
CISSP Cyber Training Podcast - CISSP Training Program
Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm. Tune in and take the reins of your cybersecurity journey—let’s ride into excellence together! 🚀
All episodes
Best episodes
Seasons
Top 10 CISSP Cyber Training Podcast - CISSP Training Program Episodes
Goodpods has curated a list of the 10 best CISSP Cyber Training Podcast - CISSP Training Program episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to CISSP Cyber Training Podcast - CISSP Training Program for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite CISSP Cyber Training Podcast - CISSP Training Program episode by adding your comments to the episode page.

CCT 235: Practice CISSP Questions - Mastering Security Control Testing (CISSP Domain 6.2)
CISSP Cyber Training Podcast - CISSP Training Program
04/10/25 • 23 min
The collision of artificial intelligence and cybersecurity takes center stage in this episode as we explore how Agentic AI is revolutionizing Security Operations Centers. Moving beyond simple assistant AI or co-pilots, this new generation of autonomous systems proactively investigates alerts, follows structured playbooks, and performs triage at scale—potentially liberating human analysts from the crushing weight of alert fatigue.
For security professionals and organizations struggling with overwhelming SOC alert volumes, this technological advancement offers a glimpse into a future where human expertise can be directed toward high-value analysis while routine investigations happen autonomously. The potential efficiency gains are substantial, though implementation requires careful consideration and perhaps starting with a proof of concept.
Following this forward-looking discussion, we dive deep into CISSP domain 6.2 with fifteen targeted questions covering essential security testing methodologies. From misuse case testing and manual code review to vulnerability assessments and penetration testing, we examine the strengths and limitations of each approach. Learn why manual code review remains superior for detecting race conditions, how behavioral anomaly detection outperforms other methods for identifying lateral movement, and the critical distinctions between various testing approaches.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's security posture, this episode delivers practical insights into both emerging technologies and fundamental security testing principles. Join us to enhance your understanding of how these methodologies can be effectively deployed to protect critical systems and data in increasingly complex environments.
Visit CISSP Cyber Training today to access free practice questions, additional resources, or comprehensive training materials to support your cybersecurity journey.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 234: Mastering Security Control Testing (CISSP Domain 6.2)
CISSP Cyber Training Podcast - CISSP Training Program
04/07/25 • 43 min
Digital signatures are coming to AI models as cybersecurity evolves to meet emerging threats. Google's collaboration with NVIDIA and HiddenLayer demonstrates how traditional security controls must adapt to protect machine learning systems vulnerable to new forms of tampering and exploitation. This essential evolution mirrors the broader need for robust security validation across all systems.
Security control testing forms the foundation of effective cybersecurity governance. Without proper validation, organizations operate on blind faith that their protections actually work. In this deep dive into Domain 6.2 of the CISSP, Sean Gerber breaks down the critical differences between assessments, testing, and audits while exploring practical approaches to vulnerability scanning, penetration testing, and log analysis.
Vulnerability assessments serve as your first line of defense by systematically identifying weaknesses across networks, hosts, applications, and wireless infrastructure. The Common Vulnerability Scoring System helps prioritize remediation efforts, but understanding your architecture remains crucial - a low-scoring vulnerability in a critical system might pose more risk than a high-scoring one in an isolated environment. Meanwhile, penetration testing takes validation further by simulating real-world attacks through carefully structured phases from reconnaissance to exploitation.
As organizations increasingly embrace APIs, ML models, and complex software architectures, security testing must evolve beyond traditional boundaries. Code reviews, interface testing, and compliance checks ensure that security is built into systems from the ground up rather than bolted on afterward. The shift toward "security left" integration aims to catch vulnerabilities earlier in the development lifecycle, reducing both costs and risks.
Ready to master security control testing and prepare for your CISSP certification? Visit CISSPCyberTraining.com to access comprehensive study materials and a step-by-step blueprint designed to help you understand not just the exam content, but the practical application of cybersecurity principles in real-world scenarios.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 040: Manage identification and authentication of people devices and services (D5.2)
CISSP Cyber Training Podcast - CISSP Training Program
05/29/23 • 38 min
Are you ready to up your cybersecurity game? Look no further, as I, Sean Gerber, take you on a deep-dive into the world of identity and access management. Together, we'll explore various authentication methods, such as passwords, tokens, biometrics, and multi-factor authentication, and analyze their strengths and vulnerabilities. We'll also tackle the all-important concept of credential creeping and discuss how to prevent unauthorized access to sensitive data.
But wait, there's more! Identity and access management isn't just about security; it's also about compliance. Join me as we examine the role of IDM in regulatory requirements like GDPR, HIPAA, CMMC, and Chinese Cyber Laws. I'll share expert tips on streamlining user management by creating and removing accounts to ensure the safety and security of your organization. Plus, we'll delve into the challenges of granting and denying access to resources based on privileges, helping you combat credential creeping effectively.
To wrap it all up, I'll reveal the best practices for identity and access management, including crafting clear and comprehensive policies, robust authentication and authorization frameworks, and privileged access management solutions. We won't stop there – I'll also discuss the significance of session and federated identity management, touching on aspects like user authentication, session tracking, session timeout, and session termination. So, don't miss this information-packed episode guaranteed to strengthen both your cybersecurity knowledge and CISSP exam preparation!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
#CISSP #CyberTraining #ExamPreparation #CISSPQuestions #Domain1 #Cybersecurity #Podcast #ShonGerber
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 019: CISSP Exam Questions (007-009)
CISSP Cyber Training Podcast - CISSP Training Program
03/16/23 • 6 min
Shon Gerber from CISSPCyberTraining.com provides you with the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will cover questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
- ISC2 Training Study Guide
Transcript:
...Hey y'all this is Shon Gerber Thanks for listening today But before we get started I wanted to update you on the launch of my CISSP cyber training membership for my listening audience. On March 5th, 2023 I began offering a monthly CISSP membership at 60% off my already low price. This is an introductory offer of $19 a month for the first year. With that insanely inexpensive price you will get all of my CISSP content practice exam questions, all my current and upcoming curated content. And finally m
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 077: Practice CISSP Questions - Risk Indicators, Backup Verification Data for DR and BC Operations (Domain 6)
CISSP Cyber Training Podcast - CISSP Training Program
10/06/23 • 18 min
Ready to step deep into the trenches of cyber security? This episode promises a riveting examination of pertinent cyber security concepts, backed by real-life case studies. First up: a chilling real-world scenario of a Nigerian individual making waves in the news for their involvement in a multi-million dollar business email compromise scheme - an in-depth look at this will make you rethink your transactions! In addition, we shed light on the nitty-gritty of disaster recovery concepts and the invaluable role of a positive control path when transferring money between companies.
Buckle up as we take flight to the intersection of aviation and cybersecurity. Borrowing lessons from aviation debriefing, we delve into how potential issues can be identified and rectified when it comes to cyber threats. We also offer a critical examination of Business Impact Analysis and various data backup systems, aiming to help you arm your organization against potential cyber threats. Whether you're preparing for the CISSP exam or simply looking to fortify your knowledge in the cyber space, this episode is a rich trove of insights!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 092: A Deep Dive into Authorization Mechanisms and Access Control Models for the CISSP Exam (CISSP Domain 5.4)
CISSP Cyber Training Podcast - CISSP Training Program
11/27/23 • 39 min
What happens when ransomware strikes a big corporation like Clorox? Imagine the chaos and the panic that ensues - not to mention, the significant impact on revenue and leadership. That’s where we kick off our conversation with Sean Gerber, who delves deep into the Clorox ransomware attack and why having a strong resiliency plan is imperative. We also shed light on the importance of authorization and discretionary access controls in maintaining organizational security.
We navigate the complex world of role-based access controls (RBAC), discussing how it can efficiently handle access permissions and even prevent fraud within an organization. But it’s not a bed of roses; role explosion and initial setup overhead are just a couple of issues when adopting RBAC. Moving forward, we unpack different types of access controls, their advantages, and challenges - think attribute-based, mandatory, and risk-based controls. You'll be surprised by their impact on enterprise security.
Wrapping up, our attention shifts towards CISSP cyber training and how it bolsters your chances of acing the CISSP exam. We share stories of triumph, tips, and tools to help you succeed. Whether you're a cybersecurity professional or just interested in staying one step ahead of cyber threats, this episode is bursting with insights and discussions that you simply can't ignore. So, forget your regular playlist; it's time to plug into some serious cyber talks!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 098: Understanding APIs and the Security Principles Associated for the CISSP Exam (CISSP Domain 8.5)
CISSP Cyber Training Podcast - CISSP Training Program
12/18/23 • 40 min
Are you ready to unlock the secrets of API security? Prepare to be enlightened, as we tackle the burning issue of cybersecurity, with a special focus on recent hacker attacks targeting US water treatment facilities. Join us in a critical dialogue on fortifying our defenses and the role of cybersecurity education in our communities. Learn how to navigate the complexities of API security, from managing authentication to role-based access and the handling of tokens and API keys.
Brace yourselves for a grand tour of the API ecosystem, where we demystify API gateways and their pivotal role in enhancing security. Discover the intricacies of managing authorized connections, safeguarding against denial of service attacks, and navigating the risks of exposing cloud infrastructure to the internet. We also delve into the importance of robust API usage policies and discuss the pros and cons of IP whitelisting and blacklisting.
To put a cap on our security pilgrimage, we journey into the realm of API security testing practices. Familiarize yourself with various testing methods, the importance of keeping abreast with evolving threats, and the balance of security and functionality. Plus, for those of you preparing for the CISSP exam, we share a wealth of resources to aid in your success. So, gear up for an enriching experience that is sure to bolster your cybersecurity knowledge and equip you to ace the CISSP exam!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 119: Practice CISSP Questions – Integrated Product Team (IPT) and Waterfall, Spiral, Agile, Scrum Development (D8.1.2-8.1.5)
CISSP Cyber Training Podcast - CISSP Training Program
02/29/24 • 15 min
Unlock the secrets to crafting impenetrable software as we delve into Domain 8 of the CISSP exam, where design and architecture reign supreme in the security integration battle. Prepare to have your coding paradigms shifted and your architectural blueprints fortified in this episode, which is nothing short of a cyber-fortification masterclass. We tackle the most critical phase of the SDLC and reveal how a well-laid foundation can make or break your software's defensive capabilities. Whether you're a seasoned professional or just starting, the insights shared here will be the cornerstone of your cyber defense strategy.
This week, we're not just passing along knowledge; we're equipping you with the tools to revolutionize your approach to software development and security. We unpack SAST techniques, emphasizing the importance of meticulous code reviews in sniffing out potential vulnerabilities. Additionally, we demystify OWASP, providing a treasure trove of resources for web application security that's ripe for the taking. And if you're intrigued by the concept of integrated product teams, you'll find our exploration into their role in software development to be invaluable. By the end of this podcast, you'll understand why these teams are integral to fostering collaboration and innovation in the pursuit of unbreakable software. Join us on this journey to elevate your CISSP readiness and cybersecurity prowess.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 100: CISSP Certification's Impact on Cybersecurity Salaries and Career Advancement
CISSP Cyber Training Podcast - CISSP Training Program
12/25/23 • 25 min
Unlock the true potential of your cybersecurity career with insights on how CISSP certification can amplify your earning power—beyond just a fancy title. As your guide, Sean Gerber, I'm taking you through a deep dive into the world of cybersecurity salaries, where your locale plays as big a role as your skills. From the bustling markets of Asia Pacific to the economic hubs in North America, we're mapping out the financial landscape and the real impact of cost of living on what you pocket. You'll learn why it's not just about having that CISSP badge, but also the years of experience you bring to the table that define your paycheck in roles across the spectrum, from security analysts to the coveted seat of a CISO.
Brace yourselves for an honest take on the CISSP journey, with the hard truths about the challenging pass rates and the significant investment of both time and money needed. Sharing from my own trials and tribulations with the exam, I shed light on the relentless preparation needed to conquer this beast and the strategic moves to make it worthwhile. But it's not all about the grind—this episode also highlights how this sought-after certification can unlock doors, bringing moonlighting opportunities into your grasp and adding a competitive edge to your resume. Join me as we unpack the rewards that come with the CISSP's demanding pursuit, and the professional growth that justifies your "sweat equity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!

CCT 128: CISSP Mastery - Deprovisioning and Role Definitions (D5.5.2-3)
CISSP Cyber Training Podcast - CISSP Training Program
04/01/24 • 40 min
Could your company's board benefit from cybersecurity expertise? Discover the untold impact security professionals can make in risk mitigation and financial stability. This week on the CISSP Cyber Training Podcast, I, Sean Gerber, navigate the critical intersection of cybersecurity and corporate governance, underscoring a need for expertise that's often overlooked. We dissect the lifecycle of role management, from the precise art of onboarding to the essential processes of deprovisioning and offboarding. Ensuring your organization's digital fortress is impenetrable requires immediate action and smart tools, which we'll cover in detail.
Struggle with managing permissions in your organization? You're not alone. We'll break down Role-Based Access Control, a system that not only fortifies your security but streamlines your access management too. By understanding the risks of credential creep and the benefits of roles defined by job functions, you'll see how a robust RBAC system can prevent conflicts of interest and align with evolving business processes. And for those in the trenches of cybersecurity, I'll outline how the synergy between compliance and security teams forms the backbone of a solid role management plan.
Finally, we turn our focus to the CISSP exam, providing a beacon for those charting a course through the vast sea of cybersecurity knowledge. With strategic guidance and essential resources, I'll steer you towards not just passing the exam, but mastering it. Ensure you're equipped with the right identity and access management tools like single sign-on, multi-factor authentication, and Identity Governance and Administration. Remember, your journey doesn't end with certification. Stay connected for continued support as we build your cybersecurity expertise into a powerhouse skill set for any organization.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Show more best episodes

Show more best episodes
FAQ
How many episodes does CISSP Cyber Training Podcast - CISSP Training Program have?
CISSP Cyber Training Podcast - CISSP Training Program currently has 237 episodes available.
What topics does CISSP Cyber Training Podcast - CISSP Training Program cover?
The podcast is about News, Tech News, Podcasts, Technology, Cyber Security, Cissp and Cybersecurity.
What is the most popular episode on CISSP Cyber Training Podcast - CISSP Training Program?
The episode title 'CCT 049: CISSP Exam Questions (Domains 1-8)' is the most popular.
What is the average episode length on CISSP Cyber Training Podcast - CISSP Training Program?
The average episode length on CISSP Cyber Training Podcast - CISSP Training Program is 27 minutes.
How often are episodes of CISSP Cyber Training Podcast - CISSP Training Program released?
Episodes of CISSP Cyber Training Podcast - CISSP Training Program are typically released every 3 days, 2 hours.
When was the first episode of CISSP Cyber Training Podcast - CISSP Training Program?
The first episode of CISSP Cyber Training Podcast - CISSP Training Program was released on Jan 30, 2023.
Show more FAQ

Show more FAQ