Domain
A major topic area covered by the SSCP exam.
Getting Started: Your SSCP Journey
Free knowledge base
Everything from the course in one searchable place: 338 entries. Use it to review before a practice test or look up a word you forgot.
338 results · showing first 300, refine your search
A major topic area covered by the SSCP exam.
Getting Started: Your SSCP Journey
The percentage of exam questions dedicated to a specific domain.
Getting Started: Your SSCP Journey
A converted raw score, adjusted for question difficulty.
Getting Started: Your SSCP Journey
Unscored questions used to evaluate future exam questions.
Getting Started: Your SSCP Journey
The testing provider for the SSCP certification exam.
Getting Started: Your SSCP Journey
Exam question format with one correct answer out of several options.
Getting Started: Your SSCP Journey
To remember the 7 domains: 'SOAR CINCS' - Security Operations, Access Controls, Risk, Cryptography, Incident Response, Network, Systems.
Getting Started: Your SSCP Journey
Memorize the seven SSCP domains and their approximate weightings. Keywords like 'Security Operations', 'Access Controls', and 'Risk Identification' are direct domain names. The exam has 125 questions, 3 hours, and a passing score of 700/1000.
Getting Started: Your SSCP Journey
Ignoring domain weightings and studying all topics equally.
Getting Started: Your SSCP Journey
Not practicing time management, leading to rushing or not finishing the exam.
Getting Started: Your SSCP Journey
Assuming a raw 70% correct answers guarantees a pass due to scaled scoring.
Getting Started: Your SSCP Journey
Preferred method for absorbing and processing information.
Getting Started: Your SSCP Journey
A structured schedule for organizing study activities.
Getting Started: Your SSCP Journey
Materials provided by the certification body (ISC)².
Getting Started: Your SSCP Journey
Simulated tests to assess knowledge and identify gaps.
Getting Started: Your SSCP Journey
Applying theoretical knowledge in practical scenarios.
Getting Started: Your SSCP Journey
Retrieving information from memory, like flashcards.
Getting Started: Your SSCP Journey
Reviewing material at increasing intervals over time.
Getting Started: Your SSCP Journey
SSCP: S-tudy S-martly, C-onstantly P-ractice!
Getting Started: Your SSCP Journey
The SSCP exam requires a practitioner-level understanding. Don't just memorize definitions; be prepared to apply concepts to scenarios. Keywords like 'implement,' 'configure,' 'identify the best,' and 'troubleshoot' indicate application-based questions.
Getting Started: Your SSCP Journey
Cramming all material right before the exam instead of consistent, spaced study.
Getting Started: Your SSCP Journey
Relying solely on memorization without understanding the 'why' or practical application.
Getting Started: Your SSCP Journey
Neglecting practice exams, leading to unfamiliarity with the question format and time constraints.
Getting Started: Your SSCP Journey
Users get minimum access needed for their job.
Access Controls Fundamentals
Dividing critical tasks among multiple individuals.
Access Controls Fundamentals
Creating and granting user accounts and access.
Access Controls Fundamentals
Revoking user access and disabling accounts.
Access Controls Fundamentals
Accumulation of unnecessary access rights over time.
Access Controls Fundamentals
Periodic audit of user permissions and access.
Access Controls Fundamentals
Single authority manages all access rights.
Access Controls Fundamentals
Access management distributed to resource owners.
Access Controls Fundamentals
L.A.S.T. P.A.R.T. for Access Control: Least privilege, Administration, Separation of duties, Timely deprovisioning, Provisioning, Auditing, Review, Training.
Access Controls Fundamentals
The exam often tests your understanding of the access control lifecycle, emphasizing the importance of both initial implementation and ongoing maintenance. Look for keywords like 'least privilege,' 'separation of duties,' 'provisioning,' and 'deprovisioning' in scenarios.
Access Controls Fundamentals
Failing to promptly deprovision access for terminated employees.
Access Controls Fundamentals
Granting excessive permissions (violating least privilege) for convenience.
Access Controls Fundamentals
Neglecting regular access control reviews, leading to 'permission creep'.
Access Controls Fundamentals
Verifying a user's identity to ensure they are who they claim to be.
Access Controls Fundamentals
Multi-Factor Authentication; requiring two or more distinct factors.
Access Controls Fundamentals
Authentication based on unique physical or behavioral human traits.
Access Controls Fundamentals
A secret string of characters used for authentication (something you know).
Access Controls Fundamentals
A physical or digital device generating codes (something you have).
Access Controls Fundamentals
Network authentication protocol using secret-key cryptography for services.
Access Controls Fundamentals
Centralized AAA protocol for network access and authentication.
Access Controls Fundamentals
Adjusts authentication requirements based on risk factors.
Access Controls Fundamentals
K-H-A: Know, Have, Are. The three factors of authentication, easy as K-H-A!
Access Controls Fundamentals
The SSCP exam frequently tests your understanding of the three authentication factors (something you know, something you have, something you are) and their application in Multi-Factor Authentication (MFA). Be ready to identify examples of each factor and explain why MFA is superior to single-factor methods.
Access Controls Fundamentals
Confusing authentication (who you are) with authorization (what you can do).
Access Controls Fundamentals
Underestimating the importance of combining multiple distinct factors for strong security.
Access Controls Fundamentals
Believing biometrics are infallible and cannot be spoofed or have privacy implications.
Access Controls Fundamentals
Determining what an authenticated user or process is permitted to do.
Access Controls Fundamentals
List of permissions attached to an object, specifying who can access it.
Access Controls Fundamentals
A token held by a subject that grants specific permissions to an object.
Access Controls Fundamentals
Access control where permissions are associated with roles, and users are assigned to roles.
Access Controls Fundamentals
Access control based on a set of predefined rules or policies.
Access Controls Fundamentals
Access control based on attributes of subject, object, action, and environment.
Access Controls Fundamentals
Users should only be granted the minimum permissions necessary to perform their job.
Access Controls Fundamentals
ACLs are like a guest list for a party (on the door). RBAC is like giving everyone a job title (Manager, Staff) with specific duties. ABAC is like a bouncer checking your ID, your outfit, and the time of day before letting you in.
Access Controls Fundamentals
For the SSCP exam, memorize the core definitions and distinctions between ACLs, RBAC, and ABAC. Pay close attention to how each model addresses scalability and granularity of control.
Access Controls Fundamentals
Confusing authorization with authentication; they are distinct steps in access control.
Access Controls Fundamentals
Over-privileging users or roles, violating the principle of least privilege.
Access Controls Fundamentals
Not periodically reviewing and updating authorization policies as roles and responsibilities change.
Access Controls Fundamentals
Framework for managing digital identities and controlling resource access.
Access Controls Fundamentals
System that creates, maintains, and manages identity information.
Access Controls Fundamentals
System or application that relies on an IdP for user authentication.
Access Controls Fundamentals
Linking user identities across multiple, disparate security domains.
Access Controls Fundamentals
Allows users to authenticate once to access multiple applications.
Access Controls Fundamentals
IAM: 'I'd Always Manage' identities, 'A'uthenticate users, and 'M'anage access.
Access Controls Fundamentals
Memorize the core components of IAM: Identity Management, Authentication, and Authorization. The SSCP exam often tests your ability to differentiate between these functions and their role in a complete access control solution.
Access Controls Fundamentals
Confusing authentication with authorization; authentication is 'who you are,' authorization is 'what you can do.'
Access Controls Fundamentals
Neglecting deprovisioning, which leaves dormant accounts as security risks.
Access Controls Fundamentals
Failing to regularly review and update user access rights as roles change.
Access Controls Fundamentals
Recording events within systems for security analysis.
Security Operations and Administration
Continuously reviewing logs and activities for anomalies.
Security Operations and Administration
Security Information and Event Management; aggregates and analyzes logs.
Security Operations and Administration
A safeguard designed to stop incidents from occurring.
Security Operations and Administration
A safeguard designed to identify incidents that have occurred.
Security Operations and Administration
Formal process to manage system modifications securely.
Security Operations and Administration
Systematic tracking and securing of organizational assets.
Security Operations and Administration
Security Operations Center; centralizes security monitoring and response.
Security Operations and Administration
To remember the types of security controls, think 'P.D.C.D.' - People Detect Crime Daily. P=Preventive, D=Detective, C=Corrective, D=Deterrent.
Security Operations and Administration
The SSCP exam frequently tests your ability to differentiate between types of security controls (preventive, detective, corrective, deterrent). Memorize examples for each category and understand their primary purpose. Also, understand the components and purpose of a SOC.
Security Operations and Administration
Failing to regularly review and update logging configurations, leading to missed critical events.
Security Operations and Administration
Implementing security controls without proper testing, causing operational disruptions or leaving gaps.
Security Operations and Administration
Bypassing change control processes for 'urgent' changes, often introducing new vulnerabilities.
Security Operations and Administration
High-level, mandatory statements defining an organization's security posture.
Security Operations and Administration
Specific, mandatory requirements for hardware, software, or configurations.
Security Operations and Administration
Detailed, step-by-step instructions for performing a specific task.
Security Operations and Administration
Recommendations or suggestions for best practices; not mandatory.
Security Operations and Administration
Minimum security configurations applied to systems or applications.
Security Operations and Administration
Framework ensuring security aligns with business objectives and manages risk.
Security Operations and Administration
Educating employees on security policies, procedures, and threats.
Security Operations and Administration
P-S-B-P-G: **P**eople **S**hould **B**e **P**rotected by **G**overnance. (Policies, Standards, Baselines, Procedures, Guidelines)
Security Operations and Administration
The SSCP exam frequently tests your ability to distinguish between policies, standards, procedures, and guidelines. Keywords to spot: 'high-level statement' (policy), 'specific mandatory requirement' (standard), 'step-by-step instructions' (procedure), 'recommendation' (guideline).
Security Operations and Administration
Confusing a policy with a procedure: Policies are 'what' to do, procedures are 'how' to do it.
Security Operations and Administration
Underestimating the importance of security awareness: Technical controls are only as strong as the weakest human link.
Security Operations and Administration
Treating security documentation as a one-time task: Policies, standards, and procedures need regular review and updates.
Security Operations and Administration
Automated process to identify known security weaknesses.
Security Operations and Administration
Simulated attack to exploit vulnerabilities and assess impact.
Security Operations and Administration
Pen test with no prior knowledge of the target system.
Security Operations and Administration
Pen test with full knowledge of the target system.
Security Operations and Administration
Pen test with partial knowledge of the target system.
Security Operations and Administration
Systematic evaluation against established security criteria.
Security Operations and Administration
Process of fixing identified security vulnerabilities.
Security Operations and Administration
Common Vulnerabilities and Exposures, a list of public vulnerabilities.
Security Operations and Administration
V-P-A-R-R: Vulnerability Scan, Pen Test, Audit, Report, Remediate. Remember the cycle!
Security Operations and Administration
The SSCP exam often distinguishes between vulnerability scanning (identifying weaknesses) and penetration testing (exploiting weaknesses). Be able to clearly define each and their respective purposes.
Security Operations and Administration
Confusing vulnerability scanning with penetration testing. Scans identify, pen tests exploit.
Security Operations and Administration
Failing to define a clear scope and rules of engagement before conducting any test.
Security Operations and Administration
Not following up on remediation efforts with retesting to verify fixes.
Security Operations and Administration
A structured approach to managing security breaches and cyberattacks.
Security Operations and Administration
Actions taken to prevent an incident from spreading further.
Security Operations and Administration
Removing the root cause of an incident and malicious components.
Security Operations and Administration
Restoring affected systems and services to normal operation.
Security Operations and Administration
Reviewing an incident to identify lessons learned and improve processes.
Security Operations and Administration
Plans to restore business operations after a catastrophic event.
Security Operations and Administration
Review process after an incident to improve future responses.
Security Operations and Administration
Prepare, Detect, Contain, Eradicate, Recover, Post-mortem (PDCREP) – like a doctor's visit for your systems!
