CISSP Exam Cram

( 11 )

Overview

Updated for 2009

Covers the critical information you’ll need to know to score higher on your CISSP exam!

  • Build and manage an effective, integrated security architecture
  • Systematically protect your physical facilities and the IT resources...
See more details below
Available through our Marketplace sellers.
Other sellers (Paperback)
  • All (12) from $1.99   
  • New (3) from $19.89   
  • Used (9) from $1.99   
Close
Sort by
Page 1 of 1
Showing All
Note: Marketplace items are not eligible for any BN.com coupons and promotions
$19.89
Seller since 2009

Feedback rating:

(386)

Condition:

New — never opened or used in original packaging.

Like New — packaging may have been opened. A "Like New" item is suitable to give as a gift.

Very Good — may have minor signs of wear on packaging but item works perfectly and has no damage.

Good — item is in good condition but packaging may have signs of shelf wear/aging or torn packaging. All specific defects should be noted in the Comments section associated with each item.

Acceptable — item is in working order but may show signs of wear such as scratches or torn packaging. All specific defects should be noted in the Comments section associated with each item.

Used — An item that has been opened and may show signs of wear. All specific defects should be noted in the Comments section associated with each item.

Refurbished — A used item that has been renewed or updated and verified to be in proper working condition. Not necessarily completed by the original manufacturer.

New
2009 Paperback New Book may contain minor shelf wear.

Ships from: Englewood, CO

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$20.70
Seller since 2006

Feedback rating:

(947)

Condition: New
2009-03-20 Paperback New New Item. Item delivered via UPS in 7-9 business days. Tracking available by request Ships from US. Please allow 1-3 weeks for delivery outside US.

Ships from: Appleton, WI

Usually ships in 1-2 business days

  • Canadian
  • International
  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
$30.14
Seller since 2005

Feedback rating:

(330)

Condition: New
2009 Softcover New CD-ROM included with book.

Ships from: Hillsboro, OR

Usually ships in 1-2 business days

  • Standard, 48 States
  • Standard (AK, HI)
  • Express, 48 States
  • Express (AK, HI)
Page 1 of 1
Showing All
Close
Sort by

Overview

Updated for 2009

Covers the critical information you’ll need to know to score higher on your CISSP exam!

  • Build and manage an effective, integrated security architecture
  • Systematically protect your physical facilities and the IT resources they contain
  • Implement and administer access control
  • Use cryptography to help guarantee data integrity, confidentiality, and authenticity
  • Secure networks, Internet connections, and communications
  • Make effective business continuity and disaster recovery plans, and execute them successfully
  • Address today’s essential legal, regulatory, and compliance issues
  • Master the basics of security forensics
  • Develop more secure applications and systems from the ground up
  • Use security best practices ranging from risk management to operations and auditing
  • Understand and perform the crucial non-technical tasks associated with IT security

CD Features Test Engine Powered by MeasureUp!

  • Detailed explanations of correct and incorrect answers
  • Multiple test modes
  • Random questions and order of answers
  • Coverage of each CISSP exam domain
Read More Show Less

Product Details

  • ISBN-13: 9780789738066
  • Publisher: Pearson IT Certification
  • Publication date: 3/24/2009
  • Series: Exam Cram Series
  • Edition description: Second Edition
  • Edition number: 2
  • Pages: 591
  • Product dimensions: 5.90 (w) x 8.90 (h) x 1.40 (d)

Meet the Author

As the founder and president of Superior Solutions, Inc., a Houston-based IT security consulting, auditing, and training firm, Michael Gregg has more than15 years experience in information security and risk management. He holds two associate’s degrees, a bachelor’s degree, and a master’s degree. Some of the certifications he holds include the following: CISSP, CISA, CISM, MCSE, CTT+, A+, N+, Security+, CNA, CCNA, CIW Security Analyst, CCE, CEH, CHFI, CEI, DCNP, ES Dragon IDS, ES Advanced Dragon IDS, and SSCP.

Michael has experience not only in performing security audits and assessments, but also is the co-author of Build Your Own Security Lab by Wiley Publishing. Other publications he has authored include CISSP Practice Questions Exam Cram, CISA Exam Prep, and CEH Exam Prep 2. Michael is a site expert for TechTarget.com websites and also serves on their editorial advisory board. His articles have been published on IT websites including CertMag.com, CramSession.com, and GoCertify.com. Michael has created security, audit, and IT networking course material for various companies and universities. Although audits and assessments are where he spends the bulk of his time, teaching and contributing to the written body of IT security knowledge is how Michael believes he can give something back to the community that has given him so much.

He is a member of the American College of Forensic Examiners and the Information Systems Audit and Control Association. When not working, Michael enjoys traveling and restoring muscle cars.

Read More Show Less

Read an Excerpt

IntroductionIntroduction

Welcome to CISSP Exam Cram! This book covers the CISSP certification exam. Whether this is your first or your fifteenth Exam Cram, you’ll find information here and in Chapter 1 that will ensure your success as you pursue knowledge, experience, and certification. This introduction explains the ISC2 certification programs in general and talks about how the Exam Cram series can help you prepare for the CISSP exam.

This book is one of the Exam Cram series of books and will help by getting you on you way to becoming an ISC2 Certified Information Systems Security Professional (CISSP).

This introduction discusses the basics of the CISSP exam. Included are sections covering preparation, how to take an exam, a description of this book’s contents, how this book is organized, and, finally, author contact information.

Each chapter in this book contains practice questions. There are also two full-length practice exams at the end of the book. Practice exams in this book should provide an accurate assessment of the level of expertise you need to obtain to pass the test. Answers and explanations are included for all test questions. It is best to obtain a level of understanding equivalent to a consistent pass rate of at least 95% or more on the practice questions and exams in this book before you attempt the real exam.

Let’s begin by looking at preparation for the exam.

How to Prepare for the Exam

Preparingfor the CISSP exam requires that you obtain and study materials designed to provide comprehensive information about security. The following list of materials will help you study and prepare:

  • The ISC2 website at http://www.ISC2.org
  • The study guide available at the ISC2 website
  • The CISSP open study guide website at http://www.cccure.org

Many people form study groups, attend seminars, and training classes to help them study for and master the material needed to pass the CISSP exam.

Practice Tests

You don’t need to know much about practice tests, other than that they are a worthwhile expense for three reasons:

  • They help you diagnose areas of weakness.
  • They are useful for getting used to the format of questions.
  • They help you to decide when you are ready to take the exam.

This book contains questions at the end of each chapter and includes two full-length practice tests. However, if you still want more, a related Exam Cram CISSP Practice Questions book has more than 500 additional questions. The questions are in paper form so that you can practice in an environment similar to the real exam; they are also available electronically as a practice test CD in the back of the book. Many other companies provide CISSP certification practice tests as well.

Taking a Certification Exam

When you have prepared for the exam, you must register with ISC2 to take the exam. The CISSP exam is given throughout the year at various locations. You can find the latest schedule at https://http://www.ISC2.org/cgi-bin/exam_schedule.cgi?displaycategory=1182. Many people decide to travel to the exam location; others wait until it is given at a location closer to them. ISC2 has implemented regional pricing: As an example, early registration is $499 in the United States, compared to standard registration of $599. Check the ISC2 website at https://www.ISC2.org/uploadedFiles/Downloads/exam_pricing.pdf to get specific details.

You can register for an exam done online, by mail, or by fax. The online form is available at http://www.ISC2.org/certification-register-now.aspx. After you register, you will receive a confirmation notice.

Arriving at the Exam Location

As with any examination, arrive at the testing center early. Be prepared! You will need to bring the confirmation letter and identification such as a driver’s license, green card, or passport. Any photo ID will suffice. Two forms of ID are usually required. The testing center staff requires proof that you are who you say you are and that someone else is not taking the test for you. Arrive early as if you are late you will be barred from entry and will not receive a refund for the cost of the exam.

Warning - You’ll be spending a lot of time in the exam room. The total test time is 6 hours, so eat a good breakfast and take a snack and bottle of water with you to the testing area. Policies differ—some locations might allow you to take the water and energy bar to your desk whereas others might make you place it at the back of the testing area.

