Thursday, January 30, 2014

Security+ Performance-Based Questions Video

I recently posted a video on YouTube for Security+ performance-based questions titled Master Security+ Performance-Based Questions. In this video I compare some of these types of questions with traditional multiple choice questions.
Master Security+ Performance Based Questions

Security+ Performance-Based Questions

While I've written several articles about these types of questions, I still hear from people occasionally that are either surprised by them, or that are very nervous about them. One of my goals with this video is to reassure people that if you know the concepts related to the objectives, many of these questions aren't that difficult.

Most of the test takers I hear from confirm this. They mention that based on their understanding of the objectives and the underlying concepts, they were able to answer these correctly, even when they were surprised by them.

In the video, I discuss the following three types of performance-based questions:
  • Drag and drop
  • Matching items
  • Order items

Drag and Drop Security+ Performance-Based Questions

In a drag and drop type question, you use the Windows drag and drop feature to answer the question. For example, you might see a list of different security types where some security types are unique to mobile devices such as smartphones, and other security types are unique to servers. The question might ask you to drag each of the items on the left to the appropriate device in the table on the right, similar to the following figure.
Drag and Drop Security+ Performance Based Question
These concepts are covered in the following objectives:
  • 3.6 Analyze and differentiate among types of mitigation and deterrent techniques
    Physical Security
  • 4.2 Carry out appropriate procedures to establish host security
    Mobile Devices
Global Positioning System (GPS) tracking is only used on mobile devices. You can use it to locate a missing smartphone or iPad. In contrast, servers operate in a stationary data center or server room. You don’t need GPS on servers because they’re always at the same place. With this in mind, you would drag the GPS Tracking security type to the Mobile Devices list like this.

Drag and Drop Security+ Performance Based Question

Admittedly, if someone breaks into your server room, they could steal the servers, and GPS might help you locate them. However, money spent to protect servers is more appropriately spent on physical security to prevent access to the server room and the servers within it.

Matching Items Security+ Performance-Based Questions

Here’s an example of a matching question. You can see a list of protocols on the left, and a list of ports on the right. In this question, you might be asked to match each of the protocols with their well-known port.
Matching Items Security+ Performance-Based Questions

For example, port 80 is the well-known port for HTTP. You would match HTTP and port 80 so that it looks similar to the following figure.

Matching Items Security+ Performance Based Question

These concepts are addressed in the following objective:
  • 1.5 Identify commonly used default network ports
 The CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide covers all these ports and has a table with the ports and protocols listed . Also, there are some blogs on this site that cover these ports:

Order Items Security+ Performance-Based Questions

Order of volatility refers to the order in which you should collect evidence. “Volatile” doesn’t mean it’s explosive, but rather that it is not permanent. In general, you should collect evidence starting with the most volatile and moving to the least volatile. In this type of question, you might be asked to rearrange the data items based on what order you should collect the data for a forensic investigation. In other words, list the items from the most volatile to the least volatile.

Order Items Security+ Performance Based Questions
These concepts are addressed in the following objective:
  • 2.3 Execute appropriate incident response procedures
    Basic forensic procedures
    Order of volatility
With these items, memory is the most volatile and the memory contents will be lost when the system is powered down. More, the memory used with the processor, the CPU cache, is more volatile than the RAM. With this in mind, you would place the CPU cache first as shown in the following graphic.

Order Items Security+ Performance Based Question

Security+ Performance-Based Questions Summary

The Master Security+ Performance-Based Questions video and this article doesn't cover all the possible performance-based questions, but it does give you some insight into what they might look like. As long as you understand the objectives, and the underlying concepts, you'll find that these are not that difficult.
Good luck.


Security+ Practice Test Questions

Full bank of 468 realistic practice test questions with in-depth explanations. All questions include explanations so you'll know why the correct answers are correct, and why the incorrect answers are incorrect. This way no matter how CompTIA words the questions, you'll be able to answer them correctly.

These questions are from the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide. Multiple quiz formats to let you use these questions based on the way you learn.
  • Learn mode - randomized. View each of the questions in random order. Learn mode allows you to keep selecting answers until you select the correct answer. Once you select the correct answer, you'll see the explanation. Click here to see how learn mode works.
  • Learn mode - not randomized. View each of the questions in the same order. Use this if you want to make sure that you see all of the questions. Learn mode allows you to keep selecting answers until you select the correct answer. Once you select the correct answer, you'll see the explanation. Click here to see how learn mode works.
  • Test mode - randomized. View each of the questions in random order. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.
  • Test mode - not randomized.View each of the questions in the same order. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.
  • Test mode - 100 random questions. View 100 random questions from the full test bank similar to how the Security+ exam has a potential maximum of 100 multiple choice questions. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.

