Items related to CISSP Exam Cram

Gregg, Michael CISSP Exam Cram ISBN 13: 9780789738066

CISSP Exam Cram - Softcover

  • 3.83 out of 5 stars
    35 ratings by Goodreads
 
9780789738066: CISSP Exam Cram

Synopsis

Updated for 2009

 

Covers the critical information you’ll need to know to score higher on your CISSP exam!

  • Build and manage an effective, integrated security architecture
  • Systematically protect your physical facilities and the IT resources they contain
  • Implement and administer access control
  • Use cryptography to help guarantee data integrity, confidentiality, and authenticity
  • Secure networks, Internet connections, and communications
  • Make effective business continuity and disaster recovery plans, and execute them successfully
  • Address today’s essential legal, regulatory, and compliance issues
  • Master the basics of security forensics
  • Develop more secure applications and systems from the ground up
  • Use security best practices ranging from risk management to operations and auditing
  • Understand and perform the crucial non-technical tasks associated with IT security

 

CD Features Test Engine Powered by MeasureUp!

  • Detailed explanations of correct and incorrect answers
  • Multiple test modes
  • Random questions and order of answers
  • Coverage of each CISSP exam domain

"synopsis" may belong to another edition of this title.

About the Author

As the founder and president of Superior Solutions, Inc., a Houston-based IT security consulting, auditing, and training firm, Michael Gregg has more than15 years experience in information security and risk management. He holds two associate’s degrees, a bachelor’s degree, and a master’s degree. Some of the certifications he holds include the following: CISSP, CISA, CISM, MCSE, CTT+, A+, N+, Security+, CNA, CCNA, CIW Security Analyst, CCE, CEH, CHFI, CEI, DCNP, ES Dragon IDS, ES Advanced Dragon IDS, and SSCP.

 

Michael has experience not only in performing security audits and assessments, but also is the co-author of Build Your Own Security Lab by Wiley Publishing. Other publications he has authored include CISSP Practice Questions Exam Cram, CISA Exam Prep, and CEH Exam Prep 2. Michael is a site expert for TechTarget.com websites and also serves on their editorial advisory board. His articles have been published on IT websites including CertMag.com, CramSession.com, and GoCertify.com. Michael has created security, audit, and IT networking course material for various companies and universities. Although audits and assessments are where he spends the bulk of his time, teaching and contributing to the written body of IT security knowledge is how Michael believes he can give something back to the community that has given him so much.

 

He is a member of the American College of Forensic Examiners and the Information Systems Audit and Control Association. When not working, Michael enjoys traveling and restoring muscle cars.

Excerpt. © Reprinted by permission. All rights reserved.

Introduction

Introduction

Welcome to CISSP Exam Cram! This book covers the CISSP certification exam. Whether this is your first or your fifteenth Exam Cram, you’ll find information here and in Chapter 1 that will ensure your success as you pursue knowledge, experience, and certification. This introduction explains the ISC2 certification programs in general and talks about how the Exam Cram series can help you prepare for the CISSP exam.

This book is one of the Exam Cram series of books and will help by getting you on you way to becoming an ISC2 Certified Information Systems Security Professional (CISSP).

This introduction discusses the basics of the CISSP exam. Included are sections covering preparation, how to take an exam, a description of this book’s contents, how this book is organized, and, finally, author contact information.

Each chapter in this book contains practice questions. There are also two full-length practice exams at the end of the book. Practice exams in this book should provide an accurate assessment of the level of expertise you need to obtain to pass the test. Answers and explanations are included for all test questions. It is best to obtain a level of understanding equivalent to a consistent pass rate of at least 95% or more on the practice questions and exams in this book before you attempt the real exam.

Let’s begin by looking at preparation for the exam.

How to Prepare for the Exam

Preparingfor the CISSP exam requires that you obtain and study materials designed to provide comprehensive information about security. The following list of materials will help you study and prepare:

  • The ISC2 website at http://www.ISC2.org
  • The study guide available at the ISC2 website
  • The CISSP open study guide website at http://www.cccure.org

Many people form study groups, attend seminars, and training classes to help them study for and master the material needed to pass the CISSP exam.

Practice Tests

You don’t need to know much about practice tests, other than that they are a worthwhile expense for three reasons:

  • They help you diagnose areas of weakness.
  • They are useful for getting used to the format of questions.
  • They help you to decide when you are ready to take the exam.

This book contains questions at the end of each chapter and includes two full-length practice tests. However, if you still want more, a related Exam Cram CISSP Practice Questions book has more than 500 additional questions. The questions are in paper form so that you can practice in an environment similar to the real exam; they are also available electronically as a practice test CD in the back of the book. Many other companies provide CISSP certification practice tests as well.

Taking a Certification Exam

When you have prepared for the exam, you must register with ISC2 to take the exam. The CISSP exam is given throughout the year at various locations. You can find the latest schedule at https://http://www.ISC2.org/cgi-bin/exam_schedule.cgi?displaycategory=1182. Many people decide to travel to the exam location; others wait until it is given at a location closer to them. ISC2 has implemented regional pricing: As an example, early registration is $499 in the United States, compared to standard registration of $599. Check the ISC2 website at https://www.ISC2.org/uploadedFiles/Downloads/exam_pricing.pdf to get specific details.

You can register for an exam done online, by mail, or by fax. The online form is available at http://www.ISC2.org/certification-register-now.aspx. After you register, you will receive a confirmation notice.

Arriving at the Exam Location

As with any examination, arrive at the testing center early. Be prepared! You will need to bring the confirmation letter and identification such as a driver’s license, green card, or passport. Any photo ID will suffice. Two forms of ID are usually required. The testing center staff requires proof that you are who you say you are and that someone else is not taking the test for you. Arrive early as if you are late you will be barred from entry and will not receive a refund for the cost of the exam.

Warning - You’ll be spending a lot of time in the exam room. The total test time is 6 hours, so eat a good breakfast and take a snack and bottle of water with you to the testing area. Policies differ—some locations might allow you to take the water and energy bar to your desk whereas others might make you place it at the back of the testing area.

In the Exam Room

You will not be allowed to take study materials or anything else into the examination room with you that could raise suspicion that you’re cheating. This includes practice test material, books, exam prep guides, or other test aids.

After the Exam

Examination results are not available after the exam. You must wait up to 4–6 weeks to get your results by email or snail mail. Most individuals receive these rather quickly within 4 weeks or so. If you pass the exam, you will simply receive a passing grade—your exact score will not be provided.

Retaking a Test

If you fail the exam you must wait at least 90 days to retake a failed examination. Candidates that do not pass will receive a complete breakdown on their score. Each of the ten domains will be shown as will the candidates score. As an example, you may have received a 95% score in the telecommunications domain and only 12% in cryptography. Use this feedback to better understand what areas you were weak in and where to spend your time and effort in your studies. Additionally, invest in some practice tests if you have not already done so. There is much to be said for getting used to a testing format.

Tracking Your CISSP Status

When you pass the exam, you still need to attest to the CISSP code of ethics and have an existing CISSP complete an endorsement form for you.

When you receive notice of your passing grade, a blank endorsement form will be sent with it. The endorsement form must be completed by someone who can attest to your professional experience and who is an active CISSP in good standing. If you don’t know anyone who is CISSP certified, ISC2 allows endorsements from other professionals who are certified, licensed, or commissioned, and an officer of the corporation where you are employed. You can review complete information on the endorsement form at the ISC2 website.

About This Book

The ideal reader for an Exam Cram book is someone seeking certification. However, it should be noted that an Exam Cram book is a very easily readable, rapid presentation of facts. Therefore, an Exam Cram book is also extremely useful as a quick reference manual.

Most people seeking certification use multiple sources of information. Check out the links at the end of each chapter to get more information about subjects you’re weak in. Practice tests can help indicate when you are ready. Various security books from retailers also describe the topics in this book in much greater detail. Don’t forget that many have described the CISSP exam as being a “mile wide.”

This book includes other helpful elements in addition to the actual logical, step-by-step learning progression of the chapters themselves. Exam Cram books use elements such as exam alerts, tips, notes, and practice questions to make information easier to read and absorb.

Note - Reading this book from start to finish is not necessary; this book is set up so that you can quickly jump back and forth to find sections you need to study.

Use the Cram Sheet to remember last-minute facts immediately before the exam. Use the practice questions to test your knowledge. You can always brush up on specific topics in detail by referring to the table of contents and the index. Even after you achieve certification, you can use this book as a rapid-access reference manual.

The Chapter Elements

Each Exam Cram book has chapters that follow a predefined structure. This structure makes Exam Cram books easy to read and provides a familiar format for all Exam Cram books. The following elements typically are used:

  • Opening hotlists
  • Chapter topics
  • Exam Alerts
  • Notes
  • Tips
  • Sidebars
  • Cautions
  • Exam preparation practice questions and answers
  • A “Need to Know More?” section at the end of each chapter

Note - Bulleted lists, numbered lists, tables, and graphics are also used where appropriate. A picture can paint a thousand words sometimes, and tables can help to associate different elements with each other visually.

Now let’s look at each of the elements in detail.

  • Opening hotlists—The start of every chapter contains a list of terms you should understand. A second hotlist identifies all the techniques and skills covered in the chapter.
  • Chapter topics—Each chapter contains details of all subject matter listed in the table of contents for that particular chapter. The objective of an Exam Cram book is to cover all the important facts without giving too much detail; it is an exam cram. When examples are required, they are included.
  • Exam Alerts—Exam Alerts address exam-specific, exam-related information. An Exam Alert addresses content that is particularly important, tricky, or likely to appear on the exam. An Exam Alert looks like this:
  • Warning - Make sure you remember the different ways in which DES can be implemented and that ECB is considered the weakest form of DES.

  • Notes—Notes typically contain useful information that is not directly related to the current topic under consideration. To avoid breaking up the flow of the text, they are set off from the regular text.
  • Note - This is a note. You have already seen several notes.

  • Tips—Tips often provide shortcuts or better ways to do things.
  • Tip - A clipping level is the point at which you set a control to distinguish between activity that should be investigated and activity that should not be investigated.

  • Sidebars—Sidebars are longer and run beside the text. They often describe real-world examples or situations.
  • How Caller ID Can Be Hacked - Sure, we all trust Caller ID, but some Voice over IP (VoIP) providers allow users to inject their own Call Party Number (CPN) into the call. Because VoIP is currently outside FCC regulation, these hacks are now possible.

  • Cautions—Cautions apply directly to the use of the technology being discussed in the Exam Cram. For example, a Caution might point out that the CER is one of the most important items to examine when examining biometric devices.
  • Caution - The Crossover Error Rate (CER) is the point at which Type 1 errors and Type 2 errors intersect. The lower the CER is, the more accurate the device is.

  • Exam preparation practice questions—At the end of every chapter is a list of at least 10 exam practice questions similar to those in the actual exam. Each chapter contains a list of questions relevant to that chapter, including answers and explanations. Test your skills as you read.
  • “Need to Know More?” section—This section at the end of each chapter describes other relevant sources of information. With respect to this chapter, the best place to look for CISSP certification information is at the ISC2 website, http://www.ISC2.org.

Other Book Elements

Most of this Exam Cram book on CISSP follows the consistent chapter structure already described. However, there are various, important elements that are not part of the standard chapter format. These elements apply to the entire book as a whole.

  • Practice exams—In addition to exam-preparation questions at the end of each chapter, two full practice exams are included at the end of the book.
  • Answers and explanations for practice exams—These follow each practice exam, providing answers and explanations to the questions in the exams.
  • Glossary—The glossary contains a listing of important terms used in this book with explanations.
  • Cram Sheet—The Cram Sheet is a quick-reference, tear-out cardboard sheet of important facts useful for last-minute preparation. Cram sheets often include a simple summary of facts that are most difficult to remember.
  • CD—The CD contains the MeasureUp exam-simulation software, which provides multiple test modes that you can use for exam preparation. MeasureUp practice tests are designed to appropriately balance the questions over each technical area (domain) covered by the exam. All concepts from the actual exam are covered thoroughly to ensure you’re prepared for the exam.

Chapter Contents

The following list provides an overview of the chapters.

  • Chapter 1, “The CISSP Certification Exam”—This chapter introduces exam strategies and considerations.
  • Chapter 2, “Physical Security”—This chapter details physical security and the threats and countermeasures available for protecting an organization’s resources. Physical security plays a key role in securing an organization’s assets. Without effective physical security, there can be no effective security structure in place.
  • Chapter 3, “Access Control Systems and Methodology”—This chapter covers the basics of access control. This chapter addresses the three A’s: authentication, authorization, and accountability. Items such as identification, single sign-on, centralized authentication, and the role of technical, administrative, and physical controls are discussed.
  • Chapter 4, “Cryptography”—This chapter discusses the methods, means, and systems used to encrypt and protect data. Symmetric, asymmetric, and hashing algorithms are introduced, along with PKI and cryptographic methods of attack.
  • Chapter 5, “Security Architecture and Models”—This chapter discusses key concepts such as computer hardware, operating system design, security models, and documentation used to verify, certify, and accredited systems and networks.
  • Chapter 6, “Telecommunications and Network Security”—This chapter discusses telecommunication technology. Items such as the OSI model, TCP/IP, netw...

"About this title" may belong to another edition of this title.

  • PublisherPearson It Certification
  • Publication date2009
  • ISBN 10 0789738066
  • ISBN 13 9780789738066
  • BindingPaperback
  • Number of pages591
  • Rating
    • 3.83 out of 5 stars
      35 ratings by Goodreads

Buy Used

Condition: Fair
This item is in overall acceptable... Learn more about this copy

Shipping: FREE
Within U.S.A.

Destination, rates & speeds

Add to basket

Top Search Results from the AbeBooks Marketplace

Stock Image

Gregg, Michael
Published by Pearson It Certification, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Softcover

Seller: Goodwill of Colorado, COLORADO SPRINGS, CO, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: Acceptable. This item is in overall acceptable condition. Covers and dust jackets are intact but may have heavy wear including creases, bends, edge wear, curled corners or minor tears as well as stickers or sticker-residue. Pages are intact but may have minor curls, bends or moderate to considerable highlighting/ writing. Binding is intact; however, spine may have heavy wear. A well-read copy overall. Please note that all items are donated goods and are in used condition. Orders shipped Monday through Friday! Your purchase helps put people to work and learn life skills to reach their full potential. Orders shipped Monday through Friday. Your purchase helps put people to work and learn life skills to reach their full potential. Thank you!. Seller Inventory # 466SK8000X6B

Contact seller

Buy Used

US$ 5.32
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Que, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: ThriftBooks-Atlanta, AUSTELL, GA, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Condition: Good. No Jacket. Pages can have notes/highlighting. Spine may show signs of wear. ~ ThriftBooks: Read More, Spend Less 1.85. Seller Inventory # G0789738066I3N00

Contact seller

Buy Used

US$ 6.41
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Que, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: ThriftBooks-Reno, Reno, NV, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Condition: Good. No Jacket. Pages can have notes/highlighting. Spine may show signs of wear. ~ ThriftBooks: Read More, Spend Less 1.85. Seller Inventory # G0789738066I3N00

Contact seller

Buy Used

US$ 6.41
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Que, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Condition: Good. No Jacket. Pages can have notes/highlighting. Spine may show signs of wear. ~ ThriftBooks: Read More, Spend Less 1.85. Seller Inventory # G0789738066I3N00

Contact seller

Buy Used

US$ 6.41
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Pearson It Certification, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Softcover

Seller: Wonder Book, Frederick, MD, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: Very Good. Very Good condition. 2nd edition, updated for 2009. A copy that may have a few cosmetic defects. May also contain light spine creasing or a few markings such as an owner's name, short gifter's inscription or light stamp. Bundled media such as CDs, DVDs, floppy disks or access codes may not be included. Seller Inventory # V14A-02625

Contact seller

Buy Used

US$ 7.17
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

-
Published by -, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: AwesomeBooks, Wallingford, United Kingdom

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Condition: Very Good. CISSP Exam Cram (Exam Cram (Pearson)) This book is in very good condition and will be shipped within 24 hours of ordering. The cover may have some limited signs of wear but the pages are clean, intact and the spine remains undamaged. This book has clearly been well maintained and looked after thus far. Money back guarantee if you are not satisfied. See all our books here, order more than 1 book and get discounted shipping. Seller Inventory # 7719-9780789738066

Contact seller

Buy Used

US$ 21.31
Convert currency
Shipping: US$ 6.70
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

-
Published by - -, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: Bahamut Media, Reading, United Kingdom

Seller rating 4 out of 5 stars 4-star rating, Learn more about seller ratings

Paperback. Condition: Very Good. This book is in very good condition and will be shipped within 24 hours of ordering. The cover may have some limited signs of wear but the pages are clean, intact and the spine remains undamaged. This book has clearly been well maintained and looked after thus far. Money back guarantee if you are not satisfied. See all our books here, order more than 1 book and get discounted shipping. Seller Inventory # 6545-9780789738066

Contact seller

Buy Used

US$ 21.31
Convert currency
Shipping: US$ 9.37
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Pearson IT Certification, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: dsmbooks, Liverpool, United Kingdom

Seller rating 4 out of 5 stars 4-star rating, Learn more about seller ratings

Paperback. Condition: Good. Good. book. Seller Inventory # D7S9-1-M-0789738066-3

Contact seller

Buy Used

US$ 78.58
Convert currency
Shipping: US$ 33.57
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Gregg, Michael
Published by Pearson IT Certification, 2009
ISBN 10: 0789738066 ISBN 13: 9780789738066
Used Paperback

Seller: The Book Spot, Sioux Falls, SD, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Seller Inventory # Abebooks196202

Contact seller

Buy Used

US$ 300.00
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket