<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material in CSSLP Study Group</title>
    <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76836#M220</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm just &lt;FONT size="3"&gt;completing the "Applied Scenarios" section of the course material.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;While I was completing "&lt;/FONT&gt;&lt;FONT size="3"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Applied Scenario: Building Custom Security Tools (Domain 7)&lt;/STRONG&gt;", I found the following issues at the second code example (send an HTTP GET request):&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT size="3"&gt;&lt;SPAN&gt;The material does not mention to install the following additional Python modules with pip&lt;/SPAN&gt;&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;requests&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;bs4&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The source code is incorrect or uses a syntax that is obsolete. See the corrected code below (I tried to include my source code and the script's output as TEXT but your system gave the following message - "&lt;EM&gt;Your post has been changed because invalid HTML was found in the message body. The invalid HTML has been removed. Please review the message and submit the message when you are satisfied.&lt;/EM&gt;") - So I stayed at the screenshots:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1738662845325.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9407i36A673983C9DBEB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1738662845325.png" alt="norbertmurzsa_0-1738662845325.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;End its output looks like the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = = &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_1-1738663085823.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9408i7DB32BB006FDCB07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_1-1738663085823.png" alt="norbertmurzsa_1-1738663085823.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sincerely.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2025 10:00:24 GMT</pubDate>
    <dc:creator>norbertmurzsa</dc:creator>
    <dc:date>2025-02-04T10:00:24Z</dc:date>
    <item>
      <title>Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/74880#M209</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've been preparing for the CSSLP exam for a while and would like to share some suggestions and comments about the material. I probably will not be able to summarize all of my suggestions in a single post, but am hoping that some of these will be addressed in the future to make the self-study material even more easily understood, comprehended and adopted.Unfortunately, I did not find a proper label for making suggestions/recommendations for content improvements. Hopefully, this also will be available sooner or later (or I may just use an incorrect place to do this - thank you for your understanding and patience).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From now on any of my suggestions will use the following structure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Purpose&lt;/STRONG&gt;: Why this suggestion is made.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current state&lt;/STRONG&gt;: What the CSSLP material includes to help the area described under 'Purpose'&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Suggestion&lt;/STRONG&gt;: Further improvements that can help the content even more accurate and optimized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But first of all, I would like to thank ISC2 for creating the self-paced material and making available for the community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;= = =&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Purpose&lt;/STRONG&gt;: To receive more accurante feedback about the exam preparation material.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current state&lt;/STRONG&gt;: The pages of the Domain Catalog at &lt;A href="https://isc2.obrizum.io/org/csslp" target="_blank" rel="noopener"&gt;https://isc2.obrizum.io/org/csslp&lt;/A&gt; include a "Did you understand the content?" question at the bottom of all pages where the candidate can rate her/his understanding about the presented materal of the page in percentage (e.g.: 80%).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Suggestion&lt;/STRONG&gt;: While the percentage can provide some feedback to the content developers, it does not help about the exact areas where improvements may be recommended. I recommend adding a "Help us with your feedback" section on every page. This makes sure that the candidate has a fresh mind and idea about s/he found inappropriate or hard to understand, and a timely suggestion can be made to improve the content.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 01:41:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/74880#M209</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2024-11-03T01:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75300#M210</link>
      <description>&lt;P&gt;Durin&lt;FONT face="arial,helvetica,sans-serif"&gt;g the surve&lt;/FONT&gt;y questions in Domain 5 I found the following question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is the built-in approach for session management &lt;U&gt;preferred&lt;/U&gt; over custom implementations?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Custom implementations are easier to maintain&lt;/LI&gt;&lt;LI&gt;Custom implementations are always more secure&lt;/LI&gt;&lt;LI&gt;Built-in approaches are technology-specific&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;Built-in approaches may not be free of vulnerabilities&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;According to the test the GREEN highlighted answer is the right one.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;This is definitely incorrect. This statement may be true even for the built-in approaches, but this is not the reason why the built-in solution is the preferred option.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;The correct answer here would probaly have been&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;- "Built-in implementations are always considered more secure" or&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;- "Built-in implementations have been thoroughly tested by various independend parties."&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 10:37:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75300#M210</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2024-11-25T10:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75301#M211</link>
      <description>&lt;P&gt;Durin&lt;FONT face="arial,helvetica,sans-serif"&gt;g the surve&lt;/FONT&gt;y questions in Domain 7 I found the following question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What additional information should vulnerability notifications provide?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Descriptions of historical vulnerabilities&lt;/LI&gt;&lt;LI&gt;Information about conflicting goals of stakeholders&lt;/LI&gt;&lt;LI&gt;Details about the software development team&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;Anticipated timelines for software development&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;While this may seem true with some further context, it lacks the full picture for this answer as:&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;The notfications should also identify &lt;U&gt;any planned longer-term remediation&lt;/U&gt; to be provided later by the software development (or maintenance) team, with &lt;U&gt;anticipated timelines for delivery/implementation&lt;/U&gt;.&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without the first underlined item, using the second underlined item is just misleading.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 11:17:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75301#M211</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2024-11-25T11:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75302#M212</link>
      <description>&lt;P&gt;Durin&lt;FONT face="arial,helvetica,sans-serif"&gt;g the surve&lt;/FONT&gt;y questions in Domain 7 I found the following question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which of the following statements accurately describes the security measures taken in the iOS and Android platforms?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;iOS and Android platforms do not implement any security measures for app protection&lt;/LI&gt;&lt;LI&gt;Both iOS and Android use sandboxing mechanisms&lt;/LI&gt;&lt;LI&gt;Both iOS and Android platforms rely on code signing to verify the integrity and authenticity of apps&lt;/LI&gt;&lt;LI&gt;Android apps have a sandboxing mechanism, while iOS apps do not have any restrictions on accessing user data&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I selected #2 and #3 but I got an error message that my selections were incorrect.&lt;/P&gt;&lt;P&gt;However:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Taken from the exam preparation material:&lt;BR /&gt;"The only executable code that iOS will allow apps to run must be signed with an Apple-issued certificate."&lt;BR /&gt;"Like iOS, Android sandboxes its apps."&lt;BR /&gt;Taken from Google:&lt;BR /&gt;"...Android apps are signed with a private key. To ensure that app updates are trustworthy, every private key has an associated public certificate that devices and services use to verify that the app update is from the same source. Devices only accept updates when its signature matches the installed app's signature."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So then, both platform uses sandboxing and code signing.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 00:54:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/75302#M212</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-01-27T00:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76593#M217</link>
      <description>&lt;P&gt;During the survey questions in Domain 8 I found the following question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which THREE of the following are recommended protocols for transferring files securely in the supply chain?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Secure File Transfer Protocol (SFTP)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Telnet&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Secure Shell (SSH) file transfer&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;File Transfer Protocol (FTP)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Though, I generally don't consider FTP (Answer #4) as a secure file transfer protocol, I marked it as correct to meet the expected THREE correct answers, and because it include an additional secure extension to be used over TLS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to use THREE correct answers in this question, I recommend updating it as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which THREE of the following are recommended protocols for transferring files securely in the supply chain?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Secure File Transfer Protocol (SFTP)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Telnet&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Secure Copy Protocol (SCP) in SSH protocol&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;File Transfer Protocol Secure (FTPs)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 23:45:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76593#M217</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-01-26T23:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76595#M218</link>
      <description>&lt;P&gt;During the survey questions in Domain 8 I found the following question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is a characteristic of more sophisticated software supply chain attacks?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Targeting patch sites with malware files&lt;/LI&gt;&lt;LI&gt;Dependency on typical customers for detection&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#FF0000"&gt;Introduction of malware &lt;U&gt;&lt;STRONG&gt;after&lt;/STRONG&gt;&lt;/U&gt; code compilation and signing&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Accidental insertion of malware into source code&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I think you probably wanted to say here that "&lt;FONT color="#339966"&gt;introduce malicious logic into the source code &lt;U&gt;&lt;STRONG&gt;prior to&lt;/STRONG&gt;&lt;/U&gt; the code being digitally signed&lt;/FONT&gt;". When the code has compiled and digitally signed, adding a malware to the binary code can be easily detected by checking the digital signature of the product.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 00:53:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76595#M218</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-01-27T00:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76833#M219</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm just completing the "Applied Scenarios" section of the course material.&lt;/P&gt;&lt;P&gt;I think the content is generally good.&lt;/P&gt;&lt;P&gt;Some notes that may help the people who complete this online course:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The offered source codes should be in TEXT windows instead of image files. This helps the candidate to copy and paste the codes quickly and run them. Some codes's syntax seems incorrect.&lt;/LI&gt;&lt;LI&gt;It would be good if the included code examples have description (what the code does). This mostly is self explanatory, but for some example, I'm not sure about the intention of the code comparing it to the previous example (e.g.: there is nothing new between example-1 and example-2)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;thanks for considering the above.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 09:18:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76833#M219</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-04T09:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76836#M220</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm just &lt;FONT size="3"&gt;completing the "Applied Scenarios" section of the course material.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;While I was completing "&lt;/FONT&gt;&lt;FONT size="3"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Applied Scenario: Building Custom Security Tools (Domain 7)&lt;/STRONG&gt;", I found the following issues at the second code example (send an HTTP GET request):&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT size="3"&gt;&lt;SPAN&gt;The material does not mention to install the following additional Python modules with pip&lt;/SPAN&gt;&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;requests&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;bs4&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The source code is incorrect or uses a syntax that is obsolete. See the corrected code below (I tried to include my source code and the script's output as TEXT but your system gave the following message - "&lt;EM&gt;Your post has been changed because invalid HTML was found in the message body. The invalid HTML has been removed. Please review the message and submit the message when you are satisfied.&lt;/EM&gt;") - So I stayed at the screenshots:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1738662845325.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9407i36A673983C9DBEB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1738662845325.png" alt="norbertmurzsa_0-1738662845325.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;End its output looks like the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = = &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_1-1738663085823.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9408i7DB32BB006FDCB07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_1-1738663085823.png" alt="norbertmurzsa_1-1738663085823.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;= = =&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sincerely.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 10:00:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76836#M220</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-04T10:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76878#M221</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm just wrapping up my preparation using the Official ISC2 CSSLP Self-Paced Material.&lt;/P&gt;&lt;P&gt;What I found was that the material at &lt;A href="https://isc2.obrizum.io" target="_blank"&gt;https://isc2.obrizum.io&lt;/A&gt; occasionally forgets the completed materials and re-marks them as "Incomplete".&lt;/P&gt;&lt;P&gt;For example the reviewed flashcards marked by a "Restart" button, while the flashcards that have not opened yet marked by a "Start" button. Even if I reviewed all of them the Obrizum.io app remarks them as unopened ones and reset the Completion level of the material from 100% back to 40-50-60-ish percentage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest to review how the app stores the time stamps of the completed materials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Norbert&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 05:35:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76878#M221</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-06T05:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76955#M222</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Purpose:&lt;/STRONG&gt; To ensure clarity and fairness at the CSSLP training's multi-choice questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current State:&lt;/STRONG&gt; The existing Official ISC2 CSSLP Self-Paced training material consists of multiple-choice questions designed to aid in studying for the official ISC2 CSSLP exam. However, each question includes the statement: "You can select one or more answers," which is often misleading.&lt;/P&gt;&lt;P&gt;In contrast, the Official ISC2 Exam Question Developer Workshops use a more effective approach, requiring candidates to choose the single BEST answer that accurately addresses the question.&lt;/P&gt;&lt;P&gt;This inconsistency in question formatting leads candidates to mistakenly assume they must ALWAYS select more than one answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Suggestion:&lt;/STRONG&gt; To ensure clarity and fairness, the exam material should explicitly indicate whether a question has a single correct answer or multiple correct answers, reducing confusion and aligning with ethical exam practices.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2025 01:58:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/76955#M222</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-09T01:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77370#M227</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1553654991"&gt;@norbertmurzsa&lt;/a&gt;&amp;nbsp;Sorry I did not see your original posts.&amp;nbsp; They are very detailed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, they may have also been missed by the folks who can do something to correct the issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/720618667"&gt;@mariatirado&lt;/a&gt;&amp;nbsp;I am not sure who this should go to but are you able to forward this chain to the correct folks internally?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 16:18:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77370#M227</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-02-25T16:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77392#M229</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I'm just finalizing my study and will book an exam very soon.&lt;/P&gt;&lt;P&gt;However, in the meantime I would like to redo the two lowest perfomed chapters' surveys for practising and further improvement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that even if my license is still valid until the end of March 2025, the Official ISC2 CSSLP Online Self-Paced Training does not let me to redo the chapter end's surveys (practice questions) again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HOME-&amp;gt; Domain #$NUMBER -&amp;gt; View -&amp;gt; Domain Catalog -&amp;gt; Survey -&amp;gt; Start -&amp;gt; End of the Content Catalog -&amp;gt; Click here for assessment -&amp;gt; ...and here it only ask about my "Overall Satisfaction" but &lt;U&gt;there is no way to redo a previously (one time completed) survey&lt;/U&gt;!... OK. I revoke it. After giving feedback about the training byanswering 5-6 question, it actually let me to redo a survey (practice questions).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I think people with less temper probably gives up trying this after the first of second "How satisfied are you with the training material?" Questions...if this comes instead of the survey they expect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please fix this.&lt;/P&gt;&lt;P&gt;N&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 10:33:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77392#M229</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-26T10:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77394#M230</link>
      <description>&lt;P&gt;I redo some past completed Domains' Survey (practice questions) and I found the following incorrect stem at Domain 2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is monitored to ensure that organization-wide operations remain within an acceptable level of risk?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Security architecture and security program&lt;/LI&gt;&lt;LI&gt;Security controls only&lt;/LI&gt;&lt;LI&gt;ISCM strategy&lt;/LI&gt;&lt;LI&gt;Changes in system development&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I select one answer, then two, then three, then all the four.&lt;/P&gt;&lt;P&gt;Unfortunately, the "Check" button always remains inactive. It does not do anything when I click on it. So now, I stack here. (second question of the Survey).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1740566781754.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9476i326B78E47AF7AD28/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1740566781754.png" alt="norbertmurzsa_0-1740566781754.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please fix this.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 10:47:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77394#M230</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-26T10:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77397#M233</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;OK. I need to admit, I wasn't right.&lt;/P&gt;&lt;P&gt;The Check button only becomes available if at least one "Confidence rate" is set to more than 0%.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 Feb 2025 10:56:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77397#M233</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-26T10:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77400#M234</link>
      <description>&lt;P&gt;When I try to redo an earlier completed Domain's survey questions, after completing a few questions (3-4), the system drop me out to the "You Successfully Completed this Survey" page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luckily, the "Continue Learning" takes me back to the Survey to continue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1740567715593.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9477i60D2E1FC83AAC1FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1740567715593.png" alt="norbertmurzsa_0-1740567715593.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Just a note that the system says I completed everything even if only 74% of the Content was covered.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_1-1740567764451.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9478iE5B0B77940B1840E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_1-1740567764451.png" alt="norbertmurzsa_1-1740567764451.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I think both should show 100% to announce the completion of the Domain.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 11:03:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77400#M234</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-02-26T11:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77542#M235</link>
      <description>&lt;P&gt;During the survey questions in Domain 2 I found the following obsolete question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the core business functions of SAMM&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Governance, Construction, Verification, and Operation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;Development, Implementation, Review, and Deployment&lt;/LI&gt;&lt;LI&gt;Strategy, Compliance, Training, and Testing&lt;/LI&gt;&lt;LI&gt;Assessment, Planning, Execution, and Monitoring&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the current OWASP Software Assurance Maturity Model (SAMM) includes five (5) business function now that are: &lt;STRONG&gt;Governance, Design, Implementation, Verification and Operations&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 10:33:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77542#M235</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-03-03T10:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77919#M236</link>
      <description>&lt;P&gt;I'm currently going through the full practice test again and agin until it let me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Unfortunately, the application does not show my progress of how much percentage I completed and remains.&lt;/LI&gt;&lt;LI&gt;When giving an incorrect answer, the survey does not take me to the relevant section to show the right answer either.&lt;/LI&gt;&lt;LI&gt;It shows the current Domain though but I think it should offer more flexible user experience.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1741992223492.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9527i68254BBA1ECECA86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1741992223492.png" alt="norbertmurzsa_0-1741992223492.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 22:44:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/77919#M236</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-03-14T22:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/78115#M238</link>
      <description>&lt;P&gt;I have found the following survey question at Domain #2 which seems to be incorrect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does an adaptive software development approach differ from the Waterfall model?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;FONT color="#FF00FF"&gt;Waterfall&lt;/FONT&gt; relies on &lt;FONT color="#FF0000"&gt;short iterations&lt;/FONT&gt;, while adaptive deconstructs the project into small components&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;Adaptive uses unfamiliar territories, uncertain outcomes, and short time-boxed iterations&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#FF00FF"&gt;Waterfall&lt;/FONT&gt; is characterized by &lt;FONT color="#FF0000"&gt;short time-boxed iterations&lt;/FONT&gt;, while adaptive uses long development iterations&lt;/LI&gt;&lt;LI&gt;Adaptive relies on long development iterations, while &lt;FONT color="#FF00FF"&gt;Waterfall&lt;/FONT&gt; uses &lt;FONT color="#FF0000"&gt;short iterations&lt;/FONT&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;Waterfall&lt;/FONT&gt; does not do or rely on &lt;FONT color="#FF0000"&gt;short iterations&lt;/FONT&gt;, or &lt;FONT color="#FF0000"&gt;short time-boxed iteratons&lt;FONT color="#000000"&gt;, so&lt;/FONT&gt;&lt;FONT color="#000000"&gt; then we can remove A1, A3 and A4 from the list and remains A2 as CORRECT and it is true indeed.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;However, the system does not accept this answer as CORRECT.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="norbertmurzsa_0-1742605604266.png" style="width: 1346px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9548i9AE19A1DC6322E3D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="norbertmurzsa_0-1742605604266.png" alt="norbertmurzsa_0-1742605604266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Can you please have a look at what the root cause here is? Thanks.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Mar 2025 01:06:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/78115#M238</guid>
      <dc:creator>norbertmurzsa</dc:creator>
      <dc:date>2025-03-22T01:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestions and Comments - Official ISC2 CSSLP Self-Paced Material</title>
      <link>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/81504#M264</link>
      <description>I found the same issue.</description>
      <pubDate>Tue, 17 Jun 2025 20:32:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CSSLP-Study-Group/Suggestions-and-Comments-Official-ISC2-CSSLP-Self-Paced-Material/m-p/81504#M264</guid>
      <dc:creator>H508339</dc:creator>
      <dc:date>2025-06-17T20:32:02Z</dc:date>
    </item>
  </channel>
</rss>

