TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Reduce Cyber Risk Podcast – Cyber Security Made Simple

    Shon Gerber from the Reduce Cyber Risk podcast provides valuable insights, guidance, and training to you each week that only a senior cyber security expert and vCISO can perform.  Shon has over 23+ years of experience in cyber security from large corporations, government, and as a college professor.  Shon provides you the information, knowledge, and training needed to help protect your company from cyber security threats.  Shon weekly provides cyber security training topics covering: Insider Threat, Operational Technology (OT) Security, Cyber Security Awareness Training, Cyber Security Training for Employees, Cyber Security Courses for the CISSP, and much, much more.  You will receive immediate and actionable information that you can put into practice immediately to protect your business, no matter the size.  Need direct and immediate assistance, Shon can also provide you with his “high touch” consulting approach with his various cyber security services.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    RCR 064: CISSP Sample Exam Questions - CISSP Training and Study Feb 01, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 2 (Asset Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 075

    As head of sales, Jim is the data owner for the sales department. Which of the following is not Jim’s responsibility as data owner?

    1. Assigning information classifications
    2. Dictating how data should be protected
    3. Verifying the availability of data
    4. Determining how long to retain data

    Answer: C. The responsibility of verifying the availability of data is the only responsibility listed that does not belong to the data (information) owner. Rather, it is the responsibility of the data (information) custodian. The data custodian is also responsible for maintaining and protecting data as dictated by the data owner. This includes performing regular backups of data, restoring data from backup media, retaining records of activity, and fulfilling information security and data protection requirements in the company’s policies, guidelines, and standards. Data owners work at a higher level than the data custodians. The data owners basically state, “This is the level of integrity, availability, and confidentiality that needs to be provided—now go do it.” The data custodian must then carry out these mandates and follow up with the installed controls to make sure they are working properly.

    From <https://www.brainscape.com/flashcards/asset-security-6578977/packs/10419165>

    ------------------------------------

    Question: 076

    Assigning data classification levels can help with all of the following except:

    1. The grouping of classified information with hierarchical and restrictive security
    2. Ensuring that nonsensitive data is not being protected by unnecessary controls
    3. Extracting data from a database
    4. Lowering the costs of protecting data

    Answer: C. Data classification does not involve the extraction of data from a database. However, data classification can be used to dictate who has access to read and write data that is stored in a database. Each classification should have separate handling requirements and procedures pertaining to how that data is accessed, used, and destroyed. For example, in a corporation, confidential information may only be accessed by senior management. Auditing could be very detailed and its results monitored daily, and degaussing or overwriting procedures may be required to erase the data. On the other hand, information classified as public may be accessed by all employees, with no special auditing or destruction methods required.

    From <https://www.brainscape.com/flashcards/asset-security-6578977/packs/10419165>

    ------------------------------------

    Question: 077

    Susan, an attorney, has been hired to fill a new position at Widgets, Inc.: chief privacy officer (CPO). What is the primary function of her new role?

    1. Ensuring the

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 063: CISSP Sample Exam Questions (Domain 2) - CISSP Training and Study Jan 29, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 2 (Asset Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 072

    Jared plays a role in his company’s data classification system. In this role, he must practice due care when accessing data and ensure that the data is used only in accordance with allowed policy while abiding by the rules set for the classification of the data. He does not determine, maintain, or evaluate controls, so what is Jared’s role?

    1. Data owner
    2. Data custodian
    3. Data user
    4. Information systems auditor

    Answer: C. Any individual who uses data for work-related tasks is a data user. Users must have the necessary level of access to the data to perform the duties within their position and are responsible for following operational security procedures to ensure the data’s confidentiality, integrity, and availability to others. This means that users must practice due care and act in accordance with both security policy and data classification rules.

    From <https://www.brainscape.com/flashcards/asset-security-6578977/packs/10419165

    ------------------------------------

    Question: 073

    Michael is charged with developing a data classification program for his company. Which of the following should he do first?

    1. Understand the different levels of protection that must be provided
    2. Specify data classification criteria
    3. Identify the data custodians
    4. Determine protection mechanisms for each classification level

    Answer: A. Before Michael begins developing his company’s classification program, he must understand the different levels of protection that must be provided. Only then can he develop the necessary classification levels and their criteria. One company may choose to use only two layers of classification, whereas another may choose to use more. Regardless, when developing classification levels, he should keep in mind that too many or too few classification levels will render the classification ineffective; there should be no overlap in the criteria definitions between classification levels; and classification levels should be developed for both data and software.

