All certifications / SSCP / Cheat sheet
SSCP Oct 2025 outline cheat sheet
Domain 1: Security concepts & practices (16%)
Exam tips
- Memorize the order: protect society first, then act honorably and legally, then serve principals, then advance the profession. When two canons conflict, choose the answer that satisfies the higher-priority, lower-numbered canon (canon one beats canon three).
- Symmetric tools such as HMAC give integrity and authenticity but never non-repudiation, because the key is shared. If the question asks for non-repudiation, look for a digital signature using a private key.
- Separation of duties prevents fraud by requiring collusion; job rotation and mandatory vacation detect it. If the question says 'no single person can complete the transaction', the answer is separation of duties.
- Due diligence = investigate and verify (knowing); due care = implement and act (doing). If the scenario is about research, assessment or checking, choose diligence; if it is about putting a reasonable protection in place, choose care.
- Answer two questions for any control: how is it implemented (technical, administrative, physical) and what does it do (prevent, detect, correct, deter, direct, compensate). The exam may ask for either, so read which dimension the question wants.
- Verification means proving a control works, not just that it exists. If an answer choice actually tests the function (for example, attempting a denied connection or reviewing whether logs arrive), it usually beats one that merely confirms installation.
- The data owner, not IT, decides classification and approves access. Retention is driven first by legal and regulatory requirements, and keeping data longer than required is a risk, not a safe default.
- Degaussing does nothing to SSDs or flash. For solid-state media choose cryptographic erase, the manufacturer's sanitize command or physical destruction. And remember: owners decide, custodians implement.
- Emergency changes still require authorization and after-the-fact documentation and review. An answer that skips approval entirely or never documents the change is wrong even in a crisis.
- Completion percentage measures attendance, not effectiveness. Look for behavioral metrics: simulation click and report rates over time, and real incidents reported by staff.
- Human life always comes first. If an answer choice makes emergency exits fail-secure or blocks evacuation to protect equipment, it is wrong.
Key terms
- Preamble
- The opening statement of the ISC2 Code of Ethics explaining why high ethical standards are required and that adherence is a condition of certification.
- Canon
- One of the four ordered principles of the code; when they conflict, the earlier canon takes priority.
- Principal
- The person or organization you provide professional services to, such as an employer or client.
- Ethics complaint
- A formal, specific allegation filed with ISC2 that a member violated the code, reviewed by an ethics committee.
- Confidentiality
- Preventing disclosure of information to unauthorized people, processes or systems.
- Integrity
- Protecting data and systems from unauthorized or accidental modification and making changes detectable.
- Availability
- Ensuring authorized users have timely, reliable access to systems and data.
- Non-repudiation
- Assurance that a party cannot credibly deny having performed an action, typically achieved with a private-key digital signature and reliable logs.
- Privacy
- An individual's right to control how their personal information is collected, used, shared and retained.
- Least privilege
- Granting only the minimum access rights needed to perform a task, for no longer than needed.
- Need to know
- Restricting access to specific information to people whose current duties require it, even if they are otherwise cleared.
- Separation of duties
- Dividing a critical process among multiple people so that no one person can complete it alone, requiring collusion to commit fraud.
- Mandatory vacation
- Requiring staff to take time off so others perform their duties, which can reveal hidden fraud or errors.
- Job rotation
- Periodically moving staff between roles to reduce single-person dependency and help detect misconduct.
- Defense in depth
- Layering multiple, varied security controls so that the failure of one does not expose the asset.
- Due care
- Taking the actions a reasonable and prudent person would take to protect assets; the doing.
- Due diligence
- Researching, assessing and continuously verifying risks and controls; the investigating and checking.
- Negligence
- Failure to exercise due care, which can create legal liability after an incident.
- Technical control
- A safeguard implemented through hardware or software, such as a firewall or encryption.
- Administrative control
- A safeguard based on policy, procedure or personnel management, such as training or background checks.
- Physical control
- A safeguard that protects facilities and hardware, such as locks, fences and guards.
- Compensating control
- An alternative control that provides comparable protection when the primary control cannot be implemented.
- Deterrent control
- A control that discourages an attack without physically preventing it, such as a warning banner.
- Security baseline
- A documented minimum set of security configurations that all systems of a given type must meet.
- Configuration drift
- Gradual divergence of a system's actual settings from its approved baseline over time.
- Golden image
- A preconfigured, hardened system image used to build new systems consistently to the baseline.
- Exception
- A documented, approved and usually time-limited deviation from a baseline or policy.
- Asset inventory
- A maintained record of an organization's hardware, software, data and services with key attributes such as owner and location.
- Asset owner
- The person or role accountable for an asset, who decides its classification and approves access.
- Classification
- Labeling assets by sensitivity and value so that protections and handling are proportional.
- Retention schedule
- A policy listing how long each type of record must be kept and how it is disposed of afterward.
- Legal hold
- An instruction to preserve specific data and suspend normal deletion because of expected litigation or investigation.
- Data owner
- The accountable business role that classifies data, sets protection requirements and approves access.
- Data custodian
- The role, usually IT, that implements and maintains the controls the owner specified, such as backups and access settings.
- Clear
- Sanitization using logical techniques such as overwriting to prevent recovery with ordinary tools.
- Purge
- Sanitization that makes recovery infeasible even with laboratory techniques, such as cryptographic erase or degaussing magnetic media.
- Destroy
- Physically rendering media unusable, such as shredding or incineration, so data cannot be recovered.
- Request for change (RFC)
- A formal proposal describing a change, its reason, scope, schedule and risk, submitted for evaluation.
- Change advisory board (CAB)
- A group of stakeholders that reviews and approves significant changes.
- Backout plan
- Documented, tested steps to reverse a change and restore the prior state if it fails.
- Emergency change
- An urgent change approved and implemented through an expedited process, then documented and reviewed afterward.
- Configuration management database (CMDB)
- A repository of configuration items, their attributes, relationships and approved states.
- Security awareness
- Broad, ongoing activity that keeps all staff alert to security risks and expected behaviors.
- Security training
- Role-specific instruction that builds the skills a person needs to perform duties securely.
- Phishing simulation
- An authorized test in which harmless, realistic phishing messages are sent to staff to measure and improve their responses.
- Report rate
- The share of users who report a suspicious or simulated message, a key measure of program effectiveness.
- Access control vestibule
- A small space with two interlocking doors that allows only one authorized person through at a time, preventing tailgating; formerly called a mantrap.
- Tailgating
- Following an authorized person through a secured entrance without their knowledge; piggybacking is the same with their consent.
- Fail-safe
- A lock that opens when power fails, prioritizing life safety.
- Fail-secure
- A lock that stays locked when power fails, prioritizing asset protection.
- Visitor log
- A record of each visitor's identity, host, purpose and entry and exit times.
Domain 2: Access controls (15%)
Exam tips
- Count factor types, not steps. Two items from the same category, such as password plus PIN, are never MFA.
- Type I = false rejection (FRR), Type II = false acceptance (FAR). FAR is the security-critical error. Lower CER means a better system.
- Kerberos questions often hinge on time synchronization and the KDC as a single point of failure. If authentication fails with correct passwords, think clock skew.
- OAuth 2.0 is authorization (delegated access), not authentication. If the question needs to know who the user is, the answer is SAML or OpenID Connect.
- Zero trust means location grants no trust: being on the internal network is not a reason to allow access. Look for answers that verify identity and device for every request and apply least privilege.
- Deprovisioning is where the exam finds most failures. The best answer is usually timely, automated removal triggered by HR, with accounts disabled first and deleted later.
- Access reviews are detective controls for privilege creep; the fix happens only when revoked access is actually removed and verified. The reviewer should be someone who knows the business need, usually the manager or data owner.
- Administrators should never do daily work such as email with their privileged account. Look for answers that separate standard and admin accounts, require MFA and use time-limited elevation.
- Labels and clearances point to MAC; owner discretion points to DAC; context such as time, location and device combined with user attributes points to ABAC. Firewall ACLs are rule-based, not role-based.
- Physical access usually defeats logical protection, so answers that combine encryption and port controls with locked spaces tend to be best. Remember that badge systems are also IT systems needing logical security.
Key terms
- Authentication factor
- A category of evidence used to prove identity: something you know, have or are.
- Multifactor authentication (MFA)
- Authentication requiring two or more different factor types.
- Multi-step authentication
- Authentication in several sequential steps, which is not MFA unless the steps use different factor types.
- TOTP
- Time-based one-time password: a short code computed from a shared secret and the current time, typically by an authenticator app.
- Push fatigue
- An attack that floods a user with MFA push prompts hoping they approve one to make them stop.
- False rejection rate (FRR)
- The rate at which a legitimate user is wrongly rejected; a Type I error.
- False acceptance rate (FAR)
- The rate at which an unauthorized person is wrongly accepted; a Type II error.
- Crossover error rate (CER)
- The point where FAR equals FRR, used to compare the overall accuracy of biometric systems; lower is better. Also called equal error rate.
- Template
- The stored mathematical representation of a person's biometric features created at enrollment.
- Liveness detection
- Checks that a biometric sample comes from a live person present at the sensor rather than a replica or recording.
- Single sign-on (SSO)
- Authenticating once to gain access to multiple systems without re-entering credentials.
- Key distribution center (KDC)
- The trusted Kerberos server, made up of the authentication service and ticket-granting service, that issues tickets.
- Ticket-granting ticket (TGT)
- A Kerberos ticket issued at login that the client uses to request service tickets without re-entering the password.
- 802.1X
- An IEEE standard for port-based network access control that authenticates devices or users, usually via RADIUS, before allowing network access.
- Trusted Platform Module (TPM)
- A hardware chip that securely stores keys and measurements, used for device identity and integrity.
- Identity provider (IdP)
- The system that authenticates users and issues assertions or tokens about them to relying parties.
- SAML
- Security Assertion Markup Language, an XML-based standard for exchanging signed authentication and attribute assertions between an IdP and a service provider.
- OAuth 2.0
- An authorization framework that issues scoped access tokens so an application can act on a user's behalf without their password.
- OpenID Connect (OIDC)
- An identity layer on OAuth 2.0 that adds a signed ID token so applications can authenticate users.
- Transitive trust
- A trust that extends through a chain, so if A trusts B and B trusts C, A also trusts C.
- Extranet
- A controlled extension of an organization's network or applications to authorized external parties such as partners and suppliers.
- Interconnection security agreement (ISA)
- A document specifying the technical and security requirements for a connection between two organizations' systems.
- Zero trust
- A security model that grants no implicit trust based on network location and verifies every access request using identity, device and context.
- Policy enforcement point (PEP)
- The component in a zero trust architecture that allows, monitors or terminates connections based on policy decisions.
- Micro-segmentation
- Dividing a network into small isolated zones so access between workloads is tightly controlled.
- Identity proofing
- Verifying that a person is who they claim to be before creating or binding an identity.
- Provisioning
- Creating accounts and granting initial access based on an approved request or authoritative source.
- Entitlement
- A specific permission, role or group membership assigned to an identity.
- Deprovisioning
- Disabling and removing an identity's access when it is no longer required.
- Orphaned account
- An account that no longer has a valid, active owner, such as one left behind after someone departs.
- Privilege creep
- The gradual accumulation of access rights beyond what a user's current role requires, usually from unrevoked old access.
- Access review
- A periodic examination of accounts and entitlements to confirm they are still appropriate.
- Recertification
- The formal attestation by a manager or data owner that a user's access is still required.
- Dormant account
- An account that has not been used for an extended period and may no longer be needed.
- Privileged access management (PAM)
- Policies and tools that control, monitor and audit the use of elevated accounts.
- Just-in-time access
- Granting elevated privileges only when needed, for a limited time, and removing them automatically.
- Password vault
- A secure repository that stores, rotates and checks out privileged credentials.
- Service account
- A non-human account used by an application or service to authenticate to other systems.
- Break-glass account
- A tightly controlled emergency account used only when normal administrative access is unavailable.
- Discretionary access control (DAC)
- A model in which the object owner decides who can access the object.
- Mandatory access control (MAC)
- A model where the system enforces access by comparing subject clearances with object labels; users cannot override it.
- Role-based access control (RBAC)
- A model that assigns permissions to roles tied to job functions and places users in roles.
- Rule-based access control
- A model that applies administrator-defined rules uniformly to all subjects, such as firewall rules.
- Attribute-based access control (ABAC)
- A model that evaluates policies over subject, object, action and environmental attributes.
- Physical access control
- A control that restricts entry to facilities, rooms or equipment, such as locks, badges and guards.
- Logical access control
- A control enforced by hardware or software that restricts access to systems and data, such as passwords, ACLs and firewalls.
- Accountability
- The ability to trace actions to a specific identity, typically through logging.
- Physical-logical integration
- Linking badge and building systems with IT identity systems so access is granted and revoked together.
Domain 3: Risk identification, monitoring & analysis (15%)
Exam tips
- A vulnerability is a weakness you have; a threat is what could exploit it. Risk exists only where they meet, and controls reduce risk by lowering likelihood, impact or both.
- Memorize SLE = AV x EF and ALE = SLE x ARO, and convert frequencies carefully: once every 4 years means ARO 0.25. A control is justified when ALE reduction exceeds its annual cost.
- Insurance transfers financial loss, never accountability. And acceptance must be documented by someone with authority; ignoring a risk is not acceptance.
- Know the RMF order: prepare, categorize, select, implement, assess, authorize, monitor. Categorize comes before select, and assess comes before authorize.
- When a scenario raises a legal or regulatory question, the practitioner's best action is usually to preserve evidence and involve legal or compliance, not to decide or notify alone.
- Credentialed scans are more accurate with fewer false positives; non-credentialed scans show the attacker's outside view. Any test without written authorization and scope is never the right answer.
- CVE identifies; CVSS scores. Prioritize by risk, combining severity with asset value, exposure and active exploitation, not by CVSS score alone. Always verify fixes with a rescan.
- Without synchronized clocks, correlation and evidence fall apart. And logs should be sent off the source system quickly, to storage its administrators cannot alter.
- Anomaly-based detection can catch new attacks but produces more false positives; signature-based detection is precise but misses the unknown. Tuning should reduce noise without creating blind spots, so exclusions must be narrow and documented.
- When a scenario gives you doubt about severity, escalating according to the documented procedure is usually the correct answer. Analysts should not take drastic unilateral action beyond their authority.
Key terms
- Asset
- Anything of value to the organization that requires protection, such as data, systems, people or reputation.
- Threat
- A potential cause of an unwanted incident that could harm an asset, carried out by a threat agent.
- Vulnerability
- A weakness in a system, process, facility or person that a threat could exploit.
- Likelihood
- The probability that a given threat will exploit a given vulnerability within a period.
- Impact
- The magnitude of harm that would result if a threat exploited a vulnerability.
- Risk appetite
- The amount and type of risk an organization is willing to accept in pursuit of its objectives.
- Single loss expectancy (SLE)
- Expected monetary loss from one occurrence of a risk event: asset value times exposure factor.
- Exposure factor (EF)
- The fraction of an asset's value lost in one occurrence of the event.
- Annualized rate of occurrence (ARO)
- The expected number of times the event occurs per year.
- Annualized loss expectancy (ALE)
- Expected yearly loss from a risk: SLE times ARO.
- Delphi technique
- A qualitative method that gathers anonymous expert opinions over several rounds to reach consensus.
- Risk avoidance
- Eliminating a risk by not performing, or ceasing, the activity that creates it.
- Risk mitigation
- Reducing a risk's likelihood or impact through controls.
- Risk transfer
- Shifting financial consequences of a risk to another party, such as an insurer, while accountability stays with the organization.
- Risk acceptance
- A documented decision by an authorized person to tolerate a risk without further treatment.
- Residual risk
- The risk remaining after controls have been applied.
- Risk register
- A record of identified risks with their owners, ratings, treatments, residual risk and status.
- NIST Risk Management Framework (RMF)
- A seven-step lifecycle (prepare, categorize, select, implement, assess, authorize, monitor) for managing risk to information systems.
- NIST SP 800-30
- NIST guidance for conducting risk assessments: prepare, conduct, communicate and maintain.
- ISO/IEC 27005
- International guidance for information security risk management supporting an ISO/IEC 27001 ISMS.
- Authorization to operate (ATO)
- A senior official's formal decision to accept a system's residual risk and allow it to operate.
- Categorization
- Determining a system's impact level from the potential harm of losing confidentiality, integrity or availability.
- Personally identifiable information (PII)
- Information that can identify a specific individual, alone or combined with other data.
- Breach notification
- A legal or contractual duty to inform regulators and affected people when protected data is compromised.
- Data residency
- The geographic location where data is stored and processed, which may be restricted by law or contract.
- Data sovereignty
- The principle that data is subject to the laws of the country in which it is located.
- Data controller
- The organization that determines the purposes and means of processing personal data; the processor acts on its behalf.
- Credentialed scan
- A vulnerability scan that logs in to systems to inspect installed software and configuration, giving more accurate results.
- Non-credentialed scan
- A scan performed without logging in, showing what an outside attacker could see.
- Penetration test
- An authorized simulated attack that attempts to exploit vulnerabilities to demonstrate real impact.
- Rules of engagement
- The written agreement defining a test's scope, permitted techniques, timing, contacts and limits.
- Audit
- A formal, independent evaluation of controls against defined criteria such as policy, standards or regulations.
- CVE
- Common Vulnerabilities and Exposures: unique public identifiers for disclosed vulnerabilities.
- CVSS
- Common Vulnerability Scoring System: a 0.0 to 10.0 severity score based on exploitability and impact metrics.
- False positive
- A reported vulnerability or alert that is not actually present.
- False negative
- A real vulnerability or attack that a tool failed to detect.
- Mean time to remediate
- The average time from discovering a vulnerability to verifying its fix.
- SIEM
- Security information and event management: a platform that collects, normalizes, correlates and alerts on logs from many sources.
- Correlation
- Linking related events from different sources to detect patterns that single events would not reveal.
- NTP
- Network Time Protocol, used to synchronize system clocks so logs from different sources align.
- Log integrity
- Assurance that log records are complete and unaltered, supported by central collection, access control, immutability and hashing.
- Normalization
- Converting logs from different formats into a common structure so they can be searched and correlated.
- Baseline
- A documented record of normal behavior for a system, network or user, used to spot deviations.
- Anomaly-based detection
- Detection that flags activity deviating significantly from an established baseline.
- Signature-based detection
- Detection that matches activity against known patterns of attacks.
- Alert fatigue
- Desensitization caused by excessive alerts, especially false positives, leading analysts to miss real threats.
- Alert tuning
- Adjusting detection rules, thresholds and exclusions to reduce false positives without creating false negatives.
- Triage
- Rapid assessment of an alert or event to determine validity, severity and priority.
- Escalation
- Passing an issue to someone with greater expertise or authority according to defined criteria.
- Benign true positive
- An alert that correctly detected real activity that turns out to be authorized or harmless.
- Out-of-band communication
- Using a separate channel, such as phone instead of corporate email, when the normal channel may be compromised.
Domain 4: Incident response & recovery (14%)
Exam tips
- Order matters: contain before you eradicate, and eradicate before you recover. Preparation is the phase most often neglected, and lessons learned feeds back into it.
- All incidents are events, but not all events are incidents. Severity should be based on defined criteria like business impact, data involved and recoverability, and it can change as facts emerge.
- Only authorized spokespeople communicate externally, and when the normal channel may be compromised, the team uses out-of-band communication. Legal counsel usually decides on contacting law enforcement.
- When an exam question asks what to collect first, pick the most volatile source (memory before disk, disk before backups). If it asks what makes evidence inadmissible, a broken or missing chain of custody is the usual answer.
- Hashing proves integrity, not confidentiality. If a question asks how to show an image has not been altered, the answer is matching hash values, and the tool that prevents alteration during acquisition is a write blocker.
- If a question asks the first thing to do when an investigation may involve legal action or employee privacy, the best answer is usually to involve legal counsel and follow policy, not to start collecting on your own authority.
- Remember the units: RTO and MTD are about how long you are down; RPO is about how much data you can lose. RTO must always be less than or equal to MTD.
- Match site type to RTO: hot for minutes to hours, warm for hours to days, cold for days to weeks. If a question says the organization wants the lowest cost and can tolerate a long outage, pick cold.
- Know the restore counts: full needs one set; differential needs the full plus the last differential; incremental needs the full plus every incremental since. Incremental is fastest to back up, full is fastest to restore.
- Memorize the order by disruption: checklist, tabletop, simulation, parallel, full interruption. If a question asks for the test that verifies recovery systems without affecting production, choose parallel.
Key terms
- Preparation
- Establishing the plan, team, tools, training and controls needed before an incident occurs.
- Containment
- Actions that limit the scope and damage of an incident, such as isolating hosts or disabling accounts.
- Eradication
- Removing the root cause and all attacker artifacts, such as malware, backdoors and compromised accounts.
- Recovery
- Restoring affected systems to normal, verified operation and monitoring for recurrence.
- Lessons learned
- A post-incident review that identifies improvements to plans, controls and training.
- Event
- Any observable occurrence in a system or network, most of which are normal.
- Adverse event
- An event with a negative consequence, such as a crash or unauthorized access attempt.
- Security incident
- A violation or imminent threat of violation of security policy or practice that jeopardizes confidentiality, integrity or availability.
- Triage
- Sorting and prioritizing events and incidents by impact and urgency to decide the response.
- Hierarchical escalation
- Raising an issue to people with greater authority to make business decisions, as opposed to functional escalation to greater technical expertise.
- Incident response plan (IRP)
- An approved document defining how the organization prepares for, detects, responds to and recovers from security incidents.
- CSIRT
- Computer security incident response team: the group responsible for handling security incidents.
- Incident commander
- The person who coordinates the response effort and decision making during an incident.
- Tabletop exercise
- A discussion-based walk-through of an incident scenario to test the plan and roles without affecting systems.
- Authorized spokesperson
- The designated person, usually in communications or PR, who speaks for the organization to media and the public.
- Order of volatility
- The sequence for collecting evidence from most short-lived (CPU cache, RAM) to most persistent (archives, backups).
- Chain of custody
- A documented, unbroken record of every person who handled evidence, when and why, from collection to presentation.
- Live acquisition
- Collecting data, especially memory, from a running system before it is powered down.
- Admissibility
- Whether evidence can be accepted in a legal proceeding, which depends on it being relevant, reliable and properly handled.
- Forensic image
- A bit-for-bit copy of a storage device that includes unallocated and slack space, not just active files.
- Write blocker
- Hardware or software that permits reads from evidence media while blocking any writes to it.
- Hash verification
- Comparing cryptographic hash values of the original and copy to prove they are identical and unchanged.
- Working copy
- A duplicate of the master image used for analysis so the master and the original remain untouched.
- Legal hold
- An instruction to preserve all data relevant to expected litigation, overriding normal retention and deletion policies.
- eDiscovery
- The process of identifying, preserving, collecting and producing electronically stored information for legal matters.
- Enticement vs entrapment
- Enticement offers an opportunity to someone already intent on wrongdoing (legal); entrapment induces someone to commit a crime they otherwise would not (illegal).
- Preponderance of the evidence
- The civil-case standard: the claim is more likely true than not.
- MTD
- Maximum tolerable downtime: the longest a function can be down before the organization suffers unacceptable harm.
- RTO
- Recovery time objective: the target time to restore a system or process after a disruption; must be less than MTD.
- RPO
- Recovery point objective: the maximum acceptable data loss measured in time, which sets backup or replication frequency.
- WRT
- Work recovery time: time after technical recovery to verify data and resume normal operations.
- BCP
- Business continuity plan: keeps critical business functions operating during and after a disruption.
- DRP
- Disaster recovery plan: restores IT systems, data and infrastructure after a disaster; part of the broader continuity effort.
- Hot site
- A fully equipped, ready-to-run alternate facility that can take over within minutes to hours.
- Cold site
- An alternate facility with only space, power and environmental controls; slowest and cheapest to activate.
- Incremental backup
- Copies data changed since the last backup of any type; fast to create, slower to restore because every increment is needed.
- Differential backup
- Copies data changed since the last full backup; restore needs only the last full and the latest differential.
- 3-2-1 rule
- Keep three copies of data on two different media, with one copy offsite.
- Restore testing
- Periodically recovering data from backups to verify it is complete, usable and meets recovery objectives.
- Parallel test
- Recovery systems are brought up and run alongside production to verify they work, without stopping the primary site.
- Full interruption test
- Primary operations are actually shut down and moved to the recovery site; most realistic and most risky.
- After-action review
- A post-test or post-incident meeting that records lessons learned and drives plan updates.
Domain 5: Cryptography (9%)
Exam tips
- If a question asks which goal only asymmetric cryptography can provide, the answer is non-repudiation. Encryption gives confidentiality; hashing gives integrity; neither alone proves who sent a message.
- Know the key counts: symmetric needs n(n-1)/2 keys, asymmetric needs 2n. And remember which key does what: encrypt for confidentiality with the recipient's public key; sign with the sender's private key.
- Map tool to goal: hash for integrity; HMAC for integrity plus authentication with a shared key; digital signature for integrity, authentication and non-repudiation. Salting defends against rainbow tables, not against a weak password.
- HSM versus TPM: an HSM serves many systems and applications and is often a separate appliance; a TPM is built into one device (as a chip or firmware) and protects that device. Dual control and split knowledge are the answers for preventing a single person from misusing a master key.
- TLS and IPsec protect the channel; S/MIME and PGP protect the message itself. If a question asks for email protection that persists after the message is stored on a server, pick S/MIME.
- If a question mentions ephemeral, DHE or ECDHE, think forward secrecy. Static RSA key exchange does not provide it. In a suite name, the first part after TLS_ is the key exchange.
- The CSR carries the public key, never the private key. For revocation checks, CRL is a downloaded list and OCSP is a real-time per-certificate query; stapling moves the OCSP query to the server.
- PGP means web of trust; X.509 and CAs mean hierarchical. If a question asks which model has no central authority, the answer is web of trust.
Key terms
- Non-repudiation
- Assurance that a sender cannot deny sending a message, provided by a digital signature from a private key only the sender holds.
- Data at rest
- Stored data, such as on disks, databases and backups, typically protected by storage encryption.
- Data in use
- Data being actively processed in memory, protected by access control and technologies like trusted execution environments.
- Kerckhoffs's principle
- A cryptosystem should be secure even if everything except the key is publicly known.
- AES
- Advanced Encryption Standard: a symmetric block cipher with a 128-bit block and 128, 192 or 256-bit keys.
- Public/private key pair
- Two linked keys in asymmetric cryptography; the public key is shared, the private key is kept secret.
- ECC
- Elliptic curve cryptography: asymmetric cryptography offering strong security with shorter keys than RSA.
- Hybrid cryptography
- Using asymmetric methods to exchange or protect a symmetric session key, which then encrypts the bulk data.
- Salt
- A unique random value added to each password before hashing so identical passwords yield different hashes and rainbow tables fail.
- HMAC
- A hash computed with a shared secret key, providing integrity and origin authentication but not non-repudiation.
- Collision
- Two different inputs that produce the same hash digest; a good hash makes collisions infeasible to find.
- Digital signature
- A hash of a message signed with the sender's private key, giving integrity, authentication and non-repudiation.
- Cryptoperiod
- The authorized time span during which a specific key may be used before it must be rotated or retired.
- Key escrow
- Storing a copy of a key with a trusted party so data can be recovered if the original key is lost or access is legally required.
- HSM
- Hardware security module: a tamper-resistant device that securely generates, stores and uses keys for many systems.
- TPM
- Trusted platform module: a chip on a single device that protects its keys and supports secure or measured boot and disk encryption.
- TLS
- Transport Layer Security: encrypts and authenticates application traffic over TCP; HTTPS uses it on port 443.
- SSH
- Secure Shell: encrypted remote administration on TCP 22, replacing Telnet.
- SFTP vs FTPS
- SFTP transfers files over SSH; FTPS is traditional FTP secured with TLS.
- S/MIME
- A standard for signing and encrypting individual email messages with X.509 certificates.
- Forward secrecy
- A property ensuring that compromise of a long-term private key does not expose past session keys.
- Ephemeral key exchange
- Key agreement (DHE or ECDHE) using temporary keys generated fresh for each session and then discarded.
- Cipher suite
- The named set of algorithms for key exchange, authentication, bulk encryption and hashing in a TLS session.
- Downgrade attack
- An attack that manipulates negotiation so parties use a weaker protocol version or cipher.
- CSR
- Certificate signing request: a message containing a public key and identity details sent to a CA to obtain a certificate.
- Chain of trust
- The path of signatures from an end-entity certificate through intermediate CAs to a trusted root.
- CRL
- Certificate revocation list: a CA-published list of serial numbers of revoked certificates.
- OCSP
- Online Certificate Status Protocol: a real-time query to check whether a single certificate has been revoked.
- Hierarchical trust
- A centralized model in which trust flows from root CAs through intermediates to end-entity certificates.
- Web of trust
- A decentralized model, used by PGP, where users sign each other's keys to vouch for their authenticity.
- Cross-certification
- Two CAs from separate PKIs sign each other's certificates to establish mutual trust.
- Trust on first use
- Accepting a key the first time it is seen and alerting if it later changes, as SSH does.
Domain 6: Network & communications security (16%)
Exam tips
- Know which layer devices work at: switches at layer 2, routers at layer 3, and application proxies and WAFs at layer 7. ARP sits at layer 2 and is replaced by NDP in IPv6.
- ARP attacks are local (same broadcast domain, layer 2); DNS poisoning can redirect users anywhere. Distributed and botnet point to DDoS; half-open connections point to SYN flood; spoofed small requests producing big replies point to amplification.
- Pairings to remember: ARP poisoning - DAI; DNS poisoning - DNSSEC; SYN flood - SYN cookies; floods and brute force - rate limiting. DNSSEC gives integrity, not confidentiality.
- RADIUS: UDP, combines authN and authZ, encrypts only the password, typical for user network access. TACACS+: TCP, encrypts everything, separates the three A's, typical for device administration.
- East-west traffic is controlled by micro-segmentation; north-south traffic crosses the perimeter. Zero trust answers questions like never trust, always verify, or access decisions based on identity rather than network location.
- AH authenticates but never encrypts; ESP encrypts. Transport mode protects the payload between hosts; tunnel mode protects the whole packet between gateways. If a question needs confidentiality, AH is never the answer.
- Inline and blocks means IPS; passive and alerts means IDS. If the question is about protecting a web application from injection, choose a WAF rather than a generic firewall.
- Order matters: specific before general, and the implicit deny sits at the end. If a question describes a rule that never triggers, think shadowing by an earlier, broader rule.
- Shared passphrase means personal; per-user credentials through RADIUS means enterprise. An AP mimicking a known SSID is an evil twin; any unauthorized AP on your network is a rogue.
- Signaling (SIP) and media (RTP) are protected separately: TLS for SIP signaling, SRTP for the media. Voice VLANs plus QoS are the standard segmentation answer for converged networks.
Key terms
- Encapsulation
- Wrapping data with each layer's header as it moves down the stack, creating segments, packets and frames.
- Three-way handshake
- The SYN, SYN-ACK, ACK exchange that establishes a TCP connection.
- NAT
- Network address translation: mapping private internal addresses to public addresses at the network edge.
- IPv6
- The 128-bit successor to IPv4, written in hexadecimal and using Neighbor Discovery instead of ARP.
- ARP poisoning
- Sending forged ARP replies to link the attacker's MAC address with another host's IP, redirecting local traffic.
- DNS cache poisoning
- Inserting false records into a DNS resolver's cache so users are sent to attacker-controlled addresses.
- On-path attack
- An attacker positioned between two parties to intercept, read or modify their communications.
- SYN flood
- A DoS attack that sends many SYNs without completing the handshake, filling the server's half-open connection backlog.
- Dynamic ARP Inspection
- A switch feature that drops ARP packets whose IP-to-MAC bindings do not match the DHCP snooping table.
- DNSSEC
- Extensions that digitally sign DNS records so resolvers can verify their integrity and origin.
- SYN cookies
- A technique that encodes connection state into the SYN-ACK sequence number so no resources are held for half-open connections.
- Egress filtering
- Blocking outbound traffic with source addresses that do not belong to your network, preventing participation in spoofed attacks.
- 802.1X
- Port-based network access control in which a supplicant authenticates through an authenticator to an authentication server before traffic is allowed.
- RADIUS
- An AAA protocol over UDP that combines authentication and authorization and encrypts only the password.
- TACACS+
- A Cisco-developed AAA protocol over TCP 49 that encrypts the full payload and separates authentication, authorization and accounting.
- Posture assessment
- Checking a device's security state, such as patches and antimalware, before granting network access.
- VLAN
- A logical layer 2 broadcast domain that separates devices on shared switches; inter-VLAN traffic must be routed.
- Screened subnet (DMZ)
- A zone between the internet and internal network that hosts public-facing services behind firewall rules.
- Micro-segmentation
- Fine-grained, often workload-level, network policy that restricts east-west traffic between systems.
- Zero trust
- A model where no request is trusted based on network location; every access is verified with least privilege and continuous evaluation.
- AH
- Authentication Header: IPsec protocol providing integrity, origin authentication and anti-replay, without encryption.
- ESP
- Encapsulating Security Payload: IPsec protocol providing encryption plus integrity and authentication.
- Tunnel mode
- IPsec mode that encapsulates and protects the whole original packet inside a new IP header, used between gateways.
- Split tunneling
- Sending only corporate-bound traffic through the VPN while other traffic goes directly to the internet.
- Stateful firewall
- A firewall that tracks connection state and allows return traffic only for established sessions.
- WAF
- Web application firewall: inspects HTTP/HTTPS requests to protect web applications from attacks like SQL injection and XSS.
- IDS vs IPS
- An IDS detects and alerts out of band; an IPS sits inline and can block traffic.
- Reverse proxy
- A server that accepts client requests on behalf of internal servers, hiding them and often terminating TLS.
- Implicit deny
- The default behavior of blocking any traffic that no rule explicitly permits.
- First-match processing
- Rules are evaluated top down and the first matching rule decides the action.
- Shadowed rule
- A rule that never takes effect because a broader rule above it always matches first.
- SAE
- Simultaneous Authentication of Equals: WPA3-Personal handshake that resists offline dictionary attacks.
- WPA2/WPA3-Enterprise
- Wi-Fi modes that authenticate each user or device through 802.1X and RADIUS rather than a shared passphrase.
- Rogue access point
- An unauthorized wireless access point connected to an organization's network.
- Evil twin
- A malicious access point that imitates a legitimate SSID to lure clients into connecting.
- SIP
- Session Initiation Protocol: the common signaling protocol for setting up and ending VoIP calls.
- SRTP
- Secure Real-time Transport Protocol: encrypts and authenticates VoIP media streams.
- Toll fraud
- Unauthorized use of a phone system to place calls, usually expensive international or premium-rate calls, at the victim's expense.
- Session border controller
- An edge device that secures, controls and normalizes VoIP signaling and media between networks.
Domain 7: Systems & application security (15%)
Exam tips
- Needs a host and user action: virus. Spreads by itself: worm. Disguised as something useful: trojan. Waits for a condition: logic bomb. Hides from the operating system: rootkit. Uses built-in tools in memory: fileless.
- Regular, periodic outbound connections point to beaconing. A new scheduled task, service or run key points to persistence. A standard account suddenly in an admin group points to privilege escalation.
- Allow-listing is the strongest answer for stopping unknown or zero-day malware on fixed-function systems. Signature-based antimalware is weakest against new variants; behavior-based detection and sandboxing help close that gap.
- HIDS alerts, HIPS blocks, and EDR adds continuous recording plus remote investigation and containment such as host isolation. Patching and hardening are preventive; EDR and HIDS are primarily detective.
- For BYOD, the privacy-friendly answer is containerization plus selective wipe. Full wipe fits corporate-owned devices. A rooted or jailbroken device should be treated as non-compliant.
- Data and identity are always the customer's responsibility in every model. The physical data center is always the provider's. Everything in between shifts toward the provider as you move from IaaS to SaaS.
- Most cloud breaches are customer misconfigurations, not provider failures. For continuously detecting misconfigurations the answer is CSPM; for visibility into SaaS usage and shadow IT the answer is CASB.
- VM escape threatens the hypervisor and every co-hosted VM; the main defenses are patching and isolating sensitive workloads. Snapshots are for quick rollback, not a backup strategy.
- The best fix for SQL injection is parameterized queries, not just input filtering or a WAF. Client-side validation is never sufficient on its own because attackers bypass the browser entirely.
Key terms
- Worm
- Self-replicating malware that spreads over networks without a host file or user action.
- Trojan
- Malware disguised as legitimate software that relies on the user installing it and does not self-replicate.
- Rootkit
- Malware that hides itself and other malicious activity by modifying the operating system, kernel, boot process or firmware.
- Fileless malware
- Malware that operates in memory using legitimate system tools, leaving few or no files on disk.
- Beaconing
- Periodic outbound communication from a compromised host to a command and control server.
- Persistence
- Techniques that let an attacker keep access across reboots and remediation, such as scheduled tasks or new services.
- Privilege escalation
- Gaining higher (vertical) or peer-level other-user (horizontal) access than originally obtained.
- Indicator of compromise
- An artifact, such as a malicious hash, domain or registry key, suggesting a system has been breached.
- Signature-based detection
- Identifying malware by matching known patterns or hashes; accurate but blind to new variants.
- Sandbox
- An isolated environment for running untrusted code and observing its behavior safely.
- Application allow-listing
- Permitting only explicitly approved software to execute and blocking everything else.
- Heuristic analysis
- Detecting likely malware by suspicious characteristics or behavior rather than exact signatures.
- HIDS/HIPS
- Host-based intrusion detection or prevention: monitors a single system's activity and alerts (HIDS) or blocks (HIPS).
- EDR
- Endpoint detection and response: records detailed endpoint telemetry for detection, investigation and remote response.
- Hardening
- Reducing a system's attack surface by removing unneeded components and applying a secure configuration baseline.
- Patch management
- The process of identifying, testing, deploying and verifying software updates that fix vulnerabilities.
- UEM
- Unified endpoint management: a single platform to manage and secure mobile devices and computers across operating systems.
- COPE
- Corporate-owned, personally enabled: the organization owns and manages the device but allows personal use.
- Containerization
- Separating corporate apps and data into an encrypted, managed area isolated from personal data on a device.
- Selective wipe
- Removing only corporate data and apps from a device while leaving personal content intact.
- IaaS
- Infrastructure as a service: the provider supplies virtualized compute, storage and networking; the customer manages OS and above.
- PaaS
- Platform as a service: the provider manages infrastructure, OS and runtime; the customer manages applications and data.
- SaaS
- Software as a service: the provider delivers a complete application; the customer manages users, settings and data.
- Shared responsibility model
- The division of security duties between cloud provider (security of the cloud) and customer (security in the cloud).
- Least privilege IAM
- Granting identities only the specific cloud permissions they need, preferably through roles and temporary credentials.
- CSPM
- Cloud security posture management: continuous scanning of cloud configurations against security and compliance policies.
- Customer-managed key
- An encryption key in a cloud KMS whose policies and rotation are controlled by the customer rather than the provider.
- Data residency
- The geographic location where data is stored and processed, often constrained by law or regulation.
- Type 1 hypervisor
- A bare-metal hypervisor that runs directly on hardware, used in data centers for performance and security.
- Type 2 hypervisor
- A hosted hypervisor that runs as an application on a conventional operating system.
- VM escape
- An attack in which code in a guest VM breaks isolation to reach the hypervisor or other VMs.
- VM sprawl
- Uncontrolled growth of VMs that are no longer tracked, patched or managed.
- Input validation
- Server-side checking that input matches expected type, length, format and range before it is used.
- Parameterized query
- A database query where user input is passed as data parameters, never interpreted as part of the SQL command.
- Cross-site scripting (XSS)
- A flaw that lets attacker-supplied script run in other users' browsers because output was not properly encoded.
- OWASP Top 10
- A periodically updated awareness list of the most critical web application security risk categories.
Study SSCP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SSCP study planLessons, quizzes, exam simulations and hands-on labs.