Free knowledge base

SSCP Systems Security Certified Practitioner — key terms, tricks & tips

Everything from the course in one searchable place: 338 entries. Use it to review before a practice test or look up a word you forgot.

338 results · showing first 300, refine your search

Key term

Domain

A major topic area covered by the SSCP exam.

Getting Started: Your SSCP Journey

Key term

Weighting

The percentage of exam questions dedicated to a specific domain.

Getting Started: Your SSCP Journey

Key term

Scaled Score

A converted raw score, adjusted for question difficulty.

Getting Started: Your SSCP Journey

Key term

Pretest Items

Unscored questions used to evaluate future exam questions.

Getting Started: Your SSCP Journey

Key term

Pearson VUE

The testing provider for the SSCP certification exam.

Getting Started: Your SSCP Journey

Key term

Multiple Choice

Exam question format with one correct answer out of several options.

Getting Started: Your SSCP Journey

Memory trick

Understanding the SSCP Exam Structure and Format

To remember the 7 domains: 'SOAR CINCS' - Security Operations, Access Controls, Risk, Cryptography, Incident Response, Network, Systems.

Getting Started: Your SSCP Journey

Exam tip

Understanding the SSCP Exam Structure and Format

Memorize the seven SSCP domains and their approximate weightings. Keywords like 'Security Operations', 'Access Controls', and 'Risk Identification' are direct domain names. The exam has 125 questions, 3 hours, and a passing score of 700/1000.

Getting Started: Your SSCP Journey

Common mistake

Understanding the SSCP Exam Structure and Format

Ignoring domain weightings and studying all topics equally.

Getting Started: Your SSCP Journey

Common mistake

Understanding the SSCP Exam Structure and Format

Not practicing time management, leading to rushing or not finishing the exam.

Getting Started: Your SSCP Journey

Common mistake

Understanding the SSCP Exam Structure and Format

Assuming a raw 70% correct answers guarantees a pass due to scaled scoring.

Getting Started: Your SSCP Journey

Key term

Learning Style

Preferred method for absorbing and processing information.

Getting Started: Your SSCP Journey

Key term

Study Plan

A structured schedule for organizing study activities.

Getting Started: Your SSCP Journey

Key term

Official Curriculum

Materials provided by the certification body (ISC)².

Getting Started: Your SSCP Journey

Key term

Practice Exam

Simulated tests to assess knowledge and identify gaps.

Getting Started: Your SSCP Journey

Key term

Hands-on Practice

Applying theoretical knowledge in practical scenarios.

Getting Started: Your SSCP Journey

Key term

Active Recall

Retrieving information from memory, like flashcards.

Getting Started: Your SSCP Journey

Key term

Spaced Repetition

Reviewing material at increasing intervals over time.

Getting Started: Your SSCP Journey

Memory trick

Effective Study Strategies for SSCP Success

SSCP: S-tudy S-martly, C-onstantly P-ractice!

Getting Started: Your SSCP Journey

Exam tip

Effective Study Strategies for SSCP Success

The SSCP exam requires a practitioner-level understanding. Don't just memorize definitions; be prepared to apply concepts to scenarios. Keywords like 'implement,' 'configure,' 'identify the best,' and 'troubleshoot' indicate application-based questions.

Getting Started: Your SSCP Journey

Common mistake

Effective Study Strategies for SSCP Success

Cramming all material right before the exam instead of consistent, spaced study.

Getting Started: Your SSCP Journey

Common mistake

Effective Study Strategies for SSCP Success

Relying solely on memorization without understanding the 'why' or practical application.

Getting Started: Your SSCP Journey

Common mistake

Effective Study Strategies for SSCP Success

Neglecting practice exams, leading to unfamiliarity with the question format and time constraints.

Getting Started: Your SSCP Journey

Key term

Least Privilege

Users get minimum access needed for their job.

Access Controls Fundamentals

Key term

Separation of Duties

Dividing critical tasks among multiple individuals.

Access Controls Fundamentals

Key term

Provisioning

Creating and granting user accounts and access.

Access Controls Fundamentals

Key term

Deprovisioning

Revoking user access and disabling accounts.

Access Controls Fundamentals

Key term

Permission Creep

Accumulation of unnecessary access rights over time.

Access Controls Fundamentals

Key term

Access Control Review

Periodic audit of user permissions and access.

Access Controls Fundamentals

Key term

Centralized Administration

Single authority manages all access rights.

Access Controls Fundamentals

Key term

Decentralized Administration

Access management distributed to resource owners.

Access Controls Fundamentals

Memory trick

Implementing and Maintaining Access Controls

L.A.S.T. P.A.R.T. for Access Control: Least privilege, Administration, Separation of duties, Timely deprovisioning, Provisioning, Auditing, Review, Training.

Access Controls Fundamentals

Exam tip

Implementing and Maintaining Access Controls

The exam often tests your understanding of the access control lifecycle, emphasizing the importance of both initial implementation and ongoing maintenance. Look for keywords like 'least privilege,' 'separation of duties,' 'provisioning,' and 'deprovisioning' in scenarios.

Access Controls Fundamentals

Common mistake

Implementing and Maintaining Access Controls

Failing to promptly deprovision access for terminated employees.

Access Controls Fundamentals

Common mistake

Implementing and Maintaining Access Controls

Granting excessive permissions (violating least privilege) for convenience.

Access Controls Fundamentals

Common mistake

Implementing and Maintaining Access Controls

Neglecting regular access control reviews, leading to 'permission creep'.

Access Controls Fundamentals

Key term

Authentication

Verifying a user's identity to ensure they are who they claim to be.

Access Controls Fundamentals

Key term

MFA

Multi-Factor Authentication; requiring two or more distinct factors.

Access Controls Fundamentals

Key term

Biometrics

Authentication based on unique physical or behavioral human traits.

Access Controls Fundamentals

Key term

Password

A secret string of characters used for authentication (something you know).

Access Controls Fundamentals

Key term

Token

A physical or digital device generating codes (something you have).

Access Controls Fundamentals

Key term

Kerberos

Network authentication protocol using secret-key cryptography for services.

Access Controls Fundamentals

Key term

RADIUS

Centralized AAA protocol for network access and authentication.

Access Controls Fundamentals

Key term

Adaptive Auth

Adjusts authentication requirements based on risk factors.

Access Controls Fundamentals

Memory trick

Authentication Methods and Technologies

K-H-A: Know, Have, Are. The three factors of authentication, easy as K-H-A!

Access Controls Fundamentals

Exam tip

Authentication Methods and Technologies

The SSCP exam frequently tests your understanding of the three authentication factors (something you know, something you have, something you are) and their application in Multi-Factor Authentication (MFA). Be ready to identify examples of each factor and explain why MFA is superior to single-factor methods.

Access Controls Fundamentals

Common mistake

Authentication Methods and Technologies

Confusing authentication (who you are) with authorization (what you can do).

Access Controls Fundamentals

Common mistake

Authentication Methods and Technologies

Underestimating the importance of combining multiple distinct factors for strong security.

Access Controls Fundamentals

Common mistake

Authentication Methods and Technologies

Believing biometrics are infallible and cannot be spoofed or have privacy implications.

Access Controls Fundamentals

Key term

Authorization

Determining what an authenticated user or process is permitted to do.

Access Controls Fundamentals

Key term

Access Control List (ACL)

List of permissions attached to an object, specifying who can access it.

Access Controls Fundamentals

Key term

Capability

A token held by a subject that grants specific permissions to an object.

Access Controls Fundamentals

Key term

Role-Based Access Control (RBAC)

Access control where permissions are associated with roles, and users are assigned to roles.

Access Controls Fundamentals

Key term

Rule-Based Access Control (RuBAC)

Access control based on a set of predefined rules or policies.

Access Controls Fundamentals

Key term

Attribute-Based Access Control (ABAC)

Access control based on attributes of subject, object, action, and environment.

Access Controls Fundamentals

Key term

Principle of Least Privilege

Users should only be granted the minimum permissions necessary to perform their job.

Access Controls Fundamentals

Memory trick

Authorization Mechanisms and Models

ACLs are like a guest list for a party (on the door). RBAC is like giving everyone a job title (Manager, Staff) with specific duties. ABAC is like a bouncer checking your ID, your outfit, and the time of day before letting you in.

Access Controls Fundamentals

Exam tip

Authorization Mechanisms and Models

For the SSCP exam, memorize the core definitions and distinctions between ACLs, RBAC, and ABAC. Pay close attention to how each model addresses scalability and granularity of control.

Access Controls Fundamentals

Common mistake

Authorization Mechanisms and Models

Confusing authorization with authentication; they are distinct steps in access control.

Access Controls Fundamentals

Common mistake

Authorization Mechanisms and Models

Over-privileging users or roles, violating the principle of least privilege.

Access Controls Fundamentals

Common mistake

Authorization Mechanisms and Models

Not periodically reviewing and updating authorization policies as roles and responsibilities change.

Access Controls Fundamentals

Key term

IAM

Framework for managing digital identities and controlling resource access.

Access Controls Fundamentals

Key term

Identity Provider (IdP)

System that creates, maintains, and manages identity information.

Access Controls Fundamentals

Key term

Service Provider (SP)

System or application that relies on an IdP for user authentication.

Access Controls Fundamentals

Key term

Identity Federation

Linking user identities across multiple, disparate security domains.

Access Controls Fundamentals

Key term

Single Sign-On (SSO)

Allows users to authenticate once to access multiple applications.

Access Controls Fundamentals

Memory trick

Identity and Access Management (IAM) Concepts

IAM: 'I'd Always Manage' identities, 'A'uthenticate users, and 'M'anage access.

Access Controls Fundamentals

Exam tip

Identity and Access Management (IAM) Concepts

Memorize the core components of IAM: Identity Management, Authentication, and Authorization. The SSCP exam often tests your ability to differentiate between these functions and their role in a complete access control solution.

Access Controls Fundamentals

Common mistake

Identity and Access Management (IAM) Concepts

Confusing authentication with authorization; authentication is 'who you are,' authorization is 'what you can do.'

Access Controls Fundamentals

Common mistake

Identity and Access Management (IAM) Concepts

Neglecting deprovisioning, which leaves dormant accounts as security risks.

Access Controls Fundamentals

Common mistake

Identity and Access Management (IAM) Concepts

Failing to regularly review and update user access rights as roles change.

Access Controls Fundamentals

Key term

Logging

Recording events within systems for security analysis.

Security Operations and Administration

Key term

Monitoring

Continuously reviewing logs and activities for anomalies.

Security Operations and Administration

Key term

SIEM

Security Information and Event Management; aggregates and analyzes logs.

Security Operations and Administration

Key term

Preventive Control

A safeguard designed to stop incidents from occurring.

Security Operations and Administration

Key term

Detective Control

A safeguard designed to identify incidents that have occurred.

Security Operations and Administration

Key term

Change Control

Formal process to manage system modifications securely.

