Skip to content
PodcastsCoursesCISSP Cyber Training Podcast - CISSP Training Program

CISSP Cyber Training Podcast - CISSP Training Program

Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur
CISSP Cyber Training Podcast - CISSP Training Program
Latest episode

377 episodes

  • CISSP Cyber Training Podcast - CISSP Training Program

    CCT 373: An AI Agent Was Told No and Got In Anyway (CISSP Domain 6.2)

    05/10/2026 | 37 mins.
    Send us Fan Mail
    An AI agent gets blocked by access controls, then calmly finds another way in anyway and that is the wake-up call. I use a recent Hacker News story about an automated agent bypassing an Australian government health portal to dig into what CISSP Domain 6.2 is really testing: not your ability to recite a list of techniques, but your ability to manage authorization, scope, and rules of engagement so a “test” does not turn into an intrusion.

    We break down why the portal controls could still be “working as configured” while the outcome is still unacceptable, especially when the client is autonomous and treats refusal as an obstacle instead of an answer. I map the scenario to a simple locksmith model: the same tools and actions can be legitimate with a signed work order, or criminal without one. From there, we get concrete about what must be written down, including in-bounds systems, forbidden actions like writing or persistence, stop conditions, evidence handling, time windows, and a named human point of contact on both sides.

    Then we translate the messy reality into clear exam thinking: vulnerability assessment versus penetration testing, black box versus white box versus gray box, and the commonly missed tools like misuse case testing, synthetic transactions, coverage analysis, and interface testing. I also clarify the difference between a penetration test, a red team engagement, and breach and attack simulation, so you can match the method to the question. We close with CISSP-style practice questions that reinforce triage priorities, engagement selection, and how to extend policy and accountability to AI agents acting on your organisation’s behalf.

    If you want more Domain 6.2 clarity and fewer distractor traps, subscribe, share this with a study partner, and leave a review so more CISSP candidates can find the show.
    Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
    Join now and start your journey toward CISSP mastery today!
  • CISSP Cyber Training Podcast - CISSP Training Program

    CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)

    28/09/2026 | 32 mins.
    Send us Fan Mail
    A stolen password is annoying. A stolen session token can be invisible, valid, and instantly profitable. Today we dig into a real warning sign from Okta threat intelligence: infostealer malware lifted live session tokens from browsers, and thousands of Google sessions were still working weeks later. No MFA prompt. No brute force. Just a legitimate session replayed by the wrong person, with real dollar damage through unauthorized usage and credits.

    We use that story to sharpen the CISSP Domain 5.6 mindset around implementing authentication systems and, more importantly, validating tokens after sign-in. I walk through why authentication and token validation are different security functions with different “owners,” why forcing password resets does not invalidate an attacker’s existing session, and what a token signature does and does not prove. Then we get practical: audience claim checks, expiration and token lifetime ceilings, scope validation, and why “skipping the audience check breaks nothing in testing” is exactly how breaches scale.

    We also cover the controls that shrink risk when you cannot reliably detect theft: short access token lifetimes, narrow scoping to limit blast radius, hardware-backed signing key storage, and automated key rotation with defined crypto periods. To lock it in, we run through four CISSP-style questions and explain the traps so you can answer like a risk-focused manager, not a spec reciter.

    Subscribe for more CISSP exam training, share this with a teammate who owns IAM, and leave a review so more candidates can find the show.
    Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
    Join now and start your journey toward CISSP mastery today!
  • CISSP Cyber Training Podcast - CISSP Training Program

    CCT 371: Secure Communication Channels and Who Is Really On Your Call (Domain 4.3)

    21/09/2026 | 30 mins.
    Send us Fan Mail
    One video hotline feels like a single, simple conversation until you trace the call path and realise there may be seven companies involved in making it work. That’s the spark for this training-focused breakdown of CISSP Domain 4.3 secure communication channels, using the viral AI “actress hotline” story to show how modern voice and video collaboration really behaves behind the curtain.

    We start with a practical analogy: you think you’re transacting with the waiter, but your meal passes through a hidden chain of people you never met. The same thing happens with telephony, video conferencing, contact centres, telehealth platforms, transcription tools, AI response generation, and cloud infrastructure. Even when every vendor is legitimate, contracted, and disclosed, your security model can fail if it only accounts for the one company you can see.