In the Exam Room

You will not be allowed to take study materials or anything else into the examination room with you that could raise suspicion that you’re cheating. This includes practice test material, books, exam prep guides, or other test aids.

After the Exam

Examination results are not available after the exam. You must wait up to 4–6 weeks to get your results by email or snail mail. Most individuals receive these rather quickly within 4 weeks or so. If you pass the exam, you will simply receive a passing grade—your exact score will not be provided.

Retaking a Test

If you fail the exam you must wait at least 90 days to retake a failed examination. Candidates that do not pass will receive a complete breakdown on their score. Each of the ten domains will be shown as will the candidates score. As an example, you may have received a 95% score in the telecommunications domain and only 12% in cryptography. Use this feedback to better understand what areas you were weak in and where to spend your time and effort in your studies. Additionally, invest in some practice tests if you have not already done so. There is much to be said for getting used to a testing format.

Tracking Your CISSP Status

When you pass the exam, you still need to attest to the CISSP code of ethics and have an existing CISSP complete an endorsement form for you.

When you receive notice of your passing grade, a blank endorsement form will be sent with it. The endorsement form must be completed by someone who can attest to your professional experience and who is an active CISSP in good standing. If you don’t know anyone who is CISSP certified, ISC2 allows endorsements from other professionals who are certified, licensed, or commissioned, and an officer of the corporation where you are employed. You can review complete information on the endorsement form at the ISC2 website.

About This Book

The ideal reader for an Exam Cram book is someone seeking certification. However, it should be noted that an Exam Cram book is a very easily readable, rapid presentation of facts. Therefore, an Exam Cram book is also extremely useful as a quick reference manual.

Most people seeking certification use multiple sources of information. Check out the links at the end of each chapter to get more information about subjects you’re weak in. Practice tests can help indicate when you are ready. Various security books from retailers also describe the topics in this book in much greater detail. Don’t forget that many have described the CISSP exam as being a “mile wide.”

This book includes other helpful elements in addition to the actual logical, step-by-step learning progression of the chapters themselves. Exam Cram books use elements such as exam alerts, tips, notes, and practice questions to make information easier to read and absorb.

Note - Reading this book from start to finish is not necessary; this book is set up so that you can quickly jump back and forth to find sections you need to study.

Use the Cram Sheet to remember last-minute facts immediately before the exam. Use the practice questions to test your knowledge. You can always brush up on specific topics in detail by referring to the table of contents and the index. Even after you achieve certification, you can use this book as a rapid-access reference manual.

The Chapter Elements

Each Exam Cram book has chapters that follow a predefined structure. This structure makes Exam Cram books easy to read and provides a familiar format for all Exam Cram books. The following elements typically are used:

  • Opening hotlists
  • Chapter topics
  • Exam Alerts
  • Notes
  • Tips
  • Sidebars
  • Cautions
  • Exam preparation practice questions and answers
  • A “Need to Know More?” section at the end of each chapter

Note - Bulleted lists, numbered lists, tables, and graphics are also used where appropriate. A picture can paint a thousand words sometimes, and tables can help to associate different elements with each other visually.

Now let’s look at each of the elements in detail.

  • Opening hotlists—The start of every chapter contains a list of terms you should understand. A second hotlist identifies all the techniques and skills covered in the chapter.
  • Chapter topics—Each chapter contains details of all subject matter listed in the table of contents for that particular chapter. The objective of an Exam Cram book is to cover all the important facts without giving too much detail; it is an exam cram. When examples are required, they are included.
  • Exam Alerts—Exam Alerts address exam-specific, exam-related information. An Exam Alert addresses content that is particularly important, tricky, or likely to appear on the exam. An Exam Alert looks like this:

    Warning - Make sure you remember the different ways in which DES can be implemented and that ECB is considered the weakest form of DES.

  • Notes—Notes typically contain useful information that is not directly related to the current topic under consideration. To avoid breaking up the flow of the text, they are set off from the regular text.

    Note - This is a note. You have already seen several notes.

  • Tips—Tips often provide shortcuts or better ways to do things.

    Tip - A clipping level is the point at which you set a control to distinguish between activity that should be investigated and activity that should not be investigated.

  • Sidebars—Sidebars are longer and run beside the text. They often describe real-world examples or situations.

    How Caller ID Can Be Hacked - Sure, we all trust Caller ID, but some Voice over IP (VoIP) providers allow users to inject their own Call Party Number (CPN) into the call. Because VoIP is currently outside FCC regulation, these hacks are now possible.

  • Cautions—Cautions apply directly to the use of the technology being discussed in the Exam Cram. For example, a Caution might point out that the CER is one of the most important items to examine when examining biometric devices.

    Caution - The Crossover Error Rate (CER) is the point at which Type 1 errors and Type 2 errors intersect. The lower the CER is, the more accurate the device is.

  • Exam preparation practice questions—At the end of every chapter is a list of at least 10 exam practice questions similar to those in the actual exam. Each chapter contains a list of questions relevant to that chapter, including answers and explanations. Test your skills as you read.
  • “Need to Know More?” section—This section at the end of each chapter describes other relevant sources of information. With respect to this chapter, the best place to look for CISSP certification information is at the ISC2 website, http://www.ISC2.org.
Other Book Elements

Most of this Exam Cram book on CISSP follows the consistent chapter structure already described. However, there are various, important elements that are not part of the standard chapter format. These elements apply to the entire book as a whole.

  • Practice exams—In addition to exam-preparation questions at the end of each chapter, two full practice exams are included at the end of the book.
  • Answers and explanations for practice exams—These follow each practice exam, providing answers and explanations to the questions in the exams.
  • Glossary—The glossary contains a listing of important terms used in this book with explanations.
  • Cram Sheet—The Cram Sheet is a quick-reference, tear-out cardboard sheet of important facts useful for last-minute preparation. Cram sheets often include a simple summary of facts that are most difficult to remember.
  • CD—The CD contains the MeasureUp exam-simulation software, which provides multiple test modes that you can use for exam preparation. MeasureUp practice tests are designed to appropriately balance the questions over each technical area (domain) covered by the exam. All concepts from the actual exam are covered thoroughly to ensure you’re prepared for the exam.
Chapter Contents

The following list provides an overview of the chapters.

  • Chapter 1, “The CISSP Certification Exam”—This chapter introduces exam strategies and considerations.
  • Chapter 2, “Physical Security”—This chapter details physical security and the threats and countermeasures available for protecting an organization’s resources. Physical security plays a key role in securing an organization’s assets. Without effective physical security, there can be no effective security structure in place.
  • Chapter 3, “Access Control Systems and Methodology”—This chapter covers the basics of access control. This chapter addresses the three A’s: authentication, authorization, and accountability. Items such as identification, single sign-on, centralized authentication, and the role of technical, administrative, and physical controls are discussed.
  • Chapter 4, “Cryptography”—This chapter discusses the methods, means, and systems used to encrypt and protect data. Symmetric, asymmetric, and hashing algorithms are introduced, along with PKI and cryptographic methods of attack.
  • Chapter 5, “Security Architecture and Models”—This chapter discusses key concepts such as computer hardware, operating system design, security models, and documentation used to verify, certify, and accredited systems and networks.
  • Chapter 6, “Telecommunications and Network Security”—This chapter discusses telecommunication technology. Items such as the OSI model, TCP/IP, network equipment, LAN, MAN, and WAN protocols, and wireless technologies are just a few of the items discussed. This is the most expansive domain and considered one of the most critical for the CISSP candidate to master.
  • Chapter 7, “Business Continuity and Disaster Recovery Planning”—This chapter covers all the aspects of the BCP and DRP process. Although some may discount the importance the importance of this domain, events such as 9/11 demonstrate the critically of this domain. This chapter addresses key elements of disaster recovery and business continuity. One important item is that no demonstrated recovery exists until the plan has been tested. Exam candidates must understand what is needed to prevent, minimize, and recover from disasters.
  • Chapter 8, “Legal Regulations, Compliance, and Investigations”—This chapter covers all legal issues from a global perspective. Readers must understand issues such as privacy and the transnational flow of information. Ethics are also discussed because CISSP candidates must understand and abide by the ISC2 code of ethics. Incident response and computer forensics are introduced in this chapter because readers must understand how to deal with the potential of computer crime.
  • Chapter 9, “Applications and Systems-Development Security”—This chapter discusses databases, the system development life cycle and the importance of building security into applications and systems as early as possible during the development process. Project management is reviewed, as are malicious code, knowledge-based systems, and application issues.
  • Chapter 10, “Information Security and Risk Management Practices”—This chapter discusses asset management and the protection of critical resources. Quantitative and qualitative risk assessment are two major topics of this chapter. Readers must understand how these concepts are used to assess and measure risk while reducing threats to the organization. Key concepts include the development of policies, procedures, guidelines, and assorted controls.
  • Chapter 11, “Operations Security”—This chapter covers operation controls—that is, the types of controls that the organization can implement. Topics such as background checks, duel controls, mandatory vacations, rotation of duties, and auditing are introduced. This chapter also reviews security assessments, ethical hacking, and vulnerability scanning.
  • Chapter 12, Practice Exam I—This is a full-length practice exam.
  • Chapter 13, Answers to Practice Exam I—This element contains the answers and explanations for the first practice exam.
  • Chapter 14, Practice Exam II—This is a second full-length practice exam.
  • Chapter 15, Answers to Practice Exam II—This element contains the answers and explanations for the second practice exam.
Contacting the Author

Hopefully, this book provides you with the tools you need to pass the CISSP exam. Feedback is appreciated. You can contact the author at mikeg@thesolutionfirm.com.

Thank you for selecting my book; I have worked to apply the same concepts in this book that I have used in the hundreds of training classes I have taught. Spend your study time wisely and you too can become a CISSP. Good luck on the exam!

Self-Assessment

This Self-Assessment section enables you to evaluate your readiness to take the CISSP certification exam. It should also help you understand what’s required to obtain the CISSP certification. Are you ready?

CISSPs in the Real World

Security continues to be on everyone’s mind. The CISSP certification continues to be one of the most sought-after security certifications. Increasing numbers of people are studying for and obtaining their CISSP certifications. Congratulations on making the decision to follow in their footsteps. If you are willing to tackle the process seriously and do what it takes to obtain the necessary experience and knowledge, you can pass the exam on the first try.

Tip - You can also assess your CISSP skill set by using the MeasureUp Certification Mode.

The Ideal CISSP Candidate

The CISSP is designed for individuals that are leading, planning, organizing, or controlling the security initiative of an organization. The ideal CISSP candidate is likely to have a 4-year college education and have at least 5–7 years experience in one or more of the 10 CISSP domains. The most applicable degree is in computer science or perhaps a related field. A degree is not a prerequisite for taking the test. However, exam candidates must have a minimum of 5 years of direct full-time security work experience in two or more of the 10 domains. One year of experience can be substituted for a four-year college degree or an approved certification such as Security +. The complete list of approved certifications can be found at https://www.ISC2.org/cgi-bin/content.cgi?page=1016. Don’t be lull-ed into thinking that this is an easy test. Some words of caution might be in order:

  • The CISSP exam requires the candidate to absorb a substantial amount of material. The test is 6 hours long and consists of 225 graded questions. Unlike Microsoft exams and most other IT vendor exams, it is not a computer-generated test.
  • The pass mark is set high, at 700 points. The individual questions are weighted, which means that harder questions are worth more than easier ones.
  • Most of the individuals attempting the exam are familiar with one to three of the domains. This means that studying for the exam can be overwhelming because there is so much material to cover. This book can help by guiding you to the areas in which you are weak or strong.
  • To be eligible for the CISSP exam, students are required to have 4 years of experience, or 3 years of experience and a college degree.
Put Yourself to the Test

In this section, you answer some simple questions. The objective is for you to understand exactly how much work and effort you must invest to pass the CISSP certification exam. The simple answer to this question is this: The experience and education you have will dictate how difficult it will be for you to pass. Be honest in your answers or you will end up wasting $500 or more on an exam you were not ready to take. From the beginning, two things should be clear:

  • Any educational background in computer science will be helpful, as will other IT certifications you have achieved.
  • Hands-on actual experience is not only essential, but also required to obtain this certification.
Your Educational Background
  • Do you have a computer science degree?

    You’ll have a good basic knowledge needed for 3 or more of the 10 domains, assuming that you finished your degree and your schooling and have some fairly sophisticated computer skills. Subject areas such as application development, networking, and database design are a great help.

  • Did you attend some type of technical school or computer cram course?

    This question applies to low-level or short-term computer courses. Many of these courses are extremely basic or focused in one particular area. Although the CISSP exam is not platform specific, training classes that focused on networking, security, hacking, or database design will help you pass the exam.

  • Have you developed any security policies, performed security audits, performed penetration tests, or developed response plans?

    If yes, you will probably be able to handle about half of the CISSP exam domains.

  • Do you have a photographic memory?

    If yes, you might have a slim chance of passing simply by reading this book, taking some practice exams, and using the Internet to brush up on the subjects you are weak in. However, the goal here is to gain a real understanding of the material. As a CISSP, you might be asked to lead, plan, organize, or control your organization’s security operations; if that happens, you’ll need a real understanding of how the various technologies and techniques work. Don’t cheat yourself or gamble with your career.

Again, the education and requirements given here are by no means absolute. Still, an education can give you a very good grounding in any endeavor—the higher the level of education, the better.

Testing Your Exam Readiness

Whether you attend a training class, form a study group, or study on your own, preparing for the CISSP exam is essential. The exam will cost you about $500, depending on where you are located, so you’ll want to do everything you can to make sure you pass on the first try. Reading, studying, and taking practice exams are the best ways to increase your readiness. Practice exams help in a number of ways:

  • Practice exams highlight weak spots for further study.
  • Practice exams give you a general perspective on the question format. Practicing the questions the way they are asked can help enormously on the actual testing day.
  • Two full-length practice exams are provided with this book. Que also publishes a second book, CISSP Practice Questions Exam, with more than 500 practice CISSP test questions; it is an excellent supplement to this book.
After the Exam

After you have passed the exam, you will need to gain continuing education credits each year to maintain your certification. Your certification will come up for renewal every 3 years, so you’ll need to obtain 120 continuing education credits (CPE) or retake the exam. Retaking the exam is probably not a likely choice. These are some ways to gain CPEs to keep your certification current:

  • Write a book.
  • Read a book. (Only one per year can be used for credit.) This will give you a couple of credits, but not enough to keep your certification current.
  • Do volunteer work that is approved by ISC2. When you are certified, you can log on to the ISC2 website for more information. A variety of volunteer work is available, including proctoring the CISSP exam.
  • Attend a training class. Just about any type of technology training class is accepted as long as it is tied to one of the domains.
  • Teach a training class.
  • Attend a college-level security class.

As you can see, the goal here is to help you stay current. As technology changes, we all must continue to learn to keep up the pace.

Now that we have covered some of the ways in which to assess you exam readiness, let’s move on to Chapter 1, “The CISSP Certification Exam,” where you will learn more about how the exam is structured and some effective test-taking strategies.

© Copyright Pearson Education. All rights reserved.

Read More Show Less

Table of Contents

Introduction 1

Chapter 1:

The CISSP Certification Exam ............................................................15

Introduction ..............................................................................................16

Assessing Exam Readiness........................................................................16

Taking the Exam.......................................................................................17

Multiple-Choice Question Format ..........................................................19

Exam Strategy...........................................................................................19

Question-Handling Strategies..................................................................21

Mastering the Inner Game.......................................................................21

Need to Know More?...............................................................................22

Chapter 2:

Physical Security ...........................................................................23

Introduction ..............................................................................................24

Physical Security Risks .............................................................................24

Natural Disasters.............................................................................25

Man-Made Threats .........................................................................26

Technical Problems .........................................................................27

Facility Concerns and Requirements.......................................................28

CPTED ...........................................................................................28

Area Concerns .................................................................................29

Location...........................................................................................30

Construction....................................................................................30

Doors, Walls, Windows, and Ceilings............................................31

Asset Placement...............................................................................34

Perimeter Controls...................................................................................34

Fences ..............................................................................................34

Gates ................................................................................................36

Bollards ............................................................................................37

CCTV Cameras ..............................................................................38

Lighting ...........................................................................................39

Guards and Dogs.............................................................................40

Locks................................................................................................41

Employee Access Control ........................................................................44

Badges, Tokens, and Cards..............................................................44

Biometric Access Controls ..............................................................46

Environmental Controls...........................................................................47

Heating, Ventilating, and Air Conditioning...................................48

Electrical Power........................................................................................49

Uninterruptible Power Supply .......................................................50

Equipment Life Cycle ..............................................................................50

Fire Prevention, Detection, and Suppression..........................................51

Fire-Detection Equipment..............................................................52

Fire Suppression ..............................................................................52

Alarm Systems...........................................................................................55

Intrusion Detection Systems...........................................................55

Monitoring and Detection ..............................................................56

Exam Prep Questions ...............................................................................58

Answers to Exam Prep Questions............................................................60

Suggested Reading and Resources ...........................................................61

Chapter 3:

Access Control Systems and Methodology .............................................63

Introduction ..............................................................................................64

Identification, Authentication, and Authorization ..................................65

Authentication .................................................................................65

Single Sign-On .........................................................................................78

Kerberos...........................................................................................78

SESAME..........................................................................................81

Authorization and Access Controls Techniques ......................................81

Discretionary Access Control .........................................................81

Mandatory Access Control..............................................................82

Role-Based Access Control .............................................................84

Other Types of Access Controls .....................................................85

Access Control Methods ..........................................................................86

Centralized Access Control.............................................................86

Decentralized Access Control.........................................................89

Access Control Types ...............................................................................90

Administrative Controls ..................................................................90

Technical Controls ..........................................................................91

Physical Controls.............................................................................91

Access Control Categories ..............................................................92

Audit and Monitoring...............................................................................93

Monitoring Access and Usage ........................................................93

Intrusion Detection Systems...........................................................94

Intrusion Prevention Systems .........................................................98

Network Access Control .................................................................98

Keystroke Monitoring.....................................................................99

Emanation Security .......................................................................100

Access Control Attacks ...........................................................................101

Password Attacks ...........................................................................101

Spoofing.........................................................................................105

Sniffing...........................................................................................105

Eavesdropping and Shoulder Surfing...........................................105

Wiretapping...................................................................................106

Identity Theft ................................................................................106

Denial of Service Attacks ..............................................................107

Distributed Denial of Service Attacks ..........................................109

Botnets ...........................................................................................109

Exam Prep Questions .............................................................................111

Answers to Exam Prep Questions..........................................................113

Suggesting Reading and Resources........................................................115

Chapter 4:

Cryptography...............................................................................117

Introduction ............................................................................................118

Cryptographic Basics ..............................................................................118

History of Encryption ............................................................................121

Steganography ........................................................................................126

Steganography Operation .............................................................127

Digital Watermark ........................................................................128

Algorithms...............................................................................................128

Cipher Types and Methods ....................................................................130

Symmetric Encryption ...........................................................................131

Data Encryption Standard ............................................................133

Triple-DES ....................................................................................136

Advanced Encryption Standard ....................................................138

International Data Encryption Algorithm....................................138

Rivest Cipher Algorithms .............................................................139

Asymmetric Encryption..........................................................................139

Diffie-Hellman ..............................................................................141

RSA ................................................................................................142

El Gamal........................................................................................143

Elliptical Curve Cryptosystem......................................................144

Merkle-Hellman Knapsack ...........................................................144

Review of Symmetric and Asymmetric Cryptographic Systems .145

Hybrid Encryption .................................................................................145

Integrity and Authentication ..................................................................146

Hashing and Message Digests ......................................................147

Digital Signatures..........................................................................150

Cryptographic System Review......................................................151

Public Key Infrastructure .......................................................................151

Certificate Authority .....................................................................152

Registration Authority...................................................................152

Certificate Revocation List ...........................................................153

Digital Certificates ........................................................................153

The Client’s Role in PKI ..............................................................155

Email Protection Mechanisms ...............................................................156

Pretty Good Privacy......................................................................156

Other Email Security Applications...............................................157

Securing TCP/IP with Cryptographic Solutions..................................157

Application/Process Layer Controls.............................................158

Host to Host Layer Controls........................................................159

Internet Layer Controls ................................................................160

Network Access Layer Controls ...................................................161

Link and End to End Encryption.................................................162

Cryptographic Attacks............................................................................163

Exam Prep Questions .............................................................................166

Answers to Exam Prep Questions..........................................................168

Need to Know More?.............................................................................170

Chapter 5:

Security Architecture and Models ......................................................171

Introduction ............................................................................................172

Computer System Architecture..............................................................172

Central Processing Unit................................................................172

Storage Media................................................................................175

I/O Bus Standards .........................................................................178

Virtual Memory and Virtual Machines.........................................178

Computer Configurations.............................................................179

Security Architecture..............................................................................180

Protection Rings............................................................................180

Trusted Computer Base ................................................................182

Open and Closed Systems.............................................................185

Security Modes of Operation........................................................185

Operating States ............................................................................186

Recovery Procedures.....................................................................187

Process Isolation............................................................................188

Security Models of Control....................................................................188

State Machine Model ....................................................................189

Confidentiality...............................................................................190

Integrity .........................................................................................191

Other Models ................................................................................194

Documents and Guidelines ....................................................................195

The Rainbow Series ......................................................................195

The Red Book: Trusted Network Interpretation.........................197

Information Technology Security Evaluation Criteria ................198

Common Criteria..........................................................................199

British Standard 7799....................................................................200

System Validation ...................................................................................200

Certification and Accreditation.....................................................201

Governance and Enterprise Architecture.....................................202

Security Architecture Threats................................................................204

Buffer Overflow.............................................................................204

Back Doors ....................................................................................205

Asynchronous Attacks ...................................................................205

Covert Channels............................................................................205

Incremental Attacks.......................................................................206

Exam Prep Questions .............................................................................207

Answers to Exam Prep Questions..........................................................209

Need to Know More?.............................................................................211

Chapter 6:

Telecommunications and Network Security...........................................213

Introduction ............................................................................................214

Network Models and Standards.............................................................214

OSI Model.....................................................................................215

Encapsulation/De-encapsulation ..................................................221

TCP/IP ...................................................................................................222

Network Access Layer...................................................................222

Internet Layer................................................................................223

Host-to-Host (Transport) Layer...................................................226

Application Layer ..........................................................................229

LANs and Their Components...............................................................232

LAN Communication Protocols ..................................................233

Network Topologies......................................................................233

LAN Cabling.................................................................................236

Network Types ..............................................................................238

Communication Standards.....................................................................239

Network Equipment...............................................................................240

Repeaters........................................................................................240

Hubs...............................................................................................240

Bridges ...........................................................................................240

Switches .........................................................................................241

Routers...........................................................................................242

Brouters .........................................................................................243

Gateways........................................................................................243

Routing....................................................................................................244

WANs and Their Components..............................................................246

Packet Switching ...........................................................................246

Circuit Switching...........................................................................248

Voice Communications and Wireless Communications.......................251

Voice over IP .................................................................................251

Cell Phones....................................................................................252

802.11 Wireless Networks and Standards....................................253

Network Security....................................................................................261

Firewalls.........................................................................................261

Demilitarized Zone .......................................................................263

Firewall Design..............................................................................264

Remote Access ........................................................................................265

Point-to-Point Protocol................................................................265

Virtual Private Networks ..............................................................266

Remote Authentication Dial-in User Service ..............................267

Terminal Access Controller Access Control System....................267

IPSec ..............................................................................................268

Message Privacy......................................................................................268

Threats to Network Security .................................................................269

DoS Attacks ...................................................................................269

