Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Lawrence C. Miller, Peter H. Gregory

Rating No ratings yet

Get CISSP certified, with this comprehensive study plan! Revised for the updated 2021 exam, CISSP For Dummies is packed with everything you need to succeed on test day. With deep content review on every domain, plenty of practice questions, and online study tools, this book helps aspiring security professionals unlock the door to success on this high-stakes exam. This book, written by CISSP experts, goes beyond the exam material and includes tips on setting up a 60-day study plan, exam-day advice, and access to an online test bank of questions. Make your test day stress-free with CISSP For Dummies! • Review every last detail you need to pass the CISSP certification exam • Master all 8 test domains, from Security and Risk Management through Software Development Security • Get familiar with the 2021 test outline • Boost your performance with an online test bank, digital flash cards, and test-day tips If you’re a security professional seeking your CISSP certification, this book is your secret weapon as you prepare for the exam.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, exam-focused study companion for security professionals preparing for the 2021 CISSP exam, combining domain-by-domain content review with a 60-day study plan, practice questions, and test-day strategy. Best for candidates who already have security experience and need a structured, no-nonsense way to organize their preparation. 【Book Arc】 - **Opening (~0%–15%)**: Frames the certification itself — (ISC)2 requirements, eligibility, study options (self-study, hands-on experience, official training, study groups, practice exams), registration, and what to expect on exam day and afterward. - **Early (~15%–30%)**: Moves into the first certification domain, Security and Risk Management, covering professional ethics, security policies/standards/procedures/guidelines, business continuity and impact analysis, personnel security, and risk management concepts including threat/vulnerability identification, risk treatment, and frameworks. - **Early–Middle (~30%–50%)**: Covers Security Architecture and Engineering — secure design principles (least privilege, defense in depth, zero trust, privacy by design), security models, evaluation criteria, system security capabilities, and vulnerability assessment across client, server, database, cloud, IoT, container, and embedded systems. - **Middle (~50%–65%)**: Continues into cryptographic systems and attacks (known plaintext, side channel, man-in-the-middle, ransomware) and physical/site security — facility design, wiring closets, utilities, environmental controls, fire suppression, and power. - **Late (~65%–90%)**: Works through the remaining domains — Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. - **Ending (~90%–100%)**: Closes with "The Part of Tens" — ten exam preparation strategies and ten test-day tips — plus a glossary and index for quick reference. 【Key Takeaways】 - **The book is organized around the eight CISSP domains** (Early–Late): each chapter maps to a domain, from Security and Risk Management through Software Development Security, so you can study in the same structure the exam tests. - **Risk management is treated as a foundational discipline** (Early): threat and vulnerability identification, risk assessment/analysis, risk appetite and tolerance, risk treatment, countermeasure selection, and continuous improvement are all covered in depth. - **Secure design principles recur across domains** (Middle): least privilege, defense in depth, secure defaults, fail securely, separation of duties, zero trust, and privacy by design are presented as reusable concepts, not one-off definitions. - **Modern system types get dedicated vulnerability coverage** (Middle): cloud, IoT, microservices, containerization, serverless, embedded, edge, and virtualized systems each receive attention, reflecting the 2021 exam outline. - **Cryptography is covered from both defensive and offensive angles** (Middle): the text addresses cryptographic systems alongside attack categories like side channel, fault injection, timing, man-in-the-middle, pass-the-hash, and Kerberos exploitation. - **Physical security is not an afterthought** (Middle): site and facility design, restricted work areas, HVAC, environmental issues, fire prevention/detection/suppression, and power are treated as exam-relevant topics. - **Exam strategy is built into the book** (Early and Ending): a 60-day study plan, guidance on when you're ready, registration logistics, and dedicated chapters of preparation and test-day tips. - **Supplementary online tools extend the text** (Opening): an online test bank, digital flash cards, and other study resources are included to reinforce domain review. 【Reading Tips】 - **Skim the certification logistics if you're already committed** (Opening): the (ISC)2 requirements and registration material is useful context, but experienced candidates can move quickly to the domains. - **Deep-read Security and Risk Management and Security Architecture and Engineering** (Early–Middle): these domains carry heavy conceptual weight and underpin many exam questions; the risk and secure-design vocabulary recurs throughout the book. - **Use the domain chapters as a checklist, not a novel** (Middle–Late): read each domain, then immediately test yourself with the online question bank to identify gaps before moving on. - **Don't skip the physical security and cryptography sections** (Middle): they can feel peripheral to day-to-day security work but are explicitly examinable and often underestimated. - **Save "The Part of Tens" for the final stretch** (Ending): the preparation and test-day tips are most useful once you've completed domain review and are close to scheduling the exam. 【Coverage Limits】 This guide is based on stratified excerpts that include the table of contents, front matter, and portions of the early and middle domains; the later domain chapters and the "Part of Tens" content are referenced by title but not covered in detail. Specific exam question formats, scoring mechanics, and the full content of later domains are not fully represented in the available excerpts.
Page 6
essed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-6011, fax (201) 748-6008, or online at http://ww...
View in text
Page 9
nd contributing to (ISC)2 publications . . . . . . . . . . . . . . . .27 Supporting the (ISC)2 Center for Cyber Safety and Education . . . .28 Participating...
View in text
Page 11
Vendor, consultant, and contractor agreements and controls . . .124 Compliance policy requirements . . . . . . . . . . . . . . . . . . . . . . . . . . .125 P...
View in text
Page 13
. . . . . . . . . . . . . . .210 Protection rings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .211 Security modes . . ....
View in text
Page 14
. . .340 Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .340 Systems and devices . . . . . . . . . . . ....
View in text
Page 16
. . . . . . . . . . . . . .436 Media protection techniques . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .438 Conduct Incident Management . . ....
View in text
Page 18
. . . . . . . . . .500 Make a 60-Day Study Plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .500 Get Organized and Read . . . . . ....
View in text
Page 20
e and protect organizations and industries around the world. Although we’ve stuffed it chock-full of good information, we don’t expect that this book will be...
View in text
Tags
AI categories
CybersecurityEducationTechnology
ISBN: 1119806895
Publish Year: 2022
Language: English
Pages: 611
File Format: PDF
File Size: 10.0 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…