Security Operations and Administration
The exam expects you to know the distinct phases of the incident response lifecycle and what activities occur in each. Pay close attention to the order and purpose of containment, eradication, and recovery.
Security Operations and Administration
Skipping documentation during any phase of the incident response process.
Security Operations and Administration
Failing to perform a 'lessons learned' review after an incident, missing opportunities for improvement.
Security Operations and Administration
Confusing incident response with disaster recovery; they address different scales of events.
Security Operations and Administration
The likelihood of a threat exploiting a vulnerability and causing harm.
Risk Identification, Monitoring, and Analysis
A potential danger that could exploit a vulnerability.
Risk Identification, Monitoring, and Analysis
A weakness in a system or process that a threat could exploit.
Risk Identification, Monitoring, and Analysis
The magnitude of harm resulting from a security incident.
Risk Identification, Monitoring, and Analysis
The amount of risk an organization is willing to accept.
Risk Identification, Monitoring, and Analysis
The risk that remains after implementing security controls.
Risk Identification, Monitoring, and Analysis
Actions taken to reduce the likelihood or impact of a risk.
Risk Identification, Monitoring, and Analysis
A structured approach for managing risk within an organization.
Risk Identification, Monitoring, and Analysis
Remember 'TV IR': Threats create Vulnerabilities, leading to an Impact, which defines the Risk. It's a chain reaction!
Risk Identification, Monitoring, and Analysis
The SSCP exam will test your understanding of the core definitions of risk, threat, vulnerability, and impact. Be prepared to distinguish between them and identify examples of each. Also, know the general steps of common frameworks like NIST RMF.
Risk Identification, Monitoring, and Analysis
Confusing 'threat' with 'vulnerability' – a threat is external (e.g., hacker), a vulnerability is internal (e.g., unpatched system).
Risk Identification, Monitoring, and Analysis
Believing all risk can be eliminated; the goal is to reduce it to an acceptable level (residual risk).
Risk Identification, Monitoring, and Analysis
Failing to continuously monitor risks, assuming controls remain effective indefinitely.
Risk Identification, Monitoring, and Analysis
Verifying that vulnerabilities have been successfully mitigated.
Risk Identification, Monitoring, and Analysis
A scan result indicating a vulnerability that doesn't exist.
Risk Identification, Monitoring, and Analysis
Examination of source code for security flaws.
Risk Identification, Monitoring, and Analysis
To remember the assessment types, think 'VAPOR': Vulnerability scans, Audits, Penetration tests, fOrensics (though not covered here), and code Reviews.
Risk Identification, Monitoring, and Analysis
The SSCP exam will often ask you to differentiate between vulnerability scanning and penetration testing. Remember: scans identify known weaknesses, while pen tests exploit them to demonstrate impact. Also, know that a 'credentialed scan' means the scanner logs in, providing deeper insight.
Risk Identification, Monitoring, and Analysis
Confusing vulnerability scanning with penetration testing: Scans find, pen tests exploit.
Risk Identification, Monitoring, and Analysis
Neglecting remediation and retesting: Finding vulnerabilities is only half the battle; fixing and verifying are crucial.
Risk Identification, Monitoring, and Analysis
Failing to define scope before an assessment: This can lead to legal issues or wasted effort on out-of-scope systems.
Risk Identification, Monitoring, and Analysis
A chronological record of events and activities on a system.
Risk Identification, Monitoring, and Analysis
A significant occurrence within a system or network.
Risk Identification, Monitoring, and Analysis
Linking related events from different sources to identify patterns.
Risk Identification, Monitoring, and Analysis
Identifying deviations from normal behavior in log data.
Risk Identification, Monitoring, and Analysis
Forensic data indicating a potential intrusion on a system.
Risk Identification, Monitoring, and Analysis
Establishing a normal activity pattern to detect deviations.
Risk Identification, Monitoring, and Analysis
A standard protocol for sending system log messages.
Risk Identification, Monitoring, and Analysis
To remember the log analysis process: 'C-A-R-E': Collect, Analyze, Report, Escalate. It helps you CARE for your logs!
Risk Identification, Monitoring, and Analysis
The exam often tests your understanding of *what* type of information is found in *which* log source (e.g., firewall logs for blocked traffic, OS logs for user authentications). Memorize common log types and their primary purpose.
Risk Identification, Monitoring, and Analysis
Ignoring alerts from SIEM systems, assuming they are false positives.
Risk Identification, Monitoring, and Analysis
Failing to centralize logs, making analysis and correlation extremely difficult.
Risk Identification, Monitoring, and Analysis
Not establishing a baseline of normal network and system activity, leading to missed anomalies.
Risk Identification, Monitoring, and Analysis
Actionable, evidence-based knowledge about cyber threats.
Risk Identification, Monitoring, and Analysis
Forensic data points indicating a potential security breach.
Risk Identification, Monitoring, and Analysis
Methods used by threat actors in cyberattacks.
Risk Identification, Monitoring, and Analysis
Standardized language for expressing cyber threat information.
Risk Identification, Monitoring, and Analysis
Protocol for exchanging cyber threat intelligence over HTTPS.
Risk Identification, Monitoring, and Analysis
Information Sharing and Analysis Center/Organization.
Risk Identification, Monitoring, and Analysis
Intelligence gathered from publicly available sources.
Risk Identification, Monitoring, and Analysis
To remember the types of intelligence, think 'STOP': Strategic, Tactical, Operational, Technical. STOP and think about the threat!
Risk Identification, Monitoring, and Analysis
The SSCP exam will test your understanding of the types of threat intelligence (strategic, tactical, operational, technical) and how they are applied. Memorize the purpose of STIX and TAXII as standards for sharing.
Risk Identification, Monitoring, and Analysis
Confusing raw data or simple IOCs with fully analyzed threat intelligence. Intelligence provides context and actionability.
Risk Identification, Monitoring, and Analysis
Failing to integrate threat intelligence into security tools and processes, making it just data, not actionable insight.
Risk Identification, Monitoring, and Analysis
Relying solely on one source of threat intelligence; a diverse set of sources provides a more complete picture.
Risk Identification, Monitoring, and Analysis
Structured process for handling security incidents.
Incident Response and Recovery
Establishing policies, tools, and training proactively.
Incident Response and Recovery
Detecting and verifying a security incident.
Incident Response and Recovery
Limiting the scope and impact of an incident.
Incident Response and Recovery
Removing the root cause and malicious components.
Incident Response and Recovery
Restoring systems and services to operation.
Incident Response and Recovery
PICERL: **P**reparation, **I**dentification, **C**ontainment, **E**radication, **R**ecovery, **L**essons Learned. Remember it like 'Pick a girl!' for short.
Incident Response and Recovery
The exam frequently tests the order of the incident response lifecycle phases. Memorize the NIST phases: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. Keywords to spot: 'first step,' 'next action,' 'post-incident activity.'
Incident Response and Recovery
Skipping the preparation phase, leading to disorganized and ineffective responses.
Incident Response and Recovery
Failing to properly contain an incident, allowing it to spread and cause more damage.
Incident Response and Recovery
Neglecting the 'Lessons Learned' phase, which prevents continuous improvement and leaves vulnerabilities open.
Incident Response and Recovery
Structured process to manage security breaches from detection to recovery.
Incident Response and Recovery
Scientific process of collecting, analyzing, and presenting digital evidence.
Incident Response and Recovery
Documented history of evidence handling to ensure its integrity and authenticity.
Incident Response and Recovery
Data that is lost when a computer is powered off, like RAM contents.
Incident Response and Recovery
Hardware or software tool preventing alteration of storage media during forensics.
Incident Response and Recovery
PICERL: **P**reparation, **I**dentification, **C**ontainment, **E**radication, **R**ecovery, **L**essons Learned – the steps of incident handling, like a 'pickle' you need to handle carefully!
Incident Response and Recovery
The SSCP exam expects you to know the distinct stages of the incident handling process (Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity) and the fundamental principles of digital forensics, especially chain of custody and evidence integrity. Look for questions differentiating immediate response from deep analysis.
Incident Response and Recovery
Confusing incident handling (immediate action) with forensics (deep investigation).
Incident Response and Recovery
Failing to maintain a proper chain of custody, which can invalidate evidence.
Incident Response and Recovery
Modifying original evidence during collection, making it inadmissible in legal proceedings.
Incident Response and Recovery
Maximum tolerable time for a system/application to be down.
Incident Response and Recovery
Maximum tolerable data loss measured in time.
Incident Response and Recovery
Fully equipped alternate facility for immediate recovery.
Incident Response and Recovery
Partially equipped alternate facility requiring some setup.
Incident Response and Recovery
Basic facility with power/cooling, no equipment.
Incident Response and Recovery
Identifies critical functions and impact of their loss.
Incident Response and Recovery
DRP testing method involving verbal walkthroughs.
Incident Response and Recovery
To remember the DR sites from fastest to slowest: 'Hot' (ready to go), 'Warm' (needs a little heat), 'Cold' (frozen, needs thawing).
Incident Response and Recovery
The SSCP exam will often test your understanding of the differences between RTO and RPO, and how they influence the choice of disaster recovery strategies (hot, warm, cold sites). Memorize the characteristics of each site type.
Incident Response and Recovery
Confusing DRP with BCP (DRP is IT-focused, BCP is broader business focus).
Incident Response and Recovery
Failing to regularly test and update the DRP.
Incident Response and Recovery
Not aligning the DRP with the organization's RTO and RPO.
Incident Response and Recovery
Overall strategy to ensure business functions continue during disruptions.
Incident Response and Recovery
Component of BCP focused on restoring IT systems after a disaster.
Incident Response and Recovery
Secondary location for operations if primary site is unavailable.
Incident Response and Recovery
BCP: 'Be Continuously Prepared!' - The 'P' reminds you it's about 'Planning' for 'Preparedness.'
Incident Response and Recovery
The exam often tests the difference between BCP and DRP. Remember, BCP is the 'what if the business can't run?' and DRP is 'what if IT systems are broken?'. Also, know that BIA is the foundational first step of BCP.
Incident Response and Recovery
Confusing BCP with DRP; BCP is broader.
Incident Response and Recovery
Failing to regularly test and update the BCP, making it obsolete.
Incident Response and Recovery
Not involving all relevant stakeholders in BCP development and testing.
Incident Response and Recovery
Ensuring data is accessible only to authorized entities.
Cryptography Essentials
Ensuring data has not been altered or tampered with.
Cryptography Essentials
Verifying the identity of a user or origin of data.
Cryptography Essentials
Preventing denial of an action or communication.
Cryptography Essentials
Uses a single shared key for encryption and decryption.
Cryptography Essentials
Uses a public/private key pair for encryption/decryption.
Cryptography Essentials
One-way function creating a fixed-size digest for integrity.
Cryptography Essentials
Ensures authenticity, integrity, and non-repudiation.
Cryptography Essentials
CIAAN: Cryptography's goals are Confidentiality, Integrity, Authenticity, Availability, and Non-repudiation. Remember 'CIAAN' as 'See-Ann' for all your security needs!
Cryptography Essentials
Memorize the core cryptographic principles (CIAAN: Confidentiality, Integrity, Authenticity, Availability, Non-repudiation) and which cryptographic mechanisms (e.g., encryption, hashing, digital signatures) primarily address each. The exam often tests your ability to match a security goal to the appropriate cryptographic tool.
Cryptography Essentials
Confusing the use cases for symmetric vs. asymmetric encryption (e.g., using asymmetric for bulk data encryption).
Cryptography Essentials
Believing hashing provides confidentiality (it only provides integrity).
Cryptography Essentials
Forgetting that digital signatures provide non-repudiation, not just authenticity and integrity.
Cryptography Essentials
A system for managing the lifecycle of cryptographic keys.
Cryptography Essentials
A physical device that safeguards and manages digital keys.
Cryptography Essentials
The practice of regularly changing cryptographic keys.
