Published: March 9, 2020, 5 p.m.

In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam.  His extensive training will cover all of the CISSP domains.

CISSP Exam Questions

Question:  122

What type of reconnaissance attack provides attackers with useful information about the services running on a system?

  1. A) Session hijacking
  2. B) Port scan
  3. C) Dumpster diving
  4. D) IP sweep

Port scan

Port scans reveal the ports associated with services running on a machine and available to the public.

Question:  123

What technology does the Java language use to minimize the threat posed by applets?

  1. A) Confidentiality
  2. B) Encryption
  3. C) Stealth
  4. D) Sandbox



The Java sandbox isolates applets and allows them to run within a protected environment, limiting the effect they may have on the rest of the system.

Question:  124

What is the most effective defense against cross-site scripting attacks?

  1. A) Limiting account privileges
  2. B) Input validation
  3. C) User authentication
  4. D) Encryption

Input validation

Input validation prevents cross-site scripting attacks by limiting user input to a predefined range. This prevents the attacker from including the HTML

