
Outline the 2021 ISC squared SSCP exam outline, detailing a 125-question, three-hour exam across seven domains, including a cryptography domain, with 700/1000 passing, and unscored questions.
Explore compliance with codes of ethics, including the ISC Squared code of ethics and organizational codes, understand the hierarchy of the four canons, and apply them to exam questions.
Explore core security concepts, including the CIA triad of confidentiality, integrity, and availability, alongside accountability, privacy, non-repudiation, least privilege, and segregation of duties.
Identify and implement security controls across technical, physical, and administrative domains, and perform ongoing compliance assessments and audits of policies, standards, baselines, and procedures.
Document and maintain functional security controls—deterrent, preventive, detective, corrective, and compensating—covering administrative, physical, or logical domains, with examples and flexible categorizations.
Learn to manage the asset lifecycle for hardware, software, and data from policy to disposal. Explore procurement, licensing, inventory, security in contracts, audits, archiving, retention, and secure destruction.
Explore the change management lifecycle, from board approval and risk analysis to testing, production deployment, and secure disposal, with emphasis on configuration management, asset inventories, baselines, and automation.
Implement security awareness and training by addressing social engineering and phishing. Choose effective delivery methods such as self-paced online, live training, or gamification and conduct content reviews and assessments.
Collaborate with physical security operations to implement defense in depth through layered controls, badges, and two-person integrity, while managing data centers, visitors, and secure facility design.
Explore domain one review, identify assets, classify controls as deterrent, preventive, or detective, differentiate intellectual property, apply two-person integrity, and align data retention with applicable laws.
Implement and maintain authentication methods, including single and multifactor authentication and single sign-on with Active Directory Federation Services, Open ID Connect, OAuth, and SAML, plus device authentication and access controls.
Examine inter-network trust architectures, from one-way to two-way and transitive trusts, with intranets, extranets, and the internet, and apply zero trust principles with encryption for third-party connections.
Participate in the identity management lifecycle from proofing to provisioning, maintenance, and deprovisioning, focusing on authorization, entitlement, and evolving access across assets, with Kerberos, Radius, and TAC X plus.
Explore mandatory, discretionary, role-based, and rule-based access controls to understand their tradeoffs. Recognize that these distinctions are arcane and not typically used, as operating systems enforce access control.
Review authenticating elements like passwords, discretionary access control, human resources identity proofing, and provisioning and de-provisioning to secure access and address internet risk.
Understand the risk management process, including risk, threat, vulnerability, risk appetite, and risk treatment options, with Nest RMF and ISO 27001 frameworks for threat modeling.
Understand legal and regulatory concerns, including jurisdiction boundaries and privacy, and how PII handling and data collection, use, and distribution vary across federal, state, tribal, and local laws.
Participate in security assessment and vulnerability management activities, including vulnerability scans and penetration tests, monitor controls, and manage risk with third-party monitoring, secure acquisition, and minimum security requirements.
Operate security platforms for continuous monitoring by collecting data from source systems, analyzing events of interest, and applying log management, aggregation, and correlation to detect anomalies and unauthorized changes.
Analyze monitoring results, baselines, anomalies, and trends using dashboards and visualizations to report findings, escalate aberrant events, and ensure clear incident response contact across the organization.
Review the SSCP domain concepts through exam-style questions on events and incidents, vulnerability scanning, zero day exploits, and risk responses like avoidance and mitigation.
Learn the incident response life cycle from policy and preparation to containment, eradication, recovery, and lessons learned, with detection, escalation, and thorough documentation guiding countermeasures.
Understand how to support forensic investigations across civil, criminal, and administrative contexts, including evidence handling, chain of custody, imaging, hashing, integrity checks, and tailored reporting for courts.
Learn to plan, test, and sustain business continuity and disaster recovery, including emergency response, backups, restoration, and alternate sites like hot, warm, or cold.
Review domain topics on forensic imaging of original evidence, evidence characteristics, civil jurisdiction in breach of contract, incident detection sources, and the definition of jurisdiction.
Explore why cryptography secures confidentiality, integrity, and authenticity, protects PII, IP, and electronic protected health information, and meets PCI DSS and ISO regulatory standards.
Explore hashing, salting, and both symmetric and asymmetric encryption, including elliptic curve cryptography, digital signatures, and certificates. Understand non-repudiation, integrity via macs, and PKI-based key management.
Explore secure protocols such as IPsec and TLS, including transport and tunnel modes. Study S/MIME and DKIM for email security, and review overhead vs. performance tradeoffs.
Explore public key infrastructure concepts, including storage, rotation, composition, generation, destruction, exchange, revocation, and escrow; understand the web of trust with PGP, GPG, and blockchain.
Review domain questions on point-to-point encryption with ipsec tunnel mode, hashing for integrity, and using Bob's public key; recognize symmetric vs asymmetric crypto for time-sensitive data and the certification authority.
Explore fundamental networking concepts, including the OSI seven-layer model and TCP/IP model, layers, topologies, transmission media, peer-to-peer and client-server relationships, and SDN and ports and protocols.
Learn about denial-of-service and distributed denial-of-service attacks, man-in-the-middle and DNS poisoning, and how content delivery networks reduce single points of failure and improve availability.
Explore how network access controls secure device joins using 802.1x, EAP, RADIUS, and TAC X and TAC X Plus, and compare thin clients and VPN for remote access security.
Explore how to manage network security through physical and logical segmentation, VLANs, ACLs, and micro segmentation, and implement secure device management for bring-your-own-device environments.
Learn to operate and configure network-based security devices, including firewalls, proxies, and web application firewalls, use IDS/IPS, routing, traffic shaping, WAN optimization, and load balancing to secure and optimize networks.
Explore secure wireless communications across cellular networks, Wi-Fi, Bluetooth, and NFC, including WEP, WPA, and WPA2, and assess IoT security risks.
Review domain six concepts, including the osi model layer one for wires and cables, 802.1X authentication, cdn use for streaming audio books, dns poisoning, and vlan-based segmentation.
Explore how various malware types and malicious activities threaten systems, and learn countermeasures including anti-malware, code signing, patching, isolation, data loss prevention, and user awareness.
Implement and operate endpoint device security with host-based firewalls, HIPs, application whitelisting, endpoint encryption like whole disk encryption, TPM, secure browsing, and EDR.
Explore how to administer mobile device management (MDM) with provisioning techniques, containerization, encryption, and mobile application management, while navigating BYOD and corporate owned devices, data ownership, privacy, and security configurations.
Examine cloud deployment models (public, private, community, hybrid) and service models (IaaS, PaaS, SaaS), virtualization basics, and data ownership, e-discovery, and SLAs for compliant security.
Operate and maintain secure virtual environments by managing hypervisors, virtual appliances, containers, and shared storage; ensure continuity and resilience with immutable or mutable configurations and countermeasures against attacks.
Review domain seven concepts for the SSCP 2021 exam, covering type one hypervisors, infrastructure as a service, network address translation, insider threats, and jurisdiction.
CANDIDATES ARE CAUTIONED THAT THIS CERTIFICATION'S EXAM OUTLINE HAS BEEN UPDATED, AND THE EXAM IS ALIGNED WITH A NEW OUTLINE AS OF SEPTEMBER 2024. This version of the course only remains posted here as a historic artifact and for contractual compliance purposes.
An explanation of the material found in the ISC2 SSCP Exam Outline, with particular focus on what you might expect to see on the exam. If you've been considering taking the SSCP test, this is the course for you. The course offers more than seven hours of video content at a highly-competitive price, and the accompanying coursebook can be purchased from the WannaBeA website. Drawn from the instructor's own experience as an official ISC2 SSCP instructor, the course is delivered in a simple, straightforward manner, designed to help you pass the exam.
Students are encouraged to review the ISC2 SSCP Exam Outline, available for free from the ISC2 website. The course includes other recommendations and suggestions for study purposes, as well as guidance on how to approach the test, and which topics are most likely to appear. This course is not a substitute for the requisite experience-- the course content does not teach many of the basics necessary for attaining certification; students are expected to have a background in IT prior to this course. At least two years of specific experience is necessary to qualify for the certification; students should have that much knowledge, as a minimum, prior to taking this course.
WannaBeA. Success and certification are only a class away.