Additional Security+ questions to help you prepare for the new performance based questions. These are included with the full bank of Security+ practice test questions and are divided into different sections. For example, you'll have access to the following links:

- Performance Based Question - Set 1

You'll see a graphic explaining what you might be required to do on the actual exam to match different types of security to mobile devices and servers in a data center. You'll then have two questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 2

You'll see a graphic explaining what you might be required to do on the actual exam to match different types of attacks with the name of the attack type. You'll then have five questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 3

You'll see a graphic showing a network with computers and servers separated by a firewall. The firewall is used to control traffic between the computers and users using rules within an access control list (ACL). You'll have three questions that test your knowledge and ability to correctly identify the relevant components of the rule. The incorrect answers and explanation provide you with insight into how to correctly answer this type of question on the actual exam.

- Performance Based Question - Set 4

You'll see a graphic explaining what you might be required to do on the actual exam related to what a forensic analyst would do during an investigation. You'll then have two questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 5

You'll see a graphic explaining what you might be required to do on the actual exam to match protocols and ports. You'll then have seven questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

Tuesday, January 28, 2014

How To Pass A Certification Exam

I am frequently asked how I have passed so many certification exams. The short answer is "one at a time." I don't mean to be flip with that answer, but it's the truth. If I could rephrase the question it would be "How do you pass a certification exam?" I can give you a much better answer to that one.
How To Pass a Certification Exam

Find a Good Study Guide to Pass a Certification Exam

I have earned almost all of my certifications through self-study. When possible, I get one or more study guides that cover the exam objectives. Ideally, a single book is enough but in general, it's always a good idea to get more than one. If you don't  understand the concepts described by one author, you can get a different perspective from another author and you end up with a deeper understanding.

I've been grateful and humbled that so many people have said tthe CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide was their single source of study. However, that isn't typical. Two or more study guides is common.

I Don't Have Time To Read The Book

I recently received an email from a reader indicating he didn't have time to read a book and asking what he could do.

The first option that came to mind isn't a good one. He could hire someone else to take the exam for him. It's expensive and unethical, but if he doesn't have the time to learn the material, it is one option.

Perhaps he meant that he doesn't learn easily by reading a book. Are their other options?  Yes.

One option is to attend a course. It's more expensive than buying one or two study guides though. For example, Security+ courses range between $1,000 and $3,000 per person depending on the location, the training materials used, what's included, and the trainer. Compare this to two study guides averaging $30 for a total of $60, and you can see the difference. Similarly, there are many video courses out there that teach the material. Some of these  video courses are expensive but there are also some videos available for free.

Another option is to look for audio on the topics. For example some books are available on the Amazon Kindle, and the Kindle has an audio feature that reads the book to you.  Additionally, you can sometimes purchase  audio files for some topics. For example, supplementary audio files for the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide are available here.

Look at the Objectives to Pass a Certification Exam

The objectives identify what you can expect to be tested on. For example, if you are studying the Security+ certification, you can check out the objectives for it on CompTIAs web site. Many study guides, including the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide include the objectives in the book along with an objective map telling you exactly where that objective is covered in the book.

When reviewing the objectives, your goal is to identify what is familiar and what is not familiar. A study guide can help you clarify these objectives and how you might be tested on them.

Research Unclear Topics to Pass a Certification Exam

It's entirely possible that all of the topics aren't clear to you. Some quick Internet searches should help you identify the answers. Additionally, there are many forums where people provide helpful answers to each other. If you post a well thought-out question to one of these forums, you can get some great responses.

Many times when I'm studying for an exam today, it's before any study guides have been published. The Internet is a great resource for me.

Use Practice Exams to Pass a Certification Exam

After you've studied the concepts related to the objectives, use practice exams to test your readiness. Many study guides including the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide include practice test questions at the end of each chapter. Use these to test your comprehension of the chapter topics. Some books also have a pre-test before the first chapter and a post-test after the last chapter. Additionally, there are many other sources for practice test questions such as the Get Certified Get Ahead Premium site.

When using practice test questions, you goal is not to get them all correct. Instead, your goal is to test your comprehension.

Ideally, you should be able to look at any question and know why the correct answer is correct and the incorrect answers are incorrect. This way no matter how the questions are worded on the actual exam, you will be able to answer it correctly.

Some questions seem incomprehensible if you only look for the correct answer. However, if you eliminate the incorrect answers, the correct answer becomes obvious. As an example, I described this process in this video. While the video is focused on Security+ performance-based questions, I also included an explanation of eliminating incorrect answers with a typical multiple choice question in the video.

Along these lines, make sure the practice test questions you use have explanations.  After writing  thousands of practice test questions for several different certifications, I know how valuable these are to the user, and to the author.
  • As a user, you can use explanations to understand why the correct answers are correct and why the incorrect answers are incorrect. Many times, the questions have a subtle twist of words making one answer obviously incorrect. You might not see  this subtle twist when you read the question, but the explanation helps make it clear.
  • As an author, the explanation forces me to think about why each answer is incorrect. During this process, I often find that one of my answers is not not necessarily incorrect, and I change the question. In contrast, some authors do not provide explanations and do not see some of these issues.  As a reader/user, you might struggle with the question way too long trying to figure out why one answer is incorrect when it is actually correct.

Beware of Brain Dumps

Brain dumps are supposedly actual questions with supposedly actual answers. Some criminals use illegal and/or unethical methods to capture the questions, they guess at the correct answers, and then sell them. They do not include explanations. Instead, the buyers are encouraged to memorize the questions and answers.

If it's discovered that you used brain dump sources to pass an exam, you can have your certification revoked.  That's bad enough, but there's a worse consequence of using them.

Many have incorrect answers. People that memorize these questions and answers memorize incorrect information without understanding the reasoning behind it. Subtle changes to the questions elude them. They fail once, twice, and more and don't understand why. I've had students in classes that had memorized incorrect brain dump answers and had a significant amount of trouble trying to relearn the correct information.

Practice Test Questions Should Not be the First or Only Option

Some people turn to practice test questions as their only source of study. This isn't recommended, especially if your goal is to learn the concepts. Especially when they don't take the time to understand why the correct answers are correct and why the incorrect answers are incorrect, they fail and don't understand why.

Also, many people seek certifications to get ahead. The certification helps them land interviews and get new jobs with more responsibility and more pay.  However, many people that only study questions do not learn the concepts. They falter during the interviews, or worse, move into a new job and falter there and end up unemployed.

Instead, seek to learn the material, and then use practice test questions to test your comprehension.

Summary How To Pass a Certification Exam

While I've focused a lot of this on Security+, these same steps can be used on just about any certification you want to earn through self-study. As a summary, the steps are:
  • Get one or more good study guides
  • Review the objectives
  • Research further to clarify any unclear topics
  • Use practice test questions to test your comprehension
    • Ensure the practice test questions have explanations
    • Read the explanations to understand why the correct answers are correct and why the incorrect answers are incorrect

Security+ Practice Test Questions

Full bank of 468 realistic practice test questions with in-depth explanations. All questions include explanations so you'll know why the correct answers are correct, and why the incorrect answers are incorrect. This way no matter how CompTIA words the questions, you'll be able to answer them correctly.

These questions are from the CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide. Multiple quiz formats to let you use these questions based on the way you learn.
  • Learn mode - randomized. View each of the questions in random order. Learn mode allows you to keep selecting answers until you select the correct answer. Once you select the correct answer, you'll see the explanation. Click here to see how learn mode works.
  • Learn mode - not randomized. View each of the questions in the same order. Use this if you want to make sure that you see all of the questions. Learn mode allows you to keep selecting answers until you select the correct answer. Once you select the correct answer, you'll see the explanation. Click here to see how learn mode works.
  • Test mode - randomized. View each of the questions in random order. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.
  • Test mode - not randomized.View each of the questions in the same order. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.
  • Test mode - 100 random questions. View 100 random questions from the full test bank similar to how the Security+ exam has a potential maximum of 100 multiple choice questions. In test mode, you can only see the correct answers and explanations after you complete the test. Click here to see how test mode works.
Special Introductory Pricing
30 Day Access 60 Day Access
Normally $29.99 Normally $39.99

Now Only $14.99

Now Only $19.99

Buy Now Button with Credit Cards Buy Now Button with Credit Cards
Full Security+ Study Packages also available.

Additional Security+ questions to help you prepare for the new performance based questions. These are included with the full bank of Security+ practice test questions and are divided into different sections. For example, you'll have access to the following links:

- Performance Based Question - Set 1

You'll see a graphic explaining what you might be required to do on the actual exam to match different types of security to mobile devices and servers in a data center. You'll then have two questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 2

You'll see a graphic explaining what you might be required to do on the actual exam to match different types of attacks with the name of the attack type. You'll then have five questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 3

You'll see a graphic showing a network with computers and servers separated by a firewall. The firewall is used to control traffic between the computers and users using rules within an access control list (ACL). You'll have three questions that test your knowledge and ability to correctly identify the relevant components of the rule. The incorrect answers and explanation provide you with insight into how to correctly answer this type of question on the actual exam.

- Performance Based Question - Set 4

You'll see a graphic explaining what you might be required to do on the actual exam related to what a forensic analyst would do during an investigation. You'll then have two questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

- Performance Based Question - Set 5

You'll see a graphic explaining what you might be required to do on the actual exam to match protocols and ports. You'll then have seven questions that test your knowledge and ability to correctly answer the questions. This question also includes a link to a graphic showing the end solution for the overall performance based question simulation.

Full Security+ Study Packages also available.

Tuesday, August 27, 2013

Security+ Study Resources

If you're studying for  the Security+ exam, you might like to check out some of these Security+ Study Resources.

Recent Security+ Blogs

Recent Security+ blogs posted on the Get Certified Get Ahead Blogs site.

Are you ready for the new performance based questions? This page has links to several blogs discussing them so that you won't be surprised by these new questions.

Security+ Acronyms Flashcards

CompTIA expects you to know and understand many acronyms when taking the Security+ exam.

This applet on the Get Certified Get Ahead site shows random Security+ acronyms as flashcardsThese  flashcards provide you with a quick reminder of many of the different Security+ related terms along with a short explanation. 

The concepts are explained in greater depth in the full version of the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide.

Here are a couple of screenshots for one of the acronyms:
Security+ Acronyms Flashcards Front
Security+ Acronyms Flashcards Back


Security+ Quiz

A Security+ quiz to help you test your comprehension of Security+ topics. The quiz randomizes the questions and answers, and provides a score at the end. After completing the exam, you can review all the questions and answers.

Questions include in-depth explanations that you can review after completing the exam so you'll know why the correct answers are correct and why the incorrect answers are incorrect. This way no matter how CompTIA words the questions, you'll be able to answer them correctly.

Here's a screenshot of one of the questions. Can you get them all correct?
Security+ Quiz


Free - Security+ Flashcards

Check out this addition to the Get Certified Get Ahead site - Security+ Flashcards.

These flashcards are similar to the flashcards in the CompTIA Security+: Get Certified Get Ahead- SY0-401 Practice Test Questions Kindle version and the flashcards in the Learnzapp Security+ practice test questions app and are derived from the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide.

Here are screenshots of one flashcard for Security+ objective 5.3.
 Security+ Flashcards
 Security+ Flashcards
They work similar to how the Security+ Acronyms Flashcards work.

Recent Get Certified Get Ahead Tweets



Security+ Study Guide

Pass the Security+ exam the first time you take it with the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide.
  • Eleven chapters present topics in an easy to understand manner and include real-world examples of security principles in action.
  • The author uses many of the same analogies and explanations he's honed in the classroom. These analogies an explanations have helped hundreds of students master the Security+ content.
  • You'll understand the important and relevant security topics for the Security+ exam, without being overloaded with unnecessary details.
You'll be ready to take and pass the exam the first time you take it.
  • Each chapter includes a comprehensive review section to help you focus on what's important.
  • Over 450 realistic practice test questions with in-depth explanations will help you test your comprehension and readiness for the exam.
  • Includes a 100 question pre-test, a 100 question post-test, and practice test questions at the end of every chapter.
  • Each practice test question includes a detailed explanation to help you understand the content and the reasoning behind the question.

Security+ Practice Test Questions Mobile App

Practice test questions for your mobile devices. Learnzapp has apps for a wide assortment of mobile devices including Apple, Android, Amazon, Nook, and Blackberry.
  • In-depth coverage of all six domains in the CompTIA Security+ SY0-401 exam.
  • App includes 275 realistic practice questions to help you assess your exam readiness.
  • Questions include in-depth explanations to help you understand why the correct answers are correct and the incorrect answers are incorrect.
  • 175 flashcards to help you review important testable concepts.
  • Buy once. Use on any device.
  • Amazing interactive user experience. Internet connection not required.
Get Certified Get Ahead - Mobile Apps

Security+ Practice Test Questions on Kindle

Check your readiness for the Security+ exam with the CompTIA Security+ SY0-401 Practice Test Questions (Get Certified Get Ahead)
book. Available in both paperback and Kindle format.
  • Includes 280 realistic practice test questions with in-depth explanations so that you'll know why the correct answers are correct, and why the incorrect answers are incorrect.
  • Kindle edition includes dozens of flash cards specifically formatted for the Kindle.
You can download free Kindle applications for just about any device from here.
Get Certified Get Ahead Practice Test Questions

The book is organized in six chapters matched to the six Security+ domains.Each chapter in the Kindle edition includes three sections:
  1. Practice test questions without answers. Created for readers that want to go through all the questions without seeing the correct answers or explanations.
  2. Practice test questions including answers formatted for the Kindle. One Kindle screen shows the question. When you decide what you think is the correct answer, go to the next Kindle screen to see the correct answer. Each question includes an in-depth explanation so you'll know why the correct answers are correct, and why the incorrect answers are incorrect.
  3. Flash cards formatted specifically for the Kindle to help reinforce important concepts. One Kindle screen shows a flash card type question and the next Kindle screen shows the answer.The introduction includes details on the exam to give you an idea of what to expect.
Additionally, the acronym list at the end of the book provides relevant details on many of the acronyms referenced in the Security+ exam.

Security+ Audio Test Questions on Facebook

Learn by Listening

Supplement your studies with Security+ audio files read directly from the CompTIA Security+ Get Certified Get Ahead SY0-401 book. A total of over 4 hours and 40 minutes are now available.
Supplement your studies with Security+ audio files you can listen to while on the go.

Listen to key topics from all the chapters of the top selling CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide, or focus on just the topics you want to brush up on.
  • Learn while driving or commuting
  • Learn while exercising
  • Learn any time

Note that these audio files are not the entire 556 page book which could easily be forty hours of listening time. Instead, they focus on key information to supplement your studies.

Choose from one of two audio downloads currently available or get them both.

You can get either the Remember This audio from the book to reaffirm key testable concepts, or the Practice Test Questions and Answers audio which includes full explanations to help you understand why the correct answers are correct, and why the incorrect answers are incorrect.

Listen on your iPod or MP3 player.

Free sample from chapter 8 available for a limited time. This audio sample includes the Remember This blocks from chapter 8 which are key topics to know for the exam.
Buy the Questions and Answers audio here.

Audio files read directly from the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide by a professional voice actor.
Buy the Remember This audio here.

Audio files read directly from the CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide by a professional voice actor.


Free Security+ Practice Test Questions on Facebook

The Get Certified Get Ahead Facebook page is dedicated to helping people pass certification exams the first time they take them. Get Certified and Get Ahead in Your career.

It includes discussions, resources, and free practice test questions on the core three CompTIA certifications: A+, Network+, and Security+. Get Certified Get Ahead is hosted by Darril Gibson, author of over 30 books including successful books on A+, Network+, and Security+ certifications.

Check out the new Security+ Quiz on the Get Certified Get Ahead site.

Saturday, August 10, 2013

Get Certified Get Ahead

I have expanded many of my post topics to include much more than just the Security+ exam. With that in mind, I am posting these blogs on my Get Certified Get Ahead blogs page. Here are some links that might be useful:

Main Pages Get Certified Get Ahead Main site
Get Certified Get Ahead Blogs
Security+ Security+ Blogs Links
Security+ Performance Based Questions
Network+ Network+ Blogs Links
Network+ Performance Based Questions
A+ A+ Blogs
Recent Blogs Tweets by Darril Gibson

Wednesday, July 24, 2013

Will This Certification Get Me A Job?

Will the Network+ Certification Get Me a Job?

Here's a question I often receive from people: "Will this certification get me a job?" It's sometimes worded a little differently. Here are a few variations.

Here's the Short Answer

No.

Long Answer

A certification helps you land an interview but is only a small part of a larger picture. Most companies are looking for someone that will be a good fit in the job within the company but they are interested in much more than just what tests you can pass. However, if you can't pass the test, you often never get the interview.
Here's the typical process for someone pursuing and being offered a job
  • An organization advertises for a job
  • You submit a resume (with or without a cover letter)
  • Your resume is picked as a possible candidate
  • You might be asked to complete one or more tests
  • You are asked to do one or more interviews
  • You are given an offer
  • You start your new job
Your certification and the underlying knowledge is important when your resume is reviewed, when you complete some technical pre-interview tests, and when you're interviewed. However, it is isn't the only important element.
Get Certified Get Ahead - Certification Get Me A Job

Rare Exception

With very few exceptions, you need more than a certification to get a job. Here's an example of a rare exception.

Imagine someone named Joe who recently left the U.S. military with a security clearance. Joe has very little IT experience but decides to pursue the A+ certification and earns it.

A contractor (called Acme of Wiley E. Coyote and Road Runner fame) has a contract with the U.S. DoD. One position recently opened up. It requires someone with an A+ certification and a security clearance. Normally, Acme gets $50 an hour for every hour a person is working in this position and they pay $30 an hour to someone working in it. Acme is losing $20 an hour (or about $800 a week) for every hour this position remains unfilled.

If Joe applies and can prove he has an A+ certification, the clearance, and a pulse, he has the job.

Your goals

When pursuing a new job, you often have two short-term goals.
  • Get an interview. The first goal is to get an interview. You have the best chance of success here if your resume has the certifications and the knowledge/skillset required for the job. A cover letter (or email introduction) also helps.
  • Shine during the interview to get an offer. You need to demonstrate that have the knowledge/skillset required by the job and you are a good fit on the organization's team. This is often much more than your technical ability.
If you're not getting interviews, improve your resume and introduction process.

Check out this article: Skills mismatch hinders the hiring of new graduates, survey finds. It mentions that "Forty-nine percent of human resource officials polled by the professional organization said this year’s college graduates lack basic English skills in grammar and spelling."  This is often reflected in applicant's resumes. A single typo can get your resume thrown in the rejection pile.

If you're not getting jobs after interviews, improve your interview techniques. Check out this article for five tips to help you during your next interview.

Elimination Phases

Hiring managers often have a very short time to look at a resume. When a job requires a certification, resumes without the certification are quickly eliminated. A hiring manager might have 100 resumes to fill a single job and this job requires a specific certification. He looks through them and sees that only about 10 include the certification. The rest are tossed aside.

If you have the certification they require, you'll make it to the next phase. However, just having this on your resume won't be enough.

Here's a resume tip I recently posted on the Get Certified Get Ahead Facebook page.

~~~ Resume Tip ~~~ Take the time to target your resume for every new position. Ensure each resume includes the key words of the position you’re applying for, so that it has a better chance of being noticed. Many employers and head hunters accept resumes online and put them into a database. They then search the databases with specific keywords. If you use a one-size-fits-all resume, you have less of a chance to get the interview and ultimately the job.

Testing  Phases

Some jobs require candidates to take one or more tests. Some tests are strictly technical asking you multiple-choice technical questions. You aren't expected to ace them, but they often give the hiring managers an idea of your technical knowledge.

Other tests are deeper. Organizations sometimes use psychological tests to gauge how someone might interact with customers or how they might respond in a highly stressful environment. Again, perfect answers aren't expected, but they do give the hiring managers some insight.

One test that will surely eliminate you is a drug test. Many companies require you to submit to drug testing to see if you are a drug user.

Background Check Phase

It's common for an organization to do a background check on a potential employee at just about any point in the hiring process. A background check typically includes legal and financial checks.

Legal checks often include local, state, and national sources to see if a potential employee has any legal issues that might impact their employment. Legal issues won't necessarily eliminate a person from a job. As an example, it probably won't matter if a person with a recent speeding ticket is applying for a technical job that doesn't require driving.  On the other hand, if a person is asked and they lie about it, it will matter. 

Financial checks are used in many different ways. I remember a student in a class telling me that insurance companies frequently use financial checks when pricing insurance policies. A poor credit score typically results in a higher priced policy. Similarly, hiring managers might equate a poor credit score with a lower level of responsibility and use this as an elimination factor.

Interview Phases

During the interview phase, you have an opportunity to shine. You can expect to be asked about your knowledge and skill set related to the job and you should be able to easily talk about anything you've included on your resume.

If you list a Security+ certification, you might be asked about the certification, or content that someone that passed the certification would be expected to know. If your answers indicate that your resume claim is incorrect, expect to be eliminated. As an example, if your resume indicates you have a certification but you admit during the interview that you don't have it, expect to be eliminated.

You can also expect to be asked questions that will bring out your personality. These types of questions are rarely direct. However, how you respond, especially to questions you aren't prepared to answer, help people understand you better. You won't hear questions like the following list, but interviewers are often curious about the answers to them just the same.
  • Are you a goal-setting achiever? Or are you are a quitter?
  • Do you enjoy participating in a team to help the company succeed? Or are you out for yourself only.
  • Are you friendly and look for the best in people? Or do you carry a chip on your shoulder looking for the worst in others?

Summary - Certifications Make you Marketable

In summary, a certification can certainly make you marketable, but it isn't the only consideration for any job. You cannot expect any certification to get you a job. You can expect a certification to make you more marketable and help you land an interview. After that, it's up to you.

 

Wednesday, July 3, 2013

Identify Social Engineering Attacks

Identify Social Engineering Attacks

Can you identify different types of social engineering attacks in the Security+ exam?

The Security+ exam expects you to to be able to analyze and differentiate different types of social engineering attacks, including shoulder surfing, dumpster diving, tailgating, impersonation, hoaxes, whaling, phishing, and vishing.  You might even see a performance based question related to these types of attacks. 

Social engineering is the practice of using social tactics to gain information. It’s often low-tech and encourages individuals to do something they wouldn’t normally do, or cause them to reveal some piece of information, such as their user credentials.

Some of the individual methods and techniques include:
  • Flattery and conning
  • Assuming a position of authority
  • Encouraging someone to perform a risky action
  • Encouraging someone to reveal sensitive information
  • Impersonating someone, such as an authorized technician
  • Tailgating or closely following authorized personnel without providing credentials

Performance Based Questions

Topics such as identifying attacks are ideally suited for the new performance based questions on the CompTIA Security+ exam. Instead of answering a multiple choice question, you might need to identify an attack and match it to the most likely target. If you're unfamiliar with the new performance based questions, check out these blogs too:

Matching Attacks Practice Question

The following table includes three columns: attack methods, attack targets, and attack types. However, they are jumbled and not in the correct order.

Would you be able to rearrange the items in the table so that each attack method is matched to the appropriate attack target and attack type? Each attack method, attack target, and attack type is used only once so your solution needs to ensure that all choices are used.
Attack Methods Attack Targets Attack Types
Identify Social Engineering Attacks - Internet Internet Web Page Identify Social Engineering Attacks - CEO CEO

Rogueware

Identify Social Engineering Attacks - Phone Attacker
Phone Attacker
Identify Social Engineering Attacks - UserUser

Vishing

 Identify Social Engineering Attacks - Email Identify Social Engineering Attacks - Receptionist Receptionist

Whaling

Pass the Security+ exam the first time you take it: CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

Phishing and Whaling

Phishing is the practice of sending e-mail to users with the purpose of tricking them into revealing personal information or clicking on a link. A phishing attack will often send the user to a malicious website that appears to the user as a legitimate site.

The classic example is where a user receives an e-mail that looks like it came from eBay, PayPal, a bank, or some other well-known company. The “phisher” doesn’t know if the recipient has an account at the company, just as a fisherman doesn’t know if any fish are in the water where he casts his line. However, if the attacker sends out enough e-mails, the odds are good that someone who receives the e-mail has an account.

Whaling is a form of spear phishing that attempts to target high-level executives.

As an example, attackers singled out as many as twenty thousand senior corporate executives in a fine-tuned whaling attack a few years ago. The e-mails looked like official subpoenas requiring the recipient to appear before a federal grand jury and included the executive’s full name and other details, such as their company name and phone number.

The e-mails also included a link for more details about the subpoena. If the executives clicked the link, it took them to a website that indicated they needed a browser add-on to read the document. If they approved this installation, they actually installed a keylogger and malware. The keylogger recorded all their keystrokes to a file, and the malware gave the attackers remote access to the executive’s systems.

Similar whale attacks have masqueraded as complaints from the Better Business Bureau or the Justice Department. Executives are sensitive to issues that may affect the company’s profit, and these attacks often get their attention. This blog also covers phishing, spear phishing, and whaling.

Vishing

Vishing attacks use the phone system to trick users into giving up personal and financial information. It often uses Voice over IP (VoIP) technology and tries to trick the user, similar to how other phishing attacks try to trick the user. When the attacker uses VoIP, it can spoof the caller ID, making it appear as though the call came from a specific company.

In one form of a vishing attack, a person receives a phone message indicating they need to call about one of their credit cards, and the message provides a phone number. In another form, the person receives an e-mail with the same information.

If the person returns the call, an automated recording gives some vague excuse about a policy and then prompts the user to verify their identity. One by one, the recording prompts the user for information like name, birthday, Social Security number, credit card number, expiration date, and so on. Once the person provides the information, the recording indicates the account is verified. What really happened, though, is that the person just gave up some important data to a criminal.

Rogueware

Rogueware (or scareware) is a type of Trojan that masquerades as a free antivirus program. When a user visits a site, a message on the web page or a popup appears indicating it detected malicious software (malware) on the user’s system. The user is encouraged to download and install free antivirus software. Users that take the bait actually download and install malware.

After a user downloads it and starts a “system scan,” it will report that it has located malware  and pop up an official looking warning. In reality, it doesn't scan for malware and will always reports bogus infections.

If users try to remove the threats, they are informed  that this is only the trial version, and the trial version won’t remove any threats. However, for the small fee such as $79.95,  users can unlock the full version to remove the threats. Many people pay. Panda security reported that criminals took in an average of $34 million a month in recent years. This blog also covers rogueware.

Matching Attacks Practice Question Answer

The following table shows the attack methods, attack targets, and attack types in the correct order.
  • Whaling is a targeted phishing email sent to CEOs and other senior executives.
  • Vishing is a type of phishing attack using a phone.
  • Rogueware is bogus antivirus software downloaded by unsuspecting users from a website.
Attack Methods Attack Targets Attack Types
 Identify Social Engineering Attacks - Email Identify Social Engineering Attacks - CEO CEO

Whaling

Identify Social Engineering Attacks - Internet Internet Web Page Identify Social Engineering Attacks - User User

Rogueware

Identify Social Engineering Attacks - Phone Attacker
Phone Attacker
Identify Social Engineering Attacks - Receptionist Receptionist

Vishing

Summary - Identify Social Engineering Attacks

Ensure you understand the basics of social engineering attacks when taking any security-based exam such as the Security+SSCP, or CISSP exams. Whaling is a targeted phishing attack against CEOs and other senior executives.  Vishing is a type of phishing attack that uses phones. Rogueware is bogus antivirus software that a user can download from a webpage on the Internet.

Monday, July 1, 2013

Microsoft TechNet Subscription Service Retiring

Microsoft TechNet Subscription Service Retiring

I was a little surprised when I opened an email from Microsoft announcing "Technet subscription service retiring."

The last day to purchase a TechNet Subscription through the TechNet Subscriptions website is August 31, 2013. Subscribers may activate purchased subscriptions through September 30, 2013.

Microsoft will continue to honor all existing TechNet Subscriptions. Subscribers with active accounts may continue to access program benefits until their current subscription period concludes.

Great for Learning

I've had a TechNet Subscription almost every year since about 1999 when I first became a Microsoft Certified Trainer (MCT). It has been an outstanding resource to obtain both new and established products. This has been absolutely essential as a trainer and author when I was writing about new products, and tremendously valuable when I was prepping for an established product that was new to me.

Need more specifics on which products are included with a TechNet Subscription? You can download the full list of products available by subscription level here.

For some of these years, Microsoft provided a TechNet subscription to all MCTs. For other years when they didn't provide it, I paid for it out of my pocket. I've certainly valued this and wonder if they plan on replacing it with anything such as an MSDN subscription. We'll see.

TechNet Subscription Alternatives

If you don't have a Technet Subscription and don't want one, you can still use these resources:
  • TechNet Evaluation Center: Free evaluation software with no feature limits, available for 30-180 days. Includes rich evaluation resources and TechNet Virtual Labs, which enable you to evaluate software without the need to install bits locally.
  • Microsoft Virtual Academy: Free online learning site, with over 200 expert-led technical training courses across more than 15 Microsoft technologies with more added weekly.
  • TechNet Forums: Free online forums where IT professionals can ask technical questions and receive rapid responses from members of the community.

MSDN is the Real Replacement

MSDN Subscriptions provide a paid set of offerings that are available for those who require access to evaluation software beyond what the above free offerings provide.

For years, MCTs have asked for MSDN Subscriptions instead of the TechNet subscription so that they could access application software available within Visual Studio. It would be great if they replaced the TechNet Subscription with MSDN. I'd seriously consider returning to teaching some application courses. 

I actually backed off teaching some application courses simply because it cost so much to get Visual Studio.At $6119 for Visual Studio Premium with MSDN, it becomes a huge investment. Especially when you compare it to the $349 for TechNet Professional.

Permanent?

If you want the the TechNet Subscription, get it now.  Microsoft might back peddle and change their mind later.  They have quite a history of making U-turns. However, if they do change their mind, I doubt it'll be soon after August 31, 2013.