Study Notes / ISC2 / SSCP

SSCP Study Guide for real security operators.

Learn the body of knowledge, practice the judgment ISC2 expects, and understand the path from passing the exam to becoming fully certified.

Certification Overview

SSCP is a practitioner-level ISC2 certification for people who implement, administer, and monitor security controls. It is vendor-neutral. The questions reward operational judgment, defensible sequencing, and control ownership more than product recall.

Exam delivery
Computerized Adaptive Testing (CAT)
Duration
120 minutes
Items
100-125
Passing score
700 out of 1000

DJames617 simulates mixed-domain practice pressure but does not reproduce ISC2's proprietary CAT algorithm.

What This Exam Is Really Testing

SSCP asks whether you can act like a responsible practitioner under constraints. The best answer is often the one that preserves evidence, follows policy, keeps authority scoped, addresses the primary risk, and leaves an auditable trail.

  • Separate technically possible from operationally appropriate.
  • Prefer documented and authorized risk decisions over informal shortcuts.
  • For FIRST or NEXT questions, preserve evidence and contain active risk before later remediation.
  • Do not confuse a control category, such as detective, with a control outcome, such as prevention.

Who This Exam Is For

The target learner understands general IT and security basics and wants practitioner-level readiness. You should be able to explain why a control exists, operate it, monitor it, and recognize when it is no longer enough.

Certification Path After Passing

Passing the SSCP exam is not the same as becoming certified. Candidates generally need one year of qualifying security work in one or more SSCP domains, endorsement/application approval, agreement to the ISC2 Code of Ethics, AMF payment, and ongoing CPE maintenance.

ISC2 currently lists one year of full-time experience in one or more SSCP domains. A qualifying bachelor's or master's degree in cybersecurity, computer science, IT, or a related approved field may satisfy up to one year.

A person who passes without the required experience may become an Associate of ISC2 and currently has up to two years to earn the one year of required SSCP experience.

Candidates who pass an ISC2 credential exam must complete the certification application within nine months of the exam date. Non-CC certifications require an endorser or ISC2 endorsement.

Current ISC2 policy lists SSCP/CGRC maintenance at 60 CPE credits over the three-year cycle and an AMF for members. Requirements can change, so learners should verify directly with ISC2 before acting.

Exam Blueprint

Domain 5: Cryptography

Cryptography purpose, hashing, salting, symmetric and asymmetric encryption, ECC, HMAC, signatures, certificates, key strength, secure protocols, attacks, cryptanalysis, and PKI.

9% of the exam blueprint.

Practice This Domain

Decision Words

ISC2-style questions often turn on one word. BEST usually means the most complete risk-appropriate answer. FIRST means sequence. MOST EFFECTIVE means outcome. LEAST often means minimum necessary impact or authority.

BEST

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

MOST

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

FIRST

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

NEXT

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

LEAST

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

PRIMARY

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

MOST EFFECTIVE

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

MOST APPROPRIATE

Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.

Critical Comparisons

Hashing vs Encryption

Hashing is not encryption. Do not choose hashing when the original value must be recovered.

IDS vs IPS

If prevention is required, a passive IDS alone is not enough.

RTO vs RPO vs MTD

Backups prove RPO only when restores are tested; they do not automatically meet RTO.

SAST vs DAST

Use both when possible; each sees a different class of risk.

Hands-On Practice

Identity Lifecycle Review Lab

Find stale access and inherited permissions in a safe lab account or directory export.

Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.

Incident Evidence Tabletop

Practice FIRST/NEXT decisions without touching production systems.

Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.

Network Segmentation Review Lab

Map trusted and untrusted network paths for a small environment.

Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.

Cryptographic Control Selection Lab

Choose controls by security property instead of by buzzword.

Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.

Final Review Checklist