CISSP (Certified Information Systems Security Professional)

Content
ThorTeaches.com
Udemy
34 hours of CISSP videos
3,250 Easy/Mid CISSP questions (exam emulation tests)
⚠️ Only 2,500
3,250 Easy/Mid CISSP questions (per-domain tests)
⚠️ Only 1,000
625 Hard CISSP questions
240 Domain practice questions (30 after each domain)
198 topic questions after each major topic
290-page CISSP Study Guides
114-page Quick Sheets
2,500 CISSP Flashcards
A 2,500-word CISSP Glossary
ThorBot: Your 24/7 AI study assistant, clarify concepts, tailor your learning, and enhance your CISSP preparation.
Bundle with everything
❌ 24 courses
CISSP Mnemonics
Offline video viewing
Subtitles in English, Spanish (Latin America), French, Arabic, Chinese, and Hindi
A CISSP study plan
Updated for the 2024 curriculum.
(Optional +$70) 700 Boson practice questions.
Access duration
Lifetime or 12-months
Lifetime
Content
ThorTeaches.com
Udemy

CISM (Certified Information Security Manager)

Content
ThorTeaches.com
Udemy
32+ hours of CISM videos
150 CISM questions
200-page CISM Study Guides
2,500 CISM Flashcards
A 2,500-word CISM Glossary
ThorBot: Your 24/7 AI study assistant, clarify concepts, tailor your learning, and enhance your CISM preparation.
Bundle with everything
❌ 5 courses
CISM Mnemonics
Offline video viewing
Subtitles in English, Spanish (Latin America), French, Arabic, Chinese, and Hindi
A CISM study plan
2022 curriculum updated, 2023, and 2024 updated.
Access duration
Lifetime or 12-months
Lifetime
Content
ThorTeaches.com
Udemy

CC (Certified in Cybersecurity)

Content
ThorTeaches.com
Udemy
17+ hours of CC (Certified in Cybersecurity) videos
1,700 CC exam emulation questions
⚠️ Only 1,200
60+ topic questions after each major topic
120-page CC Study Guides
2,500 CC Flashcards
A 2,500-word CC Glossary
ThorBot: Your 24/7 AI study assistant, clarify concepts, tailor your learning, and enhance your CC preparation.
Bundle with everything
❌ 3 courses
CC Mnemonics
Offline video viewing
Subtitles in English, Spanish (Latin America), French, Arabic, Chinese, and Hindi
A CC study plan
2022 curriculum updated, 2023, and 2024 updated.
Access duration
Lifetime or 12-months
Lifetime
Content
ThorTeaches.com
Udemy

CISSP D3 Preview | The History of Cryptography – Part 1

We have been using cryptography for 1000s of years.

Until recently, it has only been symmetric encryption where the 2 parties would have a pre-shared key.
In this video, I cover the history of cryptography at the level you need for the CISSP exam. Yes, this is very testable.

Remember, the CISSP exam is a management-level exam, you need the right point of view to pass the exam.

https://youtu.be/-KOGHeRDtxk

You can get all my courses, free study materials, my free CISSP course and much more on https://thorteaches.com/

Transcript:

In this lecture, we are going to talk about the history of cryptography and you might think, wait, what, how is that possibly relevant?
And it is relevant for two reasons.
First off, learning how something evolved and how it has been used over time can make you understand why we do some of the things we do today.
And secondly, and much more important, it’s on the exam.
This is something you might see in some of your questions, and it’s easy to learn.
It’s stuff you just need to memorize.
So these are easy win points.
Take them and be happy for them.
There are going to be plenty of questions on the exam that are convoluted, difficult, and where you end up having to pick the best of two possible right answers.
So the few times the exam is going to give you easy wins, take it.
We’re going to start out with the Spartan Scytale, and it is really just taking a piece of cloth and wrapping that cloth around a stick of a certain diameter and then writing your message.
Once you’re done writing the message, you remove it from the stick and then send it to the receiver.
Now, if someone else intercepts this message, they’re just going to see a long piece of cloth or parchment with letters that doesn’t make a lot of sense, even if for some reason they decide to wrap that around a stick, if that stick is not the exact same diameter, then it’s not going to line up and they can’t read the text.
Here, the stick of the same diameter is the shared secret that we use for our symmetric encryption.
Next up, we have Ceasar Cipher.
This is a substitution cipher.
Here we have our plain text message, and we then moved the letters a couple of rows over on the alphabet.
In the example you see over here on the right, you can see all the letters have moved three characters to the left.
So if our plain text message is “pass the exam”, moved three letters back, it would be “mxpp qeb buxj”, super super simple, but again, at the time, it was effective.
Next up, we have the Vigenère cipher.
It is a polyalphabetic cipher named after Blaise de Vigenère, a French cryptographer living in the 16th century.
If you look at the image over here on the right, you can see the English alphabet repeating both on the X and the Y axis.
And that square is called a Vigenère square, on both the X and the Y axis, the alphabet repeats 26 times.
On the X axis, you write the plaintext and then you write the key on the Y axis.
Here, let’s say our plaintext is “CISSP”, and the key is “Thor”.
That would make the ciphertext “VPGJI”.
When it was in active use, obviously both the key and the plaintext would be a lot longer.
But you get the idea right?
For the C, you go to the zero on the X axis and then you go down to the first of the key, that’s T, where they intersect, it’s a V, then you do that for the rest of the plaintext.
Now let’s take a look at cipher disks.
A cipher disk is two concentric disks with alphabets on them.
And concentric just means round.
One disk is bigger, the other is smaller.
If it is monoalphabetic or static, just like we looked at before, then T, for instance, will always be a D, but normally you would turn the inner disk, a certain number of letters in one direction after so many uses.
So for every five, 10, 20 letters, we might rotate the inner disk three spaces to the right.
Then we do another five letters in that position and then we rotate it again.
Which brings us to the Enigma.
Before and during the Second World War, Germany used the Enigma coding machine for all the secure communication.
They would encrypt it, then they would send it and then the receiver would decrypt it.
You may have seen the movie The Imitation Game, I personally thought it was an awesome movie.
If you haven’t seen it, go find it.
It’s the story about how a British group of scientists under the leadership of Alan Turing broke the Enigma encryption and how that would change the outcome of the war.
And to be fair here, there were multiple teams of people that broke the enigma.
On top of the team in the UK with Alan Turing, there was also a U.S. team of female scientists that broke the enigma as well.
You should also know there were two versions of the Enigma.
Early on before the Second World War, the Enigma had three rotors, that was broken by the Polish military when the Germans realized that.
The three rotor version was compromised.
They just added one more rotor, making it exponentially harder to break.
When it had three rotors, the options could be 26 x 26 x 26.
That gives us just over 17,500 different combinations.
When they added the fourth rotor that now changed the possible combinations to over 450,000.
So you can see what I mean when I say it was exponentially harder to break.
But as we know, it was eventually broken.
And if you have read up on it, if you have seen the movie, then, you know, they kept it a secret.
They only use the information for very, very critical targets.
If the Germans had started seeing unexplainable losses everywhere, then at some point they would figure out they were compromised.
By not acting on everything they decrypted, but only acting on the most important, they were able to conceal that they had broken the enigma.
And with the critical information they got, they were able to end the war years before it would have and saved millions of lives.
Which then brings us to Purple.
And Purple is the US name for a Japanese rotary based system very similar to the enigma.
And it was broken both by the US, the UK, and Russia.
It had three rotors, just like the Enigma did early on.
But as we know from the Enigma, three rotors was easy to break.
When Russia had broken the encryption and learned that Japan was not planning to attack Russia, they then moved the majority of their Eastern Front troops to Moscow to fight the Germans because they knew they were not a target.
They had decoded several messages saying Japan was going for Southeast Asia.
And with that we are done with this lecture.
We will finish up the history of cryptography in the next lecture.

CISSP Tips and Tricks | How to use practice questions, deconstruct them, and time management – Part 2

How you approach the CISSP exam questions is critical for passing the CISSP exam.

You need to have the right approach, you need to learn to deconstruct the CISSP questions, pick the keywords and indicators, and manage your time.

Learn these and more in this tips and tricks video!
Get the full free “CISSP: How to study course” https://thorteaches.com/get

https://youtu.be/I-mOgc_3sNU

You can get all my courses, free study materials, my free CISSP course and much more on https://thorteaches.com/

Transcript:

In this lecture, we’re going to talk about how to approach the actual questions.
Read the entire question, take the time you need to completely read it, probably read it twice and then deconstruct it.
What are they really asking?
You need to find the keywords and you need to find the indicators.
Indicators are most, best, least, can, always.
And then the keywords is what is this question actually about?
That could be PKI or self directed or something like that.
And when I say deconstruct, boil it down to its essence, it might be a full paragraph of a question but really what they’re asking is the last 10 words.
If we look at this question, “Jane is the lead of our incident response team, they have proof hackers have gained access to some of our systems and they have successfully altered some of our customer information.
Jane reports that to Bob, the IT security manager, who should notified first?”
Not a super long question, but there’s still a ton of fluff.
The fact that Jane is the lead of our incident response team, doesn’t really matter.
That we have proof does, hackers have gained access to some of our systems, the fact that Jane reports it to Bob, who should Bob notify first.
So really, the question is, we have been attacked, they have compromised us, who do we notify first?
That’s it.
Then we look at the answer options, the data owner, the regulatory agencies that govern our sector, the IT security steering committee or the customers who are compromised.
Now, very likely we would talk to all of those.
We would inform them at some point.
The question is first, would we notify the data owner?
I would say probably.
How about the agency that governs our sector?
No, we have to notify them, but they’re definitely not first.
The IT Security Steering Committee again, no, we do need to notify them, but the data owner needs to know first, and then finally, the customers.
Maybe, I don’t know.
It depends on the laws, the regulations, how bad the breach was and many other things.
And this is a question I would say is easy or mid.
It’s,not a hard question, but for the purpose of showing you how to deconstruct questions, I think it works pretty well.
Now, I have heard from many students that use different techniques to make this better.
Some read the question once they look at the options and then pick the best answer, others read the answers first.
These are the four options I have.
Then they read the question and they kind of have in the back of their mind, these are the options.
Regardless of how you do it, I suggest reading the question at least once, preferably twice, deconstruct it, figure out what are they actually asking, and then go through the answer options and argue with yourself.
Sure, we need to let the IT Security steering committee know, but do we do that first?
No, we don’t.
We let the data owner know and so on.
Does the answer option that you pick meet all the requirements that the question poses?
We need to be both accurate and precise.
Here, they’re probably all right answers but what is the most right answer.
In this specific question you have four possible right answers.
But in many questions, you have two possible right answers and you have two distracters.
That means that you can eliminate one, maybe two of the answer options.
Some of them can be just completely they don’t match.
They ask about something in the OSI model and two of the answers have to do with fire suppression and PKI.
Those are easy to eliminate.
Some of them will also list things that we do, but in the wrong order or not appropriate in this situation.
So let’s say you have a question and you’re like, I think this is the answer but it could also be this.
Well then, look through the last options.
If you have no clue and you’re not sure on any of the four, well, then you have 25%.
If you can eliminate two of them now you have 50% chance of getting it right, then you do the internal dialogue.
You argue this is a better answer because of this and once you have gone through that, it is most likely the right answer.
Another way you could think through the question is, if we can only implement or do one thing, what would best solve the problem.
In this case, if you can only notify one thing, one person, one agency, one, whatever, which one should you choose.
Again, we get the same answer, the data owner, but it can in some cases help you to argue with yourself, this is a better answer because if I can only pick one, then I would choose this.
And now that we have talked about how to approach the questions, let’s finish this lecture out with talking about some more practical stuff.
It is perfectly normal when you start on your easy questions to score somewhere around 60%, perfectly normal.
It is what you should expect because you’re just starting out.
Even if you score 50%, it really doesn’t matter, those are just numbers.
Now, what you do after the test is really what matters.
This is where you restudy, you look at all the questions you had marked for review and all the questions you got wrong.
Then you restudy those areas until you can explain what it is, where we use it, how we use it, why we use it and when we use it.
And since most people don’t have someone, they can talk to, talking to yourself works just as fine, explain the concept, all the intricacies, because when you’re able to explain something, you actually understand it.
Now, as you do more questions, you restudy more.
You’re obviously going to do better.
At some point, probably when you hit somewhere consistently, 80 to 85 percent% on the easy to mid questions that is an appropriate time to move to the hard ones.
And as mentioned, that is normally somewhere between 1500 and 3500 questions on the easy to mid.
Now, when you start on the hard questions, it’s going to feel like you’re starting over.
You’re all of a sudden going to score 60 percent or lower again.
Perfectly normal, nothing to worry about.
You do the exact same thing here, you take a test, you mark for review, you look at the ones you got wrong, and then you restudy.
You do also at some point have to start looking at time management.
Normally, I suggest it somewhere halfway in the mid to easy questions.
Let’s assume you get 150 questions on your exam.
That means with three hours you have 72 seconds per question.
And there might be questions where you spent two, three, four, five minutes on.
Well, then other questions you need to answer faster.
For the test engines where they have that timer, keep an eye on it and maybe set a pace saying, at 50 questions, I should have spent an hour.
At a hundred, two hours.
At 150, three hours.
Because I have talked to so many students that say, “I spent too much time on the first 50 questions.
I spent an hour and a half or two hours and then at some point I just started skimming over the question, answering really quickly and clicking next”, which at that point is completely fair.
You have to do that.
But if at all possible, let’s not get to that point.
Let’s learn the time management before you get to the exam.
And then when you sit in the exam and you can see you’re in question 42,
but you spent an hour and ten minutes already, you’re 75% sure that this is probably the right answer, well then choose that answer and move on.
And once you move on, once you click next, completely forget the question you just answered, you can’t go back and change the answer.
So put it out of your mind.
It’s not going to help anything if you keep obsessing about that one.
And then let’s talk about breaks, take them when you need them and preferably take them before you need them.
At this point, let’s say you’ve done 10 full, 100 to 150 question tests, then you probably also know when you’re going to hit the wall.
At one hour and 15, I’m just going to start staring blankly at the screen.
I’m going to read the same question five times and I still don’t understand it.
And it is less of a problem now because the test is shorter, but it is still a problem.
So if you know, at one hour and 15 minutes-ish, I hit the wall, well maybe take a break at one hour.
Either just close your eyes for 20 seconds, meditate, do whatever you can or get up, walk around, go to the bathroom if possible, eat some sugar, drink some caffeine, and then get back to the test.
The test does not stop.
If you take a ten minute break, you have ten minutes left for the exam.
If you take half an hour, well then half an hour.
That said, I still think they’re a good idea.
Reset your mind and back to the exam, and do as much of this as you can when you take practice tests to emulate what would actually happen on the exam.
Do the full test, three hours, lock yourself in a room, take the breaks but don’t let anything else distract you, because if you just take 50 questions here, 50 questions there, you don’t really know how your brain is going to react when you hit question 100 or 125.
And I think to finish this lecture out,I’m going to talk about what happens when you hit question 101.
Most students I talk to, when they don’t pass at 100 starts to panic, and saying don’t is obviously easier said than done, but don’t.
If the exam gives you question 101, that means you’re still in the game.
The exam engine has not yet predicted with 95% certainty that you pass or fail.
So in your preparation, mentally prepare to do 150 questions.
100 is the earliest point you can pass, 150 is the last.
Now from 100 to 150, as soon as the test engine can predict with 95% certainty that you fail or pass, well, then you fail or pass.
If it never gets to that point, well, then you go all the way to 150.
I hope all of this has helped you demystify the exams, help you figure out how to approach questions and how you can most effectively and efficiently prepare for your tests and pass your exam.
And with that, we’re done with this lecture.
I will see you in the next one.

10 years ago, I passed my CISSP, now it is your turn!

I took my CISSP exam 10 years ago.
Back then the exam was paper based, the tests were sent in a lockbox to (ISC)², and it would take around 6 weeks to get your exam results.
I thought I had failed, so I kept studying, but 6 weeks later I got an email letting me know that I had passed. It was weirdly anti-climactic and yet awesome!

My Facebook post from 10 years ago 😀 

My “Congratulations” email.

Being CISSP certified has played a major role in landing every single job I have had since then. My other certifications have helped, but the CISSP really sets you apart from everyone else.