Disclosure Attacks .........................................................................270

Destruction, Alteration, or Theft .................................................271

Exam Prep Questions .............................................................................274

Answers to Exam Prep Questions..........................................................277

Need to Know More?.............................................................................278

Chapter 7:

Business Continuity and Disaster Recovery Planning...............................279

Introduction ............................................................................................280

Threats to Business Operations .............................................................280

Disaster Recovery and Business Continuity Management ...................281

Project Management and Initiation..............................................283

Business Impact Analysis...............................................................285

Recovery Strategy..........................................................................290

Plan Design and Development .....................................................303

Implementation .............................................................................306

Testing............................................................................................307

Monitoring and Maintenance .......................................................309

Disaster Life Cycle .................................................................................310

Teams and Responsibilities ...........................................................312

Exam Prep Questions .............................................................................314

Answers to Exam Prep Questions..........................................................316

Need to Know More?.............................................................................318

Chapter 8:

Legal, Regulations, Compliance, and Investigations ...............................319

Introduction ............................................................................................320

United States Legal System and Laws...................................................320

International Legal Systems and Laws ..................................................321

International Property Laws ..................................................................323

Piracy and Issues with Copyrights................................................323

Privacy Laws and Protection of Personal Information .........................325

Privacy Impact Assessment ...........................................................327

Computer Crime Laws...........................................................................328

Ethics.......................................................................................................328

ISC2 Code of Ethics ......................................................................329

Computer Ethics Institute ............................................................330

Internet Architecture Board..........................................................331

NIST 800-14 .................................................................................332

Computer Crime and Criminals ............................................................332

Pornography ..................................................................................335

Well-Known Computer Crimes ............................................................335

How Computer Crime Has Changed....................................................336

Attack Vectors .........................................................................................338

Keystroke Logging........................................................................338

Wiretapping...................................................................................339

Spoofing Attacks............................................................................339

Manipulation Attacks ....................................................................340

Social Engineering ........................................................................341

Dumpster Diving...........................................................................341

Investigating Computer Crime ..............................................................342

Computer Crime Jurisdiction .......................................................343

Incident Response .........................................................................343

Forensics .................................................................................................347

Standardization of Forensic Procedures.......................................349

Computer Forensics ......................................................................349

Investigations ..........................................................................................354

Search, Seizure, and Surveillance .................................................354

Interviews and Interrogations .......................................................355

Honeypots and Honeynets ...........................................................355

Evidence Types..............................................................................356

Trial .........................................................................................................357

The Evidence Life Cycle ..............................................................358

Exam Prep Questions .............................................................................359

Answers to Exam Prep Questions..........................................................362

Need to Know More?.............................................................................364

Chapter 9:

Applications and Systems-Development Security ...................................365

Introduction ............................................................................................366

System Development..............................................................................366

Avoiding System Failure ...............................................................367

The System Development Life Cycle ..........................................369

System Development Methods ..............................................................376

The Waterfall Model ....................................................................376

The Spiral Model ..........................................................................376

Joint Application Development ....................................................377

Rapid Application Development...................................................377

Incremental Development ............................................................377

Prototyping....................................................................................378

Computer-Aided Software Engineering.......................................378

Agile Development Methods ........................................................378

Capability Maturity Model ...........................................................379

Scheduling .....................................................................................380

Change Management..............................................................................380

Programming Languages .......................................................................382

Object-Oriented Programming ....................................................384

CORBA..........................................................................................385

Database Management ...........................................................................385

Database Terms .............................................................................386

Integrity .........................................................................................388

Transaction Processing..................................................................388

Data Warehousing.........................................................................388

Data Mining ..................................................................................389

Knowledge Management ..............................................................390

Artificial Intelligence and Expert Systems ...................................390

Malicious Code .......................................................................................391

Viruses............................................................................................391

Worms............................................................................................393

Spyware..........................................................................................394

Back Doors and Trapdoors ...........................................................394

Change Detection .........................................................................395

Malformed Input (SQL Injection)................................................395

Mobile Code..................................................................................396

Financial Attacks............................................................................396

Buffer Overflow.............................................................................397

Denial of Service ...........................................................................398

Distributed Denial of Service .......................................................399

Exam Prep Questions .............................................................................400

Answers to Exam Prep Questions..........................................................402

Need to Know More?.............................................................................404

Chapter 10:

Information Security and Risk Management Practices..............................405

Introduction ............................................................................................406

Basic Security Principles ........................................................................406

Security Management and Governance.................................................408

Asset Identification .................................................................................410

Risk Assessment ......................................................................................411

Risk Management..........................................................................412

Policies Development.............................................................................427

Security Policy...............................................................................428

Standards........................................................................................430

Baselines.........................................................................................430

Guidelines......................................................................................431

Procedures .....................................................................................431

Data Classification.........................................................................431

Implementation.......................................................................................434

Roles and Responsibility ...............................................................434

Security Controls...........................................................................436

Training and Education..........................................................................438

Security Awareness ........................................................................439

Social Engineering ........................................................................440

Auditing Your Security Infrastructure ...................................................441

The Risk of Poor Security Management...............................................442

Exam Prep Questions .............................................................................443

Answers to Exam Prep Questions..........................................................445

Need to Know More?.............................................................................447

Chapter 11:

Operations Security .......................................................................449

Introduction ............................................................................................450

Operational Security...............................................................................450

Employee Recruitment .................................................................451

New-Hire Orientation ..................................................................452

Separation of Duties......................................................................452

Job Rotation...................................................................................452

Least Privilege ...............................................................................453

Mandatory Vacations.....................................................................453

Termination ...................................................................................454

Accountability .........................................................................................454

Controls ..................................................................................................456

Security Controls...........................................................................456

Operational Controls ....................................................................458

Auditing and Monitoring .......................................................................465

Auditing .........................................................................................466

Monitoring Controls.....................................................................467

Clipping Levels..............................................................................468

Intrusion Detection .......................................................................469

Keystroke Monitoring...................................................................470

Antivirus.........................................................................................470

Facility Access Control..................................................................471

Telecommunication Controls.................................................................472

Fax..................................................................................................472

PBX................................................................................................473

Email..............................................................................................474

Backup, Fault Tolerance, and Recovery Controls .................................476

Backups ..........................................................................................477

Fault Tolerance..............................................................................478

RAID..............................................................................................480

Recovery Controls.........................................................................482

Security Assessments ..............................................................................483

Policy Reviews ...............................................................................484

Vulnerability Scanning ..................................................................484

Penetration Testing .......................................................................485

Operational Security Threats and Vulnerabilities.................................489

Common Attack Methodologies...................................................490

Attack Terms and Techniques .......................................................492

Exam Prep Questions .............................................................................494

Answers to Exam Prep Questions..........................................................497

Need to Know More?.............................................................................499

Chapter 12:

Practice Exam I ............................................................................501

Chapter 13:

Answers to Practice Exam I..............................................................515

Chapter 14:

Practice Exam II ...........................................................................531

Chapter 15:

Answers to Practice Exam II.............................................................545

Appendix A:

What’s on the CD ..........................................................................559

Index ........................................................................................563

Read More Show Less

Preface

Introduction

Welcome to CISSP Exam Cram! This book covers the CISSP certification exam. Whether this is your first or your fifteenth Exam Cram, you’ll find information here and in Chapter 1 that will ensure your success as you pursue knowledge, experience, and certification. This introduction explains the ISC2 certification programs in general and talks about how the Exam Cram series can help you prepare for the CISSP exam.

This book is one of the Exam Cram series of books and will help by getting you on you way to becoming an ISC2 Certified Information Systems Security Professional (CISSP).

This introduction discusses the basics of the CISSP exam. Included are sections covering preparation, how to take an exam, a description of this book’s contents, how this book is organized, and, finally, author contact information.

Each chapter in this book contains practice questions. There are also two full-length practice exams at the end of the book. Practice exams in this book should provide an accurate assessment of the level of expertise you need to obtain to pass the test. Answers and explanations are included for all test questions. It is best to obtain a level of understanding equivalent to a consistent pass rate of at least 95% or more on the practice questions and exams in this book before you attempt the real exam.