Security Operations and Administration

Key term

Asset Management

Systematic tracking and securing of organizational assets.

Security Operations and Administration

Key term

SOC

Security Operations Center; centralizes security monitoring and response.

Security Operations and Administration

Memory trick

Security Operations Concepts and Practices

To remember the types of security controls, think 'P.D.C.D.' - People Detect Crime Daily. P=Preventive, D=Detective, C=Corrective, D=Deterrent.

Security Operations and Administration

Exam tip

Security Operations Concepts and Practices

The SSCP exam frequently tests your ability to differentiate between types of security controls (preventive, detective, corrective, deterrent). Memorize examples for each category and understand their primary purpose. Also, understand the components and purpose of a SOC.

Security Operations and Administration

Common mistake

Security Operations Concepts and Practices

Failing to regularly review and update logging configurations, leading to missed critical events.

Security Operations and Administration

Common mistake

Security Operations Concepts and Practices

Implementing security controls without proper testing, causing operational disruptions or leaving gaps.

Security Operations and Administration

Common mistake

Security Operations Concepts and Practices

Bypassing change control processes for 'urgent' changes, often introducing new vulnerabilities.

Security Operations and Administration

Key term

Security Policy

High-level, mandatory statements defining an organization's security posture.

Security Operations and Administration

Key term

Security Standard

Specific, mandatory requirements for hardware, software, or configurations.

Security Operations and Administration

Key term

Security Procedure

Detailed, step-by-step instructions for performing a specific task.

Security Operations and Administration

Key term

Security Guideline

Recommendations or suggestions for best practices; not mandatory.

Security Operations and Administration

Key term

Security Baseline

Minimum security configurations applied to systems or applications.

Security Operations and Administration

Key term

Security Governance

Framework ensuring security aligns with business objectives and manages risk.

Security Operations and Administration

Key term

Awareness Training

Educating employees on security policies, procedures, and threats.

Security Operations and Administration

Memory trick

Security Policies, Procedures, and Awareness

P-S-B-P-G: **P**eople **S**hould **B**e **P**rotected by **G**overnance. (Policies, Standards, Baselines, Procedures, Guidelines)

Security Operations and Administration

Exam tip

Security Policies, Procedures, and Awareness

The SSCP exam frequently tests your ability to distinguish between policies, standards, procedures, and guidelines. Keywords to spot: 'high-level statement' (policy), 'specific mandatory requirement' (standard), 'step-by-step instructions' (procedure), 'recommendation' (guideline).

Security Operations and Administration

Common mistake

Security Policies, Procedures, and Awareness

Confusing a policy with a procedure: Policies are 'what' to do, procedures are 'how' to do it.

Security Operations and Administration

Common mistake

Security Policies, Procedures, and Awareness

Underestimating the importance of security awareness: Technical controls are only as strong as the weakest human link.

Security Operations and Administration

Common mistake

Security Policies, Procedures, and Awareness

Treating security documentation as a one-time task: Policies, standards, and procedures need regular review and updates.

Security Operations and Administration

Key term

Vulnerability Scan

Automated process to identify known security weaknesses.

Security Operations and Administration

Key term

Penetration Test

Simulated attack to exploit vulnerabilities and assess impact.

Security Operations and Administration

Key term

Black Box Testing

Pen test with no prior knowledge of the target system.

Security Operations and Administration

Key term

White Box Testing

Pen test with full knowledge of the target system.

Security Operations and Administration

Key term

Gray Box Testing

Pen test with partial knowledge of the target system.

Security Operations and Administration

Key term

Security Audit

Systematic evaluation against established security criteria.

Security Operations and Administration

Key term

Remediation

Process of fixing identified security vulnerabilities.

Security Operations and Administration

Key term

CVE

Common Vulnerabilities and Exposures, a list of public vulnerabilities.

Security Operations and Administration

Memory trick

Security Assessment and Testing Methodologies

V-P-A-R-R: Vulnerability Scan, Pen Test, Audit, Report, Remediate. Remember the cycle!

Security Operations and Administration

Exam tip

Security Assessment and Testing Methodologies

The SSCP exam often distinguishes between vulnerability scanning (identifying weaknesses) and penetration testing (exploiting weaknesses). Be able to clearly define each and their respective purposes.

Security Operations and Administration

Common mistake

Security Assessment and Testing Methodologies

Confusing vulnerability scanning with penetration testing. Scans identify, pen tests exploit.

Security Operations and Administration

Common mistake

Security Assessment and Testing Methodologies

Failing to define a clear scope and rules of engagement before conducting any test.

Security Operations and Administration

Common mistake

Security Assessment and Testing Methodologies

Not following up on remediation efforts with retesting to verify fixes.

Security Operations and Administration

Key term

Incident Response (IR)

A structured approach to managing security breaches and cyberattacks.

Security Operations and Administration

Key term

Containment

Actions taken to prevent an incident from spreading further.

Security Operations and Administration

Key term

Eradication

Removing the root cause of an incident and malicious components.

Security Operations and Administration

Key term

Recovery

Restoring affected systems and services to normal operation.

Security Operations and Administration

Key term

Post-Incident Activity

Reviewing an incident to identify lessons learned and improve processes.

Security Operations and Administration

Key term

Disaster Recovery (DR)

Plans to restore business operations after a catastrophic event.

Security Operations and Administration

Key term

Lessons Learned

Review process after an incident to improve future responses.

Security Operations and Administration

Memory trick

Incident Response and Recovery Participation

Prepare, Detect, Contain, Eradicate, Recover, Post-mortem (PDCREP) – like a doctor's visit for your systems!

