on top of the OAuth 2.0 protocol.
Managing Identities and Access
Open standard for access delegation, granting limited access.
Managing Identities and Access
Using stolen credentials from one breach to try logging into other services.
Managing Identities and Access
Allows users to authenticate once and access multiple applications.
Managing Identities and Access
Method allowing users to authenticate across multiple, independent systems.
Managing Identities and Access
To remember the key identity protocols, think: 'SAML is for Security Assertions, OIDC is for OpenID (identity), and OAuth is for Authorization.'
Managing Identities and Access
The CISSP exam frequently tests your understanding of the benefits and risks of IDaaS and third-party identity providers. Be prepared to identify common protocols like SAML, OIDC, and OAuth, and their specific purposes. Also, know the attack vectors like credential stuffing and phishing, and their countermeasures.
Managing Identities and Access
Assuming IDaaS automatically solves all identity security problems without proper configuration or due diligence.
Managing Identities and Access
Neglecting to implement MFA even when using IDaaS or third-party identity services.
Managing Identities and Access
Failing to conduct regular audits and reviews of third-party identity provider security practices and compliance.
Managing Identities and Access
Creating user accounts and assigning initial access.
Managing Identities and Access
Revoking access and disabling/deleting user accounts.
Managing Identities and Access
Modifying access rights due to role or status changes.
Managing Identities and Access
An active account no longer linked to an active user.
Managing Identities and Access
Policies and processes for managing digital identities.
Managing Identities and Access
Identity and Access Management; systems for managing identities.
Managing Identities and Access
P-R-R-D: 'People Rarely Remember Details' to recall the stages: Provisioning, Review, Reprovisioning, Deprovisioning.
Managing Identities and Access
The exam often tests your understanding of the 'cradle-to-grave' management of identities. Look for questions about the security implications of neglecting any stage, especially deprovisioning. Remember that automated processes are generally preferred for efficiency and security over manual ones.
Managing Identities and Access
Forgetting to deprovision accounts promptly, leading to security vulnerabilities.
Managing Identities and Access
Granting excessive privileges during provisioning, violating the principle of least privilege.
Managing Identities and Access
Failing to conduct regular access reviews, allowing stale or unnecessary access to persist.
Managing Identities and Access
A record of events within a system.
Security Operations Fundamentals
Continuous review of system activities for anomalies.
Security Operations Fundamentals
Security Information and Event Management system.
Security Operations Fundamentals
Security Orchestration, Automation, Response platform.
Security Operations Fundamentals
Indicator of Compromise, evidence of a breach.
Security Operations Fundamentals
Documented history of evidence handling.
Security Operations Fundamentals
Scientific process of collecting and analyzing digital evidence.
Security Operations Fundamentals
Predefined automated actions in SOAR.
Security Operations Fundamentals
L.M.S.I.F.R. - Logs Make Security Investigations Fun, Right? (Logging, Monitoring, SIEM, Investigations, Forensics, Reporting)
Security Operations Fundamentals
For the CISSP exam, memorize the typical phases of an incident response process (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) and understand the distinct roles of SIEM (detection, correlation) vs. SOAR (automation, orchestration).
Security Operations Fundamentals
Not retaining logs for a sufficient period, leading to gaps in investigation data.
Security Operations Fundamentals
Failing to establish a clear chain of custody for digital evidence, making it inadmissible.
Security Operations Fundamentals
Over-relying on automated tools without human oversight, leading to missed threats or false positives.
Security Operations Fundamentals
Safeguarding assets to ensure CIA.
Security Operations Fundamentals
Proactive measures to stop security incidents.
Security Operations Fundamentals
Systematic handling of security incidents.
Security Operations Fundamentals
Documented procedures for incident handling.
Security Operations Fundamentals
Limiting an incident's scope and impact.
Security Operations Fundamentals
Removing the root cause of an incident.
Security Operations Fundamentals
Restoring systems to normal operations.
Security Operations Fundamentals
P-D-C-E-R-P: 'Please Don't Cause Every Robot Pain' helps remember Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.
Security Operations Fundamentals
Memorize the phases of the incident management lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) as they are frequently tested in order and purpose. Look for questions asking about the 'next step' or 'primary goal' of a specific phase.
Security Operations Fundamentals
Confusing incident prevention with incident response; prevention is proactive, response is reactive.
Security Operations Fundamentals
Failing to regularly test the Incident Response Plan (IRP), leading to ineffective response during a real incident.
Security Operations Fundamentals
Neglecting the 'lessons learned' phase, missing opportunities for continuous improvement.
Security Operations Fundamentals
Systematic process of applying software updates to fix bugs and vulnerabilities.
Security Operations Fundamentals
Process of identifying and quantifying security weaknesses in systems and applications.
Security Operations Fundamentals
Formal process for controlling all changes to IT infrastructure and services.
Security Operations Fundamentals
Authorized simulated attack to exploit vulnerabilities and test security defenses.
Security Operations Fundamentals
A list of publicly disclosed cybersecurity vulnerabilities.
Security Operations Fundamentals
The act of correcting or fixing a identified security vulnerability.
Security Operations Fundamentals
The sum of all points where an unauthorized user can try to enter or extract data from an environment.
Security Operations Fundamentals
P.V.C. for Security: Patches, Vulnerabilities, Changes. Think of PVC pipes – strong and secure when properly managed!
Security Operations Fundamentals
The CISSP exam frequently tests the *order* of operations within these processes. Memorize the typical sequence for patch deployment and change management. Also, clearly distinguish between vulnerability scanning (identification) and penetration testing (exploitation/validation).
Security Operations Fundamentals
Skipping testing of patches in a non-production environment, leading to system outages.
Security Operations Fundamentals
Confusing vulnerability scanning with penetration testing; one identifies, the other exploits.
Security Operations Fundamentals
Bypassing the formal change management process for 'quick fixes,' introducing unmanaged risks.
Security Operations Fundamentals
Plan to maintain business functions during disruption.
Security Operations Fundamentals
Plan to restore IT systems after a disaster.
Security Operations Fundamentals
Identifies critical functions and impact of their loss.
Security Operations Fundamentals
RTO is 'Time' (how long till back online), RPO is 'Point' (how much data can be lost).
Security Operations Fundamentals