Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
How To Pass Your INFOSEC Exam, Part 1
Rating: 4.7 out of 5(39 ratings)
176 students

How To Pass Your INFOSEC Exam, Part 1

A Guide To Passing the SSCP, CISSP, CCSP, CISA, CISM, Security+, and CCSK
Created byBen Malisow
Last updated 4/2021
English
English [Auto],

What you'll learn

  • How To Pass Your INFOSEC Exam
  • A Guide To Passing The SSCP, CISSP, CCSP, CISA, CISM, Security+, and CCSK

Course content

3 sections59 lectures5h 13m total length
  • Course Overview and Instructor Introduction2:02

    Explore fundamentals common to infosec certifications, including security, IT basics, encryption, legal issues, personnel training, and disaster response, plus strategies for taking the exams.

  • 1.1: Security Fundamentals and the CIA Triad4:29

    Learn how security serves business goals by balancing confidentiality, integrity, and availability with cost-effective controls, prioritizing people's safety, accountability, and appropriate access control.

  • 1.2 - Risks and Threats2:58

    Identify risk as the potential for negative organizational impact, including data and monetary loss, and describe threats, vulnerabilities, and natural, anthropomorphic, and user-driven risks.

  • 1.3 - Vulnerabilities2:17

    Identify vulnerabilities as any path threats can exploit across actions, processes, hardware, software, and people. Understand administrative, contractual, and regulatory risk that affects availability and liability.

  • 1.4 - Determining Risk2:33

    Perform risk analysis to identify threats and vulnerabilities using qualitative or quantitative methods, then use CIA asset inventory and BIA to value, prioritize, and protect critical assets.

  • 1.5 - Risk Management and Mitigation16:15

    Learn to manage risk using avoidance, acceptance, transfer, and mitigation, and apply seven controls: deterrent, detective, compensating, preventive, directive, corrective, and recovery across administrative, physical, and logical domains.

  • 1.6 - Personnel Security6:38

    Learn essential personnel security practices, including least privilege, need-to-know, separation of duties, dual control, job rotation, and mandatory leave to reduce risk and prevent fraud.

  • 1.7 - Governance6:26

    Governance defines organizational decision making through policies, standards, and processes within a GRC framework. Senior management involvement, broad department input, and regular reviews ensure policies remain clear, legitimate, and compliant.

  • 1.8 - Configuration Management5:14

    Explore configuration management and change management, learn how to establish a formal inventory, review requests with a change control board, test before production, and manage deployment, maintenance, and disposal.

  • 1.9 - CCB2:25

    Identify who should sit on the ECB and how security representatives bring essential operations perspectives. Use a 'yes, but' approach, implicitly approve with required controls, budgets, and risk acceptance.

  • 1.10 - Patching4:02

    Patch management balances routine and reactive updates to keep IT environments secure, interoperable, and prepared with backups and post-approval rules.

  • 1.11 - Continuous Monitoring2:49

    Learn continuous monitoring to secure IT environments through vulnerability scans and pen tests. Understand zero-day exploits and the value of third-party, non-destructive testing for safe risk validation.

  • Section 1 Review4:12

    Review section one of how to pass your infosec exam, focusing on risk acceptance, control categories, need-to-know, separation of duties, and the role of checklists and job rotation.

Requirements

  • Basic IT and security knowledge

Description

If you’re a professional in the field of IT, IT security, audit, or general security, you know that certifications are the key to better job opportunities and higher pay. There are many available, from various sources; many of them come from manufacturers and vendors of specific products, many from certification bodies and organizations, and some from government and quasi-government sources. The certifications usually require that you pass a multiple-choice test.
This course is meant to help you pass these tests. It contains lists and descriptions of material usually tested, regardless of certifier or test.


I have the SSCP, CISSP, CCSP, CISM, CCSK, and Security+ certifications, and used to hold the SANS GSEC. I’ve taught prep courses for most of them, and am familiar with material that shows up over and over again, on all of them. I’m not an expert in any single area of IT or INFOSEC, nor am I even all that smart....but I am good at passing multiple-choice tests, and I am told that I’m good at conveying information. So I’m offering that knowledge to you.
I hope you find this course useful

This course is not a standalone product: you won’t be able to take the course and just pass the test. The course is designed for practitioners in the field: people who have trained and worked in INFOSEC for some time, who have the background and essentials to get the certifications. In addition to the course, you should be reviewing other sources (especially the sourcebook from the certifying body for the test you’re taking), including sample tests, primary sources, books, other classes, and online content. This course will show you the information you need to know, but you may have to do some additional research to get more comprehensive details about that information; I recommend Wikipedia and other online sources, because they are both exhaustive and -often- free.


I hope the course helps you pass your exam and get your certification. Please let me know what you think of it, whether you think it helped your study efforts or if you know some way it could be improved. Good luck!

Who this course is for:

  • Security professionals seeking certification