Now it is time for you to pass your CISSP exam.
To help with that I am having a 96-hour sale on Udemy and ThorTeaches.
Get 10% off on https://thorteaches.com/get, use the coupon “CISSP10YEARS” at checkout.
or
Get the lowest possible instructor prices on Udemy by using the embedded coupons here: https://thorteaches.com/udemy/

Updates we are working on  💻 🗓️ 

  • A course on using generative AI for Project Management.

Updates we have completed 🍾 🎯 

Video and test courses updates:

Practice question updates:

CC (Certified in Cybersecurity): Get them here

Added 1,700 new questions. 

CISSP: Get them here
Added 3,250 new Easy/Mid CISSP questions – both as exam emulation and per-domain tests.
Added 125 new Hard CISSP questions.
Added 198 new CISSP topic quizzes added to our CISSP videos after each major topic.

Other:
150+ student names added to our practice questions, we want you to be part of our questions. 

Glossary updates:

Our FREE 2,500 word IT and Cybersecurity Glossary – CISSP, CISM, CC, CCSP:  
https://thorteaches.com/glossary/

ThorBots (Chatbots) updates:

ThorBot:

Your 24/7 AI study assistant, clarify concepts, tailor your learning, and enhance your CISSP, CISM, and CC preparation. The ThorBots are included in our CISSP, CISM, and CC courses here on ThorTeaches.com

Indexes for acceability updates:

Added page indexes to all our Study Guides and Quick Sheets for better accessibility and navigation.

The NEW Thor's CISSP Quick Sheets:

Introducing the NEW “Thor’s CISSP Quick Sheets”.

Streamline your review sessions, maximize your retention! We know you're busy, and that's why we've distilled our comprehensive CISSP Study Guides down to the essentials.
ThorTeaches.com proudly presents our new CISSP Quick Sheets – the ultimate condensed study notes tailored for your review sessions.
We have already added the CISSP Quick Sheets to our courses on Udemy and ThorTeaches.com, there is no additional charge or price increase, just another awesome study resource to help you succeed.
You can download them from the resources section in the first or second lecture of the course.

Our Flashcards on ThorTeaches.com are LIVE!

After many many months of working, our 2,500 CISSP, CISM, and CC Flashcards are finally here for you to use.

They are separated into primary domains for each certification as the perfect study aide for self-testing, review sessions, and reinforcing the material covered in our courses.

Where can I get the Flashcards?
They are ONLY available for our students with our CISSP, CISM, and CC courses on ThorTeaches.com, they are not available for Udemy students (sorry but it is an Udemy platform limitation).

Do they cost extra or will you raise your prices?
No, they are part of our full bundles. They were added to all our ThorTeaches.com CISSP, CISM, and CC students courses (right after the domain videos and the Glossary).

Can I use them on mobile devices too?
Yes, they are also accessible on your phone or tablet.

Can I download the flashcards?
No, they are only available on ThorTeaches.com in the courses.

Practice question updates:

CC (Certified in Cybersecurity): Get them here
Added 1,700 new questions. 

CISSP: Get them here
Added 3,250 new Easy/Mid CISSP questions – both as exam emulation and per-domain tests.
Added 125 new Hard CISSP questions.
Added 198 new CISSP topic quizzes added to our CISSP videos after each major topic.

Other:
150+ student names added to our practice questions, we want you to be part of our questions. 

Yes, there will be detailed explanations of why the correct answer is correct and why the incorrect answers are incorrect.

Easy (E) level sample question:
Louise is the IT security manager for a large financial institution. She has recently implemented a new access control system that utilizes multi-factor authentication for all employees to access sensitive data. One of her employees, Hanna, has reported that she is unable to access certain data that she should have access to. After investigating the issue, Louise discovered that Hanna's access privileges were inadvertently revoked by another employee. What is the most appropriate action to take in this situation?

  1. Reassign Hanna's access privileges to the appropriate level.
  2. Have Hanna go through the multi-factor authentication process again to verify her identity.
  3. Have Hanna go through the entire onboarding process again, including security training and background checks.
  4. Terminate Hanna's employment for security breaches.

The correct answer:
Reassign Hanna's access privileges to the appropriate level: This is the most reasonable and efficient solution. The issue at hand is that Hanna's access privileges were mistakenly revoked. The most direct way to resolve the problem is to reassign these privileges at the level that is appropriate for her role. This should allow Hanna to access the data she needs for his work. We might also want to investigate how it happened to see if we want to implement further checks to avoid this in the future.

The incorrect answers:
Have Hanna go through the multi-factor authentication process again to verify her identity: The issue isn't with Hanna's identity verification but rather with her access privileges. Re-doing the multi-factor authentication won't restore access to the resources she needs.
Have Hanna go through the entire onboarding process again, including security training and background checks. This approach is unnecessary and time-consuming. The issue doesn't stem from Hanna's actions or a lack of training. It's a mistake in the access control settings. Also, making an employee repeat the onboarding process because of a simple administrative error could lead to frustration and lower morale.
Terminate Hanna's employment for security breaches: This is inappropriate because Hanna didn't commit any security breaches. In fact, she reported the problem. Her access was revoked due to an internal administrative error, not because of her own actions. Taking such a drastic step as termination would not only be unjust, but it could also create a hostile environment where employees may be afraid to report problems in the future.

All of them will be on ThorTeaches.com; most will be on Udemy.

CC Udemy has 1,200 CC questions, ThorTeaches.com has all 1,700 questions. 

The CISSP courses on Udemy has 2,500 Easy/Mid questions as exam emulation and 1,000 as per-domain questions.
ThorTeaches.com has 3,250 Easy/Mid questions as exam emulation and 3,250 as per-domain questions.
Both have 625 HARD CISSP questions.

For UB (Udemy Business) students, you should have access to the new Udemy tests as soon as they are added to UB.

All the E/M tests are being retired and replaced with newer and better tests. all this is done in place, so your courses get updated for free. Hard questions are being added to.
On Udemy, we are updating questions in the current tests. We are also making new courses on Udemy for all the other questions.
On ThorTeaches.com, we are adding all the new questions to the bundles there; if you are a current subscriber, you get them all for free.
We plan to raise our prices to match all the new content, but we will announce a 1-week period where you can buy the bundle at the old price but still get all the new questions for free.

They will be better formulated with much better explanations. The test interface stays the same on Udemy and ThorTeaches.com.

Yes, all questions are based on the current CC (2023), CISSP (2021), and CCSP (2022) exams, and they will be updated when the exams change again.

The CISSP exam, will update April 15th. 2024, CCSP 2025, CC 2026, and CISM 2027. Questions will be updated at that time.

It's the same place you do now; we are just updating the back-end practice tests.

A ton of student requests, “Why don’t you have more questions?”, “Can you make more questions, please?”, “I really want just to use your questions,” and many more.
You ask, I listen 😊

Yes, just like you can now, you can take and retake the tests as many times as you want.
 
We asked our students on our discord server and in our Facebook group if they wanted their names included in our practice tests, here are the 150+ names that were included:

Aamir, Abhishek, Abiola, Abwino, Adeel, Adu, Ala, Alamgeer, Alfred, Alpesh, Alvin, Amolak, André, Andreas, Ashish, Ashlyn, Brent, Chinthake, Chirayu, Claire, Daniel, Debashish, Dhievy, Donita, Edward, Emmanuelle, Erin, Esther, Evan, Fahim, Garry, Gireesha, Guru, Gurudev, Habib, Hannah, Hind, Hrishikesh, Ishara, Ismail, Ivan, Ivy, Jacob, Jai, Javed, Jay, Jeyapaul, Joe, Joy, Joye, KaTina, Kazim., Khoa, Kobamelo, Kojo, Krzysztof, Kundai, Kushal, Leny, Livaniel, Liz, Malini, Marc, Marius, Maston, Melissa, Mervin, Michael, Moshood, Moxi, Nader, Neeraj, Newton, Olatunde, Omar, Philip, Pierre, Prasanth, Raghavendran, Rami, Ravi, Ritesh, Riz, Robert, Rogelio, Rohit, Ron, Ryan, Saad, Saeed, Sajeevkumar, Sameer, Sartsatat, Serena, Seth, Stuart, Syed, Tai, Taye, Terence, Tewfik, Thilina, Travis, Tristan, Tunde, Vihanga, Vikas, Vinit, Yokesh, Zaw, Scott, Jason, Prashant, Marteen, Fadi, Luc, Shon, Ku'uipo, Chris, Kaimana, Sara, Yasmine, Maria, Melissa, Fatma, Fatima, Nora, Mariam, Emma, Olivia, Isabella, Victoria, Ana Maria, Carmen, Helena, Manuela, Guadalupe, Malu, Esther, Kyra, Sofía, Luna, Zahra, Himari, Latifa, Shu-fen, Amelia, Freja, Agnes, Lív, Ronja, Louise, Hanna, Kamilė, Zuzanna, Anastasia, Astrid, Amelia, Leilani, Kalea, Makana, Kamalani, Francesca, Juanita, Prabh, Ana,Henry, Mikey, Syed, Ushakiran, Sanjay, Paskorn, Suobo, Darwin, Adeel, Jose

Our FREE 2,500 word IT and Cybersecurity Glossary – CISSP, CISM, CC, CCSP:  https://thorteaches.com/glossary/

Our Flashcards on ThorTeaches.com are LIVE!

After many many months of working, our 2,500 CISSP, CISM, and CC Flashcards are finally here for you to use.

They are separated into primary domains for each certification as the perfect study aide for self-testing, review sessions, and reinforcing the material covered in our courses.

Where can I get the Flashcards?
They are ONLY available for our students with our CISSP, CISM, and CC courses on ThorTeaches.com, they are not available for Udemy students (sorry but it is an Udemy platform limitation).

Do they cost extra or will you raise your prices?
No, they are part of our full bundles. They were added to all our ThorTeaches.com CISSP, CISM, and CC students courses (right after the domain videos and the Glossary).

Can I use them on mobile devices too?
Yes, they are also accessible on your phone or tablet.

Can I download the flashcards?
No, they are only available on ThorTeaches.com in the courses.

ThorBot:

Your 24/7 AI study assistant, clarify concepts, tailor your learning, and enhance your CISSP, CISM, and CC preparation.
The ThorBots are included in our CISSP, CISM, and CC courses here on ThorTeaches.com.
Updated again Feb 2024 with better back-end (ChatGPT 4-Turbo 128 and better command training.

Added page indexes to all our Study Guides and Quick Sheets for better accessibility and navigation.

Introducing the NEW “Thor’s CISSP Quick Sheets”.

Streamline your review sessions, maximize your retention! We know you're busy, and that's why we've distilled our comprehensive CISSP Study Guides down to the essentials.
ThorTeaches.com proudly presents our new CISSP Quick Sheets – the ultimate condensed study notes tailored for your review sessions.
We have already added the CISSP Quick Sheets to our courses on Udemy and ThorTeaches.com, there is no additional charge or price increase, just another awesome study resource to help you succeed.
You can download them from the resources section in the first or second lecture of the course.

What are the main practical changes in the CISSP 2024 exam update?

My video on the changes: 
https://www.youtube.com/watch?v=nFd0TQ5oBT8

The CISSP 2024 exam update, includes a 1% weight shift from Domain 8 to Domain 1, fewer exam questions (100 to 150 instead of 125 to 175), and a shorter exam duration (3 hours instead of 4). Additionally, there’s an update in curriculum content across various domains, including new and expanded topics.

What are the actual curriculum changes?

Most of the changes is more emphasis on topics that are more relevant and in focus now like cloud computing, AI, privacy, etc.

Domain 1: Added external dependencies in business impact analysis.
Domain 2: No changes we know of.
Domain 3: Added Secure Access Service Edge (SASE), Quantum key distribution, and managing the information system lifecycle.
Domain 4: Added transport architecture, performance metrics, traffic flows, physical segmentations, edge networks, virtual private clouds, and network monitoring and management.
Domain 5: Added services in the control of physical and logical access to assets, policy decision and enforcement points, and service account management.
Domain 6: Emphasis on location context (on-premise, cloud, hybrid) for audit strategies.
Domain 7: Added communication during the testing of Disaster Recovery Plans (DRP).
Domain 8: Added Scaled Agile Framework and software composition analysis.

When will your new content be out for the CISSP changes?

Content for 2024 curriculum changes is now live . 

Is anything of the current curriculum getting removed?

We do not think so, as far as we know no curriculum is being removed.

Will there be any new domains introduced in the updated CISSP exam?

No, the eight domains will remain the same; only the content within some domains will be updated or expanded.

How will the question format be affected by the update?

The question format will remain a Computer Adaptive Testing (CAT) format, but with a different number of questions and reduced exam duration.

If I’m already studying, should I attempt the exam before or after the update?

It is generally recommended to take the exam before the update, given that the current materials are available, and you might be more familiar with them. However, if that’s not possible, the changes are considered minor and should not significantly impact your preparation.

Will I need to repurchase your study courses for the updated exam if I already have them?

No, if you have purchased courses from ThorTeaches.com or Udemy, you will receive updates for free. Only the versions on these platforms will be updated.

Can I take the CISSP exam remotely after the update?

No, all exams must be taken in-person at an authorized Pearson-Vue testing center.

What happens if I have already purchased study materials for the current exam but plan to take it after the update?

You should be fine, the changes are very minor. It is advisable to review the new topics from other sources as the update will introduce new content.

When will the new study materials for the 2024 exam changes be available?

For ThorTeaches.com and Udemy courses, updates will be made available before the exam changes. The official study guides, AIO, and practice questions from ISC2 typically become available 3 to 6 months after the exam updates.

Is there going to be a price change for the CISSP exam after the update?

There are no planned changes to the exam pricing.

How can I best prepare for the CISSP exam with the upcoming changes?

It is recommended to continue studying the current materials and familiarize yourself with the new topics. Taking advantage of the free course on how to study for the exam at free.thorteaches.com can provide valuable insights into effective preparation strategies.

Will the format of questions change in the updated CISSP exam?

The format will remain Computer Adaptive Testing (CAT), but there will be a total of 100 to 150 questions instead of the previous range of 125 to 175.

I am scheduled to take the CISSP exam right before the update; will my exam still be valid?

Yes, your exam and assuming you pass and get endorsed, your CISSP certification will be just as valid regardless of whether you take the exam before or after the update.

How much time will I have per question in the updated exam?

If you receive the maximum of 150 questions in your exam, you will have approximately 72 seconds per question within the 3-hour time limit.

What is the passing score for the updated CISSP exam?

The passing score for the CISSP exam remains the same, which is a scaled score of 700 out of 1000 points.

Will there be any changes to the CISSP experience requirements after the update?

There have been no announcements regarding changes to the CISSP experience requirements, which currently entail a minimum of five years of professional security work experience.

Do the CISSP exam updates include changes to the continuing professional education (CPE) requirements?

There are no changes to the CPE requirements for maintaining your CISSP certification.

Will beta questions be included in the updated CISSP exam?

Yes, there will be 25 beta questions randomly dispersed within the first 100 questions of the exam.

Are the beta questions counted towards the final score?

No, beta questions are not counted toward your final score. They are used by ISC2 to validate the questions for future exams.

Will the beta questions be distinguishable from the scored questions?

No, you will not be able to distinguish beta questions from scored questions during the exam.

Can we expect new types of interactive questions in the updated CISSP exam?

There is no specific mention of new question types; the update focuses on content rather than question format.

How will the changes affect the weight of each domain in the CISSP exam?

All domains except for Domain 1 and Domain 8 will maintain their current weights. Domain 1 will increase by 1%, compensated for by a 1% decrease in Domain 8.

Will the difficulty level of the CISSP exam change after the update?

The difficulty is calibrated through the CAT format to reflect a consistent standard of knowledge, so it should remain comparable.

How frequently are the CISSP exam questions updated?

While there is a major curriculum update every three years, the actual exam questions can be updated more frequently to reflect current industry standards and practices.

Will the update affect the application process for the CISSP exam?

The application process for the CISSP exam is not expected to change with the update.

Are there any changes to the CISSP endorsement process after passing the exam?

No changes to the endorsement process have been announced.

Why is Lifetime Access more expensive than the standard 12-month access?
The premium price of Lifetime Access accounts for the ongoing costs to maintain, host, and update the course materials on our platform indefinitely, rather than just for 12 months.

Do I get access to all your courses on ThorTeaches.com when I buy lifetime access?
No, the lifetime access is purchased on a course level. If you want lifetime access to more courses, you need to purchase the courses you want.

