Exam AZ-500: Microsoft Azure Security Technologies – Exam Review
CISSP-Esp: Dominio 6 Evaluación y pruebas de seguridad – Preguntas y Respuestas
CISSP Practice Exams
This fully updated self-study guide offers complete coverage of all eight Certified Information Systems Security Professional exam domains developed by the International Information Systems Security Certification Consortium (ISC)2®. To reinforce important skills and facilitate retention, every question is accompanied by in-depth explanations for both correct and incorrect answers. Designed to help you pass the test with ease, this book is the ideal companion to the bestselling CISSP All-in-One Exam Guide.
Covers all 8 CISSP® domains:
•Security and risk management
•Asset security
•Security architecture and engineering
•Communication and network security
•Identity and access management
•Security assessment and testing
•Security operations
•Software development security
CISSP Dominio 4 – Comunicacin y Seguridad de la Red
CISSP Dominio 5 – Gestion de Identidad y Accesso – Preguntas y Respuestas
CISSP – preguntas para practicar – Pregunta101
Exchange Server attacks: Run this Microsoft malware scanner now, CISA tells government agencies
The Microsoft scanner can use up a lot of a server’s processing capacity, so CISA recommends running the scan during off-peak hours.
"By 12:00 pm Eastern Daylight Time on Monday, April 5, 2021, download and run the current version of Microsoft Safety Scanner (MSERT) in Full Scan mode and report results to CISA using the provided reporting template," it notes.
Critical F5 BIG-IP Bug Under Active Attacks After PoC Exploit Posted Online
The flaws affect BIG-IP versions 11.6 or 12.x and newer, with a critical remote code execution (CVE-2021-22986) also impacting BIG-IQ versions 6.x and 7.x. CVE-2021-22986 (CVSS score: 9.8) is notable for the fact that it’s an unauthenticated, remote command execution vulnerability affecting the iControl REST interface, allowing an attacker to execute arbitrary system commands, create or delete files, and disable services without the need for any authentication.
https://thehackernews.com/2021/03/latest-f5-big-ip-bug-under-active.html
Burnt by SolarWinds attack? US releases tool for post-compromise detection
CISA says CHIRP currently looks for:
- The presence of malware identified by security researchers as TEARDROP and RAINDROP;
- Credential dumping certificate pulls;
- Certain persistence mechanisms identified as associated with this campaign;
- System, network, and M365 enumeration; and
- Known observable indicators of lateral movement.
CHIRP is available on GitHub as a compiled executable or as a Python script.
FireEye in January also released a free tool on GitHub called Azure AD Investigator.
Burnt by SolarWinds attack? US releases tool for post-compromise detection | ZDNet




