Certification Overview
SSCP is a practitioner-level ISC2 certification for people who implement, administer, and monitor security controls. It is vendor-neutral. The questions reward operational judgment, defensible sequencing, and control ownership more than product recall.
- Exam delivery
- Computerized Adaptive Testing (CAT)
- Duration
- 120 minutes
- Items
- 100-125
- Passing score
- 700 out of 1000
DJames617 simulates mixed-domain practice pressure but does not reproduce ISC2's proprietary CAT algorithm.
What This Exam Is Really Testing
SSCP asks whether you can act like a responsible practitioner under constraints. The best answer is often the one that preserves evidence, follows policy, keeps authority scoped, addresses the primary risk, and leaves an auditable trail.
- Separate technically possible from operationally appropriate.
- Prefer documented and authorized risk decisions over informal shortcuts.
- For FIRST or NEXT questions, preserve evidence and contain active risk before later remediation.
- Do not confuse a control category, such as detective, with a control outcome, such as prevention.
Who This Exam Is For
The target learner understands general IT and security basics and wants practitioner-level readiness. You should be able to explain why a control exists, operate it, monitor it, and recognize when it is no longer enough.
Certification Path After Passing
Passing the SSCP exam is not the same as becoming certified. Candidates generally need one year of qualifying security work in one or more SSCP domains, endorsement/application approval, agreement to the ISC2 Code of Ethics, AMF payment, and ongoing CPE maintenance.
ISC2 currently lists one year of full-time experience in one or more SSCP domains. A qualifying bachelor's or master's degree in cybersecurity, computer science, IT, or a related approved field may satisfy up to one year.
A person who passes without the required experience may become an Associate of ISC2 and currently has up to two years to earn the one year of required SSCP experience.
Candidates who pass an ISC2 credential exam must complete the certification application within nine months of the exam date. Non-CC certifications require an endorser or ISC2 endorsement.
Current ISC2 policy lists SSCP/CGRC maintenance at 60 CPE credits over the three-year cycle and an AMF for members. Requirements can change, so learners should verify directly with ISC2 before acting.
Exam Blueprint
Domain 1: Security Concepts and Practices
Core security principles, control types, ethics, asset management, change management, awareness, and physical security collaboration.
16% of the exam blueprint.
Practice This DomainDomain 2: Access Controls
Authentication, trust relationships, identity lifecycle, authorization, access-control models, federation, and privilege administration.
15% of the exam blueprint.
Practice This DomainDomain 3: Risk Identification, Monitoring and Analysis
Risk management, legal and regulatory context, vulnerability management, security monitoring, SIEM, baselines, metrics, trend analysis, and escalation.
15% of the exam blueprint.
Practice This DomainDomain 4: Incident Response and Recovery
Incident lifecycle support, forensics, evidence handling, business continuity, disaster recovery, backup, redundancy, RTO, RPO, MTD, drills, and lessons learned.
14% of the exam blueprint.
Practice This DomainDomain 5: Cryptography
Cryptography purpose, hashing, salting, symmetric and asymmetric encryption, ECC, HMAC, signatures, certificates, key strength, secure protocols, attacks, cryptanalysis, and PKI.
9% of the exam blueprint.
Practice This DomainDomain 6: Network and Communications Security
Networking fundamentals, attacks, access control, remote access, segmentation, secure device management, firewalls, proxies, IDS/IPS, routers, switches, NAC, DLP, UTM, wireless security, and IoT monitoring.
16% of the exam blueprint.
Practice This DomainDomain 7: Systems and Application Security
Malware and malicious activity, endpoint protection, mobile device management, cloud security, virtualization, containers, cloud service and deployment models, shared responsibility, and virtual environment operations.
15% of the exam blueprint.
Practice This DomainDecision Words
ISC2-style questions often turn on one word. BEST usually means the most complete risk-appropriate answer. FIRST means sequence. MOST EFFECTIVE means outcome. LEAST often means minimum necessary impact or authority.
BEST
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
MOST
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
FIRST
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
NEXT
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
LEAST
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
PRIMARY
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
MOST EFFECTIVE
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
MOST APPROPRIATE
Mark the word, identify the role, find the highest-priority constraint, then eliminate answers that are useful but incomplete for that specific demand.
Critical Comparisons
Authentication vs Authorization
If the user is logged in but can access another user record, the issue is authorization, not authentication.
RBAC vs ABAC vs DAC vs MAC
When many conditions drive a decision, ABAC is often stronger than trying to create endless roles.
Preventive vs Detective vs Corrective Controls
Do not call a monitoring control preventive unless it actually blocks the action.
Risk Avoidance vs Mitigation vs Transfer vs Acceptance
Acceptance must be explicit and authorized; informal tolerance is not governance.
Symmetric vs Asymmetric Encryption
Use the property needed: confidentiality, integrity, authenticity, or non-repudiation.
Hashing vs Encryption
Hashing is not encryption. Do not choose hashing when the original value must be recovered.
IDS vs IPS
If prevention is required, a passive IDS alone is not enough.
RTO vs RPO vs MTD
Backups prove RPO only when restores are tested; they do not automatically meet RTO.
Hot vs Warm vs Cold Recovery Sites
Choose based on RTO/MTD and cost tolerance, not on the most impressive architecture.
SAST vs DAST
Use both when possible; each sees a different class of risk.
Hands-On Practice
Identity Lifecycle Review Lab
Find stale access and inherited permissions in a safe lab account or directory export.
Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.
Incident Evidence Tabletop
Practice FIRST/NEXT decisions without touching production systems.
Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.
Network Segmentation Review Lab
Map trusted and untrusted network paths for a small environment.
Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.
Cryptographic Control Selection Lab
Choose controls by security property instead of by buzzword.
Estimated cost: Free if performed with local diagrams or lab exports; verify before using real services.