Security Operations and Administration

Exam tip

Incident Response and Recovery Participation

The exam expects you to know the distinct phases of the incident response lifecycle and what activities occur in each. Pay close attention to the order and purpose of containment, eradication, and recovery.

Security Operations and Administration

Common mistake

Incident Response and Recovery Participation

Skipping documentation during any phase of the incident response process.

Security Operations and Administration

Common mistake

Incident Response and Recovery Participation

Failing to perform a 'lessons learned' review after an incident, missing opportunities for improvement.

Security Operations and Administration

Common mistake

Incident Response and Recovery Participation

Confusing incident response with disaster recovery; they address different scales of events.

Security Operations and Administration

Key term

Risk

The likelihood of a threat exploiting a vulnerability and causing harm.

Risk Identification, Monitoring, and Analysis

Key term

Threat

A potential danger that could exploit a vulnerability.

Risk Identification, Monitoring, and Analysis

Key term

Vulnerability

A weakness in a system or process that a threat could exploit.

Risk Identification, Monitoring, and Analysis

Key term

Impact

The magnitude of harm resulting from a security incident.

Risk Identification, Monitoring, and Analysis

Key term

Risk Appetite

The amount of risk an organization is willing to accept.

Risk Identification, Monitoring, and Analysis

Key term

Residual Risk

The risk that remains after implementing security controls.

Risk Identification, Monitoring, and Analysis

Key term

Risk Mitigation

Actions taken to reduce the likelihood or impact of a risk.

Risk Identification, Monitoring, and Analysis

Key term

Risk Framework

A structured approach for managing risk within an organization.

Risk Identification, Monitoring, and Analysis

Memory trick

Risk Management Concepts and Frameworks

Remember 'TV IR': Threats create Vulnerabilities, leading to an Impact, which defines the Risk. It's a chain reaction!

Risk Identification, Monitoring, and Analysis

Exam tip

Risk Management Concepts and Frameworks

The SSCP exam will test your understanding of the core definitions of risk, threat, vulnerability, and impact. Be prepared to distinguish between them and identify examples of each. Also, know the general steps of common frameworks like NIST RMF.

Risk Identification, Monitoring, and Analysis

Common mistake

Risk Management Concepts and Frameworks

Confusing 'threat' with 'vulnerability' – a threat is external (e.g., hacker), a vulnerability is internal (e.g., unpatched system).

Risk Identification, Monitoring, and Analysis

Common mistake

Risk Management Concepts and Frameworks

Believing all risk can be eliminated; the goal is to reduce it to an acceptable level (residual risk).

Risk Identification, Monitoring, and Analysis

Common mistake

Risk Management Concepts and Frameworks

Failing to continuously monitor risks, assuming controls remain effective indefinitely.

Risk Identification, Monitoring, and Analysis

Key term

Retesting

Verifying that vulnerabilities have been successfully mitigated.

Risk Identification, Monitoring, and Analysis

Key term

False Positive

A scan result indicating a vulnerability that doesn't exist.

Risk Identification, Monitoring, and Analysis

Key term

Code Review

Examination of source code for security flaws.

Risk Identification, Monitoring, and Analysis

Memory trick

Performing Security Assessments and Vulnerability Scans

To remember the assessment types, think 'VAPOR': Vulnerability scans, Audits, Penetration tests, fOrensics (though not covered here), and code Reviews.

Risk Identification, Monitoring, and Analysis

Exam tip

Performing Security Assessments and Vulnerability Scans

The SSCP exam will often ask you to differentiate between vulnerability scanning and penetration testing. Remember: scans identify known weaknesses, while pen tests exploit them to demonstrate impact. Also, know that a 'credentialed scan' means the scanner logs in, providing deeper insight.

Risk Identification, Monitoring, and Analysis

Common mistake

Performing Security Assessments and Vulnerability Scans

Confusing vulnerability scanning with penetration testing: Scans find, pen tests exploit.

Risk Identification, Monitoring, and Analysis

Common mistake

Performing Security Assessments and Vulnerability Scans

Neglecting remediation and retesting: Finding vulnerabilities is only half the battle; fixing and verifying are crucial.

Risk Identification, Monitoring, and Analysis

Common mistake

Performing Security Assessments and Vulnerability Scans

Failing to define scope before an assessment: This can lead to legal issues or wasted effort on out-of-scope systems.

Risk Identification, Monitoring, and Analysis

Key term

Log

A chronological record of events and activities on a system.

Risk Identification, Monitoring, and Analysis

Key term

Event

A significant occurrence within a system or network.

Risk Identification, Monitoring, and Analysis

Key term

Correlation

Linking related events from different sources to identify patterns.

Risk Identification, Monitoring, and Analysis

Key term

Anomaly Detection

Identifying deviations from normal behavior in log data.

Risk Identification, Monitoring, and Analysis

Key term

IOC (Indicator of Compromise)

Forensic data indicating a potential intrusion on a system.

Risk Identification, Monitoring, and Analysis

Key term

Baselining

Establishing a normal activity pattern to detect deviations.

Risk Identification, Monitoring, and Analysis

Key term

Syslog

A standard protocol for sending system log messages.

Risk Identification, Monitoring, and Analysis

Memory trick

Analyzing and Reporting Security Events and Logs

To remember the log analysis process: 'C-A-R-E': Collect, Analyze, Report, Escalate. It helps you CARE for your logs!

Risk Identification, Monitoring, and Analysis

Exam tip

Analyzing and Reporting Security Events and Logs

The exam often tests your understanding of *what* type of information is found in *which* log source (e.g., firewall logs for blocked traffic, OS logs for user authentications). Memorize common log types and their primary purpose.

Risk Identification, Monitoring, and Analysis

Common mistake

Analyzing and Reporting Security Events and Logs

Ignoring alerts from SIEM systems, assuming they are false positives.

Risk Identification, Monitoring, and Analysis

Common mistake

Analyzing and Reporting Security Events and Logs

Failing to centralize logs, making analysis and correlation extremely difficult.

Risk Identification, Monitoring, and Analysis

Common mistake

Analyzing and Reporting Security Events and Logs

Not establishing a baseline of normal network and system activity, leading to missed anomalies.

Risk Identification, Monitoring, and Analysis

Key term

Threat Intelligence

Actionable, evidence-based knowledge about cyber threats.

Risk Identification, Monitoring, and Analysis

Key term

Indicators of Compromise (IOCs)

Forensic data points indicating a potential security breach.

Risk Identification, Monitoring, and Analysis

Key term

Tactics, Techniques, and Procedures (TTPs)

Methods used by threat actors in cyberattacks.

Risk Identification, Monitoring, and Analysis

Key term

STIX

Standardized language for expressing cyber threat information.

Risk Identification, Monitoring, and Analysis

Key term

TAXII

Protocol for exchanging cyber threat intelligence over HTTPS.

Risk Identification, Monitoring, and Analysis

Key term

ISAC/ISAO

Information Sharing and Analysis Center/Organization.

Risk Identification, Monitoring, and Analysis

Key term

Open-Source Intelligence (OSINT)

Intelligence gathered from publicly available sources.

Risk Identification, Monitoring, and Analysis

Memory trick

Understanding and Applying Threat Intelligence

To remember the types of intelligence, think 'STOP': Strategic, Tactical, Operational, Technical. STOP and think about the threat!

Risk Identification, Monitoring, and Analysis

Exam tip

Understanding and Applying Threat Intelligence

The SSCP exam will test your understanding of the types of threat intelligence (strategic, tactical, operational, technical) and how they are applied. Memorize the purpose of STIX and TAXII as standards for sharing.

Risk Identification, Monitoring, and Analysis

Common mistake

Understanding and Applying Threat Intelligence

Confusing raw data or simple IOCs with fully analyzed threat intelligence. Intelligence provides context and actionability.

Risk Identification, Monitoring, and Analysis

Common mistake

Understanding and Applying Threat Intelligence

Failing to integrate threat intelligence into security tools and processes, making it just data, not actionable insight.

Risk Identification, Monitoring, and Analysis

Common mistake

Understanding and Applying Threat Intelligence

Relying solely on one source of threat intelligence; a diverse set of sources provides a more complete picture.

Risk Identification, Monitoring, and Analysis

Key term

IR Lifecycle

Structured process for handling security incidents.

Incident Response and Recovery

Key term

Preparation Phase

Establishing policies, tools, and training proactively.

Incident Response and Recovery

Key term

Identification Phase

Detecting and verifying a security incident.

Incident Response and Recovery

Key term

Containment Phase

Limiting the scope and impact of an incident.

Incident Response and Recovery

Key term

Eradication Phase

Removing the root cause and malicious components.

Incident Response and Recovery

Key term

Recovery Phase

Restoring systems and services to operation.

Incident Response and Recovery

Memory trick

Incident Response Concepts and Lifecycle

PICERL: **P**reparation, **I**dentification, **C**ontainment, **E**radication, **R**ecovery, **L**essons Learned. Remember it like 'Pick a girl!' for short.

Incident Response and Recovery

Exam tip

Incident Response Concepts and Lifecycle

The exam frequently tests the order of the incident response lifecycle phases. Memorize the NIST phases: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. Keywords to spot: 'first step,' 'next action,' 'post-incident activity.'

Incident Response and Recovery

Common mistake

Incident Response Concepts and Lifecycle

Skipping the preparation phase, leading to disorganized and ineffective responses.

Incident Response and Recovery

Common mistake

Incident Response Concepts and Lifecycle

Failing to properly contain an incident, allowing it to spread and cause more damage.

Incident Response and Recovery

Common mistake

Incident Response Concepts and Lifecycle

Neglecting the 'Lessons Learned' phase, which prevents continuous improvement and leaves vulnerabilities open.

Incident Response and Recovery

Key term

Incident Handling

Structured process to manage security breaches from detection to recovery.

Incident Response and Recovery

Key term

Digital Forensics

Scientific process of collecting, analyzing, and presenting digital evidence.

Incident Response and Recovery

Key term

Chain of Custody

Documented history of evidence handling to ensure its integrity and authenticity.

Incident Response and Recovery

Key term

Volatile Data

Data that is lost when a computer is powered off, like RAM contents.

Incident Response and Recovery

Key term

Write-Blocker

Hardware or software tool preventing alteration of storage media during forensics.

Incident Response and Recovery

Memory trick

Incident Handling and Forensics

PICERL: **P**reparation, **I**dentification, **C**ontainment, **E**radication, **R**ecovery, **L**essons Learned – the steps of incident handling, like a 'pickle' you need to handle carefully!

Incident Response and Recovery

Exam tip

Incident Handling and Forensics

The SSCP exam expects you to know the distinct stages of the incident handling process (Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity) and the fundamental principles of digital forensics, especially chain of custody and evidence integrity. Look for questions differentiating immediate response from deep analysis.

Incident Response and Recovery

Common mistake

Incident Handling and Forensics

Confusing incident handling (immediate action) with forensics (deep investigation).

Incident Response and Recovery

Common mistake

Incident Handling and Forensics

Failing to maintain a proper chain of custody, which can invalidate evidence.

Incident Response and Recovery

Common mistake

Incident Handling and Forensics

Modifying original evidence during collection, making it inadmissible in legal proceedings.

Incident Response and Recovery

Key term

Recovery Time Objective (RTO)

Maximum tolerable time for a system/application to be down.

Incident Response and Recovery

Key term

Recovery Point Objective (RPO)

Maximum tolerable data loss measured in time.

Incident Response and Recovery

Key term

Hot Site

Fully equipped alternate facility for immediate recovery.

Incident Response and Recovery

Key term

Warm Site

Partially equipped alternate facility requiring some setup.

Incident Response and Recovery

Key term

Cold Site

Basic facility with power/cooling, no equipment.

Incident Response and Recovery

Key term

Business Impact Analysis (BIA)

Identifies critical functions and impact of their loss.

Incident Response and Recovery

Key term

Tabletop Exercise

DRP testing method involving verbal walkthroughs.

Incident Response and Recovery

Memory trick

Disaster Recovery Planning and Strategies

To remember the DR sites from fastest to slowest: 'Hot' (ready to go), 'Warm' (needs a little heat), 'Cold' (frozen, needs thawing).

Incident Response and Recovery

Exam tip

Disaster Recovery Planning and Strategies

The SSCP exam will often test your understanding of the differences between RTO and RPO, and how they influence the choice of disaster recovery strategies (hot, warm, cold sites). Memorize the characteristics of each site type.

Incident Response and Recovery

Common mistake

Disaster Recovery Planning and Strategies

Confusing DRP with BCP (DRP is IT-focused, BCP is broader business focus).

Incident Response and Recovery

Common mistake

Disaster Recovery Planning and Strategies

Failing to regularly test and update the DRP.

Incident Response and Recovery

Common mistake

Disaster Recovery Planning and Strategies

Not aligning the DRP with the organization's RTO and RPO.

Incident Response and Recovery

Key term

Business Continuity Planning (BCP)

Overall strategy to ensure business functions continue during disruptions.

Incident Response and Recovery

Key term

Disaster Recovery Planning (DRP)

Component of BCP focused on restoring IT systems after a disaster.

Incident Response and Recovery

Key term

Alternate Site

Secondary location for operations if primary site is unavailable.

Incident Response and Recovery

Memory trick

Business Continuity Planning and Implementation

BCP: 'Be Continuously Prepared!' - The 'P' reminds you it's about 'Planning' for 'Preparedness.'

Incident Response and Recovery

Exam tip

Business Continuity Planning and Implementation

The exam often tests the difference between BCP and DRP. Remember, BCP is the 'what if the business can't run?' and DRP is 'what if IT systems are broken?'. Also, know that BIA is the foundational first step of BCP.

Incident Response and Recovery

Common mistake

Business Continuity Planning and Implementation

Confusing BCP with DRP; BCP is broader.

Incident Response and Recovery

Common mistake

Business Continuity Planning and Implementation

Failing to regularly test and update the BCP, making it obsolete.

Incident Response and Recovery

Common mistake

Business Continuity Planning and Implementation

Not involving all relevant stakeholders in BCP development and testing.

Incident Response and Recovery

Key term

Confidentiality

Ensuring data is accessible only to authorized entities.

Cryptography Essentials

Key term

Integrity

Ensuring data has not been altered or tampered with.

Cryptography Essentials

Key term

Authenticity

Verifying the identity of a user or origin of data.

Cryptography Essentials

Key term

Non-repudiation

Preventing denial of an action or communication.

Cryptography Essentials

Key term

Symmetric Encryption

Uses a single shared key for encryption and decryption.

Cryptography Essentials

Key term

Asymmetric Encryption

Uses a public/private key pair for encryption/decryption.

Cryptography Essentials

Key term

Hashing

One-way function creating a fixed-size digest for integrity.

Cryptography Essentials

Key term

Digital Signature

Ensures authenticity, integrity, and non-repudiation.

Cryptography Essentials

Memory trick

Cryptographic Concepts and Algorithms

CIAAN: Cryptography's goals are Confidentiality, Integrity, Authenticity, Availability, and Non-repudiation. Remember 'CIAAN' as 'See-Ann' for all your security needs!

Cryptography Essentials

Exam tip

Cryptographic Concepts and Algorithms

Memorize the core cryptographic principles (CIAAN: Confidentiality, Integrity, Authenticity, Availability, Non-repudiation) and which cryptographic mechanisms (e.g., encryption, hashing, digital signatures) primarily address each. The exam often tests your ability to match a security goal to the appropriate cryptographic tool.

Cryptography Essentials

Common mistake

Cryptographic Concepts and Algorithms

Confusing the use cases for symmetric vs. asymmetric encryption (e.g., using asymmetric for bulk data encryption).

Cryptography Essentials

Common mistake

Cryptographic Concepts and Algorithms

Believing hashing provides confidentiality (it only provides integrity).

Cryptography Essentials

Common mistake

Cryptographic Concepts and Algorithms

Forgetting that digital signatures provide non-repudiation, not just authenticity and integrity.

Cryptography Essentials

Key term

Key Management System (KMS)

A system for managing the lifecycle of cryptographic keys.

Cryptography Essentials

Key term

Hardware Security Module (HSM)

A physical device that safeguards and manages digital keys.

Cryptography Essentials

Key term

Key Rotation

The practice of regularly changing cryptographic keys.

Cryptography Essentials

Key term

Key Escrow

Storing a copy of a cryptographic key for recovery or legal access.

Cryptography Essentials

Key term

Transparent Data Encryption (TDE)

Encrypts an entire database at the file system level without application changes.

Cryptography Essentials

Key term

Full Disk Encryption (FDE)

Encrypts all data on a disk, including the operating system.

Cryptography Essentials

Key term

Interoperability

Ability of different systems to work together using cryptography.

Cryptography Essentials

Memory trick

Implementing Cryptographic Solutions

KISS: Keep It Simple, Secure, and Symmetric (when possible for performance).

Cryptography Essentials

Exam tip

Implementing Cryptographic Solutions

The exam often tests your understanding of key management challenges and best practices, especially regarding key generation, storage, and revocation. Remember that HSMs are the gold standard for key protection.

Cryptography Essentials

Common mistake

Implementing Cryptographic Solutions

Using weak or default cryptographic keys, making systems vulnerable to brute-force attacks.

Cryptography Essentials

Common mistake

Implementing Cryptographic Solutions

Failing to regularly rotate cryptographic keys, increasing the risk if a key is compromised.

Cryptography Essentials

Common mistake

Implementing Cryptographic Solutions

Not properly securing key storage, leaving keys exposed to unauthorized access.

Cryptography Essentials

Key term

Certificate Authority (CA)

Trusted entity issuing and managing digital certificates.

Cryptography Essentials

Key term

Registration Authority (RA)

Verifies identity of certificate requesters for the CA.

Cryptography Essentials

Key term

Digital Certificate

Electronic document binding a public key to an identity.

Cryptography Essentials

Key term

Certificate Revocation List (CRL)

List of digital certificates that have been revoked.

Cryptography Essentials

Key term

Online Certificate Status Protocol (OCSP)

Real-time protocol to check the revocation status of a certificate.

Cryptography Essentials

Key term

X.509

The most common standard for digital certificates.

Cryptography Essentials

Key term

Key Archival

Securely storing copies of private keys for recovery.

Cryptography Essentials

Key term

Chain of Trust

Hierarchical relationship from a root CA to end-entity certificates.

Cryptography Essentials

Memory trick

PKI Components and Their Roles

Remember 'CARL's Key' for the main components: CA (Certificate Authority), RA (Registration Authority), CRL (Certificate Revocation List), and Key (for Digital Certificates and Key Archival).

Cryptography Essentials

Exam tip

PKI Components and Their Roles

The SSCP exam frequently tests your understanding of the roles and responsibilities of each PKI component. Pay close attention to the distinct functions of CAs, RAs, and the purpose of CRLs/OCSP. Keywords to spot include 'issuance,' 'revocation,' 'identity verification,' and 'trust anchor.'

Cryptography Essentials

Common mistake

PKI Components and Their Roles

Confusing the roles of a CA and an RA: CAs issue certificates, RAs verify identities.

Cryptography Essentials

Common mistake

PKI Components and Their Roles

Believing CRLs provide real-time revocation status; OCSP is for real-time, CRLs are periodic.

Cryptography Essentials

Common mistake

PKI Components and Their Roles

Thinking all private keys should be archived; private keys for digital signatures should generally not be archived to maintain non-repudiation.

Cryptography Essentials

Key term

Certificate Policy (CP)

A set of rules defining certificate applicability and usage.

Cryptography Essentials

Key term

Certificate Practice Statement (CPS)

Details how a CA implements its Certificate Policy.

Cryptography Essentials

Memory trick

PKI Management and Best Practices

To remember the certificate lifecycle stages: 'RIVUAR' - Request, Issuance, Validation, Usage, Archival, Revocation (or Expiration).

Cryptography Essentials

Exam tip

PKI Management and Best Practices

The exam often tests your understanding of the different PKI roles (CA, RA, End Entity) and their distinct responsibilities. Memorize the difference between CRLs and OCSP, particularly their timeliness and operational models. Also, know that a Certificate Policy (CP) is a high-level document, while a Certificate Practice Statement (CPS) details the implementation.

Cryptography Essentials

Common mistake

PKI Management and Best Practices

Failing to monitor certificate expiration dates, leading to service outages.

Cryptography Essentials

Common mistake

PKI Management and Best Practices

Not having a clear revocation process for compromised keys, leaving systems vulnerable.

Cryptography Essentials

Common mistake

PKI Management and Best Practices

Allowing a single individual to have too many PKI management roles, violating segregation of duties.

Cryptography Essentials

Key term

CIA Triad

Confidentiality, Integrity, Availability – core security goals.

Network and Communications Security

Key term

DMZ (Demilitarized Zone)

Perimeter network protecting internal LAN from untrusted traffic.

Network and Communications Security

Key term

Network Segmentation

Dividing a network into smaller, isolated subnetworks.

Network and Communications Security

Key term

VLAN (Virtual LAN)

Logical network segmentation using software, not physical hardware.

Network and Communications Security

Key term

Defense-in-Depth

Layered security approach using multiple controls.

Network and Communications Security

Memory trick

Network Security Concepts and Architectures

Remember 'DMZ' stands for 'Don't Mess with Zillions' of internal data, so keep public servers there!

Network and Communications Security

Exam tip

Network Security Concepts and Architectures

The SSCP exam frequently tests your understanding of the purpose and placement of a DMZ, as well as the differences and uses of physical vs. logical segmentation. Memorize the core components of the CIA triad.

Network and Communications Security

Common mistake

Network Security Concepts and Architectures

Confusing the DMZ as a completely secure zone; it's a controlled exposure zone.

Network and Communications Security

Common mistake

Network Security Concepts and Architectures

Believing logical segmentation (VLANs) is inherently less secure than physical segmentation; both depend on proper configuration.

Network and Communications Security

Common mistake

Network Security Concepts and Architectures

Underestimating the importance of internal segmentation; a flat internal network is a major vulnerability.

Network and Communications Security

Key term

Firewall

Monitors and controls network traffic based on security rules.

Network and Communications Security

Key term

IDS

Detects suspicious activity or policy violations on a network.

Network and Communications Security

Key term

IPS

Detects and actively prevents malicious network activity.

Network and Communications Security

Key term

NGFW

Advanced firewall with integrated security features.

Network and Communications Security

Key term

WAF

Protects web applications from common web-based attacks.

Network and Communications Security

Key term

VPN Concentrator

Manages multiple encrypted VPN connections.

Network and Communications Security

Key term

DLP

Prevents sensitive data from leaving the organization.

Network and Communications Security

Key term

ACL

Set of rules defining network access permissions.

Network and Communications Security

Memory trick

Implementing and Maintaining Network Security Devices

F-I-P-S: **F**irewalls **I**ntercept, **P**revent, and **S**ecure. Remember their core actions!

Network and Communications Security

Exam tip

Implementing and Maintaining Network Security Devices

The SSCP exam often tests your understanding of the *purpose* and *placement* of different security devices. For example, know that a WAF protects web applications (Layer 7), while a traditional firewall operates at lower layers. Also, differentiate between IDS (detects) and IPS (prevents).

Network and Communications Security

Common mistake

Implementing and Maintaining Network Security Devices

Over-reliance on default configurations without customization.

Network and Communications Security

Common mistake

Implementing and Maintaining Network Security Devices

Neglecting regular firmware updates and signature database updates.

Network and Communications Security

Common mistake

Implementing and Maintaining Network Security Devices

Creating overly permissive firewall rules that expose internal systems.

Network and Communications Security

Key term

WEP

Wired Equivalent Privacy, an old, insecure wireless security protocol.

Network and Communications Security

Key term

WPA2

Wi-Fi Protected Access II, current standard using AES/CCMP for strong encryption.

Network and Communications Security

Key term

WPA3

Wi-Fi Protected Access III, latest standard with enhanced security features.

Network and Communications Security

Key term

802.1X

IEEE standard for port-based network access control, used in WPA2/3-Enterprise.

Network and Communications Security

Key term

SSID

Service Set Identifier, the name of a wireless network.

Network and Communications Security

Key term

Rogue AP

An unauthorized access point installed on a network, often by attackers.

Network and Communications Security

Key term

PMF

Protected Management Frames, a WPA3 feature preventing eavesdropping.

Network and Communications Security

Memory trick

Wireless Security Protocols and Best Practices

W-E-P was Weak, W-P-A was Alright, W-P-A2 is A-OK, W-P-A3 is Awesome!

Network and Communications Security

Exam tip

Wireless Security Protocols and Best Practices

The SSCP exam will definitely test your knowledge of WPA2 and WPA3. Memorize that WPA2 uses AES/CCMP and WPA3 introduces SAE and PMF. Also, know the difference between WPA-Personal (PSK) and WPA-Enterprise (802.1X/RADIUS).

Network and Communications Security

Common mistake

Wireless Security Protocols and Best Practices

Relying solely on disabling SSID broadcasting for security, as it can be easily circumvented.

Network and Communications Security

Common mistake

Wireless Security Protocols and Best Practices

Using default administrator credentials on wireless access points, making them easy targets for attackers.

Network and Communications Security

Common mistake

Wireless Security Protocols and Best Practices

Confusing WPA-Personal (PSK) with WPA-Enterprise (802.1X/RADIUS) and not understanding their different use cases.

Network and Communications Security

Key term

VLAN

Virtual Local Area Network; logically segments a physical network.

Network and Communications Security

Key term

ACL (Access Control List)

Rules defining network traffic permissions.

Network and Communications Security

Key term

Threat Modeling

Proactively identifying potential threats and vulnerabilities.

Network and Communications Security

Key term

Risk Assessment

Evaluating likelihood and impact of identified threats.

Network and Communications Security

Memory trick

Secure Network Design Principles

To remember secure design principles, think: 'S.E.C.U.R.E.': Segmentation, Encryption, Configuration, Updates, Risk Assessment, Education.

Network and Communications Security

Exam tip

Secure Network Design Principles

For the SSCP exam, memorize the core tenets of defense-in-depth and least privilege. Understand that network segmentation is a primary control for limiting lateral movement and containing breaches. Keywords to spot: 'layered security,' 'minimum necessary access,' 'VLANs,' 'firewall rules.'

Network and Communications Security

Common mistake

Secure Network Design Principles

Relying on a single security control instead of a layered approach.

Network and Communications Security

Common mistake

Secure Network Design Principles

Leaving default credentials or unnecessary services enabled on network devices.

Network and Communications Security

Common mistake

Secure Network Design Principles

Failing to segment networks, allowing an attacker to move freely if one part is compromised.

Network and Communications Security

Key term

Hardening

Process of securing a system by reducing its attack surface and vulnerabilities.

Systems and Application Security

Key term

Secure Baseline

A documented set of security configurations for a system or application.

Systems and Application Security

Key term

Defense in Depth

Employing multiple layers of security controls to protect assets.

Systems and Application Security

Key term

Configuration Drift

Deviation of a system's configuration from its intended secure baseline.

Systems and Application Security