dc dotCreds
Reference guide

ISC2 SSCP Course Notes

Study ISC2 SSCP section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 1Security Concepts and Practices (16%)Preview
More in this section
  • 15 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 34 more related questions in Pro version

Summary

Professional operational security: ethics, foundational security properties, control categories/functions, asset/change lifecycle, awareness, and physical security.

Key Points

  • 1.1 Comply with codes of ethics: Professional ethics govern conduct even when an action is technically possible.

Common Mistakes

  • Confusing control category (technical/physical/admin) with control function (prevent/detect/etc.).

Exam Tips

  • Ethics: public safety/trust comes before convenience.
Section 2Access Controls (15%)Preview
More in this section
  • 7 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 31 more related questions in Pro version

Summary

Identity and access: MFA/SSO/federation, device identity, trust boundaries, identity lifecycle, access-control models, and privileged access.

Key Points

  • 2.1 Implement and maintain authentication methods: MFA uses independent factor categories; two passwords are still one factor type.

Common Mistakes

  • Calling OAuth 2.0 an authentication protocol by itself.

Exam Tips

  • Count MFA factor categories, not prompts.
Section 3Risk Identification, Monitoring and Analysis (15%)Preview
More in this section
  • 9 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 2 more related questions in Pro version

Summary

Risk and monitoring: risk visibility/treatment, legal/privacy constraints, assessment and vulnerability lifecycle, SIEM/log operations, and analysis/escalation.

Key Points

  • 3.1 Understand risk management: Risk is evaluated from likelihood and impact in business context, informed by assets, threats, vulnerabilities, exposure and controls.

Common Mistakes

  • Using CVSS as the entire risk decision.

Exam Tips

  • Business context beats raw vulnerability severity.
Section 4Incident Response and Recovery (14%)Preview
More in this section
  • 5 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 29 more related questions in Pro version

Summary

Incident response, forensics, and resilience: sequence response correctly, preserve evidence, and restore critical business/IT services to defined recovery objectives.

Key Points

  • 4.1 Understand and support incident response lifecycle: Preparation establishes plans, roles, contacts, tools, access, logging, training and communications.

Common Mistakes

  • Eradicating before containing a spreading threat.

Exam Tips

  • NEXT-action questions: identify the current phase first.
Section 5Cryptography (9%)Preview
More in this section
  • 7 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 18 more related questions in Pro version

Summary

Cryptography: select the right property and mechanism, use secure protocols, and protect keys/certificates through their full lifecycle.

Key Points

  • 5.1 Understand reasons and requirements for cryptography: Encryption primarily provides confidentiality; hashes/MACs/signatures support integrity/authenticity in different ways.

Common Mistakes

  • Using hashing for confidentiality.

Exam Tips

  • Property first, primitive second.
Section 6Network and Communications Security (16%)Preview
More in this section
  • 13 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 34 more related questions in Pro version

Summary

Network security: layers and ports, attack patterns, NAC/AAA, segmentation and device placement, security appliances, wireless, and IoT.

Key Points

  • 6.1 Understand and apply fundamental concepts of networking: OSI: 7 Application, 6 Presentation, 5 Session, 4 Transport, 3 Network, 2 Data Link, 1 Physical.

Common Mistakes

  • Assuming a VLAN alone is a complete security boundary.

Exam Tips

  • Layer first, then control.
Section 7Systems and Application Security (15%)Preview
More in this section
  • 9 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 31 more related questions in Pro version

Summary

Systems security: malicious code/activity, endpoint controls, mobile/BYOD, cloud shared responsibility, and virtualized/containerized environments.

Key Points

  • 7.1 Identify and analyze malicious code and activity: Virus attaches to a host/file and usually needs execution; worm self-propagates.

Common Mistakes

  • Relying only on signature AV against fileless behavior.

Exam Tips

  • Identify malicious behavior before selecting controls.