    From <https://www.brainscape.com/flashcards/asset-security-6578977/packs/10419165

    ------------------------------------

    Question: 074

    Which of the following is NOT a factor in determining the sensitivity of data?

    1. Who should be accessing the data
    2. The value of the data
    3. How the data will be used
    4. The level of damage that could be caused should the data be exposed

    Answer: C. How the data will be used has no bearing on how sensitive it is. In other words, the data is sensitive no matter how it will be used—even if it is not used at all.

    From <

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 062: Understanding Asset Ownership (Domain 2) - CISSP Study and Training! Jan 27, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.

    • CISSP Article – Best Practices for Data Management
    • CISSP Training – Determine and maintain information and asset ownership
    • CISSP Exam Questions

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 069

    You work as an IT professional for a defense contractor that handles classified military information. Which one of the following data classifications applies to information that could be expected to cause serious damage to national security if disclosed in an unauthorized fashion?

    1. SBU
    2. Top Secret
    3. Secret
    4. Confidential - Given

    Top Secret classification is \"applied to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security.\" Confidential classification is \"applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security.\" Sensitive But Unclassified (SBU) information is protected information that does not reach the threshold for classified information

    From <https://www.techveze.com/cissp-asset-security/>

    ------------------------------------

    Question: 070

    You are using symmetric encryption to protect data stored on a hard drive that will be shipped across the country. What key(s) are involved in the protection of this information?

    1. Shared secret
    2. Public key
    3. Public and private keys
    4. Private key

    Public keys are used to encrypt information intended for a specific recipient in asymmetric cryptography. They are not used in symmetric cryptography. Private keys are used to decrypt information in asymmetric cryptography. They are not used in symmetric cryptography. Public and private keypairs are used in asymmetric cryptography. They are not used in symmetric cryptography.

    From <https://www.techveze.com/cissp-asset-security/>

    ------------------------------------

    Question: 071

    Which one of the following is NOT a European Union data handling principle required for participation in the Safe Harbor program?

    1. Onward Transfer
    2. Choice
    3. Encryption
    4. Notice

    The Notice principle states that organizations must inform individuals about the purpose and scope of data collection efforts. The Choice principle states that organizations must offer individuals the ability to opt out of information collection and storage programs. The Onward Transfer principle states that organizations must only share information with other organizations that comply with the data privacy directive

    From <https://www.techveze.com/cissp-asset-security/>

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    Linke

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 061 - Best CISSP Exam Questions for Test Preparation (Domain 1) Jan 18, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 1 (Security and Risk Management) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 066

    Which of the following would generally not be considered an asset in a risk analysis?

    1. A) A development process
    2. B) An IT infrastructure
    3. C) A proprietary system resource
    4. D) Users' personal files

    Answer: [D] Users' personal files - The personal files of users are not usually considered assets of the organization and thus are not considered in a risk analysis.

    From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Question: 067

    You've performed a basic quantitative risk analysis on a specific threat/vulnerability/risk relation. You select a possible countermeasure. When performing the calculations again, which of the following factors will change?

    1. A) Exposure factor
    2. B) Single loss expectancy
    3. C) Asset value
    4. D) Annualized rate of occurrence

    Answer: [d] Annualized rate of occurrence - A countermeasure directly affects the annualized rate of occurrence, primarily because the countermeasure is designed to prevent the occurrence of the risk, thus reducing its frequency per year.

    From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Question: 068

    What ensures that the subject of an activity or event cannot deny that the event occurred?

    1. A) CIA Triad
    2. B) Abstraction
    3. C) Nonrepudiation
    4. D) Hash totals

    Answer: [c] Nonrepudiation - Nonrepudiation ensures that the subject of an activity or event cannot deny that the event occurred.

    From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 060 - How to Prepare with CISSP Sample Questions (Domain 1) Jan 15, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 1 (Security and Risk Management) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 063

    When seeking to hire new employees, what is the first step?

    1. A) Create a job description.
    2. B) Set position classification.
    3. C) Screen candidates.
    4. D) Request resumes.

    Answer: A. Create a job description.

    The first step in hiring new employees is to create a job description. Without a job description, there is no consensus on what type of individual needs to be found and hired.

    Source: From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Question: 064

    Which of the following describes the freedom from being observed, monitored, or examined without consent or knowledge?

    1. A) Integrity
    2. B) Privacy
    3. C) Authentication
    4. D) Accountability

    Answer: [b] Privacy - One definition of privacy is freedom from being observed, monitored, or examined without consent or knowledge.

    Source: From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Question: 065

    Which of the following is typically not a characteristic considered when classifying data?

    1. A) Value
    2. B) Size of object
    3. C) Useful lifetime
    4. D) National security implications

    Answer: [b] Size of object - Size is not a criterion for establishing data classification. When classifying an object, you should take value, lifetime, and security implications into consideration.

    From <https://www.brainscape.com/flashcards/information-security-guidelines-and-risk-973829/packs/1774328>

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 059 - How to Understand Threat Modeling for the CISSP Exam Prep Jan 13, 2020
    Show notes

    Description:

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.

    • CISSP Article – Threat Modeling
    • CISSP Training – Data Integrity and Threat Modeling
    • CISSP Exam Questions

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 060

    You are a security consultant. A large enterprise customer hires you to ensure that their security operations are following industry standard control frameworks. For this project, the customer wants you to focus on technology solutions that will discourage malicious activities. Which type of control framework should you focus on?

    • A. Preventative
    • B. Deterrent
    • C. Detective
    • D. Corrective
    • E. Assessment

    Answer: [B] Explanation: Deterrent frameworks are technology-related and used to discourage malicious activities. For example, an intrusion prevention system or a firewall would be appropriate in this framework.

    There are three other primary control frameworks. A preventative framework helps establish security policies and

    security awareness training. A detective framework is focused on finding unauthorized activity in your environment

    after a security incident. A corrective framework focuses on activities to get your environment back after a security

    incident. There isn’t an assessment framework.

    Source: From <https://blog.netwrix.com/2018/05/16/cissp-practice-exam-free-online-test-questions/>

    ------------------------------------

    Question: 061

    You are performing a risk analysis for an internet service provider (ISP) that has thousands of customers on its broadband network. Over the past 5 years, some customers have been compromised or experienced data breaches. The ISP has a large amount of monitoring and log data for all customers. You need to figure out the chances of additional customers experiencing a security incident based on that data. Which type of approach should you use for the risk analysis?

    • A. Qualitative
    • B. Quantitative
    • C. STRIDE
    • D. Reduction
    • E. Market

    Answer: [B] Explanation: You have three risk analysis methods to choose from: qualitative (which uses a risk analysis matrix), quantitative (which uses money or metrics to compute), or hybrid (a combination of qualitative and quantitative but not an answer choice in this scenario). Because the ISP has monitoring and log data, you should use a quantitative approach; it will help quantify the chances of additional customers experiencing a security risk.

    STRIDE is used for threat modeling. A market approach is used for asset valuation. A reduction analysis attempts to eliminate duplicate analysis and is tied to threat modeling.

    Source: From <https://blog.netwrix.com/2018/05/16/c

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 058 - Software Development Questions for the CISSP Exam (Domain 8) Jan 12, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    Want to find Shon Gerber elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources
    • TechTarget
      • https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 057 - CISSP Exam Questions for Cyber Investigations (Domain 8) Jan 11, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    Want to find Shon Gerber elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources
    • TechTarget
      • https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 056 - Chain of Custody Questions for the CISSP Exam (Domain 8) Jan 08, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    Want to find Shon Gerber elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources
    • TechTarget
      • https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 055 - Understanding SDLC to pass the CISSP Exam (Domain 8) Jan 06, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about the following items that are included within Domain 8 (Software Development Security) of the CISSP Exam.

    • CISSP Articles – RAYGUN - SDLC: 7 phases, popular models, benefits, and more
    • CISSP Training – Integrate Security in the Software Development Life Cycle (SDLC)
    • CISSP Exam Questions

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    Want to find Shon Gerber elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources
    • Raygun
      • https://raygun.com/blog/software-development-life-cycle/
    • TechTarget
      • https://searchsecurity.techtarget.com/quiz/CISSP-Domain-5-quiz-Types-of-access-control-systems?q0=1&q1=2&q2=2&q3=3&q4=2&q5=2&q6=2&q7=2&q8=2&q9=2&x=70&y=11
    • Vendors:
      • LastPass.com
        • https://www.lastpass.com/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    Previous 1 9 10 11 12 13 19 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights