ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

18h 10mIntermediate2025-01-28

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

This course provides an in-depth exploration of the ISC2 Systems Security Certified Practitioner (SSCP) exam domains, equipping you with the cybersecurity skills you need to tackle the official exam. Instructor Mike Chapple covers the seven core domains of the exam: Security Concepts and Practices; Access Controls; Risk Identification, Monitoring, and Analysis; Incident Response and Recovery; Cryptography; Network and Communications Security; and Systems and Application Security. Ideal for experienced cybersecurity and cloud computing professionals tasked with managing and mitigating security risks, this course is designed to help prepare you for the SSCP exam.

Skills covered

Network SecurityIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Earning your SSCP

The SSCP Exam

  • The SSCP exam
  • Is the SSCP right for you
  • Careers in information security
  • Value of certification
  • Study resources

Inside the SSCP Exam

  • Registering for the exam
  • Exam environment
  • Question types
  • Passing the SSCP exam

Preparing for the Exam

  • Exam tips
  • Meeting the experience requirement
  • Continuing education requirements

Domain 1 - Security Concepts and Practices

  • Overview of the Security Concepts and Practices Domain

Security Concepts

  • The goals of information security
  • Confidentiality
  • Integrity
  • Availability
  • Accountability
  • Need to know and least privilege
  • Segregation of duties (SoD)
  • Privacy compliance
  • Employee privacy
  • Ethics

Resource Security

  • Physical asset management
  • Software licensing
  • Change and configuration management

Data Security

  • Understanding data security
  • Data security policies
  • Data security roles
  • Limiting data collection
  • The data lifecycle

Security Standards

  • Developing security baselines
  • Leveraging industry standards
  • Customizing security standards

Security Controls

  • Security control selection and implementation
  • Control and risk frameworks
  • Security policy framework
  • DevOps and DevSecOps

Assessing Security Controls

  • Collect security process data
  • Management review
  • Security metrics
  • Audits and assessments
  • Control management

Awareness and Training

  • Security awareness and training
  • Compliance training
  • User habits
  • Social engineering
  • Measuring compliance and security posture

Physical Security

  • Site and facility design
  • Data center environmental controls
  • Data center environmental protection
  • Physical access control
  • Visitor management

Domain 2 - Access Controls

  • Overview of the Access Controls Domain

Identity and Access Management

  • Access controls
  • Identification, authentication, and authorization

Identification

  • Usernames and access cards
  • Biometrics
  • Registration and identity proofing

Authentication

  • Authentication factors
  • Multifactor authentication
  • Something you have
  • Password authentication protocols
  • SSO and federation
  • Internetwork trust architectures
  • Third-party connections
  • Zero-trust network architectures
  • SAML
  • OAuth and OpenID Connect
  • Device authentication

Identity Management Lifecycle

  • Understand account and privilege management
  • Account policies
  • Password policies
  • Manage roles
  • Monitoring, reporting, and maintenance
  • Provisioning and deprovisioning

Authorization

  • Understand authorization
  • Mandatory access controls
  • Discretionary access controls
  • Access control lists
  • Advanced authorization concepts

Domain 3 - Risk Identification, Monitoring, and Analysis

  • Overview of the Risk Identification, Monitoring, and Analysis Domain

Risk Management

  • Risk assessment
  • Quantitative risk assessment
  • Risk management
  • Ongoing risk management
  • Risk management frameworks
  • Risk visibility and reporting

Threat Modeling

  • Threat intelligence
  • Managing threat indicators
  • Intelligence sharing
  • Identifying threats
  • Automating threat intelligence
  • Threat hunting
  • MITRE ATT&CK

Understanding Vulnerability Types

  • Vulnerability impacts
  • Supply chain vulnerabilities
  • Configuration vulnerabilities
  • Architectural vulnerabilities

Vulnerability Scanning

  • What is vulnerability management
  • Identifying scan targets
  • Scan configuration
  • Scan perspective
  • SCAP
  • CVSS
  • Interpreting CVSS scores
  • Analyzing scan reports
  • Correlating scan results

Legal and Regulatory Concerns

  • Legal and compliance risks
  • Legal definitions
  • Data privacy
  • Data breaches

Security Monitoring

  • Monitoring log files
  • Security information and event management
  • Continuous security monitoring
  • Visualization and reporting
  • Compliance monitoring
  • Legal and ethical issues in monitoring

Domain 4 - Incident Response and Recovery

  • Overview of the Incident Response and Recovery Domain

Incident Management

  • Build an incident response program
  • Creating an incident response team
  • Incident communications plan
  • Incident detection
  • Escalation and notification
  • Mitigation
  • Containment techniques
  • Incident eradication and recovery
  • Validation
  • Post-incident activities
  • Incident response exercises

Investigations and Forensics

  • Conducting investigations
  • Evidence types
  • Introduction to forensics
  • System and file forensics
  • Network forensics
  • Software forensics
  • Mobile device forensics
  • Embedded device forensics
  • Chain of custody
  • Reporting and documenting incidents
  • Electronic discovery (ediscovery)

Business Continuity

  • Business continuity planning
  • Business continuity controls
  • High availability and fault tolerance

