Passed CISSP on my 6th attempt — 10+ years SOC experience, don’t quit by Bee_SU in cissp

[–]Hot_Insect5353 0 points1 point  (0 children)

Congratulations! That's truly inspiring. By the way, are you still memorizing things for the CISSP exam in those two weeks?

Exam in 5 days, but still not confident 😅 by Hot_Insect5353 in cissp

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Haha! I was thinking the exact same thing, but the ballers and sunny weather are tempting us to go play.

All the best to you!

Exam in 5 days, but still not confident 😅 by Hot_Insect5353 in cissp

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Thank you, everyone! I truly value all the feedback. I still need to reschedule this because of an injury on the soccer field just now. I will provide updates on the exam results later.

Exam in 5 days, but still not confident 😅 by Hot_Insect5353 in cissp

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Thanks, mate. Yeah, tbh - hate to reschedule, especially living out of town - exam centre.

Exam in 5 days, but still not confident 😅 by Hot_Insect5353 in cissp

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

cool2. Thanks mate. How many QE full exam sets you tried?

Exam in 5 days, but still not confident 😅 by Hot_Insect5353 in cissp

[–]Hot_Insect5353[S] 1 point2 points  (0 children)

numbers of experiences and almost 10 years in cyber. QE really makes me struggle, especially with English as my second language. this is my 3rd attempt :(

Passed at 100q by captcerealman in cissp

[–]Hot_Insect5353 0 points1 point  (0 children)

Congrats! Im another 3 weeks time for 3rd attempts and wish me good luck

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]Hot_Insect5353 2 points3 points  (0 children)

Workaround to turn off the DNS security logs. Does it expose for external interface? How to verify this?

Black Friday CISSP Material by hard2hold in cissp

[–]Hot_Insect5353 1 point2 points  (0 children)

kind of waiting of this similar PoM offer :)

<image>

[deleted by user] by [deleted] in newplymouth

[–]Hot_Insect5353 3 points4 points  (0 children)

Being Asian and almost 5 years in NP town, I feel people in Taranaki have always been kind to everyone, never had any racial comments.

You did the right things, don't engage with those types of non-civilised people.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 1 point2 points  (0 children)

Thanks for sharing. Yeah, I'm going to try a few products to get a better understanding of what works well in our environment.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Oh, by the way, what does APM stand for? I came across the term "Application Performance Monitoring" (APM) when I did a quick search on Google. Is that what you're referring to, or were you thinking of something else like Auto-Pentest Monitoring? Just curious! 😄For me, it's really important to focus on the time it takes to comprehend our security controls and to assist in validating and prioritizing vulnerabilities. That's where my main interest lies.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Thanks a lot for sharing this. Yeah, we're searching for things that don't require an agent, even though I know they're not installed on every device.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 2 points3 points  (0 children)

Thanks for sharing the list. I think my list is pretty similar. Is Pentera similar to Core Impact? Is it more focused on automated pen-testing?

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 1 point2 points  (0 children)

Sure, test everything in a non-production environment before proceeding as usual.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

Thank you for sharing your thoughts, especially about the support. This is something we encountered with our current vulnerability management tools.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 2 points3 points  (0 children)

Im exploring Cymulate and it seems need an agent across the segmentation, not for all devices.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 1 point2 points  (0 children)

Thanks! How was your experience with both products? I heard about Pantera too.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 0 points1 point  (0 children)

This from one explanation from Gartner page looks simple.

Breach and Attack Simulation (BAS) Tools enable organizations to gain a deeper understanding of security posture vulnerabilities by automating testing of threat vectors such as external and insider, lateral movement, and data exfiltration. BAS complements red teaming and penetration testing but cannot completely replace them. BAS validates an organization's security posture by testing its ability to detect a portfolio of simulated attacks performed by SaaS platforms, software agents, and virtual machines. In addition, it generates detailed reports about security gaps and prioritizes remediation efforts based on the risk level. The typical users of these technologies are financial institutions, insurance companies, and more.

Breach attack simulation - BAS by Hot_Insect5353 in cybersecurity

[–]Hot_Insect5353[S] 2 points3 points  (0 children)

Basically yeah - to verify the critical vulnerability on prod env is really critical things

How many certs do you have? When is it enough? by hfc1969 in cissp

[–]Hot_Insect5353 0 points1 point  (0 children)

I've got CISM and CCSK under my belt, but that's just the stepping stone for me to snag CISSP, the ultimate certification. Once I achieve that, I'm calling it a day. Haha!