Can I upgrade to Lifetime Access on courses I have not purchased?
You can only upgrade courses you own to lifetime access, or you can buy them initially with Lifetime Access.

Will I receive updates to the course with Lifetime Access?
Yes, all in-place updates to the course content are included with Lifetime Access. You’ll automatically receive the most current material without additional charges.

What does Lifetime mean on ThorTeaches.com?
In the context of this policy, “Lifetime” refers to the operational lifetime of the course on our platform, not the lifetime of the individual purchaser. Should ThorTeaches LLC undergo a business transition, such as cessation, sale, or restructuring, you will be provided a download link for the full course and all materials that you are enrolled in, preserving your educational investment. There are no near or long term plans for this, but proper contingencies should be clear.

Are there any maintenance or hidden fees associated with Lifetime Access?
No, there are no maintenance or hidden fees. The one-time premium payment covers all costs associated with the lifetime access to the course materials.

Can I switch from a 12-month access plan to Lifetime Access after my initial purchase?
Yes, you can upgrade to Lifetime Access at any time during your 12-month access period or after it expires. There is no deadline, even if your initial access has expired you can still get lifetime for 45% of the current course list price. It’s more cost-effective to select Lifetime Access at the time of your initial purchase.

Is Lifetime Access transferable to another student or individual?
No, Lifetime Access is non-transferable and is linked exclusively to the account of the original purchaser to ensure the integrity and security of account access.

Does Lifetime Access apply to all courses offered on ThorTeaches.com?
Yes, it is available for all our courses.

Will I still be able to access the course after I finish it?
Absolutely. Once you’ve finish the course, you will retain access to it for as long as your account remains in good standing. That means you can revisit and review the course content whenever you need a refresher or want to retake the entire course.

How often is the course content updated?
We update courses to align with the current exam version, all updates are done in-place. With Lifetime Access, you’re guaranteed to receive all these updates.

Can I get Lifetime Access for the Boson questions?
No, the Lifetime Access is only for our courses, we resell the Boson vouchers, so they are only 12-months access.

Yes, there will be detailed explanations of why the correct answer is correct and why the incorrect answers are incorrect.

Easy (E) level sample question:
Louise is the IT security manager for a large financial institution. She has recently implemented a new access control system that utilizes multi-factor authentication for all employees to access sensitive data. One of her employees, Hanna, has reported that she is unable to access certain data that she should have access to. After investigating the issue, Louise discovered that Hanna's access privileges were inadvertently revoked by another employee. What is the most appropriate action to take in this situation?

  1. Reassign Hanna's access privileges to the appropriate level.
  2. Have Hanna go through the multi-factor authentication process again to verify her identity.
  3. Have Hanna go through the entire onboarding process again, including security training and background checks.
  4. Terminate Hanna's employment for security breaches.

The correct answer:
Reassign Hanna's access privileges to the appropriate level: This is the most reasonable and efficient solution. The issue at hand is that Hanna's access privileges were mistakenly revoked. The most direct way to resolve the problem is to reassign these privileges at the level that is appropriate for her role. This should allow Hanna to access the data she needs for his work. We might also want to investigate how it happened to see if we want to implement further checks to avoid this in the future.

The incorrect answers:
Have Hanna go through the multi-factor authentication process again to verify her identity: The issue isn't with Hanna's identity verification but rather with her access privileges. Re-doing the multi-factor authentication won't restore access to the resources she needs.
Have Hanna go through the entire onboarding process again, including security training and background checks. This approach is unnecessary and time-consuming. The issue doesn't stem from Hanna's actions or a lack of training. It's a mistake in the access control settings. Also, making an employee repeat the onboarding process because of a simple administrative error could lead to frustration and lower morale.
Terminate Hanna's employment for security breaches: This is inappropriate because Hanna didn't commit any security breaches. In fact, she reported the problem. Her access was revoked due to an internal administrative error, not because of her own actions. Taking such a drastic step as termination would not only be unjust, but it could also create a hostile environment where employees may be afraid to report problems in the future.

All of them will be on ThorTeaches.com; most will be on Udemy.

CC Udemy has 1,200 CC questions, ThorTeaches.com has all 1,700 questions. 

The CISSP courses on Udemy has 2,500 Easy/Mid questions as exam emulation and 1,000 as per-domain questions.
ThorTeaches.com has 3,250 Easy/Mid questions as exam emulation and 3,250 as per-domain questions.
Both have 625 HARD CISSP questions.

For UB (Udemy Business) students, you should have access to the new Udemy tests as soon as they are added to UB.

All the E/M tests are being retired and replaced with newer and better tests. all this is done in place, so your courses get updated for free. Hard questions are being added to.
On Udemy, we are updating questions in the current tests. We are also making new courses on Udemy for all the other questions.
On ThorTeaches.com, we are adding all the new questions to the bundles there; if you are a current subscriber, you get them all for free.
We plan to raise our prices to match all the new content, but we will announce a 1-week period where you can buy the bundle at the old price but still get all the new questions for free.

They will be better formulated with much better explanations. The test interface stays the same on Udemy and ThorTeaches.com.

Yes, all questions are based on the current CC (2023), CISSP (2021), and CCSP (2022) exams, and they will be updated when the exams change again.

The CISSP exam, will update April 15th. 2024, CCSP 2025, CC 2026, and CISM 2027. Questions will be updated at that time.

It's the same place you do now; we are just updating the back-end practice tests.

A ton of student requests, “Why don’t you have more questions?”, “Can you make more questions, please?”, “I really want just to use your questions,” and many more.
You ask, I listen 😊

Yes, just like you can now, you can take and retake the tests as many times as you want.
 