    From there, we get concrete about what CISSP candidates are tested on: who can join a call, what services are attached (recording, transcription, analytics), what survives after the call, and where trust boundaries actually sit. We also tackle a classic trap: encryption in transit can stop interception, but it does not prevent authorised intermediaries like transcription providers or model services from decrypting and processing content. Finally, we connect the dots to retention “clocks” and transborder data flows, including how Domain 4 channel design intersects with Domain 1 legal transfer mechanisms and accountability.

    If you’re studying for the CISSP exam or building a real-world secure communications programme, you’ll leave with a clearer mental model and a set of exam-style questions you can use right away. Subscribe, share this with a fellow CISSP candidate, and leave a review so more security pros can find the show.
    Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
    Join now and start your journey toward CISSP mastery today!
  • CISSP Cyber Training Podcast - CISSP Training Program

    CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

    14/09/2026 | 38 mins.
    Send us Fan Mail
    A compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to what’s happening with FIPS 140 validations: your VPN can keep encrypting, your database can keep protecting data, and yet an assessor can still mark you down because “working” is not the same as “validated.”

    We walk through the practical CISSP Domain 3 lesson behind the noise: the difference between an algorithm claim (we use AES-256), a configuration claim (we run in FIPS mode), and an evidence claim (we hold an active FIPS 140 validation on the CMVP list). With FIPS 140-2 certificates moving to historical status and FIPS 140-3 testing queues stretching beyond 500 days, the manager move is not wishful thinking. It’s documenting the gap, treating it as risk, and getting formal risk acceptance with executive sign-off plus a real remediation plan, especially if you’re facing CMMC or customer security assessments.

    From there we connect the dots across cryptographic life cycle management, cryptographic agility, and the real places crypto fails: key management and implementation. We cover HSM storage, rotation, dual control versus split knowledge, PKI revocation choices (CRL, OCSP, OCSP stapling), common cryptanalysis categories, and why side-channel and fault-injection attacks hit modules rather than “the math.” We then get clear on quantum risk, harvest now decrypt later, and what NIST’s post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) mean for your migration plan starting with a cryptographic inventory.

    Subscribe for more CISSP exam-ready training, share this with a teammate who owns compliance evidence, and leave a review if it helped. What would fail first in your environment: the crypto itself, or the proof you can show an auditor?
    Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
    Join now and start your journey toward CISSP mastery today!
  • CISSP Cyber Training Podcast - CISSP Training Program

    CCT 369: Security Models Demystified - CISSP Domain 3.2 (Replay of CCT 278)

    07/09/2026 | 31 mins.
    Send us Fan Mail
    🔁 REPLAY — this episode originally aired as CCT 278 in September 2025.

    I'm heads-down finishing a Domain 3 cryptography episode, so I'm re-running one
    of the strongest episodes in the archive rather than shipping something thin.

    If you're newer to the show, you haven't heard this one. And if you're studying
    Domain 3 right now the timing works in your favor — security models are the
    foundation the rest of the domain sits on, and next week's episode picks up in
    the same domain.

    New material next Monday.

    ---

    Security models represent some of the most difficult concepts for CISSP exam
    candidates to master, yet they form the foundation of implementing and
    understanding security controls. This episode breaks down Domain 3.2's security
    models using plain language and practical examples.

    The episode opens with analysis of the TransUnion data breach affecting 4.4
    million individuals, demonstrating why proper security architecture matters. It
    then explores the Trusted Computing Base (TCB) — the foundation for secure code —
    covering key components like the Security Kernel, Reference Monitor, Trusted
    Path, and TCB Boundary.

    The core focus examines the eight major security models essential for exam
    preparation. These include Bell-LaPadula's confidentiality-focused "no read up,
    no write down" principle, Biba's integrity-centered approach, Clark-Wilson's
    business integrity enforcement through duty separation, and Brewer-Nash's
    conflict-of-interest prevention. Additional models addressing specific security
    concerns are also covered.

    The episode concludes with exam preparation guidance, highlighting which models
    deserve priority study attention.

    ⚠️ Since this is a replay: the TransUnion breach discussed at the top is from
    2025. The Domain 3.2 material is unchanged and still current.

    Ready to stop guessing on Domain 3?
    Accelerator $19/mo · Pro $39/mo · Sprint Cohort
    https://www.cisspcybertraining.com
    Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox!  Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
    Join now and start your journey toward CISSP mastery today!
More Courses podcasts
About CISSP Cyber Training Podcast - CISSP Training Program
Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm. Tune in and take the reins of your cybersecurity journey—let’s ride into excellence together! 🚀
Podcast website

Listen to CISSP Cyber Training Podcast - CISSP Training Program, Australian Aboriginal History and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features