Let’s begin by looking at preparation for the exam.

How to Prepare for the Exam

Preparingfor the CISSP exam requires that you obtain and study materials designed to provide comprehensive information about security. The following list of materials will help you study and prepare:

  • The ISC2 website at http://www.ISC2.org
  • The study guide available at the ISC2 website
  • The CISSP open study guide website at http://www.cccure.org

Many people form study groups, attend seminars, and training classes to help them study for and master the material needed to pass the CISSP exam.

Practice Tests

You don’t need to know much about practice tests, other than that they are a worthwhile expense for three reasons:

  • They help you diagnose areas of weakness.
  • They are useful for getting used to the format of questions.
  • They help you to decide when you are ready to take the exam.

This book contains questions at the end of each chapter and includes two full-length practice tests. However, if you still want more, a related Exam Cram CISSP Practice Questions book has more than 500 additional questions. The questions are in paper form so that you can practice in an environment similar to the real exam; they are also available electronically as a practice test CD in the back of the book. Many other companies provide CISSP certification practice tests as well.

Taking a Certification Exam

When you have prepared for the exam, you must register with ISC2 to take the exam. The CISSP exam is given throughout the year at various locations. You can find the latest schedule at https://http://www.ISC2.org/cgi-bin/exam_schedule.cgi?displaycategory=1182. Many people decide to travel to the exam location; others wait until it is given at a location closer to them. ISC2 has implemented regional pricing: As an example, early registration is $499 in the United States, compared to standard registration of $599. Check the ISC2 website at https://www.ISC2.org/uploadedFiles/Downloads/exam_pricing.pdf to get specific details.

You can register for an exam done online, by mail, or by fax. The online form is available at http://www.ISC2.org/certification-register-now.aspx. After you register, you will receive a confirmation notice.

Arriving at the Exam Location

As with any examination, arrive at the testing center early. Be prepared! You will need to bring the confirmation letter and identification such as a driver’s license, green card, or passport. Any photo ID will suffice. Two forms of ID are usually required. The testing center staff requires proof that you are who you say you are and that someone else is not taking the test for you. Arrive early as if you are late you will be barred from entry and will not receive a refund for the cost of the exam.


Warning - You’ll be spending a lot of time in the exam room. The total test time is 6 hours, so eat a good breakfast and take a snack and bottle of water with you to the testing area. Policies differ—some locations might allow you to take the water and energy bar to your desk whereas others might make you place it at the back of the testing area.


In the Exam Room

You will not be allowed to take study materials or anything else into the examination room with you that could raise suspicion that you’re cheating. This includes practice test material, books, exam prep guides, or other test aids.

After the Exam

Examination results are not available after the exam. You must wait up to 4–6 weeks to get your results by email or snail mail. Most individuals receive these rather quickly within 4 weeks or so. If you pass the exam, you will simply receive a passing grade—your exact score will not be provided.

Retaking a Test

If you fail the exam you must wait at least 90 days to retake a failed examination. Candidates that do not pass will receive a complete breakdown on their score. Each of the ten domains will be shown as will the candidates score. As an example, you may have received a 95% score in the telecommunications domain and only 12% in cryptography. Use this feedback to better understand what areas you were weak in and where to spend your time and effort in your studies. Additionally, invest in some practice tests if you have not already done so. There is much to be said for getting used to a testing format.

Tracking Your CISSP Status

When you pass the exam, you still need to attest to the CISSP code of ethics and have an existing CISSP complete an endorsement form for you.

When you receive notice of your passing grade, a blank endorsement form will be sent with it. The endorsement form must be completed by someone who can attest to your professional experience and who is an active CISSP in good standing. If you don’t know anyone who is CISSP certified, ISC2 allows endorsements from other professionals who are certified, licensed, or commissioned, and an officer of the corporation where you are employed. You can review complete information on the endorsement form at the ISC2 website.

About This Book

The ideal reader for an Exam Cram book is someone seeking certification. However, it should be noted that an Exam Cram book is a very easily readable, rapid presentation of facts. Therefore, an Exam Cram book is also extremely useful as a quick reference manual.

Most people seeking certification use multiple sources of information. Check out the links at the end of each chapter to get more information about subjects you’re weak in. Practice tests can help indicate when you are ready. Various security books from retailers also describe the topics in this book in much greater detail. Don’t forget that many have described the CISSP exam as being a “mile wide.”

This book includes other helpful elements in addition to the actual logical, step-by-step learning progression of the chapters themselves. Exam Cram books use elements such as exam alerts, tips, notes, and practice questions to make information easier to read and absorb.


Note - Reading this book from start to finish is not necessary; this book is set up so that you can quickly jump back and forth to find sections you need to study.


Use the Cram Sheet to remember last-minute facts immediately before the exam. Use the practice questions to test your knowledge. You can always brush up on specific topics in detail by referring to the table of contents and the index. Even after you achieve certification, you can use this book as a rapid-access reference manual.

The Chapter Elements

Each Exam Cram book has chapters that follow a predefined structure. This structure makes Exam Cram books easy to read and provides a familiar format for all Exam Cram books. The following elements typically are used:

  • Opening hotlists
  • Chapter topics
  • Exam Alerts
  • Notes
  • Tips
  • Sidebars
  • Cautions
  • Exam preparation practice questions and answers
  • A “Need to Know More?” section at the end of each chapter

Note - Bulleted lists, numbered lists, tables, and graphics are also used where appropriate. A picture can paint a thousand words sometimes, and tables can help to associate different elements with each other visually.


Now let’s look at each of the elements in detail.

  • Opening hotlists—The start of every chapter contains a list of terms you should understand. A second hotlist identifies all the techniques and skills covered in the chapter.
  • Chapter topics—Each chapter contains details of all subject matter listed in the table of contents for that particular chapter. The objective of an Exam Cram book is to cover all the important facts without giving too much detail; it is an exam cram. When examples are required, they are included.
  • Exam Alerts—Exam Alerts address exam-specific, exam-related information. An Exam Alert addresses content that is particularly important, tricky, or likely to appear on the exam. An Exam Alert looks like this:

  • Warning - Make sure you remember the different ways in which DES can be implemented and that ECB is considered the weakest form of DES.


  • Notes—Notes typically contain useful information that is not directly related to the current topic under consideration. To avoid breaking up the flow of the text, they are set off from the regular text.

  • Note - This is a note. You have already seen several notes.


  • Tips—Tips often provide shortcuts or better ways to do things.

  • Tip - A clipping level is the point at which you set a control to distinguish between activity that should be investigated and activity that should not be investigated.


  • Sidebars—Sidebars are longer and run beside the text. They often describe real-world examples or situations.

  • How Caller ID Can Be Hacked - Sure, we all trust Caller ID, but some Voice over IP (VoIP) providers allow users to inject their own Call Party Number (CPN) into the call. Because VoIP is currently outside FCC regulation, these hacks are now possible.


  • Cautions—Cautions apply directly to the use of the technology being discussed in the Exam Cram. For example, a Caution might point out that the CER is one of the most important items to examine when examining biometric devices.

  • Caution - The Crossover Error Rate (CER) is the point at which Type 1 errors and Type 2 errors intersect. The lower the CER is, the more accurate the device is.


  • Exam preparation practice questions—At the end of every chapter is a list of at least 10 exam practice questions similar to those in the actual exam. Each chapter contains a list of questions relevant to that chapter, including answers and explanations. Test your skills as you read.
  • “Need to Know More?” section—This section at the end of each chapter describes other relevant sources of information. With respect to this chapter, the best place to look for CISSP certification information is at the ISC2 website, http://www.ISC2.org.

Other Book Elements

Most of this Exam Cram book on CISSP follows the consistent chapter structure already described. However, there are various, important elements that are not part of the standard chapter format. These elements apply to the entire book as a whole.

  • Practice exams—In addition to exam-preparation questions at the end of each chapter, two full practice exams are included at the end of the book.
  • Answers and explanations for practice exams—These follow each practice exam, providing answers and explanations to the questions in the exams.
  • Glossary—The glossary contains a listing of important terms used in this book with explanations.
  • Cram Sheet—The Cram Sheet is a quick-reference, tear-out cardboard sheet of important facts useful for last-minute preparation. Cram sheets often include a simple summary of facts that are most difficult to remember.
  • CD—The CD contains the MeasureUp exam-simulation software, which provides multiple test modes that you can use for exam preparation. MeasureUp practice tests are designed to appropriately balance the questions over each technical area (domain) covered by the exam. All concepts from the actual exam are covered thoroughly to ensure you’re prepared for the exam.

Chapter Contents

The following list provides an overview of the chapters.

  • Chapter 1, “The CISSP Certification Exam”—This chapter introduces exam strategies and considerations.
  • Chapter 2, “Physical Security”—This chapter details physical security and the threats and countermeasures available for protecting an organization’s resources. Physical security plays a key role in securing an organization’s assets. Without effective physical security, there can be no effective security structure in place.
  • Chapter 3, “Access Control Systems and Methodology”—This chapter covers the basics of access control. This chapter addresses the three A’s: authentication, authorization, and accountability. Items such as identification, single sign-on, centralized authentication, and the role of technical, administrative, and physical controls are discussed.
  • Chapter 4, “Cryptography”—This chapter discusses the methods, means, and systems used to encrypt and protect data. Symmetric, asymmetric, and hashing algorithms are introduced, along with PKI and cryptographic methods of attack.
  • Chapter 5, “Security Architecture and Models”—This chapter discusses key concepts such as computer hardware, operating system design, security models, and documentation used to verify, certify, and accredited systems and networks.
  • Chapter 6, “Telecommunications and Network Security”—This chapter discusses telecommunication technology. Items such as the OSI model, TCP/IP, network equipment, LAN, MAN, and WAN protocols, and wireless technologies are just a few of the items discussed. This is the most expansive domain and considered one of the most critical for the CISSP candidate to master.
  • Chapter 7, “Business Continuity and Disaster Recovery Planning”—This chapter covers all the aspects of the BCP and DRP process. Although some may discount the importance the importance of this domain, events such as 9/11 demonstrate the critically of this domain. This chapter addresses key elements of disaster recovery and business continuity. One important item is that no demonstrated recovery exists until the plan has been tested. Exam candidates must understand what is needed to prevent, minimize, and recover from disasters.
  • Chapter 8, “Legal Regulations, Compliance, and Investigations”—This chapter covers all legal issues from a global perspective. Readers must understand issues such as privacy and the transnational flow of information. Ethics are also discussed because CISSP candidates must understand and abide by the ISC2 code of ethics. Incident response and computer forensics are introduced in this chapter because readers must understand how to deal with the potential of computer crime.
  • Chapter 9, “Applications and Systems-Development Security”—This chapter discusses databases, the system development life cycle and the importance of building security into applications and systems as early as possible during the development process. Project management is reviewed, as are malicious code, knowledge-based systems, and application issues.
  • Chapter 10, “Information Security and Risk Management Practices”—This chapter discusses asset management and the protection of critical resources. Quantitative and qualitative risk assessment are two major topics of this chapter. Readers must understand how these concepts are used to assess and measure risk while reducing threats to the organization. Key concepts include the development of policies, procedures, guidelines, and assorted controls.
  • Chapter 11, “Operations Security”—This chapter covers operation controls—that is, the types of controls that the organization can implement. Topics such as background checks, duel controls, mandatory vacations, rotation of duties, and auditing are introduced. This chapter also reviews security assessments, ethical hacking, and vulnerability scanning.
  • Chapter 12, Practice Exam I—This is a full-length practice exam.
  • Chapter 13, Answers to Practice Exam I—This element contains the answers and explanations for the first practice exam.
  • Chapter 14, Practice Exam II—This is a second full-length practice exam.
  • Chapter 15, Answers to Practice Exam II—This element contains the answers and explanations for the second practice exam.

Contacting the Author

Hopefully, this book provides you with the tools you need to pass the CISSP exam. Feedback is appreciated. You can contact the author at mikeg@thesolutionfirm.com.

Thank you for selecting my book; I have worked to apply the same concepts in this book that I have used in the hundreds of training classes I have taught. Spend your study time wisely and you too can become a CISSP. Good luck on the exam!

Self-Assessment

This Self-Assessment section enables you to evaluate your readiness to take the CISSP certification exam. It should also help you understand what’s required to obtain the CISSP certification. Are you ready?

CISSPs in the Real World

Security continues to be on everyone’s mind. The CISSP certification continues to be one of the most sought-after security certifications. Increasing numbers of people are studying for and obtaining their CISSP certifications. Congratulations on making the decision to follow in their footsteps. If you are willing to tackle the process seriously and do what it takes to obtain the necessary experience and knowledge, you can pass the exam on the first try.


Tip - You can also assess your CISSP skill set by using the MeasureUp Certification Mode.


The Ideal CISSP Candidate

The CISSP is designed for individuals that are leading, planning, organizing, or controlling the security initiative of an organization. The ideal CISSP candidate is likely to have a 4-year college education and have at least 5–7 years experience in one or more of the 10 CISSP domains. The most applicable degree is in computer science or perhaps a related field. A degree is not a prerequisite for taking the test. However, exam candidates must have a minimum of 5 years of direct full-time security work experience in two or more of the 10 domains. One year of experience can be substituted for a four-year college degree or an approved certification such as Security +. The complete list of approved certifications can be found at https://www.ISC2.org/cgi-bin/content.cgi?page=1016. Don’t be lull-ed into thinking that this is an easy test. Some words of caution might be in order:

  • The CISSP exam requires the candidate to absorb a substantial amount of material. The test is 6 hours long and consists of 225 graded questions. Unlike Microsoft exams and most other IT vendor exams, it is not a computer-generated test.
  • The pass mark is set high, at 700 points. The individual questions are weighted, which means that harder questions are worth more than easier ones.
  • Most of the individuals attempting the exam are familiar with one to three of the domains. This means that studying for the exam can be overwhelming because there is so much material to cover. This book can help by guiding you to the areas in which you are weak or strong.
  • To be eligible for the CISSP exam, students are required to have 4 years of experience, or 3 years of experience and a college degree.

Put Yourself to the Test

In this section, you answer some simple questions. The objective is for you to understand exactly how much work and effort you must invest to pass the CISSP certification exam. The simple answer to this question is this: The experience and education you have will dictate how difficult it will be for you to pass. Be honest in your answers or you will end up wasting $500 or more on an exam you were not ready to take. From the beginning, two things should be clear:

  • Any educational background in computer science will be helpful, as will other IT certifications you have achieved.
  • Hands-on actual experience is not only essential, but also required to obtain this certification.

Your Educational Background

  • Do you have a computer science degree?
  • You’ll have a good basic knowledge needed for 3 or more of the 10 domains, assuming that you finished your degree and your schooling and have some fairly sophisticated computer skills. Subject areas such as application development, networking, and database design are a great help.

  • Did you attend some type of technical school or computer cram course?
  • This question applies to low-level or short-term computer courses. Many of these courses are extremely basic or focused in one particular area. Although the CISSP exam is not platform specific, training classes that focused on networking, security, hacking, or database design will help you pass the exam.

  • Have you developed any security policies, performed security audits, performed penetration tests, or developed response plans?
  • If yes, you will probably be able to handle about half of the CISSP exam domains.

  • Do you have a photographic memory?
  • If yes, you might have a slim chance of passing simply by reading this book, taking some practice exams, and using the Internet to brush up on the subjects you are weak in. However, the goal here is to gain a real understanding of the material. As a CISSP, you might be asked to lead, plan, organize, or control your organization’s security operations; if that happens, you’ll need a real understanding of how the various technologies and techniques work. Don’t cheat yourself or gamble with your career.

Again, the education and requirements given here are by no means absolute. Still, an education can give you a very good grounding in any endeavor—the higher the level of education, the better.

