Friday, September 11, 2015
How You Can Generate Results From Promoted Pins on Pinterest
Pinterest's devoted users and ability to manufacture intent have made it a great way to drive valuable traffic to your site. http://www.entrepreneur.com/article/249893
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Thursday, September 10, 2015
The 7 Habits of a Highly Effective Web Marketer
There are as many strategies to improving website performance as there are best practices for doing so -- just ask the Good Idea Fairy. http://www.entrepreneur.com/article/250380
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Wednesday, September 9, 2015
12 Sites That Will Teach You Coding for Free
Programming has helped me to become a much better entrepreneur, and you can learn this skill without spending a dime. http://www.entrepreneur.com/article/250323
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
Coding,
Computer Programming,
Programming Language
3 Steps to Boost Your Social-Media Marketing With Image Tagging
Use the new online tools that give your brand images enhanced context and make them easier to find. http://www.entrepreneur.com/article/248877
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Tuesday, September 8, 2015
Selling Products Online? How to Build a Perfect Checkout Page (Infographic)
A look at how to create a checkout experience that nudges online shoppers to actually buy what they put in their shopping carts. http://www.entrepreneur.com/article/250135
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Online Shopping,
Online Store
Monday, September 7, 2015
3 Inexpensive Ways to Build Up Your Website Content
Fulfilling the demand for information and entertainment can be a challenge for smaller companies with limited manpower and financial resources but working within these limits is not impossible. http://www.entrepreneur.com/article/250049
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Website Content
Sunday, September 6, 2015
6 Growth-Hacking Tips to Boost Your Website's Traffic
These cheat sheets will help boost lead generation and increase your contacts. http://www.entrepreneur.com/article/250265
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Website Traffic
Friday, September 4, 2015
CISSP Exam Preparation (Question 311)
(311) Which one of the following is a characteristic of a penetration
testing project?
A. The project is open-ended
until all known vulnerabilities are identified.
B. The project schedule is
plotted to produce a critical path.
C. The project tasks are to break
into a targeted system.
D. The project plan is reviewed
with the target audience.
Correct Answer: C
Explanation
Explanation/Reference:
"One common method to test the strength of your
security measures is to perform penetration testing. Penetration testing is a
vigorous attempt to break into a protected network using any means
necessary." Pg 430 Tittel: CISSP Study Guide
- Muhammad Idham Azhari
17 Ways To Immediately Improve Your Website Traffic
If you need traffic, then this guide is for you. http://www.entrepreneur.com/article/249125
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Website Traffic
Thursday, September 3, 2015
3 Ways Social Video Marketing Can Propel Your Brand
This recent trend harnesses the power of emotions to deliver a subtle message to viewers. http://www.entrepreneur.com/article/249848
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Video Marketing
Tuesday, September 1, 2015
Improve Your Website's Conversion Rates With These 6 Design Tips
Naturally, the more conversions your website produces, the more revenue your business is going to produce. http://www.entrepreneur.com/article/250059
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Labels:
internet marketing,
online biz,
Website Design
Monday, August 31, 2015
How to Create a Social-Media Marketing Plan From Scratch (Infographic)
You should choose the social networks that best fit your strategy and the goals you want to achieve on social media. http://www.entrepreneur.com/article/249306
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Sunday, August 30, 2015
What the Color of Your Logo Says About Your Company (Infographic)
The Golden Arches just wouldn't communicate the same thing if they were purple. http://www.entrepreneur.com/article/247783
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Friday, August 28, 2015
CISSP Exam Preparation (Question 310)
(310) Management can expect penetration tests to provide all of the
following EXCEPT
A. identification of security
flaws
B. demonstration of the effects
of the flaws
C. a method to correct the
security flaws.
D. verification of the levels of
existing infiltration resistance
Correct Answer: C
Explanation
Explanation/Reference:
Explanation:
Penetration testing is a set of procedures designed
to test and possibly bypass security controls of a system. Its goal is to
measure an organization's resistance to an attack and to uncover any weaknesses within the
environment...The result of a penetration test is a report given to management
describing the list of vulnerabilities that were identified and the severity
of those vulnerabilities. From here, it is up to management to determine
how the vulnerabilities are dealt with and what countermeasures are implemented. - Shon Harris
All-in-one CISSP Certification Guide pg 837-839
- Muhammad Idham Azhari
Thursday, August 27, 2015
5 Million-Dollar Home-Based Business Ideas You Can Use Today
Teach an online course. Write an ebook. Conceive a product you yourself need. The ideas are out there. Get started! http://www.entrepreneur.com/article/249670
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Wednesday, August 26, 2015
How Online Customer Reviews Help SEO and Drive Sales Growth
But, beware: Bad reviews hurt you more than you think. http://www.entrepreneur.com/article/248176
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Sunday, August 23, 2015
3 Simple Tips to Boost Your SEO on YouTube
You need to have a presence on the second largest search engine. Here are a few pointers to get you started. http://www.entrepreneur.com/article/249482
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Friday, August 21, 2015
CISSP Exam Preparation (Question 309)
(309) Why would an information security policy require that
communications test equipment be controlled?
A. The equipment is susceptible
to damage
B. The equipment can be used to
browse information passing on a network
C. The equipment must always be
available for replacement if necessary
D. The equipment can be used to
reconfigure the network multiplexers
Correct Answer: B
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
How to Overcome 6 Obstacles Facing Every Online Marketer
The Internet offers a vastly bigger marketing opportunity than ever existed. You're not the only one who finds it overwhelming sometimes. http://www.entrepreneur.com/article/249687
- Muhammad Idham Azhari
- Muhammad Idham Azhari
Friday, August 14, 2015
CISSP Exam Preparation (Question 308)
(308) Which of the following statements pertaining to ethical hacking is
incorrect?
A. An organization should use
ethical hackers who do not sell auditing, consulting, hardware, software, firewall,
hosting, and/or networking services
B. Testing should be done
remotely
C. Ethical hacking should not
involve writing to or modifying the target systems
D. Ethical hackers should never
use tools that have potential of exploiting vulnerabilities in the organizations
IT system.
Correct Answer: D
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, August 7, 2015
CISSP Exam Preparation (Question 307)
(307) What tool do you use to determine whether a host is vulnerable to
known attacks?
A. Padded Cells
B. Vulnerability analysis
C. Honey Pots
D. IDS
Correct Answer: B
Explanation
Explanation/Reference:
Explanation:
Vulnerability analysis (also known as vulnerability
assessment) tools test to determine whether a network or host is vulnerable to
known attacks. Vulnerability assessment represents a special case of the
intrusion detection process. The information sources used are system state
attributes and outcomes of attempted attacks. The information sources are
collected by a part of the assessment engine. The timing of analysis is interval-based
or batch-mode, and the type of analysis is misuse detection. This means that
vulnerability assessment systems are essentially batch mode misuse detectors
that operate on system state information and results of specified test
routines.
- Muhammad Idham Azhari
Friday, July 31, 2015
CISSP Exam Preparation (Question 306)
(306) The absence or weakness in a system that may possibly be exploited
is called a(n)?
A. Threat
B. Exposure
C. Vulnerability
D. Risk
Correct Answer: C
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 24, 2015
CISSP Exam Preparation (Question 305)
(305) Which of the following is an advantage of a qualitative over
quantitative risk analysis?
A. It prioritizes the risks and
identifies areas for immediate improvement in addressing the vulnerabilities.
B. It provides specific
quantifiable measurements of the magnitude of the impacts
C. It makes cost-benefit analysis
of recommended controls easier
Correct Answer: A
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 10, 2015
CISSP Exam Preparation (Question 304)
(304) How should a risk be handled when the cost of the countermeasures
outweighs the cost of the risk?
A. Reject the risk
B. Perform another risk analysis
C. Accept the risk
D. Reduce the risk
Correct Answer: C
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 3, 2015
CISSP Exam Preparation (Question 303)
(303) Risk is commonly expressed as a function of the
A. Systems vulnerabilities and
the cost to mitigate.
B. Types of countermeasures
needed and the system's vulnerabilities.
C. Likelihood that the harm will
occur and its potential impact.
D. Computer system-related assets
and their costs.
Correct Answer: C
Explanation
Explanation/Reference:
The likelihood of a threat agent taking advantage of
a vulnerability. A risk is the loss potential, or probability, that a threat
will exploit a vulnerability. - Shon Harris All-in-one CISSP Certification
Guide pg 937
- Muhammad Idham Azhari
Friday, June 26, 2015
CISSP Exam Preparation (Question 302)
(302) Which one of the following risk analysis terms characterizes the
absence or weakness of a risk-reducing safegaurd?
A. Threat
B. Probability
C. Vulnerability
D. Loss expectancy
Correct Answer: C
Explanation
Explanation/Reference:
A weakness in system security procedures, system
design, implementation, internal controls, and so on that could be exploited to
violate system security policy. -Ronald Krutz The CISSP PREP Guide (gold edition)
pg 927
- Muhammad Idham Azhari
Friday, June 19, 2015
CISSP Exam Preparation (Question 301)
(301) When conducting a risk assessment, which one of the following is
NOT an acceptable social engineering practice?
A. Shoulder surfing
B. Misrepresentation
C. Subversion
D. Dumpster diving
Correct Answer: A
Explanation/Reference:
Explanation:
Shoulder Surfing: Attackers can thwart
confidentiality mechanisms by network monitoring, shoulder surfing, stealing
password files, and social engineering. These topics will be address more
in-depth in later chapters, but shoulder surfing is when a person looks over
another person's shoulder and watches keystrokes or data as it appears on the
screen. Social engineering is tricking another person into sharing confidential
information by posing as an authorized individual to that information. Shon
Harris: CISSP Certification pg. 63. Shoulder surfing is not social engineering.
- Muhammad Idham Azhari
Friday, June 12, 2015
CISSP Exam Preparation (Question 300)
(300) A new worm has been released on the Internet. After investigation,
you have not been able to determine if you are at risk of exposure. Management
is concerned as they have heard that a number of their counterparts are being
affected by the worm. How could you determine if you are at risk?
A. Evaluate evolving environment.
B. Contact your anti-virus
vendor.
C. Discuss threat with a peer in
another organization.
D. Wait for notification from an
anti-virus vendor.
Correct Answer: B
Explanation/Reference:
- Muhammad Idham Azhari
Friday, June 5, 2015
CISSP Exam Preparation (Question 299)
(299) Which of the following is not a part of risk analysis?
A. Identify risks
B. Quantify the impact of
potential threats
C. Provide an economic balance
between the impact of the risk and the cost of the associated
countermeasures
D. Choose the best countermeasure
Correct Answer: D
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 29, 2015
CISSP Exam Preparation (Question 298)
(298) Which one of the following is not one of the outcomes of a
vulnerability analysis?
A. Quantative loss assessment
B. Qualitative loss assessment
C. Formal approval of BCP scope
and initiation document
D. Defining critical support
areas
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 22, 2015
CISSP Exam Preparation (Question 297)
(297) Risk analysis is MOST useful when applied during which phase of
the system development process?
A. Project identification
B. Requirements definition
C. System construction
D. Implementation planning
Correct Answer: A
Explanation/Reference:
Reference: pg 684 Shon Harris: All-in-One CISSP
Certification
- Muhammad Idham Azhari
Friday, May 15, 2015
CISSP Exam Preparation (Question 296)
(296) Which of the following is not a compensating measure for access violations?
A. Backups
B. Business continuity planning
C. Insurance
D. Security awareness
Correct Answer: D
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 8, 2015
CISSP Exam Preparation (Question 295)
(295) Which of the following best explains why computerized information
systems frequently fail to meet the needs of users?
A. Inadequate quality assurance
(QA) tools
B. Constantly changing user needs
C. Inadequate user participation
in defining the system's requirements
D. Inadequate project management.
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Thursday, April 30, 2015
CISSP Exam Preparation (Question 294)
(294) Which of the following would be best suited to provide information
during a review of the controls over the process of defining IT service levels?
A. Systems programmer
B. Legal stuff
C. Business unit manager
D. Programmer
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Friday, April 24, 2015
CISSP Exam Preparation (Question 293)
(293) In developing a security awareness program, it is MOST important
to
A. Understand the corporate
culture and how it will affect security.
B. Understand employees
preferences for information security.
C. Know what security awareness
products are available.
D. Identify weakness in line
management support.
Correct Answer: A
Explanation/Reference:
The controls and procedures of a security program
should reflect the nature of the data being
processed...These different types of companies would
also have very different cultures. For a security awareness program to be
effective, these considerations must be understood and the program should be developed
in a fashion that makes sense per environment - Shon Harris All-in-one CISSP Certification
Guide pg 109
- Muhammad Idham Azhari
Friday, April 17, 2015
CISSP Exam Preparation (Question 292)
(292) Which one of the following is the MAIN goal of a security
awareness program when addressing senior management?
A. Provide a vehicle for
communicating security procedures.
B. Provide a clear understanding
of potential risk and exposure.
C. Provide a forum for disclosing
exposure and risk analysis.
D. Provide a forum to communicate
user responsibilities.
Correct Answer: B
Explanation/Reference:
Explanation:
When the Security Officer is addressing Senior
Management, the focus would not be on user
responsibilities, it would be on making sure the
Senior Management have a clear understanding of the risk and
potential liability is Not D: Item D would be correct in a situation where
Senior Management is addressing organizational staff.
- Muhammad Idham Azhari
Subscribe to:
Posts (Atom)


















