Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

   
 
Reply to this topicStart new topic
> CISSP exam, How to study for this exam
KeyboardWalker
post Feb 17 2008, 08:21 AM
Post #1


New Member
*

Group: New Member
Posts: 1
Joined: 17-February 08
From: Northern VA
Member No.: 76,896
Operating System: Windows XP



pullhair.gif Any suggestions on how to study to pass this exam?
Go to the top of the page
 
+Quote Post
paws
post Feb 17 2008, 12:26 PM
Post #2


SuperMember
Group Icon

Group: Tech Team
Posts: 1,849
Joined: 11-November 04
From: Lat' 51N, Long' not much East or West, (UK)
Member No.: 18,221
Operating System: Win XP (Pro & Home) Win 2000, Linux



Hi and welcome to the WTT forums.
welcome.gif
Senior colleagues in the malware removal forum, the Classroom Teachers and Administrative staff here may be able to give you further information, but assuming you have the required levels of practical experience and have the necessary academic qualifications then I have heard good reports on the 5 day preparation courses that are available. The pass rates are generally high and in the case of the UK are around 90%

The academic qualifications required are usually along the lines of:
:
Students must subscribe to the (ISC)2 Code of Ethics.
Students must have a minimum of four years of direct full-time security professional work experience in one or more of the ten test domains of Common Body of Knowledge (CBK), or three years of direct full-time security professional work experience in one or more of the ten test domains of the CBK with a college degree. A master's degree in Information Security from a National Center of Excellence can substitute for one year of the four-year requirement.

Note: Valid experience includes information systems security-related work performed as a practitioner, auditor, consultant, vendor, investigator, or instructor, or that which requires IS security knowledge and involves direct application of that knowledge.

The multiple choice nature of the exam takes some getting used to for those folks who have not encountered that method of testing previously or recently. As the maximum time allowed for the exam is 6 hours and there are generally 250 questions, speed is of the essence, you will have considerably less than 1.5 minutes to read each question, eliminate the distractors, note the possibles, and then select the appropriate responses. This time allocation allows no time for reviewing the questions about which you are unsure, or considering in depth the accuracy and exact interpretation of the meanings behind the questions (that can sometimes be tricky!)........

A good practical guide is to train yourself to require only 1 minute for each question, so you have sufficient time to review areas of uncertanty and check thoroughly your anwers.

Assuming you "know your stuff" then examination technique is an important, some would say vital part of your preparation.

I only have knowledge and experience of the UK situation but I assume that similar fast track courses will be available to you in your local area.
The 10 domains that can usually be covered include:

CISSP Domain 1) Security Management Practices
Types of Security Controls
Security Policies, Standards, Procedures, and Guidelines
Risk Management and Analysis

CISSP Domain 2) Access Control Systems
Identification, Authentication, and Authorization Technologies
Discretionary versus Mandatory Access Control Models
Rule-based and Role-based Access Control

CISSP Domain 3) Telecommunications and Network Security
TCP\IP Suite
LAN, MAN, and WAN Topologies and Technologies
Firewall Types and Architectures

CISSP Domain 4) Cryptography
Block and Stream Ciphers
Explanation and Uses of Symmetric Key Algorithms
Explanation and Uses of Asymmetric Key Algorithms

CISSP Domain 5) Security Architecture and Models
Critical Components of Every Computer
Access Control Models
Certification and Accreditation

CISSP Domain 6) Operations Security
Operations Department Responsibilities
Personnel and Roles
Media Library and Resource Protection

CISSP Domain 7) Application and System Development
Software Development Models
Database Models
Relational Database Components

CISSP Domain 8) Business Continuity and Disaster Recovery Planning
Roles and Responsibilities
Liability and Due Care Issues
Business Impact Analysis

CISSP Domain 9) Law, Investigation and Ethics
Privacy Laws and Concerns
Complications of Computer Crime Investigation
Types of Evidence and How to Collect It

CISSP Domain 10) Physical Security
Facility Location and Construction Issues
Physical Vulnerabilities and Threats
Fencing, Lighting, and Perimeter Protection

I hope you are able to find out further information on facilities more local to you as, of necessity, my comments are from a UK perspective.
Good luck with your preparations.
Regards
paws
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts 0 -Rando- 393 11th January 2006 - 03:19 PM
Last post by: -Rando-

RSS Time is now: 20th November 2008 - 12:20 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy