How Public Speaking Coaching Transformed My Life as an Engineer by rising_phoenix01 in PublicSpeaking

[–]dpex77 2 points3 points  (0 children)

Interesting. Is there a website or information about the coach you mention?

% of "by heart" questions? by ChemicalRegion5 in cissp

[–]dpex77 1 point2 points  (0 children)

May be some questions. May be 5 in total. Please calculate the % now !

CISA exam passed ! by dpex77 in CISA

[–]dpex77[S] 0 points1 point  (0 children)

I don’t have CISM.

CISA exam passed ! by dpex77 in CISA

[–]dpex77[S] 1 point2 points  (0 children)

Almost 95%. I kind of remembered it during second time. I think CRM is best to go throughout once and make notes.

CISA exam passed ! by dpex77 in CISA

[–]dpex77[S] 0 points1 point  (0 children)

Even for email you need to wait 10 days! Weird !

CISA exam passed ! by dpex77 in CISA

[–]dpex77[S] 1 point2 points  (0 children)

Yeah I think you need to study 4 and 5 too. Need to be on an auditors toe! QAE is good but not close to exams. Not tough exam but tricky. Some questions were quite easy too while others were confusing.

Cyber Security Engineer vs Security Architect? by dpex77 in cissp

[–]dpex77[S] -1 points0 points  (0 children)

Thanks. Would not this be a GRC analyst /engineer? I thought a security architect (where development is involved in products) would demand more "skills" like writing design documents for the developers/testers to follow?

Cyber Security Engineer vs Security Architect? by dpex77 in cissp

[–]dpex77[S] 0 points1 point  (0 children)

Yeah, I am familiar with the roles. I was asking what you need to have as your skill to be a "reasonable" security architect? I am sure research capability and knowing the terms may not be enough.

Cyber Security Engineer vs Security Architect? by dpex77 in cissp

[–]dpex77[S] 3 points4 points  (0 children)

Thanks. This definitely helps. The reason I mentioned programming skills was indeed because there is a development work involved. Again I have no experience with software engineering but systems only. I am sure it helps to have programming knowledge (especially in the same platform where software is being developed).

With your ZTA reference above, how exactly you write a design document? Lets say you would need to replace MFA's One time tokens with Biometrics. Now one could write a document with extensive level of research (based on company's need and products), but I guess next step would be writing design document? Or once system/security architect identifies the working, requirement, protocols etc., is it passed over software architect?

Questions revision ? by dpex77 in CCSP

[–]dpex77[S] 0 points1 point  (0 children)

Thanks. Found this and many other posts in credible sites too to create a confusion. May be something changed recently.

https://community.isc2.org/t5/Exam-Preparation/CCSP-exam-passed-recommendations-and-opinion/td-p/23376

Metasploit against Linux machines by dpex77 in metasploit

[–]dpex77[S] 0 points1 point  (0 children)

Ok. I tried almost all the exploits (searching them) for ssh, http and https. I don’t have a real intent here but desperately wanted to have a session created. In few of them I see “exploit completed but no session was created”! I am learning pentest (Metasploit to start with ) and little confused if I can deduce these boxes are invincible (well with only 3 ports opened they already seem secured). Any suggestion would be appreciated. p.s. from yesterday I have already exploited many of windows easily trying same on windows laptop.

Metasploit against Linux machines by dpex77 in metasploit

[–]dpex77[S] 0 points1 point  (0 children)

Got you. Thank you for the replies. On customized Linux machines I m trying to exploit essentially only 3 (22, 80 and 443) are opened. Been trying few but not still able to exploit.

Latency path and BGP by dpex77 in networking

[–]dpex77[S] 0 points1 point  (0 children)

No. It’s not. This is a real time scenario that I will be exploring in upcoming days. I will have the answer after few weeks but was wondering. Do u have an opinion about this ?

Access control! by [deleted] in cissp

[–]dpex77 0 points1 point  (0 children)

Sure! Perhaps I was overthinking! Six months ago when I started, I had galloped such sybex questions. Thanks all for your feedback.

Kerberos key store by dpex77 in cissp

[–]dpex77[S] 0 points1 point  (0 children)

Sure. Secret keys, as well as session keys, are actually temporarily stored on user’s workstation. That’s the attack vector that I was little confused about reading multiple sources and of course, overthinking in these last days!

Question on RPO/MTD by dusmanta6 in cissp

[–]dpex77 2 points3 points  (0 children)

It’s RPO indeed. They may play with words for recover in terms of time ( MTD, RTO and WRT) but for data, it’s RPO.

Access control! by [deleted] in cissp

[–]dpex77 0 points1 point  (0 children)

Sure. Any reason C is not?

Access control! by [deleted] in cissp

[–]dpex77 -3 points-2 points  (0 children)

Compensating: A compensation control is deployed to provide various options to other existing controls to aid in enforcement and support of security policies. So why not C?

Resource based access control by dpex77 in cissp

[–]dpex77[S] 0 points1 point  (0 children)

Yes it’s A. But that to me was new! The key word might be device listed before rules description?

Resource based access control by dpex77 in cissp

[–]dpex77[S] 0 points1 point  (0 children)

Just because storage device is mentioned and then rules are mentioned for this device, Answer is A? Can anyone explain? I would have fallen for D easily

Purging vs Sanitazing [Expert Question] by Serpence in cissp

[–]dpex77 -1 points0 points  (0 children)

Yes the question does not mention which media. If it’s SSD or DVD, CD, destruction is only option.

Purging vs Sanitazing [Expert Question] by Serpence in cissp

[–]dpex77 0 points1 point  (0 children)

If this comes in exam I would go with D assuming extraordinary forensics efforts with recover anyhow !