Cryptography Essentials
Storing a copy of a cryptographic key for recovery or legal access.
Cryptography Essentials
Encrypts an entire database at the file system level without application changes.
Cryptography Essentials
Encrypts all data on a disk, including the operating system.
Cryptography Essentials
Ability of different systems to work together using cryptography.
Cryptography Essentials
KISS: Keep It Simple, Secure, and Symmetric (when possible for performance).
Cryptography Essentials
The exam often tests your understanding of key management challenges and best practices, especially regarding key generation, storage, and revocation. Remember that HSMs are the gold standard for key protection.
Cryptography Essentials
Using weak or default cryptographic keys, making systems vulnerable to brute-force attacks.
Cryptography Essentials
Failing to regularly rotate cryptographic keys, increasing the risk if a key is compromised.
Cryptography Essentials
Not properly securing key storage, leaving keys exposed to unauthorized access.
Cryptography Essentials
Trusted entity issuing and managing digital certificates.
Cryptography Essentials
Verifies identity of certificate requesters for the CA.
Cryptography Essentials
Electronic document binding a public key to an identity.
Cryptography Essentials
List of digital certificates that have been revoked.
Cryptography Essentials
Real-time protocol to check the revocation status of a certificate.
Cryptography Essentials
The most common standard for digital certificates.
Cryptography Essentials
Securely storing copies of private keys for recovery.
Cryptography Essentials
Hierarchical relationship from a root CA to end-entity certificates.
Cryptography Essentials
Remember 'CARL's Key' for the main components: CA (Certificate Authority), RA (Registration Authority), CRL (Certificate Revocation List), and Key (for Digital Certificates and Key Archival).
Cryptography Essentials
The SSCP exam frequently tests your understanding of the roles and responsibilities of each PKI component. Pay close attention to the distinct functions of CAs, RAs, and the purpose of CRLs/OCSP. Keywords to spot include 'issuance,' 'revocation,' 'identity verification,' and 'trust anchor.'
Cryptography Essentials
Confusing the roles of a CA and an RA: CAs issue certificates, RAs verify identities.
Cryptography Essentials
Believing CRLs provide real-time revocation status; OCSP is for real-time, CRLs are periodic.
Cryptography Essentials
Thinking all private keys should be archived; private keys for digital signatures should generally not be archived to maintain non-repudiation.
Cryptography Essentials
A set of rules defining certificate applicability and usage.
Cryptography Essentials
Details how a CA implements its Certificate Policy.
Cryptography Essentials
To remember the certificate lifecycle stages: 'RIVUAR' - Request, Issuance, Validation, Usage, Archival, Revocation (or Expiration).
Cryptography Essentials
The exam often tests your understanding of the different PKI roles (CA, RA, End Entity) and their distinct responsibilities. Memorize the difference between CRLs and OCSP, particularly their timeliness and operational models. Also, know that a Certificate Policy (CP) is a high-level document, while a Certificate Practice Statement (CPS) details the implementation.
Cryptography Essentials
Failing to monitor certificate expiration dates, leading to service outages.
Cryptography Essentials
Not having a clear revocation process for compromised keys, leaving systems vulnerable.
Cryptography Essentials
Allowing a single individual to have too many PKI management roles, violating segregation of duties.
Cryptography Essentials
Confidentiality, Integrity, Availability – core security goals.
Network and Communications Security
Perimeter network protecting internal LAN from untrusted traffic.
Network and Communications Security
Dividing a network into smaller, isolated subnetworks.
Network and Communications Security
Logical network segmentation using software, not physical hardware.
Network and Communications Security
Layered security approach using multiple controls.
Network and Communications Security
Remember 'DMZ' stands for 'Don't Mess with Zillions' of internal data, so keep public servers there!
Network and Communications Security
The SSCP exam frequently tests your understanding of the purpose and placement of a DMZ, as well as the differences and uses of physical vs. logical segmentation. Memorize the core components of the CIA triad.
Network and Communications Security
Confusing the DMZ as a completely secure zone; it's a controlled exposure zone.
Network and Communications Security
Believing logical segmentation (VLANs) is inherently less secure than physical segmentation; both depend on proper configuration.
Network and Communications Security
Underestimating the importance of internal segmentation; a flat internal network is a major vulnerability.
Network and Communications Security
Monitors and controls network traffic based on security rules.
Network and Communications Security
Detects suspicious activity or policy violations on a network.
Network and Communications Security
Detects and actively prevents malicious network activity.
Network and Communications Security
Advanced firewall with integrated security features.
Network and Communications Security
Protects web applications from common web-based attacks.
Network and Communications Security
Manages multiple encrypted VPN connections.
Network and Communications Security
Prevents sensitive data from leaving the organization.
Network and Communications Security
Set of rules defining network access permissions.
Network and Communications Security
F-I-P-S: **F**irewalls **I**ntercept, **P**revent, and **S**ecure. Remember their core actions!
Network and Communications Security
The SSCP exam often tests your understanding of the *purpose* and *placement* of different security devices. For example, know that a WAF protects web applications (Layer 7), while a traditional firewall operates at lower layers. Also, differentiate between IDS (detects) and IPS (prevents).
Network and Communications Security
Over-reliance on default configurations without customization.
Network and Communications Security
Neglecting regular firmware updates and signature database updates.
Network and Communications Security
Creating overly permissive firewall rules that expose internal systems.
Network and Communications Security
Wired Equivalent Privacy, an old, insecure wireless security protocol.
Network and Communications Security
Wi-Fi Protected Access II, current standard using AES/CCMP for strong encryption.
Network and Communications Security
Wi-Fi Protected Access III, latest standard with enhanced security features.
Network and Communications Security
IEEE standard for port-based network access control, used in WPA2/3-Enterprise.
Network and Communications Security
Service Set Identifier, the name of a wireless network.
Network and Communications Security
An unauthorized access point installed on a network, often by attackers.
Network and Communications Security
Protected Management Frames, a WPA3 feature preventing eavesdropping.
Network and Communications Security
W-E-P was Weak, W-P-A was Alright, W-P-A2 is A-OK, W-P-A3 is Awesome!
Network and Communications Security
The SSCP exam will definitely test your knowledge of WPA2 and WPA3. Memorize that WPA2 uses AES/CCMP and WPA3 introduces SAE and PMF. Also, know the difference between WPA-Personal (PSK) and WPA-Enterprise (802.1X/RADIUS).
Network and Communications Security
Relying solely on disabling SSID broadcasting for security, as it can be easily circumvented.
Network and Communications Security
Using default administrator credentials on wireless access points, making them easy targets for attackers.
Network and Communications Security
Confusing WPA-Personal (PSK) with WPA-Enterprise (802.1X/RADIUS) and not understanding their different use cases.
Network and Communications Security
Virtual Local Area Network; logically segments a physical network.
Network and Communications Security
Rules defining network traffic permissions.
Network and Communications Security
Proactively identifying potential threats and vulnerabilities.
Network and Communications Security
Evaluating likelihood and impact of identified threats.
Network and Communications Security
To remember secure design principles, think: 'S.E.C.U.R.E.': Segmentation, Encryption, Configuration, Updates, Risk Assessment, Education.
Network and Communications Security
For the SSCP exam, memorize the core tenets of defense-in-depth and least privilege. Understand that network segmentation is a primary control for limiting lateral movement and containing breaches. Keywords to spot: 'layered security,' 'minimum necessary access,' 'VLANs,' 'firewall rules.'
Network and Communications Security
Relying on a single security control instead of a layered approach.
Network and Communications Security
Leaving default credentials or unnecessary services enabled on network devices.
Network and Communications Security
Failing to segment networks, allowing an attacker to move freely if one part is compromised.
Network and Communications Security
Process of securing a system by reducing its attack surface and vulnerabilities.
Systems and Application Security
A documented set of security configurations for a system or application.
Systems and Application Security
Employing multiple layers of security controls to protect assets.
Systems and Application Security
Deviation of a system's configuration from its intended secure baseline.
Systems and Application Security