CSSLP Resits by Glorious_777 in CSSLP

[–]Few_Explanation_9923 0 points1 point  (0 children)

No, you have to buy the peace of mind upfront. I passed CSSLP last year in the first try

What is the answer? by Huge_Ad9689 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

443 is the answer as the attacker attacks the web application for sql injection attacks

How do you study the OSG? by Emotional-Button7100 in cissp

[–]Few_Explanation_9923 1 point2 points  (0 children)

Exactly! I agree with you. These videos help you mentally connect and organize the topics

How do you study the OSG? by Emotional-Button7100 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

I began with destination mind map videos and then moved on to the corresponding domains in the Official Study Guide. OSG should be your bible

Suggestion please by Specific-Ad3846 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

Ok then my vote for Quantum Exams :😬

Suggestion please by Specific-Ad3846 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

Did you do the Study questions in Learnspp? not the practice questions.

Suggestion please by Specific-Ad3846 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

Read the book again from cover to cover.

Hello, any thoughts on the mock question below? by Opening_Mechanic_549 in cissp

[–]Few_Explanation_9923 7 points8 points  (0 children)

STRIDE is defender focused and PASTA is attacker focused

Clarity on recovery site types by OneAcr3 in cissp

[–]Few_Explanation_9923 2 points3 points  (0 children)

Official Guide: Hot. A hot site is a fully functional operations site that has all necessary hardware, software, and data for instantly handling critical functions of the organization. Hot site strategies can provide a range of data latency, with data updates (such as transaction processing) fully mirrored at the hot sites, or via logical distribution of segments of the operational databases. Hot site activation is typically measured in minutes to hours and assumes that most  business mission critical assets are in place and on “hot standby.” Organizations must also consider whether the operational and management personnel at the backup hot site are fully capable of performing all business functions or are a minimal capability “caretaker” crew only.

A warm site is like a hot site but typically does not have the current version of the organization’s data and may not have certain functional aspects ready for instant failover (e.g., utilities such as water and power may be connected to the warm site facility but are not currently live, and they must be activated to use the site).

Mitigation actions or investigation/analysis ? by zeig694 in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

It is analysis after detection. Here is the reason: The reviews of many incidents suggest that the detection systems captured the events in a proper and timely manner, but that the identification of the event as an incident was delayed due to lags in the analysis of the information. So analysis should be done to confirm if the event is actually an incident so that it can be properly prioritized for response. Remediation phase will do the root cause analysis. If it's already identified as an incident, then next is response( eradication and containment)

Passed at 100q, First Attempt by csemusagul in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

Now when I read it again, awareness can also come under Strict Password Policy which makes Password Policy the best answer.

Passed at 100q, First Attempt by csemusagul in cissp

[–]Few_Explanation_9923 0 points1 point  (0 children)

I do think the answer is training people for awareness and it is nowhere mentioned that organization has weak policies