StudyToCert

All certifications / SSCP / Cheat sheet

SSCP Oct 2025 outline cheat sheet

Every exam tip and key term from the free SSCP lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Security concepts & practices (16%)

Exam tips

Key terms

Preamble
The opening statement of the ISC2 Code of Ethics explaining why high ethical standards are required and that adherence is a condition of certification.
Canon
One of the four ordered principles of the code; when they conflict, the earlier canon takes priority.
Principal
The person or organization you provide professional services to, such as an employer or client.
Ethics complaint
A formal, specific allegation filed with ISC2 that a member violated the code, reviewed by an ethics committee.
Confidentiality
Preventing disclosure of information to unauthorized people, processes or systems.
Integrity
Protecting data and systems from unauthorized or accidental modification and making changes detectable.
Availability
Ensuring authorized users have timely, reliable access to systems and data.
Non-repudiation
Assurance that a party cannot credibly deny having performed an action, typically achieved with a private-key digital signature and reliable logs.
Privacy
An individual's right to control how their personal information is collected, used, shared and retained.
Least privilege
Granting only the minimum access rights needed to perform a task, for no longer than needed.
Need to know
Restricting access to specific information to people whose current duties require it, even if they are otherwise cleared.
Separation of duties
Dividing a critical process among multiple people so that no one person can complete it alone, requiring collusion to commit fraud.
Mandatory vacation
Requiring staff to take time off so others perform their duties, which can reveal hidden fraud or errors.
Job rotation
Periodically moving staff between roles to reduce single-person dependency and help detect misconduct.
Defense in depth
Layering multiple, varied security controls so that the failure of one does not expose the asset.
Due care
Taking the actions a reasonable and prudent person would take to protect assets; the doing.
Due diligence
Researching, assessing and continuously verifying risks and controls; the investigating and checking.
Negligence
Failure to exercise due care, which can create legal liability after an incident.
Technical control
A safeguard implemented through hardware or software, such as a firewall or encryption.
Administrative control
A safeguard based on policy, procedure or personnel management, such as training or background checks.
Physical control
A safeguard that protects facilities and hardware, such as locks, fences and guards.
Compensating control
An alternative control that provides comparable protection when the primary control cannot be implemented.
Deterrent control
A control that discourages an attack without physically preventing it, such as a warning banner.
Security baseline
A documented minimum set of security configurations that all systems of a given type must meet.
Configuration drift
Gradual divergence of a system's actual settings from its approved baseline over time.
Golden image
A preconfigured, hardened system image used to build new systems consistently to the baseline.
Exception
A documented, approved and usually time-limited deviation from a baseline or policy.
Asset inventory
A maintained record of an organization's hardware, software, data and services with key attributes such as owner and location.
Asset owner
The person or role accountable for an asset, who decides its classification and approves access.
Classification
Labeling assets by sensitivity and value so that protections and handling are proportional.
Retention schedule
A policy listing how long each type of record must be kept and how it is disposed of afterward.
Legal hold
An instruction to preserve specific data and suspend normal deletion because of expected litigation or investigation.
Data owner
The accountable business role that classifies data, sets protection requirements and approves access.
Data custodian
The role, usually IT, that implements and maintains the controls the owner specified, such as backups and access settings.
Clear
Sanitization using logical techniques such as overwriting to prevent recovery with ordinary tools.
Purge
Sanitization that makes recovery infeasible even with laboratory techniques, such as cryptographic erase or degaussing magnetic media.
Destroy
Physically rendering media unusable, such as shredding or incineration, so data cannot be recovered.
Request for change (RFC)
A formal proposal describing a change, its reason, scope, schedule and risk, submitted for evaluation.
Change advisory board (CAB)
A group of stakeholders that reviews and approves significant changes.
Backout plan
Documented, tested steps to reverse a change and restore the prior state if it fails.
Emergency change
An urgent change approved and implemented through an expedited process, then documented and reviewed afterward.
Configuration management database (CMDB)
A repository of configuration items, their attributes, relationships and approved states.
Security awareness
Broad, ongoing activity that keeps all staff alert to security risks and expected behaviors.
Security training
Role-specific instruction that builds the skills a person needs to perform duties securely.
Phishing simulation
An authorized test in which harmless, realistic phishing messages are sent to staff to measure and improve their responses.
Report rate
The share of users who report a suspicious or simulated message, a key measure of program effectiveness.
Access control vestibule
A small space with two interlocking doors that allows only one authorized person through at a time, preventing tailgating; formerly called a mantrap.
Tailgating
Following an authorized person through a secured entrance without their knowledge; piggybacking is the same with their consent.
Fail-safe
A lock that opens when power fails, prioritizing life safety.
Fail-secure
A lock that stays locked when power fails, prioritizing asset protection.
Visitor log
A record of each visitor's identity, host, purpose and entry and exit times.

Domain 2: Access controls (15%)

Exam tips

Key terms

Authentication factor
A category of evidence used to prove identity: something you know, have or are.
Multifactor authentication (MFA)
Authentication requiring two or more different factor types.
Multi-step authentication
Authentication in several sequential steps, which is not MFA unless the steps use different factor types.
TOTP
Time-based one-time password: a short code computed from a shared secret and the current time, typically by an authenticator app.
Push fatigue
An attack that floods a user with MFA push prompts hoping they approve one to make them stop.
False rejection rate (FRR)
The rate at which a legitimate user is wrongly rejected; a Type I error.
False acceptance rate (FAR)
The rate at which an unauthorized person is wrongly accepted; a Type II error.
Crossover error rate (CER)
The point where FAR equals FRR, used to compare the overall accuracy of biometric systems; lower is better. Also called equal error rate.
Template
The stored mathematical representation of a person's biometric features created at enrollment.
Liveness detection
Checks that a biometric sample comes from a live person present at the sensor rather than a replica or recording.
Single sign-on (SSO)
Authenticating once to gain access to multiple systems without re-entering credentials.
Key distribution center (KDC)
The trusted Kerberos server, made up of the authentication service and ticket-granting service, that issues tickets.
Ticket-granting ticket (TGT)
A Kerberos ticket issued at login that the client uses to request service tickets without re-entering the password.
802.1X
An IEEE standard for port-based network access control that authenticates devices or users, usually via RADIUS, before allowing network access.
Trusted Platform Module (TPM)
A hardware chip that securely stores keys and measurements, used for device identity and integrity.
Identity provider (IdP)
The system that authenticates users and issues assertions or tokens about them to relying parties.
SAML
Security Assertion Markup Language, an XML-based standard for exchanging signed authentication and attribute assertions between an IdP and a service provider.
OAuth 2.0
An authorization framework that issues scoped access tokens so an application can act on a user's behalf without their password.
OpenID Connect (OIDC)
An identity layer on OAuth 2.0 that adds a signed ID token so applications can authenticate users.
Transitive trust
A trust that extends through a chain, so if A trusts B and B trusts C, A also trusts C.
Extranet
A controlled extension of an organization's network or applications to authorized external parties such as partners and suppliers.
Interconnection security agreement (ISA)
A document specifying the technical and security requirements for a connection between two organizations' systems.
Zero trust
A security model that grants no implicit trust based on network location and verifies every access request using identity, device and context.
Policy enforcement point (PEP)
The component in a zero trust architecture that allows, monitors or terminates connections based on policy decisions.
Micro-segmentation
Dividing a network into small isolated zones so access between workloads is tightly controlled.
Identity proofing
Verifying that a person is who they claim to be before creating or binding an identity.
Provisioning
Creating accounts and granting initial access based on an approved request or authoritative source.
Entitlement
A specific permission, role or group membership assigned to an identity.
Deprovisioning
Disabling and removing an identity's access when it is no longer required.
Orphaned account
An account that no longer has a valid, active owner, such as one left behind after someone departs.
Privilege creep
The gradual accumulation of access rights beyond what a user's current role requires, usually from unrevoked old access.
Access review
A periodic examination of accounts and entitlements to confirm they are still appropriate.
Recertification
The formal attestation by a manager or data owner that a user's access is still required.
Dormant account
An account that has not been used for an extended period and may no longer be needed.
Privileged access management (PAM)
Policies and tools that control, monitor and audit the use of elevated accounts.
Just-in-time access
Granting elevated privileges only when needed, for a limited time, and removing them automatically.
Password vault
A secure repository that stores, rotates and checks out privileged credentials.
Service account
A non-human account used by an application or service to authenticate to other systems.
Break-glass account
A tightly controlled emergency account used only when normal administrative access is unavailable.
Discretionary access control (DAC)
A model in which the object owner decides who can access the object.
Mandatory access control (MAC)
A model where the system enforces access by comparing subject clearances with object labels; users cannot override it.
Role-based access control (RBAC)
A model that assigns permissions to roles tied to job functions and places users in roles.
Rule-based access control
A model that applies administrator-defined rules uniformly to all subjects, such as firewall rules.
Attribute-based access control (ABAC)
A model that evaluates policies over subject, object, action and environmental attributes.
Physical access control
A control that restricts entry to facilities, rooms or equipment, such as locks, badges and guards.
Logical access control
A control enforced by hardware or software that restricts access to systems and data, such as passwords, ACLs and firewalls.
Accountability
The ability to trace actions to a specific identity, typically through logging.
Physical-logical integration
Linking badge and building systems with IT identity systems so access is granted and revoked together.

Domain 3: Risk identification, monitoring & analysis (15%)

Exam tips

Key terms

Asset
Anything of value to the organization that requires protection, such as data, systems, people or reputation.
Threat
A potential cause of an unwanted incident that could harm an asset, carried out by a threat agent.
Vulnerability
A weakness in a system, process, facility or person that a threat could exploit.
Likelihood
The probability that a given threat will exploit a given vulnerability within a period.
Impact
The magnitude of harm that would result if a threat exploited a vulnerability.
Risk appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
Single loss expectancy (SLE)
Expected monetary loss from one occurrence of a risk event: asset value times exposure factor.
Exposure factor (EF)
The fraction of an asset's value lost in one occurrence of the event.
Annualized rate of occurrence (ARO)
The expected number of times the event occurs per year.
Annualized loss expectancy (ALE)
Expected yearly loss from a risk: SLE times ARO.
Delphi technique
A qualitative method that gathers anonymous expert opinions over several rounds to reach consensus.
Risk avoidance
Eliminating a risk by not performing, or ceasing, the activity that creates it.
Risk mitigation
Reducing a risk's likelihood or impact through controls.
Risk transfer
Shifting financial consequences of a risk to another party, such as an insurer, while accountability stays with the organization.
Risk acceptance
A documented decision by an authorized person to tolerate a risk without further treatment.
Residual risk
The risk remaining after controls have been applied.
Risk register
A record of identified risks with their owners, ratings, treatments, residual risk and status.
NIST Risk Management Framework (RMF)
A seven-step lifecycle (prepare, categorize, select, implement, assess, authorize, monitor) for managing risk to information systems.
NIST SP 800-30
NIST guidance for conducting risk assessments: prepare, conduct, communicate and maintain.
ISO/IEC 27005
International guidance for information security risk management supporting an ISO/IEC 27001 ISMS.
Authorization to operate (ATO)
A senior official's formal decision to accept a system's residual risk and allow it to operate.
Categorization
Determining a system's impact level from the potential harm of losing confidentiality, integrity or availability.
Personally identifiable information (PII)
Information that can identify a specific individual, alone or combined with other data.
Breach notification
A legal or contractual duty to inform regulators and affected people when protected data is compromised.
Data residency
The geographic location where data is stored and processed, which may be restricted by law or contract.
Data sovereignty
The principle that data is subject to the laws of the country in which it is located.
Data controller
The organization that determines the purposes and means of processing personal data; the processor acts on its behalf.
Credentialed scan
A vulnerability scan that logs in to systems to inspect installed software and configuration, giving more accurate results.
Non-credentialed scan
A scan performed without logging in, showing what an outside attacker could see.
Penetration test
An authorized simulated attack that attempts to exploit vulnerabilities to demonstrate real impact.
Rules of engagement
The written agreement defining a test's scope, permitted techniques, timing, contacts and limits.
Audit
A formal, independent evaluation of controls against defined criteria such as policy, standards or regulations.
CVE
Common Vulnerabilities and Exposures: unique public identifiers for disclosed vulnerabilities.
CVSS
Common Vulnerability Scoring System: a 0.0 to 10.0 severity score based on exploitability and impact metrics.
False positive
A reported vulnerability or alert that is not actually present.
False negative
A real vulnerability or attack that a tool failed to detect.
Mean time to remediate
The average time from discovering a vulnerability to verifying its fix.
SIEM
Security information and event management: a platform that collects, normalizes, correlates and alerts on logs from many sources.
Correlation
Linking related events from different sources to detect patterns that single events would not reveal.
NTP
Network Time Protocol, used to synchronize system clocks so logs from different sources align.
Log integrity
Assurance that log records are complete and unaltered, supported by central collection, access control, immutability and hashing.
Normalization
Converting logs from different formats into a common structure so they can be searched and correlated.
Baseline
A documented record of normal behavior for a system, network or user, used to spot deviations.
Anomaly-based detection
Detection that flags activity deviating significantly from an established baseline.
Signature-based detection
Detection that matches activity against known patterns of attacks.
Alert fatigue
Desensitization caused by excessive alerts, especially false positives, leading analysts to miss real threats.
Alert tuning
Adjusting detection rules, thresholds and exclusions to reduce false positives without creating false negatives.
Triage
Rapid assessment of an alert or event to determine validity, severity and priority.
Escalation
Passing an issue to someone with greater expertise or authority according to defined criteria.
Benign true positive
An alert that correctly detected real activity that turns out to be authorized or harmless.
Out-of-band communication
Using a separate channel, such as phone instead of corporate email, when the normal channel may be compromised.

Domain 4: Incident response & recovery (14%)

Exam tips

Key terms

Preparation
Establishing the plan, team, tools, training and controls needed before an incident occurs.
Containment
Actions that limit the scope and damage of an incident, such as isolating hosts or disabling accounts.
Eradication
Removing the root cause and all attacker artifacts, such as malware, backdoors and compromised accounts.
Recovery
Restoring affected systems to normal, verified operation and monitoring for recurrence.
Lessons learned
A post-incident review that identifies improvements to plans, controls and training.
Event
Any observable occurrence in a system or network, most of which are normal.
Adverse event
An event with a negative consequence, such as a crash or unauthorized access attempt.
Security incident
A violation or imminent threat of violation of security policy or practice that jeopardizes confidentiality, integrity or availability.
Triage
Sorting and prioritizing events and incidents by impact and urgency to decide the response.
Hierarchical escalation
Raising an issue to people with greater authority to make business decisions, as opposed to functional escalation to greater technical expertise.
Incident response plan (IRP)
An approved document defining how the organization prepares for, detects, responds to and recovers from security incidents.
CSIRT
Computer security incident response team: the group responsible for handling security incidents.
Incident commander
The person who coordinates the response effort and decision making during an incident.
Tabletop exercise
A discussion-based walk-through of an incident scenario to test the plan and roles without affecting systems.
Authorized spokesperson
The designated person, usually in communications or PR, who speaks for the organization to media and the public.
Order of volatility
The sequence for collecting evidence from most short-lived (CPU cache, RAM) to most persistent (archives, backups).
Chain of custody
A documented, unbroken record of every person who handled evidence, when and why, from collection to presentation.
Live acquisition
Collecting data, especially memory, from a running system before it is powered down.
Admissibility
Whether evidence can be accepted in a legal proceeding, which depends on it being relevant, reliable and properly handled.
Forensic image
A bit-for-bit copy of a storage device that includes unallocated and slack space, not just active files.
Write blocker
Hardware or software that permits reads from evidence media while blocking any writes to it.
Hash verification
Comparing cryptographic hash values of the original and copy to prove they are identical and unchanged.
Working copy
A duplicate of the master image used for analysis so the master and the original remain untouched.
Legal hold
An instruction to preserve all data relevant to expected litigation, overriding normal retention and deletion policies.
eDiscovery
The process of identifying, preserving, collecting and producing electronically stored information for legal matters.
Enticement vs entrapment
Enticement offers an opportunity to someone already intent on wrongdoing (legal); entrapment induces someone to commit a crime they otherwise would not (illegal).
Preponderance of the evidence
The civil-case standard: the claim is more likely true than not.
MTD
Maximum tolerable downtime: the longest a function can be down before the organization suffers unacceptable harm.
RTO
Recovery time objective: the target time to restore a system or process after a disruption; must be less than MTD.
RPO
Recovery point objective: the maximum acceptable data loss measured in time, which sets backup or replication frequency.
WRT
Work recovery time: time after technical recovery to verify data and resume normal operations.
BCP
Business continuity plan: keeps critical business functions operating during and after a disruption.
DRP
Disaster recovery plan: restores IT systems, data and infrastructure after a disaster; part of the broader continuity effort.
Hot site
A fully equipped, ready-to-run alternate facility that can take over within minutes to hours.
Cold site
An alternate facility with only space, power and environmental controls; slowest and cheapest to activate.
Incremental backup
Copies data changed since the last backup of any type; fast to create, slower to restore because every increment is needed.
Differential backup
Copies data changed since the last full backup; restore needs only the last full and the latest differential.
3-2-1 rule
Keep three copies of data on two different media, with one copy offsite.
Restore testing
Periodically recovering data from backups to verify it is complete, usable and meets recovery objectives.
Parallel test
Recovery systems are brought up and run alongside production to verify they work, without stopping the primary site.
Full interruption test
Primary operations are actually shut down and moved to the recovery site; most realistic and most risky.
After-action review
A post-test or post-incident meeting that records lessons learned and drives plan updates.

Domain 5: Cryptography (9%)

Exam tips

Key terms

Non-repudiation
Assurance that a sender cannot deny sending a message, provided by a digital signature from a private key only the sender holds.
Data at rest
Stored data, such as on disks, databases and backups, typically protected by storage encryption.
Data in use
Data being actively processed in memory, protected by access control and technologies like trusted execution environments.
Kerckhoffs's principle
A cryptosystem should be secure even if everything except the key is publicly known.
AES
Advanced Encryption Standard: a symmetric block cipher with a 128-bit block and 128, 192 or 256-bit keys.
Public/private key pair
Two linked keys in asymmetric cryptography; the public key is shared, the private key is kept secret.
ECC
Elliptic curve cryptography: asymmetric cryptography offering strong security with shorter keys than RSA.
Hybrid cryptography
Using asymmetric methods to exchange or protect a symmetric session key, which then encrypts the bulk data.
Salt
A unique random value added to each password before hashing so identical passwords yield different hashes and rainbow tables fail.
HMAC
A hash computed with a shared secret key, providing integrity and origin authentication but not non-repudiation.
Collision
Two different inputs that produce the same hash digest; a good hash makes collisions infeasible to find.
Digital signature
A hash of a message signed with the sender's private key, giving integrity, authentication and non-repudiation.
Cryptoperiod
The authorized time span during which a specific key may be used before it must be rotated or retired.
Key escrow
Storing a copy of a key with a trusted party so data can be recovered if the original key is lost or access is legally required.
HSM
Hardware security module: a tamper-resistant device that securely generates, stores and uses keys for many systems.
TPM
Trusted platform module: a chip on a single device that protects its keys and supports secure or measured boot and disk encryption.
TLS
Transport Layer Security: encrypts and authenticates application traffic over TCP; HTTPS uses it on port 443.
SSH
Secure Shell: encrypted remote administration on TCP 22, replacing Telnet.
SFTP vs FTPS
SFTP transfers files over SSH; FTPS is traditional FTP secured with TLS.
S/MIME
A standard for signing and encrypting individual email messages with X.509 certificates.
Forward secrecy
A property ensuring that compromise of a long-term private key does not expose past session keys.
Ephemeral key exchange
Key agreement (DHE or ECDHE) using temporary keys generated fresh for each session and then discarded.
Cipher suite
The named set of algorithms for key exchange, authentication, bulk encryption and hashing in a TLS session.
Downgrade attack
An attack that manipulates negotiation so parties use a weaker protocol version or cipher.
CSR
Certificate signing request: a message containing a public key and identity details sent to a CA to obtain a certificate.
Chain of trust
The path of signatures from an end-entity certificate through intermediate CAs to a trusted root.
CRL
Certificate revocation list: a CA-published list of serial numbers of revoked certificates.
OCSP
Online Certificate Status Protocol: a real-time query to check whether a single certificate has been revoked.
Hierarchical trust
A centralized model in which trust flows from root CAs through intermediates to end-entity certificates.
Web of trust
A decentralized model, used by PGP, where users sign each other's keys to vouch for their authenticity.
Cross-certification
Two CAs from separate PKIs sign each other's certificates to establish mutual trust.
Trust on first use
Accepting a key the first time it is seen and alerting if it later changes, as SSH does.

Domain 6: Network & communications security (16%)

Exam tips

Key terms

Encapsulation
Wrapping data with each layer's header as it moves down the stack, creating segments, packets and frames.
Three-way handshake
The SYN, SYN-ACK, ACK exchange that establishes a TCP connection.
NAT
Network address translation: mapping private internal addresses to public addresses at the network edge.
IPv6
The 128-bit successor to IPv4, written in hexadecimal and using Neighbor Discovery instead of ARP.
ARP poisoning
Sending forged ARP replies to link the attacker's MAC address with another host's IP, redirecting local traffic.
DNS cache poisoning
Inserting false records into a DNS resolver's cache so users are sent to attacker-controlled addresses.
On-path attack
An attacker positioned between two parties to intercept, read or modify their communications.
SYN flood
A DoS attack that sends many SYNs without completing the handshake, filling the server's half-open connection backlog.
Dynamic ARP Inspection
A switch feature that drops ARP packets whose IP-to-MAC bindings do not match the DHCP snooping table.
DNSSEC
Extensions that digitally sign DNS records so resolvers can verify their integrity and origin.
SYN cookies
A technique that encodes connection state into the SYN-ACK sequence number so no resources are held for half-open connections.
Egress filtering
Blocking outbound traffic with source addresses that do not belong to your network, preventing participation in spoofed attacks.
802.1X
Port-based network access control in which a supplicant authenticates through an authenticator to an authentication server before traffic is allowed.
RADIUS
An AAA protocol over UDP that combines authentication and authorization and encrypts only the password.
TACACS+
A Cisco-developed AAA protocol over TCP 49 that encrypts the full payload and separates authentication, authorization and accounting.
Posture assessment
Checking a device's security state, such as patches and antimalware, before granting network access.
VLAN
A logical layer 2 broadcast domain that separates devices on shared switches; inter-VLAN traffic must be routed.
Screened subnet (DMZ)
A zone between the internet and internal network that hosts public-facing services behind firewall rules.
Micro-segmentation
Fine-grained, often workload-level, network policy that restricts east-west traffic between systems.
Zero trust
A model where no request is trusted based on network location; every access is verified with least privilege and continuous evaluation.
AH
Authentication Header: IPsec protocol providing integrity, origin authentication and anti-replay, without encryption.
ESP
Encapsulating Security Payload: IPsec protocol providing encryption plus integrity and authentication.
Tunnel mode
IPsec mode that encapsulates and protects the whole original packet inside a new IP header, used between gateways.
Split tunneling
Sending only corporate-bound traffic through the VPN while other traffic goes directly to the internet.
Stateful firewall
A firewall that tracks connection state and allows return traffic only for established sessions.
WAF
Web application firewall: inspects HTTP/HTTPS requests to protect web applications from attacks like SQL injection and XSS.
IDS vs IPS
An IDS detects and alerts out of band; an IPS sits inline and can block traffic.
Reverse proxy
A server that accepts client requests on behalf of internal servers, hiding them and often terminating TLS.
Implicit deny
The default behavior of blocking any traffic that no rule explicitly permits.
First-match processing
Rules are evaluated top down and the first matching rule decides the action.
Shadowed rule
A rule that never takes effect because a broader rule above it always matches first.
SAE
Simultaneous Authentication of Equals: WPA3-Personal handshake that resists offline dictionary attacks.
WPA2/WPA3-Enterprise
Wi-Fi modes that authenticate each user or device through 802.1X and RADIUS rather than a shared passphrase.
Rogue access point
An unauthorized wireless access point connected to an organization's network.
Evil twin
A malicious access point that imitates a legitimate SSID to lure clients into connecting.
SIP
Session Initiation Protocol: the common signaling protocol for setting up and ending VoIP calls.
SRTP
Secure Real-time Transport Protocol: encrypts and authenticates VoIP media streams.
Toll fraud
Unauthorized use of a phone system to place calls, usually expensive international or premium-rate calls, at the victim's expense.
Session border controller
An edge device that secures, controls and normalizes VoIP signaling and media between networks.

Domain 7: Systems & application security (15%)

Exam tips

Key terms

Worm
Self-replicating malware that spreads over networks without a host file or user action.
Trojan
Malware disguised as legitimate software that relies on the user installing it and does not self-replicate.
Rootkit
Malware that hides itself and other malicious activity by modifying the operating system, kernel, boot process or firmware.
Fileless malware
Malware that operates in memory using legitimate system tools, leaving few or no files on disk.
Beaconing
Periodic outbound communication from a compromised host to a command and control server.
Persistence
Techniques that let an attacker keep access across reboots and remediation, such as scheduled tasks or new services.
Privilege escalation
Gaining higher (vertical) or peer-level other-user (horizontal) access than originally obtained.
Indicator of compromise
An artifact, such as a malicious hash, domain or registry key, suggesting a system has been breached.
Signature-based detection
Identifying malware by matching known patterns or hashes; accurate but blind to new variants.
Sandbox
An isolated environment for running untrusted code and observing its behavior safely.
Application allow-listing
Permitting only explicitly approved software to execute and blocking everything else.
Heuristic analysis
Detecting likely malware by suspicious characteristics or behavior rather than exact signatures.
HIDS/HIPS
Host-based intrusion detection or prevention: monitors a single system's activity and alerts (HIDS) or blocks (HIPS).
EDR
Endpoint detection and response: records detailed endpoint telemetry for detection, investigation and remote response.
Hardening
Reducing a system's attack surface by removing unneeded components and applying a secure configuration baseline.
Patch management
The process of identifying, testing, deploying and verifying software updates that fix vulnerabilities.
UEM
Unified endpoint management: a single platform to manage and secure mobile devices and computers across operating systems.
COPE
Corporate-owned, personally enabled: the organization owns and manages the device but allows personal use.
Containerization
Separating corporate apps and data into an encrypted, managed area isolated from personal data on a device.
Selective wipe
Removing only corporate data and apps from a device while leaving personal content intact.
IaaS
Infrastructure as a service: the provider supplies virtualized compute, storage and networking; the customer manages OS and above.
PaaS
Platform as a service: the provider manages infrastructure, OS and runtime; the customer manages applications and data.
SaaS
Software as a service: the provider delivers a complete application; the customer manages users, settings and data.
Shared responsibility model
The division of security duties between cloud provider (security of the cloud) and customer (security in the cloud).
Least privilege IAM
Granting identities only the specific cloud permissions they need, preferably through roles and temporary credentials.
CSPM
Cloud security posture management: continuous scanning of cloud configurations against security and compliance policies.
Customer-managed key
An encryption key in a cloud KMS whose policies and rotation are controlled by the customer rather than the provider.
Data residency
The geographic location where data is stored and processed, often constrained by law or regulation.
Type 1 hypervisor
A bare-metal hypervisor that runs directly on hardware, used in data centers for performance and security.
Type 2 hypervisor
A hosted hypervisor that runs as an application on a conventional operating system.
VM escape
An attack in which code in a guest VM breaks isolation to reach the hypervisor or other VMs.
VM sprawl
Uncontrolled growth of VMs that are no longer tracked, patched or managed.
Input validation
Server-side checking that input matches expected type, length, format and range before it is used.
Parameterized query
A database query where user input is passed as data parameters, never interpreted as part of the SQL command.
Cross-site scripting (XSS)
A flaw that lets attacker-supplied script run in other users' browsers because output was not properly encoded.
OWASP Top 10
A periodically updated awareness list of the most critical web application security risk categories.
Study SSCP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SSCP study plan