Testing Your Exam Readiness

Whether you attend a training class, form a study group, or study on your own, preparing for the CISSP exam is essential. The exam will cost you about $500, depending on where you are located, so you’ll want to do everything you can to make sure you pass on the first try. Reading, studying, and taking practice exams are the best ways to increase your readiness. Practice exams help in a number of ways:

  • Practice exams highlight weak spots for further study.
  • Practice exams give you a general perspective on the question format. Practicing the questions the way they are asked can help enormously on the actual testing day.
  • Two full-length practice exams are provided with this book. Que also publishes a second book, CISSP Practice Questions Exam, with more than 500 practice CISSP test questions; it is an excellent supplement to this book.

After the Exam

After you have passed the exam, you will need to gain continuing education credits each year to maintain your certification. Your certification will come up for renewal every 3 years, so you’ll need to obtain 120 continuing education credits (CPE) or retake the exam. Retaking the exam is probably not a likely choice. These are some ways to gain CPEs to keep your certification current:

  • Write a book.
  • Read a book. (Only one per year can be used for credit.) This will give you a couple of credits, but not enough to keep your certification current.
  • Do volunteer work that is approved by ISC2. When you are certified, you can log on to the ISC2 website for more information. A variety of volunteer work is available, including proctoring the CISSP exam.
  • Attend a training class. Just about any type of technology training class is accepted as long as it is tied to one of the domains.
  • Teach a training class.
  • Attend a college-level security class.

As you can see, the goal here is to help you stay current. As technology changes, we all must continue to learn to keep up the pace.

Now that we have covered some of the ways in which to assess you exam readiness, let’s move on to Chapter 1, “The CISSP Certification Exam,” where you will learn more about how the exam is structured and some effective test-taking strategies.

© Copyright Pearson Education. All rights reserved.

Read More Show Less

Customer Reviews

Average Rating 3.5
( 11 )
Rating Distribution

5 Star

(3)

4 Star

(3)

3 Star

(3)

2 Star

(2)

1 Star

(0)

Your Rating:

Your Name: Create a Pen Name or

Barnes & Noble.com Review Rules

Our reader reviews allow you to share your comments on titles you liked, or didn't, with others. By submitting an online review, you are representing to Barnes & Noble.com that all information contained in your review is original and accurate in all respects, and that the submission of such content by you and the posting of such content by Barnes & Noble.com does not and will not violate the rights of any third party. Please follow the rules below to help ensure that your review can be posted.

Reviews by Our Customers Under the Age of 13

We highly value and respect everyone's opinion concerning the titles we offer. However, we cannot allow persons under the age of 13 to have accounts at BN.com or to post customer reviews. Please see our Terms of Use for more details.

What to exclude from your review:

Please do not write about reviews, commentary, or information posted on the product page. If you see any errors in the information on the product page, please send us an email.

Reviews should not contain any of the following:

  • - HTML tags, profanity, obscenities, vulgarities, or comments that defame anyone
  • - Time-sensitive information such as tour dates, signings, lectures, etc.
  • - Single-word reviews. Other people will read your review to discover why you liked or didn't like the title. Be descriptive.
  • - Comments focusing on the author or that may ruin the ending for others
  • - Phone numbers, addresses, URLs
  • - Pricing and availability information or alternative ordering information
  • - Advertisements or commercial solicitation

Reminder:

  • - By submitting a review, you grant to Barnes & Noble.com and its sublicensees the royalty-free, perpetual, irrevocable right and license to use the review in accordance with the Barnes & Noble.com Terms of Use.
  • - Barnes & Noble.com reserves the right not to post any review -- particularly those that do not follow the terms and conditions of these Rules. Barnes & Noble.com also reserves the right to remove any review at any time without notice.
  • - See Terms of Use for other conditions and disclaimers.
Search for Products You'd Like to Recommend

Recommend other products that relate to your review. Just search for them below and share!

Create a Pen Name

Your Pen Name is your unique identity on BN.com. It will appear on the reviews you write and other website activities. Your Pen Name cannot be edited, changed or deleted once submitted.

 
Your Pen Name can be any combination of alphanumeric characters (plus - and _), and must be at least two characters long.

Continue Anonymously
Sort by: Showing 1 – 15 of 11 Customer Reviews
  • Anonymous

    Posted January 3, 2011

    NO CD IN NOOK for PC VERSION!

    I was disappointed that there is no CD in the Nook version AND Barnes&Noble doesn't tell you -- or at least I can't find that little tid bit of useful information. I would not have purchased this for the NOOK had I known there was no CD.

    2 out of 2 people found this review helpful.

    Was this review helpful? Yes  No   Report this review
  • Posted December 5, 2009

    more from this reviewer

    Inaccuracies and questionable referencing

    I purchased the Exam Cram CISSP Second Edition a few months ago but have only just started reading through. Although I've only gotten about 30 pages in, I'm already dismayed by some of the questionable referencing and blatant inaccuracies in some of the example information.

    In terms of questionable references, for instance, page 26 includes a wikipedia reference in discussing laptop theft. As virtually any college professor will say, wikipedia is an unreliable source at best. There is a reason most colleges do not allow wikipedia as a reference for term papers.

    As for blatant inaccuracies, page 31 references the Triangle Shirtwaist Factory fire but states that the event occurred in 1991. The actual Triangle Shirtwaist fire happened in 1911. While this is an editorial mistake, such mistakes in a study/reference guide don't instill confidence in the overall quality of the material.

    Please bear in mind that this review is based on only a few pages of the book so I cannot yet offer a complete review. That being said, I'd be wary of purchasing this one.

    1 out of 1 people found this review helpful.

    Was this review helpful? Yes  No   Report this review
  • Anonymous

    Posted November 19, 2012

    The first key thing to note here, is that this was one of my key

    The first key thing to note here, is that this was one of my key resources and I passed the exam on the first try. This was an excellent book for getting familiar with the basic concepts of CISSP. Strengths of this book include excellent explanation of basic core concepts and detailed, yet simple descriptions of technical foundations.

    That said, it was one of several books that I read/studied and among them it was not the best at preparing me for the actual exam. Weaknesses included lots of unbroken text, structured in a way that tended to hide some of the most important key elements that were good to memorize for the test. This book was one of the resources that I actually learned the most from though (a few things I will use, beyond just the test). One challenge is that this version is quite outdated and the test has been recently revised. Many concepts on the test were not covered in this book (as such, I found several surprises on the test/all of my books were outdated). There is a more recent version presently available; however, I did not read the newer version and as such cannot comment on the revised product.

    If you are preparing for the CISSP exam my recommendation is to have several quality resources, at least some of which are among the most recent publications, and study them all fastidiously. It is a difficult exam that covers lots of material. This book will serve you well as one of several such resources. In conclusion, I am pleased that this book was one of my key resources in studying for the exam.

    Was this review helpful? Yes  No   Report this review
  • Anonymous

    Posted August 2, 2009

    This help me Get my CISSP the first time that I took the test and I passed

    I really like this book it goes into great security and if you study hard and know computers you'll pass the test with this book.

    0 out of 1 people found this review helpful.

    Was this review helpful? Yes  No   Report this review
  • Anonymous

    Posted January 26, 2010

    No text was provided for this review.

  • Anonymous

    Posted June 25, 2010

    No text was provided for this review.

  • Anonymous

    Posted January 9, 2010

    No text was provided for this review.

  • Anonymous

    Posted February 14, 2011

    No text was provided for this review.

  • Anonymous

    Posted January 27, 2010

    No text was provided for this review.

  • Anonymous

    Posted March 3, 2011

    No text was provided for this review.

  • Anonymous

    Posted May 1, 2011

    No text was provided for this review.

  • Anonymous

    Posted February 15, 2013

    No text was provided for this review.

  • Anonymous

    Posted July 2, 2010

    No text was provided for this review.

  • Anonymous

    Posted January 25, 2010

    No text was provided for this review.

  • Anonymous

    Posted May 24, 2011

    No text was provided for this review.

Sort by: Showing 1 – 15 of 11 Customer Reviews

If you find inappropriate content, please report it to Barnes & Noble
Why is this product inappropriate?
Comments (optional)