We asked our students on our discord server and in our Facebook group if they wanted their names included in our practice tests, here are the 150+ names that were included:

Aamir, Abhishek, Abiola, Abwino, Adeel, Adu, Ala, Alamgeer, Alfred, Alpesh, Alvin, Amolak, André, Andreas, Ashish, Ashlyn, Brent, Chinthake, Chirayu, Claire, Daniel, Debashish, Dhievy, Donita, Edward, Emmanuelle, Erin, Esther, Evan, Fahim, Garry, Gireesha, Guru, Gurudev, Habib, Hannah, Hind, Hrishikesh, Ishara, Ismail, Ivan, Ivy, Jacob, Jai, Javed, Jay, Jeyapaul, Joe, Joy, Joye, KaTina, Kazim., Khoa, Kobamelo, Kojo, Krzysztof, Kundai, Kushal, Leny, Livaniel, Liz, Malini, Marc, Marius, Maston, Melissa, Mervin, Michael, Moshood, Moxi, Nader, Neeraj, Newton, Olatunde, Omar, Philip, Pierre, Prasanth, Raghavendran, Rami, Ravi, Ritesh, Riz, Robert, Rogelio, Rohit, Ron, Ryan, Saad, Saeed, Sajeevkumar, Sameer, Sartsatat, Serena, Seth, Stuart, Syed, Tai, Taye, Terence, Tewfik, Thilina, Travis, Tristan, Tunde, Vihanga, Vikas, Vinit, Yokesh, Zaw, Scott, Jason, Prashant, Marteen, Fadi, Luc, Shon, Ku'uipo, Chris, Kaimana, Sara, Yasmine, Maria, Melissa, Fatma, Fatima, Nora, Mariam, Emma, Olivia, Isabella, Victoria, Ana Maria, Carmen, Helena, Manuela, Guadalupe, Malu, Esther, Kyra, Sofía, Luna, Zahra, Himari, Latifa, Shu-fen, Amelia, Freja, Agnes, Lív, Ronja, Louise, Hanna, Kamilė, Zuzanna, Anastasia, Astrid, Amelia, Leilani, Kalea, Makana, Kamalani, Francesca, Juanita, Prabh, Ana,Henry, Mikey, Syed, Ushakiran, Sanjay, Paskorn, Suobo, Darwin, Adeel, Jose

Can I get CPEs/CEUs for finishing your courses?

Yes, when you finish our course you get a Certificate of completion worth 1 CPE per hour of video watched.
You can use them for CPEs with ISACA, CompTIA, ISC2, and many other certification providers.

  • The CISSP course is 32 hours long, worth 32 CPEs.
  • The CISM course is 32 hours long, worth 32 CPEs.
  • The CC (Certified in Cybersecurity) course is 17 hours long, worth 17 CPEs.
  • What are the ThorTeaches Chatbots?

    Our AI Chatbots are digital study assistants that support interactive learning, offer on-demand assistance, and provide smart study strategies for CISSP, CISM, and Certified in Cybersecurity (CC) certifications.

  • How do I access the chatbots?

    The chatbots are available exclusively for ThorTeaches.com students. Just log in to your account, and you'll find them ready to assist you.

  • Can anyone use the chatbots?

    While full access is reserved for our students, we offer a free version with limited features on our website for everyone to try.

  • What kind of materials are the chatbots trained on?

    The chatbots are trained using our video courses, study guides, mnemonics, NIST documents, Wikipedia articles, ISC2 and ISACA websites, our own "How to Study" materials, and various study guides like The CISSP Process Guide, The Sunflower Notes, and The Memory Palace.

  • Can the chatbots help me understand complex topics?

    Yes, you can ask them to explain complicated subjects in simpler terms to enhance your understanding.

  • Are the chatbots available 24/7?

    Absolutely! Our chatbots are ready to provide assistance around the clock, any day of the week.

  • Will the chatbots provide personalized study tips?

    They sure can. The chatbots will offer tailored advice based on our proven study methods and resources.

  • Can I rely on the chatbots for accurate information?

    While the chatbots are trained to provide accurate information, please be aware that they may occasionally make errors. Always cross-reference with authoritative sources when in doubt.

  • Do the chatbots offer support for exam logistics and scheduling?

    Yes, they can provide information on exam rules, registration, and scheduling processes.

  • What is the cost of using the chatbots?

    The chatbots are included as part of the educational resources provided to students of ThorTeaches.com. The slimmed-down version on our website is free.

  • How do the chatbots handle copyrighted content?

    Our chatbots are trained on non-copyrighted, copyright with attribution, or proprietary ThorTeaches materials.

  • Can the chatbots help with mnemonic devices?

    Yes, they can teach you mnemonics to improve your memory of important concepts.

  • Can the chatbots help with mnemonic devices?

    Yes, they can teach you mnemonics to improve your memory of important concepts.

  • Is there a limit to the number of questions I can ask the chatbots?

    No, you can ask unlimited questions and engage with the chatbots as much as you need.

  • Are the chatbots updated regularly?

    Yes, we ensure our chatbots are updated in line with the latest information and best practices.

  • Do the chatbots cover all domains of the certification exams?

    Yes, they provide assistance across all domains covered in the CISSP, CISM, and CC exams.

  • Will the chatbots replace my need for traditional study methods?

    No, they act as a complement to traditional methods by providing interactive and dynamic learning assistance.

  • Can the chatbots help me prioritize my study topics?

    Yes, ask the chatbot for advice on which topics to focus on based on your knowledge gaps and exam weightings.

Get our courses: