CISSP Exam Cram 2

Paperback (BK&CD-ROM)
$33.92
BN.com price
$34.99 List Price (Save 3%)
Marketplace (New and Used)
from
$1.07
$34.99 List Price (Save 97%)
All (23)  
Used (15)  
New (8)  
Close
Sort by
Page 1 of 3
Showing 1 – 10 of 23 (3 pages)
$1.07
(Save 97%)
Seller since 2009

Feedback rating:

(1778)

Condition:

New — never opened or used in original packaging.

Like New — packaging may have been opened. A "Like New" item is suitable to give as a gift.

Very Good — may have minor signs of wear on packaging but item works perfectly and has no damage.

Good — item is in good condition but packaging may have signs of shelf wear/aging or torn packaging. All specific defects should be noted in the Comments section associated with each item.

Acceptable — item is in working order but may show signs of wear such as scratches or torn packaging. All specific defects should be noted in the Comments section associated with each item.

Used — An item that has been opened and may show signs of wear. All specific defects should be noted in the Comments section associated with each item.

Refurbished — A used item that has been renewed or updated and verified to be in proper working condition. Not necessarily completed by the original manufacturer.

Like New
10/2/2005 Paperback Fine 078973446X Very little wear on corners and edges, book might be slightly bent or rubbing on cover. Ships Within 24 Hours. Tracking Number available for ... all USA orders. Excellent Customer Service. Upto 15 Days 100% Money Back Gurantee. Try Our Fast! ! ! ! Shipping With Tracking Number. Read more Show Less

Ships from: Bensalem, PA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.08
(Save 97%)
Seller since 2005

Feedback rating:

(1228)

Condition: Acceptable
2005 Paperback Fair This is a used book. Potential defects may exist (folds, creases, highlighting, writing/markings, staining, stickers and/or sticker residue, ETC. ) COAS ... Books, A Bookstore for Everyone. Buy with confidence-Satisfaction Guaranteed! Read more Show Less

Ships from: Las Cruces, NM

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.09
(Save 97%)
Seller since 2011

Feedback rating:

(317)

Condition: Like New
PAPERBACK Fine 078973446X Very little wear on corners and edges, book might be slightly bent or rubbing on cover. FROM A COMPANY YOU TRUST, HUGE SELECTION. RELIABLE CUSTOMER ... SERVICE! ! HASSLE FREE RETURN POLICY, SATISFACTION GURANTEED**** Read more Show Less

Ships from: Philadelphia, PA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.99
(Save 94%)
Seller since 2006

Feedback rating:

(6084)

Condition: Very Good
Pap/Cdr. 2005 Paperback. Orders usually ship on or before next business day. May have highlighting. We send best copy available.

Ships from: Murray, KY

Usually ships in 1-2 business days

  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.99
(Save 94%)
Seller since 2012

Feedback rating:

(1010)

Condition: Good
Book has a small amount of wear visible on the binding, cover, pages. Free State Books. Never settle for less.

Ships from: Halethorpe, MD

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.99
(Save 94%)
Seller since 2010

Feedback rating:

(1296)

Condition: Good
Book has a small amount of wear visible on the binding, cover, pages. Selection as wide as the Mississippi.

Ships from: St Louis, MO

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.99
(Save 94%)
Seller since 2007

Feedback rating:

(5906)

Condition: Acceptable
Ex-Library book - will contain library markings. Millions of satisfied customers and climbing. Thriftbooks is the name you can trust, guaranteed. Spend Less. Read More.

Ships from: Auburn, WA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$1.99
(Save 94%)
Seller since 2009

Feedback rating:

(8063)

Condition: Like New
Book almost like new. Cover and pages are undamaged. A tradition of southern quality and service. All books guaranteed at the Atlanta Book Company. Our mailers are 100% ... recyclable. Read more Show Less

Ships from: Atlanta, GA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$3.65
(Save 90%)
Seller since 2012

Feedback rating:

(6)

Condition: Like New
PAPERBACK Fine 078973446X Ships within 24 hours. Best customer service. 100% money back return policy. May have a remainder mark.

Ships from: Churchville, PA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$3.86
(Save 89%)
Seller since 2011

Feedback rating:

(317)

Condition: New
PAPERBACK New 078973446X FROM A COMPANY YOU TRUST, HUGE SELECTION. RELIABLE CUSTOMER SERVICE! ! HASSLE FREE RETURN POLICY, SATISFACTION GURANTEED****

Ships from: Philadelphia, PA

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
Page 1 of 3
Showing 1 – 10 of 23 (3 pages)
Close
Sort by

Overview

A new edition of this title is available, ISBN-10: 0789738066 ISBN-13: 9780789738066

 

Learn what you need to know to master the CISSP security technology and the certification exam with the CISSP Exam Cram 2. A perfect compliment to larger study guides, the CISSP Exam Cram 2 is a great way to find out exactly what will be expected of you during the real exam. The book includes:

  • Exam topic-focused chapters.
  • ...
See more details below
Sending request ...

Overview

A new edition of this title is available, ISBN-10: 0789738066 ISBN-13: 9780789738066

 

Learn what you need to know to master the CISSP security technology and the certification exam with the CISSP Exam Cram 2. A perfect compliment to larger study guides, the CISSP Exam Cram 2 is a great way to find out exactly what will be expected of you during the real exam. The book includes:

  • Exam topic-focused chapters.
  • Practice questions at the end of each chapter.
  • Exam Alerts that highlight key terms and areas.
  • Two full-length practice exams.
  • An electronic test engine provided by MeasureUp on CD-ROM with additional practice exams.
  • The "Cram Sheet" tearcard for last minute exam review.

Prepare for the CISSP certification exam with the proven Exam Cram 2 learning tools provided in the CISSP Exam Cram 2.

 

Product Details

  • ISBN-13: 9780789734464
  • Publisher: Que
  • Publication date: 9/28/2005
  • Edition description: BK&CD-ROM
  • Pages: 351
  • Series: Exam Cram 2 Series
  • Product dimensions: 6.00 (w) x 9.02 (h) x 0.88 (d)

Meet the Author

Michael Gregg, CISSP is the president of Superior Solutions, Inc., a Houston based training and consulting firm. He has more than 20 years experience in the IT field. He holds two associate's degrees, a bachelor's degree, and a master's degree. He presently maintains the following certifications: CISSP, MCSE, MCT, CTT+, A+, N+, Security+, CNA, CCNA, CIW Security Analyst, CCE, CEH, CHFI, CEI, DCNP, ES Dragon IDS, ES Advanced Dragon IDS, and TICSA. He has consulted and taught for many organizations, and he is a 9-time winner of Global Knowledge's Perfect Instructor Award. He is the author of the Que publication CISSP Practice Questions Exam Cram 2.

Table of Contents

1. The CISSP Certification Exam.

    Introduction.

    Assessing Exam Readiness.

    Taking the Exam.

    Multiple-Choice Question Format.

    Exam Strategy.

    Question-Handling Strategies.

    Mastering the Inner Game.

    Need to Know More?

2. Physical Security.

    Introduction.

    Physical Security Risks.

      Natural Disasters.

      Man-Made Threats.

      Emergency Situations.

    Requirements for New Site Locations.

      Location.

      Construction.

      Doors, Walls, Windows, and Ceilings.

    Building Defense in Depth.

      Perimeter Controls.

      Server Placement.

      Intrusion Detection.

    Environmental Controls.

    Electrical Power.

      Uninterruptible Power Supply (UPS).

    Equipment Life Cycle.

    Fire Prevention, Detection, and Suppression.

      Fire-Detection Equipment.

      Fire Suppression.

    Exam Prep Questions.

    Answers to Exam PrepQuestions.

    Need to Know More?

3. Security-Management Practices.

    Introduction.

    The Risk of Poor Security Management.

    The Role of CIA.

    Risk Assessment.

      Risk Management.

    Policies, Procedures, Standards, Baselines, and Guidelines.

      Security Policy.

      Standards.

      Baselines.

      Guidelines.

      Procedures.

    Implementation.

      Data Classification.

      Roles and Responsibility.

      Security Controls.

    Training and Education.

      Security Awareness.

    Auditing Your Security Infrastructure.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

4. Access-Control Systems and Methodology.

    Introduction.

    Threats Against Access Control.

      Password Attacks.

      Emanation Security.

      Denial of Service/Distributed Denial of Service (DoS/DDoS).

    Access-Control Types.

      Administrative Controls.

      Technical Controls.

      Physical Controls.

    Identification, Authentication, and Authorization.

      Authentication.

    Single Sign-On.

      Kerberos.

      SESAME.

      Access-Control Models.

    Data Access Controls.

      Discretionary Access Control (DAC).

      Mandatory Access Control (MAC).

      Role-Based Access Control (RBAC).

      Other Types of Access Controls.

    Intrusion-Detection Systems (IDS).

      Network-Based Intrusion-Detection Systems (NIDS).

      Host-Based Intrusion-Detection Systems (HIDS).

      Signature-Based and Behavior-Based IDS Systems.

    Penetration Testing.

    Honeypots.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

5. System Architecture and Models.

    Introduction.

    Common Flaws in the Security Architecture.

      Buffer Overflow.

      Back Doors.

      Asynchronous Attacks.

      Covert Channels.

      Incremental Attacks.

    Computer System Architecture.

      Central Processing Unit (CPU).

      Storage Media.

    Security Mechanisms.

      Process Isolation.

      Operation States.

      Protection Rings.

      Trusted Computer Base.

    Security Models of Control.

      Integrity.

      Confidentiality.

      Other Models.

      Open and Closed Systems.

    Documents and Guidelines.

      The Rainbow Series.

      The Red Book: Trusted Network Interpretation.

      Information Technology Security Evaluation Criteria (ITSEC).

      Common Criteria.

      British Standard 7799.

    System Validation.

      Certification and Accreditation.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

6. Telecommunications and Network Security.

    Introduction.

    Threats to Network Security.

      DoS Attacks.

      Disclosure Attacks.

      Destruction, Alteration, or Theft.

    LANs and Their Components.

      LAN Communication Protocols.

      Network Topologies.

      LAN Cabling.

      802.11 Wireless Networking.

      Bluetooth.

    WANS and Their Components.

      Packet Switching.

      Circuit Switching.

    Network Models and Standards.

      OSI Model.

      TCP/IP.

    Network Equipment.

      Hubs.

      Bridges.

      Switches.

      Routers.

    Access Methods and Remote Connectivity.

      Point-to-Point Protocol (PPP).

      Password Authentication Protocol (PAP).

      Virtual Private Networks (VPNs).

      Remote Authentication Dial-in User Service (RADIUS).

      Terminal Access Controller Access Control System (TACACS).

      IPSec.

    Message Privacy.

      PGP.

      S/MIME.

      Privacy Enhanced Mail (PEM).

    Network Access Controls.

      Firewalls.

      Demilitarized Zone (DMZ).

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

7. Applications and Systems-Development Security.

    Introduction.

    Malicious Code.

      Viruses and Worms.

      Buffer Overflow.

      Denial of Service (DoS).

      Distributed Denial of Service (DDoS).

      Malformed Input (SQL Injection).

      Spyware.

      Back Doors and Trapdoors.

      Change Detection.

    Failure States.

    The System Development Life Cycle.

      Project Initiation.

      Development and Acquisition.

      Acceptance Testing/Implementation.

      Operations/Maintenance.

      Disposal.

    Software-Development Methods.

      The Waterfall Model.

      The Spiral Model.

      Joint Application Development (JAD).

      Rapid Application Development (RAD).

      Computer-Aided Software Engineering (CASE).

    Change Management.

    Programming Languages.

      Object-Oriented Programming.

      CORBA.

    Database Management.

      Transaction Processing.

      Database Terms.

      Data Warehousing.

      Data Mining.

      Knowledge Management.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

8. Operations Security.

    Introduction.

    Hack Attacks.

      Common Attack Methodologies.

      Phreakers and Their Targets.

    Operational Security.

      New-Hire Orientation.

      Separation of Duties.

      Job Rotation.

      Least Privilege.

      Mandatory Vacations.

      Termination.

    Auditing and Monitoring.

      Auditing.

      Clipping Levels.

      Intrusion Detection.

      Keystroke Monitoring.

      Facility Access Control.

    Categories of Control.

    Fax Control.

    Ethical Hacking.

      Penetration Testing.

    Contingency Planning, Backup, and Recovery.

      RAID.

      Backups.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

9. Business Continuity Planning.

    Introduction.

    The Risks of Poor Business Planning.

    Business Continuity Management.

    Business Continuity Plan (BCP).

      Project Management and Initiation.

      Business Impact Analysis (BIA).

      Recovery Strategy.

      Plan Design and Development.

      Testing, Maintenance, Awareness, and Training.

    Disaster Recovery Planning (DRP).

      Alternative Sites and Hardware Backup.

      Software Backups.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

10. Law, Investigations, and Ethics.

    Introduction.

    Computer Crimes.

      Software Piracy.

      Terrorism.

      Pornography.

    Common Attacks.

      Keystroke Logging.

      Wiretapping.

      Spoofing Attacks.

      Manipulation Attacks.

      Social Engineering.

      Dumpster Diving.

    Ethics.

      ISC2 Code of Ethics.

      Computer Ethics Institute.

      Internet Activities Board.

    International Property Laws.

      Privacy Laws.

    Parameters of Investigation.

      Computer Crime Investigation.

      Incident-Response Procedures.

      Incident-Response Team.

    Forensics.

      Handling Evidence.

      Drive Wiping.

      Standardization of Forensic Procedures.

    Major Legal Systems.

      Evidence Types.

      Trial.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

11. Cryptography.

    Introduction.

    Cryptographic Basics.

    History of Encryption.

    Symmetric Encryption.

      Data Encryption Standard (DES).

      Triple-DES (3DES).

      Advanced Encryption Standard (AES).

      International Data Encryption Algorithm (IDEA).

      Other Symmetric Algorithms.

    Asymmetric Encryption.

      RSA.

      Diffie-Hellman.

      El Gamal.

      Elliptical Curve Cryptosystem (ECC).

      Merkle-Hellman Knapsack.

    Integrity and Authentication.

      Message Digests.

      MD Series.

      Digital Signatures.

    Steganography.

    Public Key Infrastructure (PKI).

      Certificate Authority (CA).

      Registration Authority (RA).

      Certificate Revocation List (CRL).

      Digital Certificates.

      The Client’s Role in PKI.

    Cryptographic Services.

      Secure Email.

      Secure TCP/IP Protocols.

    Cryptographic Attacks.

    Exam Prep Questions.

    Answers to Exam Prep Questions.

    Need to Know More?

12. Practice Exam 1.

    Practice Exam Questions.

13. Answers to Practice Exam 1.

    Answer Key.

    Answers to Practice Exam Questions.

14. Practice Exam 2.

    Practice Exam Questions.

15. Answers to Practice Exam 2.

    Answer Key.

    Answers to Practice Exam Questions.

Appendix A: What’s on the CD.

    Multiple Test Modes.

      Study Mode.

      Certification Mode.

      Custom Mode.

      Adaptive Mode.

      Missed Question Mode.

      Non-Duplicate Mode.

    Question Types.

    Random Questions and Order of Answers.

    Detailed Explanations of Correct and Incorrect Answers.

    Attention to Exam Objectives.

    Installing the CD.

      Creating a Shortcut to the MeasureUp Practice Tests.

    Technical Support.

Glossary.

Index.

Preface

CISSP Exam Cram 2Introduction

Welcome to CISSP Exam Cram 2! This book covers the CISSP certification exam. Whether this is your first or your fifteenth Exam Cram 2, you'll find information here and in Chapter 1 that will ensure your success as you pursue knowledge, experience, and certification. This introduction explains the ISC2 certification programs in general and talks about how the Exam Cram 2 series can help you prepare for the CISSP exam.

This book is one of the Exam Cram 2 series of books and will help by getting you on you way to becoming an ISC2 Certified Information Systems Security Professional (CISSP).

This introduction discusses the basics of the CISSP exam. Included are sections covering preparation, how to take an exam, a description of this book's contents, how this book is organized, and, finally, author contact information.

Each chapter in this book contains practice questions. There are also two full-length practice exams at the end of the book. Practice exams in this book should provide an accurate assessment of the level of expertise you need to obtain to pass the test. Answers and explanations are included for all test questions. It is best to obtain a level of understanding equivalent to a consistent pass rate of at least 95% or more on the practice questions and exams in this book before you attempt the real exam.

Let's begin by looking at preparation for the exam.

How to Prepare for the Exam

Preparing for the CISSP exam requires that you obtain and study materials designed to provide comprehensive information about security. The following list of materialswill help you study and prepare:

  • The ISC2 website, at http://www.isc2.org

  • The study guide available at the ISC2 website

  • The CISSP open study guide website, at http://www.cccure.org

Many people form study groups to help them study for and master the material needed to pass the CISSP exam.

Practice Tests

You don't need to know much about practice tests, other than that they are a worthwhile expense for three reasons. First, they help you diagnose areas of weakness. Second, they are useful for getting used to the format of questions. Third, they help you to decide when you are ready to take the exam. This book contains questions at the end of each chapter and includes two full-length practice tests. However, if you still want more, a related Exam Cram 2 CISSP Practice Questions Exam book has more than 500 additional questions. The questions are in paper form so that you can practice in an environment similar to the real exam; they are also available electronically as a practice test CD in the back of the book. Many other companies provide CISSP certification practice tests as well.

Taking a Certification Exam

When you have prepared for the exam, you must register with ISC2 to take the exam. The CISSP exam is given throughout the year at various locations. You can find the latest scheduleat http://www.isc2.org/cgi-bin/exam_schedule.cgi?displaycategory=1182.Many peopledecideto travelto theexam location;otherswait untilit isgivenat a locationcloserto them.ISC2 hasimplementedregionalpricing:As anexample,earlyregistrationis $499in theU.S.,comparedto standardregistrationof $599.Checkthe ISC2websiteat http://www.isc2.org/download/regional_pricing.pdf to get specific details.

You can register for an exam done online, by mail, or by fax. The online form is availableat http://www.isc2.org/cgi-bin/content.cgi?category=542. After you register, you will receive a confirmation notice.

Arriving at the Exam Location

As with any examination, arrive at the testing center early. Be prepared! You will need to bring the confirmation letter and identification such as a driver's license, green card, or passport. Any photo ID will suffice. Two forms of ID are usually required. The testing center staff requires proof that you are who you say you are and that someone else is not taking the test for you.

Caution - You'll be spending a lot of time in the exam room. The total test time is 6 hours, so eat a good breakfast and take a snack and bottle of water with you to the testing area.

In the Exam Room

You will not be allowed to take study materials or anything else into the examination room with you that could raise the suspicion that you're cheating.

After the Exam

Examination results are not available after the exam. You must wait up to 4–6 weeks to get your results by email or snail mail.

Retaking a Test

You must wait at least 90 days to retake a failed examination. If you fail, you should use that time to brush up on your areas of weakness. Additionally, invest in some practice tests if you have not already done so. There is much to be said for "getting used to" a testing format.

Tracking Your CISSP Status

When you pass the exam, you still need to attest to the CISSP code of ethics and have an existing CISSP complete a endorsement form for you.

When you receive notice of your passing grade, a blank endorsement form will be sent with it. The endorsement form must be completed by someone who can attest to your professional experience and who is an active CISSP in good standing. If you don't know anyone who is CISSP certified, ISC2 allows endorsements from other professionals who are certified, licensed, or commissioned, and an officer of the corporation where you are employed. You can review complete information on the endorsement form at the ISC2 website.

About This Book

The ideal reader for an Exam Cram 2 book is someone seeking certification. However, it should be noted that an Exam Cram 2 book is a very easily readable, rapid presentation of facts. Therefore, an Exam Cram 2 book is also extremely useful as a quick reference manual.

Most people seeking certification use multiple sources of information. Check out the links at the end of each chapter to get more information about subjects you're weak in. Practice tests can help indicate when you are ready. Various security books from retailers also describe the topics in this book in much greater detail. Don't forget that many have described the CISSP exam as being a "mile wide."

This book includes other helpful elements in addition to the actual logical, step-by-step learning progression of the chapters themselves. Exam Cram 2 books use elements such as exam alerts, tips, notes, and practice questions to make information easier to read and absorb.

Reading this book from start to finish is not necessary; this book is set up so you can quickly jump back and forth to find sections you need to study.

Use the Cram Sheet to remember last-minute facts immediately before the exam. Use the practice questions to test your knowledge. You can always brush up on specific topics in detail by referring to the table of contents and the index. Even after you achieve certification, you can use this book as a rapid-access reference manual.

The Chapter Elements

Each Exam Cram 2 book has chapters that follow a predefined structure. This structure makes Exam Cram 2 books easy to read and provides a familiar format for all Exam Cram 2 books. These elements typically are used:

  • Opening hotlists

  • Chapter topics

  • Exam Alerts

  • Notes

  • Tips

  • Sidebars

  • Cautions

  • Exam-preparation practice questions and answers

  • A "Need to Know More?" section at the end of each chapter

Bulleted lists, numbered lists, tables, and graphics are also used, where appropriate. A picture can paint a thousand words sometimes, and tables can help to associate different elements with each other visually.

Now let's take a look at each of the elements in detail.

  • Opening hotlists—The start of every chapter contains a list of terms you should understand. A second hotlist identifies all the techniques and skills covered in the chapter.

  • Chapter topics—Each chapter contains details of all subject matter listed in the table of contents for that particular chapter. The objective of an Exam Cram 2 book is to cover all the important facts without giving too much detail; it is an exam cram. When examples are required, they are included.

  • Exam Alerts—Exam Alerts address exam-specific, exam-related information. An Exam Alert addresses content that is particularly important, tricky, or likely to appear on the exam. Exam Alerts look like this:

  • Caution - Make sure you remember the different ways in which DES can be implemented and that ECB is considered the weakest form of DES.

  • Notes—Notes typically contain useful information that is not directly related to the current topic under consideration. To avoid breaking up the flow of the text, they are set off from the regular text.

  • Note - This is a note. You have already seen several notes.

  • Tips—Tips often provide shortcuts or better ways to do things.

  • Tip - A clipping level is the point at which you set a control to distinguish between activity that should be investigated and activity that should not be investigated.

  • Sidebars—Sidebars are longer and run beside the text. They often describe real-world examples or situations.

  • How Caller ID Can Be Hacked

    Sure, we all trust Caller ID, but some Voice over IP (VoIP) providers allow users to inject their own Call Party Number (CPN) into the call. Because VoIP is currently outside FCC regulation, these hacks are now possible.

  • Cautions—Cautions apply directly to the use of the technology being discussed in the Exam Cram. For example, a Caution might point out that the CER is one of the most important items to examine when examining biometric devices.

  • Caution - The Crossover Error Rate (CER) is the point at which Type 1 errors and Type 2 errors intersect. The lower the CER is, the more accurate the device is.

  • Exam-preparation practice questions—At the end of every chapter is a list of 10–15 exam practice questions similar to those in the actual exam. Each chapter contains a list of questions relevant to that chapter, including answers and explanations. Test your skills as you read.

  • "Need to Know More?" section—This section at the end of each chapter describes other relevant sources of information. With respect to this chapter, the best place to look for CISSP certification information is at the ISC2 website, http://www.ISC2.org.

Other Book Elements

Most of this Exam Cram 2 book on CISSP follows the consistent chapter structure already described. However, there are various, important elements that are not part of the standard chapter format. These elements apply to the entire book as a whole.

  • Practice exams—In addition to exam-preparation questions at the end of each chapter, two full practice exams are included at the end of the book.

  • Answers and explanations for practice exams—These follow each practice exam, providing answers and explanations to the questions in the exams.

  • Glossary—The glossary contains a listing of important terms used in this book with explanations.

  • Cram Sheet—The Cram Sheet is a quick-reference, tear-out cardboard sheet of important facts useful for last-minute preparation. Cram sheets often include a simple summary of facts that are most difficult to remember.

  • CD—The CD contains the PrepLogic Practice Exams, Preview Edition exam-simulation software. The preview edition exhibits most of the full functionality of the Premium Edition, but it contains only one exam's worth of questions. To get the complete set of practice questions and full exam functionality, visit http://www.preplogic.com.

Chapter Contents

The following list provides an overview of the chapters.

  • Chapter 1: "The CISSP Certification Exam"—This chapter introduces exam strategies and considerations.

  • Chapter 2: "Physical Security"—This chapter details physical security and the threats and countermeasures available for protecting an organization's resources.

  • Chapter 3: "Security-Management Practices"—This chapter discusses the organization's information assets and means of protection, including policies, procedures, guidelines, and assorted controls.

  • Chapter 4: "Access-Control Systems and Methodology"—This chapter covers the basics of access control. Items such as identification, authentication, and authorization are discussed, as are biometric access-control systems.

  • Chapter 5: "System Architecture and Models"—This chapter discusses the ways to design, monitor, implement, and lock down computer systems.

  • Chapter 6: "Telecommunications and Network Security"—One of the longest chapters, this chapter discusses telecommunication technology. Items such as TCP/IP, the OSI model, routing protocols, and networking equipment are discussed.

  • Chapter 7: "Applications and Systems-Development Security"—This chapter discusses databases, malicious code, knowledge-based systems, and application issues.

  • Chapter 8: "Operations Security"—This chapter covers security concepts, operation controls, auditing, and resource protection.

  • Chapter 9: "Business-Continuity Planning"—This chapter covers all the aspects of the BCP and DRP process. Its goal is to help the reader understand what is needed to prevent, minimize, and recover from disasters.

  • Chapter 10: "Law, Investigations, and Ethics"—This chapter covers all things legal, from international law and incident response to forensics. It also covers the ethical standards that CISSP candidates must understand and abide by.

  • Chapter 11: "Cryptography"—This chapter discusses the methods, means, and systems used to encrypt and protect data. Symmetric, asymmetric, and hashing algorithms are introduced, along with PKI and cryptographic methods of attack.

  • Chapter 12: "Practice Exam 1"—This is a full-length practice exam.

  • Chapter 13: "Answers to Practice Exam 1"—This element contains the answers and explanations for the first practice exam.

  • Chapter 14: "Practice Exam 2"—This is a second full-length practice exam.

  • Chapter 15: "Answers to Practice Exam 2"—This element contains the answers and explanations for the second practice exam.

Contacting the Author

Hopefully, this book provides you with the tools you need to pass the CISSP exam. Feedback is appreciated. The author can be contacted at info@thesolutionfirm.com.

Thank you for selecting my book; I hope you like it. Good luck!


© Copyright Pearson Education. All rights reserved.

Customer Reviews

Be the first to write a review
( 0 )

Rating Distribution

5 Star

(0)

4 Star

(0)

3 Star

(0)

2 Star

(0)

1 Star

(0)

Your Rating:

Your Name: Create a Pen Name or Leave Anonymously

Barnes & Noble.com Review Rules

Our reader reviews allow you to share your comments on titles you liked, or didn't, with others. By submitting an online review, you are representing to Barnes & Noble.com that all information contained in your review is original and accurate in all respects, and that the submission of such content by you and the posting of such content by Barnes & Noble.com does not and will not violate the rights of any third party. Please follow the rules below to help ensure that your review can be posted.

Reviews by Our Customers Under the Age of 13

We highly value and respect everyone's opinion concerning the titles we offer. However, we cannot allow persons under the age of 13 to have accounts at BN.com or to post customer reviews. Please see our Terms of Use for more details.

What to exclude from your review:

Please do not write about reviews, commentary, or information posted on the product page. If you see any errors in the information on the product page, please send us an email.

Reviews should not contain any of the following:

  • - HTML tags, profanity, obscenities, vulgarities, or comments that defame anyone
  • - Time-sensitive information such as tour dates, signings, lectures, etc.
  • - Single-word reviews. Other people will read your review to discover why you liked or didn't like the title. Be descriptive.
  • - Comments focusing on the author or that may ruin the ending for others
  • - Phone numbers, addresses, URLs
  • - Pricing and availability information or alternative ordering information
  • - Advertisements or commercial solicitation

Reminder:

  • - By submitting a review, you grant to Barnes & Noble.com and its sublicensees the royalty-free, perpetual, irrevocable right and license to use the review in accordance with the Barnes & Noble.com Terms of Use.
  • - Barnes & Noble.com reserves the right not to post any review -- particularly those that do not follow the terms and conditions of these Rules. Barnes & Noble.com also reserves the right to remove any review at any time without notice.
  • - See Terms of Use for other conditions and disclaimers.
Search for Products You'd Like to Recommend

Recommend other products that relate to your review. Just search for them below and share!

Create a Pen Name

Your Pen Name is your unique identiy on BN.com. It will appear on the reviews you write and other website activities. Your Pen Name cannot be edited, changed or deleted once submitted.

Your Pen Name can be any combination of alphanumeric characters (plus - and _), and must be at least two characters long.

Continue Anonymously

We're sorry, but penname is already taken.

Please select one of the following:
Your Pen Name can be any combination of alphanumeric characters (plus - and _), and must be at least two characters long.

Continue Anonymously

penname is available!

By visiting the BN.com website or marking a purchase on BN.com, a User is deemed to have accepted the Terms of Use.

Continue Anonymously

Welcome, penname

You have successfully created your Pen Name. Start enjoying the benefits of the BN.com Community today.


If you find inappropriate content, please report it to Barnes & Noble
Why is this product inappropriate?
Comments (optional)
500 character limit