End of Life vs End of Support: The Two Dates CISSP Candidates Confuse
What End of Life and End of Support mean, why only the second date is a security cliff, and how CISSP scenarios may test the difference between them.
Running security day to day: watching what is happening now, testing your own defences before somebody else does, and handling it properly when something goes wrong, from incident response to chain of custody. CISSP Domains 6 and 7.
What End of Life and End of Support mean, why only the second date is a security cliff, and how CISSP scenarios may test the difference between them.
An assessment advises the organisation and can be self-performed. An audit gives an outsider a formal opinion, so independence is mandatory.
What SOC 1, SOC 2 and SOC 3 cover, how Type 1 differs from Type 2, and what a CISSP candidate needs to know about third party assurance.
Documented, unbroken record of who collected, handled, transferred, and stored evidence, with times and locations, proving it was not altered between collection and court.
Formal process taking every change through request, approval, testing, and rollback planning before implementation, so changes are deliberate, documented, and reversible.
The servers and communication channels an attacker uses to send instructions to compromised systems, such as the bots in a botnet, and to receive data back from them.
Watching traffic that leaves the network for signs of data exfiltration, command-and-control beacons, and policy violations; the outbound counterpart to inbound-facing defences.
Reducing a system's attack surface by removing unneeded software and services, closing ports, patching and applying secure settings, to bring it to a defined secure baseline.
Decoy system with no production value, deployed to attract attackers so their tools and methods can be observed; any interaction with it is suspicious by definition.
Managed lifecycle for handling security incidents: detection, response, mitigation, reporting, recovery, remediation, and lessons learned, limiting damage and preventing recurrence.
Monitoring control that inspects network traffic or host activity for signs of attack and raises alerts without blocking; detection is signature-based or anomaly-based.
A forward-looking metric that warns risk exposure is approaching an unacceptable level, triggering management action before loss occurs, unlike a KPI, which measures achieved performance.
Testing that verifies what a system must not allow, inverting use cases into abuse scenarios to prove that invalid, malicious, or out-of-sequence actions are rejected.
Central tooling that enrols phones, tablets and laptops and enforces configuration, encryption, passcode, app and remote-wipe policy on the devices that hold organisational data.
An authorised simulated attack, run under written rules of engagement, that proves whether weaknesses are actually exploitable rather than merely listing them.
Running untrusted code in an isolated environment so its behaviour can be observed and contained without risk to production; the basis of malware detonation and browser isolation.
A formal, evidence-based evaluation of controls against a defined standard, performed by internal, external, or third-party auditors whose independence determines its credibility.
A structured evaluation of whether controls are implemented correctly, operating as intended, and producing the required outcome, evidenced by examining, interviewing and testing.
Centralised platform that aggregates logs from across the estate, normalises them, correlates events from multiple sources in near real time, and raises alerts for investigation.
Scripted, pre-built transactions run against live systems to verify functionality, availability, and response times proactively, catching failures before real users hit them.
A systematic scan that identifies, quantifies, and ranks weaknesses across systems without exploiting them, trading depth for breadth and requiring validation of false positives.