Disaster Recovery

  • Disaster recovery planning
  • Backups
  • Restoring backups
  • Disaster recovery sites
  • Testing BC DR plans
  • After action reports

Emergency Response

  • Building an emergency response plan

Domain 5 - Cryptography

  • Overview of the Cryptography Domain

Encryption

  • Understanding encryption
  • Symmetric and asymmetric cryptography
  • Goals of cryptography
  • Codes and ciphers
  • Choosing encryption algorithms
  • The perfect encryption algorithm
  • The cryptographic lifecycle

Symmetric Cryptography

  • Data encryption standard
  • 3DES
  • AES, Blowfish, and Twofish
  • RC4
  • Steganography

Asymmetric Cryptography

  • Rivest-Shamir-Adleman (RSA)
  • PGP and GnuPG
  • Elliptic curve and quantum cryptography

Key Management

  • Cryptographic key security
  • Key exchange
  • Diffie-Hellman
  • Key escrow
  • Key stretching

Public Key Infrastructure

  • Trust models
  • PKI and digital certificates
  • Hash functions
  • Digital signatures
  • Create a digital certificate
  • Revoke a digital certificate
  • Certificate stapling
  • Certificate authorities
  • Certificate subjects
  • Certificate types
  • Certificate formats

Transport Encryption

  • TLS and SSL
  • IPSec
  • Securing common protocols
  • DKIM
  • Tor and perfect forward secrecy
  • Blockchain

Cryptanalytic Attacks

  • Brute-force attacks
  • Knowledge-based attacks
  • Limitations of encryption algorithms

Domain 6 - Network and Communications Security

  • Overview of the Network and Communications Security Domain

TCP IP Networking

  • Introducing TCP IP
  • IP addressing and DHCP
  • Domain Name System (DNS)
  • Network ports
  • ICMP
  • Network topologies
  • Network relationships

Network Security Devices

  • Routers, switches, and bridges
  • Firewalls
  • Proxy servers
  • Load balancers
  • VPNs and VPN concentrators
  • Network intrusion detection and prevention
  • Protocol analyzers
  • Content distribution networks
  • Traffic shaping and WAN optimization
  • Unified threat management

Secure Network Design

  • Public and private addressing
  • Subnetting
  • Security zones
  • VLANs and network segmentation
  • Security device placement
  • Software-defined networking (SDN)
  • Transmission media

Network Security Technologies

  • Restricting network access
  • Network access control
  • RADIUS and TACACS
  • Firewall rule management
  • Router configuration security
  • Switch configuration security
  • Maintaining network availability
  • Network monitoring
  • SNMP
  • Isolating sensitive systems

Remote Network Access

  • Remote network access
  • Desktop and application virtualization

Wireless Networking

  • Understanding wireless networking
  • Wireless encryption
  • Wireless authentication
  • Wireless signal propagation
  • Wireless networking equipment

Network Attacks

  • Denial of service attacks
  • Eavesdropping attacks
  • DNS attacks
  • Layer 2 attacks
  • Network address spoofing
  • Wireless attacks
  • Propagation attacks
  • Preventing rogues and evil twins
  • Disassociation attacks
  • Understanding Bluetooth and NFC attacks

Domain 7 - Systems and Application Security

  • Overview of the Systems and Application Security Domain

Malware

  • Comparing viruses, worms, and trojans
  • Malware payloads
  • Understanding backdoors and logic bombs
  • Looking at advanced malware
  • Understanding botnets
  • Code signing

Understanding Attackers

  • Cybersecurity adversaries
  • Preventing insider threats
  • Attack vectors
  • Zero-days and the Advanced Persistent Threat

Social Engineering Attacks

  • Social engineering
  • Impersonation attacks
  • Identity fraud and pretexting
  • Watering hole attacks
  • Physical social engineering

Web Application Attacks

  • OWASP Top Ten
  • Application security
  • Preventing SQL injection
  • Understanding cross-site scripting
  • Request forgery
  • Defending against directory traversal
  • Overflow attacks
  • Explaining cookies and attachments
  • Session hijacking
  • Code execution attacks

Host Security

  • Operating system security
  • Malware prevention
  • Application management
  • Host-based network security controls
  • File integrity monitoring
  • Data loss prevention
  • Endpoint monitoring

Hardware Security

  • Hardware encryption
  • Hardware and firmware security
  • Peripheral security

Mobile Device Security

  • Mobile connection methods
  • Mobile device security
  • Mobile device management
  • Mobile device tracking
  • Mobile application management
  • Mobile security enforcement
  • Bring Your Own Device (BYOD)
  • Mobile deployment models

Embedded Systems Security

  • Industrial control systems
  • Internet of Things
  • Securing smart devices
  • Secure networking for smart devices

Cloud Computing

  • What is the cloud
  • Cloud activities and the Cloud Reference Architecture
  • Cloud deployment models
  • Cloud service categories
  • Virtualization
  • Cloud compute resources
  • Cloud storage
  • Containers

Cloud Issues

  • Security and privacy concerns in the cloud
  • Data sovereignty
  • Cloud access security brokers
  • Operational concerns in the cloud

Conclusion

  • Preparing for the exam
250,000 Toman