TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Reduce Cyber Risk Podcast – Cyber Security Made Simple

    Shon Gerber from the Reduce Cyber Risk podcast provides valuable insights, guidance, and training to you each week that only a senior cyber security expert and vCISO can perform.  Shon has over 23+ years of experience in cyber security from large corporations, government, and as a college professor.  Shon provides you the information, knowledge, and training needed to help protect your company from cyber security threats.  Shon weekly provides cyber security training topics covering: Insider Threat, Operational Technology (OT) Security, Cyber Security Awareness Training, Cyber Security Training for Employees, Cyber Security Courses for the CISSP, and much, much more.  You will receive immediate and actionable information that you can put into practice immediately to protect your business, no matter the size.  Need direct and immediate assistance, Shon can also provide you with his “high touch” consulting approach with his various cyber security services.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    RCR 094: CISSP Exam Questions around Data Hiding – CISSP Training and Study! Jul 11, 2020
    Show notes

    Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS

    Description:

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question: 165

    Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection.
    Which of the following best describes an item the software development team needs to address to ensure that drivers cannot be loaded in an unauthorized manner?
    A. Improved security kernel processes
    B. Improved security perimeter processes
    C. Improved application programming interface processes
    D. Improved garbage collection processes

    1. If device drivers can be loaded improperly, then either the access control rules outlined within the reference monitor need to be improved upon or the current rules need to be better enforced through the security kernel processes. Only authorized subjects should be able to install sensitive software components that run within ring 0 of a system.

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 166

    Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address spac

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 093: CISSP Exam Questions for Software Development Jul 08, 2020
    Show notes

    Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS

    Description:

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question: 162

    John has been told that one of the applications installed on a web server within the DMZ accepts any length of information that a customer using a web browser inputs into the form the web server provides to collect new customer data. Which of the following describes an issue that John should be aware of pertaining to this type of issue?
    A. Application is written in the C programming language.
    B. Application is not carrying out enforcement of the trusted computing base.
    C. Application is running in ring 3 of a ring-based architecture.
    D. Application is not interacting with the memory manager properly.

    1. The C language is susceptible to buffer overflow attacks because it allows for direct pointer manipulations to take place. Specific commands can provide access to low-level memory addresses without carrying out bounds checking.

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 163

    Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection.
    A. Non-protected ROM sections
    B. Vulnerabilities that allowed malicious code to execute in protected memory sections
    C. Lack of a predefined and implemented trusted computing base
    D. Lack of a predefined and implemented security kernel

    1. If testers suggested to the team that address space layout randomization and data execution protection should be integrated, this is most likely

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 092: Endpoint Detection and Response – CISSP Training and Study! Apr 20, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    Shon will provide CISSP study and training for Domain 4 (Communication and Network Security) of the CISSP Exam. His knowledge will provide the skills needed to pass the CISSP.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question:  159

    Vulnerabilities and risks are evaluated based on their threats against which of the following?

    A) One or more of the CIA Triad principles

    B) Data usefulness

    C) Due care

    D) Extent of liability

    One or more of the CIA Triad principles

    Vulnerabilities and risks are evaluated based on their threats against one or more of the CIA Triad principles.

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 160

    While performing a risk analysis, you identify a threat of fire and a vulnerability because there are no fire extinguishers. Based on this information, which of the following is a possible risk?

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 091: CISSP Exam Questions for Risk Management – CISSP Training and Study! Apr 11, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question:  156

    If a security mechanism offers availability, then it offers a high level of assurance that authorized subjects can _________ the data, objects, and resources.

    A) Control

    B) Audit

    C) Access

    D) Repudiate

    Access

    Accessibility of data, objects, and resources is the goal of availability. If a security mechanism offers availability, then it is highly likely that the data, objects, and resources are accessible to authorized subjects.

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 157

    All but which of the following items require awareness for all individuals affected?

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 090: CISSP Exam Questions for Risk Analysis – CISSP Training and Study! Apr 08, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question:  153

    Which commercial business/private sector data classification is used to control information about individuals within an organization?

    A) Confidential

    B) Private

    C) Sensitive

    D) Proprietary

    Private

    The commercial business/private sector data classification of private is used to protect information about individuals.

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 154

    Which of the following is not an element of the risk analysis process?

    A) Analyzing an environment for risks

    B) Creating a cost/benefit report for safeguards to present to upper management

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 089: Trusted Computing Base and the CISSP – CISSP Training and Study! Apr 06, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    Shon will provide CISSP study and training for Domain 3 (Engineering Secure Design) of the CISSP Exam. His knowledge will provide the skills needed to pass the CISSP.

    BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/

    Available Courses:

    • CISSP Training Course - https://www.shongerber.com/offers/zYsL6MCB
    • CISO Training Course - https://www.shongerber.com/offers/zd2RbL6o

    CISSP Exam Questions

    Question:  150

    How is the value of a safeguard to a company calculated?

    A) ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard

    B) ALE before safeguard * ARO of safeguard

    C) ALE after implementing safeguard - annual cost of safeguard - controls gap

    D) Total risk - controls gap

    [A] ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard

    The value of a safeguard to an organization is calculated by ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard [(ALE1 -- ALE2) - ACS].

    https://www.brainscape.com/subjects/cissp-domains

    ------------------------------------

    Question: 151

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 088: CISSP Exam Questions for Parallel Testing - CISSP Training and Study Mar 28, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

    In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question:  144

    To get proper management support and approval of the plan, a business case must be made. Which of the following is least important to this business case?
    A. Regulatory and legal requirements
    B. Company vulnerabilities to disasters and disruptions
    C. How other companies are dealing with these issues
    D. The impact the company can endure if a disaster hits

    C. The other three answers are key components when building a business case. Although it is a good idea to investigate and learn about how other companies are dealing with similar issues, it is the least important of the four items listed.

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  145

    Which of the following describes a parallel test?
    A. It is performed to ensure that operations performed at the alternate site also give the same results as at the primary site.
    B. All departments receive a copy of the disaster recovery plan and walk through it.
    C. Representatives from each department come together and go through the test collectively.
    D. Normal operations are shut down.

    A. In a parallel test, some systems are run at the alternate site, and the results are compared with how processing takes place at the primary site. This is to ensure that the systems work in that area and productivity is not affected. This also extends the previous test and allows

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 087: CISSP Exam Questions for Business Continuity - CISSP Training and Study! Mar 25, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

    In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question:  141

    Who has the final approval of the business continuity plan?
    A. The planning committee
    B. Each representative of each department
    C. Management
    D. External authority

    C. Management really has the final approval over everything within a company, including these plans.

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  142

    What is the most crucial requirement in developing a business continuity plan?
    A. Business impact analysis
    B. Implementation, testing, and following through
    C. Participation from each and every department
    D. Management support

    D. Management’s support is the first thing to obtain before putting any real effort into developing these plans. Without management’s support, the effort will not receive the necessary attention, resources, funds, or enforcement.

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  143

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 086: Information Classification in 6 Steps - CISSP Training and Study! Mar 23, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question:  138

    Which of the following is something that should be required of an offsite backup facility that stores backed-up media for companies?
    A. The facility should be within 10 to 15 minutes of the original facility to ensure easy access.
    B. The facility should contain all necessary PCs and servers and should have raised flooring.
    C. The facility should be protected by an armed guard.
    D. The facility should protect against unauthorized access and entry.

    D. This question addresses a facility that is used to store backed-up data; it is not talking about an offsite facility used for disaster recovery purposes. The facility should not be only 10 to 15 minutes away, because some types of disasters could destroy both the company’s main facility and this facility if they are that close together, in which case the company would lose all of its information. The facility should have the same security standards as the company’s security, including protection against unauthorized access.

    https://www.brainscape.com/flashcards/cissp-chapter-8-business-continuity-and-d-1538409/packs/2943708

    ------------------------------------

    Question: 139

    Which item will a business impact analysis not identify?
    A. Whether the company is best suited for a parallel or full-interrupt test
    B. What areas would suffer the greatest operational and financial loss in the event of a particular disaster or disruption
    C. What systems are critical for the company and must be highly protected

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 085: Practice CISSP Exam Questions (BCP) - CISSP Training and Study! Mar 21, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

    In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question:  135

    Which of the following contains references to expected business continuity planning (BCP) practices that organizations must implement

    A. ISO 17799:2008, Section 1
    B. ISO 27005:2008, Section 8
    C. ISO 27002:2005, Section 10
    D. ISO 27001:2005, Annex A

    Answer: D

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  136

    What process identifies the business continuity requirements for the organization's assets?
    A. risk analysis
    B. business impact analysis
    C. threat analysis
    D. asset classification

    Answer: B

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  137

    A contingency plans should be written to
    A. address all possible risk scenarios

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    Previous 1 6 7 8 9 10 19 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights