TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Reduce Cyber Risk Podcast – Cyber Security Made Simple

    Shon Gerber from the Reduce Cyber Risk podcast provides valuable insights, guidance, and training to you each week that only a senior cyber security expert and vCISO can perform.  Shon has over 23+ years of experience in cyber security from large corporations, government, and as a college professor.  Shon provides you the information, knowledge, and training needed to help protect your company from cyber security threats.  Shon weekly provides cyber security training topics covering: Insider Threat, Operational Technology (OT) Security, Cyber Security Awareness Training, Cyber Security Training for Employees, Cyber Security Courses for the CISSP, and much, much more.  You will receive immediate and actionable information that you can put into practice immediately to protect your business, no matter the size.  Need direct and immediate assistance, Shon can also provide you with his “high touch” consulting approach with his various cyber security services.

    Advertise
    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    RCR 084: Practice CISSP Exam Questions (BCP) - CISSP Training and Study! Mar 18, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

    In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question:  132

    Which of the following is less likely to accompany a contingency plan, either within the plan itself or in the form of an appendix?


    A. Contact information for all personnel

    B. Vendor contract information, including offsite storage and alternate site

    C. Equipment ad system requirements lists of hardware, software, firmware, and other resources required to support system operations

    D. The Business Impact Analysis

    Answer: D Explanation: You use the BIA as a guideline to create the contingency plan.

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925

    ------------------------------------

    Question:  133

    The first step in contingency planning is to perform:

    A. A hardware backup
    B. A data backup
    C. An operating system software backup
    D. An application software backup

    Answer: B

    https://www.brainscape.com/flashcards/business-continuity-planning-4303634/pac

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 083: Business Continuity Planning (BCP) - CISSP Training and Study! Mar 16, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 129

    Which of the following could lead to the conclusion that a disaster recovery plan may not be operational within the timeframe the business needs to recover?
    A. )The alternate site is a warm site
    B. Critical recovery priority levels are not defined
    C. Offsite backups are located away from the alternate site
    D. The alternate site is located 70 miles away from the primary site

    Answer: B
    Explanation:

    From <https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328>

    ------------------------------------

    Question: 130

    What are the four domains of communication in the disaster planning and recovery process?
    A. Plan manual, plan communication, primer for survival, warning and alarms
    B. Plan communication, primer for survival, escalation, declaration
    C. Plan manual, warning and alarm, declaration, primer for survival
    D. Primer for survival, escalation, plan communication, warning and alarm

    Answer: C
    Explanation:

    From <

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 082: Practice CISSP Exam Questions - CISSP Training and Study! Mar 14, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 128

    In what type of software testing does the tester have access to the underlying source code?

    1. A) Static testing
    2. B) Dynamic testing
    3. C) Cross-site scripting testing
    4. D) Black box testing

    Static testing

    In order to conduct a static test, the tester must have access to the underlying source code.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 129

    What portion of the change management process allows developers to prioritize tasks?

    1. A) Release control
    2. B) Configuration control
    3. C) Request control
    4. D) Change audit

    Request control

    The request control provides users with a framework to request changes and developers with the opportunity to prioritize those requests.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 130

    Which one of the following key types is used to enforce referential integrity between database tables?

    1. A) Candidate key
    2. B) Primary key
    3. C) Foreign key
    4. D) Super key

    Foreign key

    Foreign keys are used to enforce referential integrity constraints between tables that participate in a relationship.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 081: Practice CISSP Exam Questions - CISSP Training and Study! Mar 11, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 125

    What type of virus utilizes more than one propagation technique to maximize the number of penetrated systems?

    1. A) Stealth virus
    2. B) Companion virus
    3. C) Polymorphic virus
    4. D) Multipartite virus

    Multipartite virus

    Multipartite viruses use two or more propagation techniques (for example, file infection and boot sector infection) to maximize their reach.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 126

    What programming language(s) can be used to develop ActiveX controls for use on an Internet site?

    1. A) Visual Basic
    2. B) C
    3. C) Java
    4. D) All of these are correct.

    All of these are correct

    Microsoft's ActiveX technology supports a number of programming languages, including Visual Basic, C, C++, and Java. On the other hand, only the Java language can be used to write Java applets.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 127

    What transaction management principle ensures that two transactions do not interfere with each other as they operate on the same data?

    1. A) Atomicity
    2. B) Consistency
    3. C) Isolation
    4. D) Durability

    Isolation

    The isolation principle states that two transactions operating on the same data must be temporarily separated from each other such that one does not interfere with the other.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 080: Creating a Secure Development Environment - CISSP Training and Study! Mar 09, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 122

    What type of reconnaissance attack provides attackers with useful information about the services running on a system?

    1. A) Session hijacking
    2. B) Port scan
    3. C) Dumpster diving
    4. D) IP sweep

    Port scan

    Port scans reveal the ports associated with services running on a machine and available to the public.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 123

    What technology does the Java language use to minimize the threat posed by applets?

    1. A) Confidentiality
    2. B) Encryption
    3. C) Stealth
    4. D) Sandbox

    Sandbox

    The Java sandbox isolates applets and allows them to run within a protected environment, limiting the effect they may have on the rest of the system.

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Question: 124

    What is the most effective defense against cross-site scripting attacks?

    1. A) Limiting account privileges
    2. B) Input validation
    3. C) User authentication
    4. D) Encryption

    Input validation

    Input validation prevents cross-site scripting attacks by limiting user input to a predefined range. This prevents the attacker from including the HTML

    From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 079: Practice CISSP Exam Questions - CISSP Training and Study! Mar 07, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 119

    1. What is considered a Computer Security Incident?
      1. Earthquake hits your data center rendering it unusable
      2. A patch was implemented resulting in a loss of a critical system
      3. Local construction workers cut the fiber line that provides a network feed for your building
      4. An employee violated the company's acceptable use policy by downloading pirated software

    Explanation: [d] A violation of a company's acceptable use policy is considered a Computer Security Incident. The other options fit within the broad concept of an incident.

    ------------------------------------

    Question: 120

    1. What is the primary goal of a Change Management Process within an organization?
      1. Provide good structure for making changes within a network
      2. Avoid outages within your network
      3. Provide documentation on all changes within a network
      4. All the above

    Explanation: [b] The primary goal of a Change Management Process is to avoid outages within your network environment. All of the above are important, but the primary goal is to avoid outages.

    ------------------------------------

    Question: 121

    1. Which of the following is are considered a strategic strategy for backups within a business environment?
      1. Full Backup
      2. Incremental Backup
      3. Differential Backup
      4. All the above

    Explanation: [d] All of the above are considered a strategic solution for you backups within a business environment.

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 078: Practice CISSP Exam Questions - CISSP Training and Study! Mar 04, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 116

    1. What is the highest potential risk for keeping log files from computer and network devices within your environment?
      1. Subject to legal discovery
      2. Consume large amounts of storage
      3. Continuously increasing storage costs
      4. None of the above

    Explanation: [a] All of the above are reasons not to keep log files too long on your environment, but the highest risk to your organization is the opportunity for legal discovery.

    -----------------------------------

    Question: 117

    1. Organizations focused on the concept of "least privilege" focus on which of the following?
      1. Only a few have the most network access within a company
      2. Only decision makers have the necessary access needed within the company
      3. Each person only needs access based on role/requirements
      4. Most senior individuals within the company have the majority of the access

    Explanation: [c] Each person should only have the access needed for their role/position. Typically, employees’ access will increase over time as access is granted, but rarely removed.

    ------------------------------------

    Question: 118

    1. Compact Disks (CD) and Data Video Disks (DVD) do not degrade over time and are considered safe for long term storage of data?
      1. True
      2. False

    Explanation: [b] CDs / DVDs will degrade over time and should not be considered good storage media for data for long periods of time.

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 077: Understanding Investigation Aspects for the CISSP Exam - CISSP Training and Study! Mar 02, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 113

    1. When conducting an incident investigation within an organization what are some keep items to keep in mind before starting?
    2. Assemble a team with best skillsets to meet objectives
    3. Operate under your Incident Response Process
    4. Define specific Rules of Engagement (ROEs) around Law Enforcement, Interviewing Employees, etc.
    5. All of the above

    Explanation: [d] All of the above should be considered when conducting an investigation of an incident within your organization.

    ------------------------------------

    Question: 114

    1. What are the three options used for gathering evidence for an investigation?
    2. Voluntary Surrender, Subpoena, Search Warrant
    3. Involuntary Surrender, Subpoena, Search Warrant
    4. Voluntary Surrender, Search and Seizure, Warrant
    5. Involuntary Surrender, Search and Seizure, Warrant

    Explanation: [a] When gathering evidence there are three legal options available to gain access to evidence: Voluntary Surrender, Subpoena, and a Search Warrant.

    ------------------------------------

    Question: 115

    1. What of the following steps will not be included within the change management process?
    2. Immediate change, if leadership wants the change to occur
    3. A change request
    4. Rollback plan for the change
    5. Documenting the change

    Explanation: [a] There are situations where emergency changes need to occur, but it should be an emergency and not the desire of an individual to just make the change.

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 076: CISSP Exam Questions on Encryption - CISSP Training and Study Mar 01, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 6 (Security Assessment and Testing) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 110

    Tom would like to test system that lie within his network for vulnerabilities that could be exploited by the most recent set of ransomware variants. Which one of the following tools would be best suited to accomplish this task?

    1. Network discovery scanner
    2. Network vulnerability scanner
    3. Web vulnerability scanner
    4. Ping sweep

    Explanation [b] A network vulnerability scanner would be the best tool for discovering what vulnerabilities reside within your network.

    -----------------------------------

    Question: 111

    1. When trying to gain the most detailed information about a system from a scan, what is the best scan to meet that objective?
      1. Port Scan
      2. Authenticated Scan
      3. Vulnerability Scan
      4. Unauthenticated Scan

    Explanation: [b] An authenticated scan allows you to use credentials which will provide you the most detailed information. An unauthenticated scan will only provide you a view that is available from the outside and may not be an adequate or fair assessment of the system.

    ------------------------------------

    Question: 112

    What is the most common port used to communicated encrypted traffic on a web server?

    1. 22
    2. 143
    3. 80
    4. 443

    Explanation: [d] 443 is the common standard where encrypted communications use for transmitting data. However, any port can be used for encrypted data, but 443 is considered the common standard.

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook - https://www.facebook.com/CyberRiskReduced/

    LINKS:

    • ISC2 Training Study Guide
      • https://www.isc2.org/Training/Self-Study-Resources

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    RCR 075: Practice CISSP Exam Questions - CISSP Training and Study! Feb 26, 2020
    Show notes

    Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.

    In this episode, Shon will provide CISSP training for Domain 6 (Security Assessment and Testing) of the CISSP Exam. His extensive training will cover all of the CISSP domains.

    BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/

    CISSP Exam Questions

    Question: 108

    What are the various phases associated with completing a Penetration Test for an organization.

    1. Planning, Reporting, Vulnerability Management, Exploiting, Information Gathering
    2. Production, Registration, Vulnerability Management, Exploiting, Information Gathering
    3. Planning, Reporting, Vulnerability Scanning, Exploiting, Information Gathering
    4. Production, Reporting, Vulnerability Management, Exploiting, Information Gathering

    Explanation: [c] Planning, Reporting, Vulnerability Scanning, Exploiting, and Information Gathering (not in order) are the phases of completing a penetration test for an organization.

    ------------------------------------

    Question: 109

    When creating metrics for your leadership, what are first items you should focus first on and what should be your level of complexity for the report?

    1. Very complex metrics focused on all systems; Open vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance Issues
    2. Very simple metrics focused on critical systems; Open vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance Issues
    3. Very simple metrics focused on critical systems; Management processes, Closed vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance issues
    4. Very simple metrics focused on critical systems; Open vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance Issues

    Explanation: [b] Starting off with simple metrics focused on critical systems with the following metrics: Open vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance Issues is the best method to get started. Obviously, you organization may be different and you will have to modify to meet your needs, but it is good place to get started….keep it simple.

    ------------------------------------

    Question: 110

    When completing a Penetration Test of your organization who needs to be involved in the discussion and decision?

    1. No one; informing people that the penetration test will occur will taint the results resulting in waste
    2. Everyone; it is important that people don't feel duped that this test was designed to trick them
    3. Key personnel; it is important to focus on only telling the decision makers/influencers (CEO/CIO, Legal, Public Affairs, Compliance) as it relates to a penetration test.
    4. None of the above

    Explanation: [c] It is important the right people are involved in the decision making process as a Pen Test can have significant impact on an organization and cause a disruption within a company.

    ------------------------------------

    Want to find Shon elsewhere on the internet?

    LinkedIn – www.linkedin.com/in/shongerber

    Facebook -

    Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.


    Previous 1 7 8 9 10 11 19 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights