ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep
18h 10mIntermediate2025-01-28
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
This course provides an in-depth exploration of the ISC2 Systems Security Certified Practitioner (SSCP) exam domains, equipping you with the cybersecurity skills you need to tackle the official exam. Instructor Mike Chapple covers the seven core domains of the exam: Security Concepts and Practices; Access Controls; Risk Identification, Monitoring, and Analysis; Incident Response and Recovery; Cryptography; Network and Communications Security; and Systems and Application Security. Ideal for experienced cybersecurity and cloud computing professionals tasked with managing and mitigating security risks, this course is designed to help prepare you for the SSCP exam.
Skills covered
Network SecurityIncident ResponseCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Earning your SSCP
1. The SSCP Exam
- 02 - The SSCP exam
- 03 - Is the SSCP right for you
- 04 - Careers in information security
- 05 - Value of certification
- 06 - Study resources
2. Inside the SSCP Exam
- 07 - Registering for the exam
- 08 - Exam environment
- 09 - Question types
- 10 - Passing the SSCP exam
3. Preparing for the Exam
- 11 - Exam tips
- 12 - Meeting the experience requirement
- 13 - Continuing education requirements
4. Domain 1 - Security Concepts and Practices
- 14 - Overview of the Security Concepts and Practices Domain
5. Security Concepts
- 15 - The goals of information security
- 16 - Confidentiality
- 17 - Integrity
- 18 - Availability
- 19 - Accountability
- 20 - Need to know and least privilege
- 21 - Segregation of duties (SoD)
- 22 - Privacy compliance
- 23 - Employee privacy
- 24 - Ethics
6. Resource Security
- 25 - Physical asset management
- 26 - Software licensing
- 27 - Change and configuration management
7. Data Security
- 28 - Understanding data security
- 29 - Data security policies
- 30 - Data security roles
- 31 - Limiting data collection
- 32 - The data lifecycle
8. Security Standards
- 33 - Developing security baselines
- 34 - Leveraging industry standards
- 35 - Customizing security standards
9. Security Controls
- 36 - Security control selection and implementation
- 37 - Control and risk frameworks
- 38 - Security policy framework
- 39 - DevOps and DevSecOps
10. Assessing Security Controls
- 40 - Collect security process data
- 41 - Management review
- 42 - Security metrics
- 43 - Audits and assessments
- 44 - Control management
11. Awareness and Training
- 45 - Security awareness and training
- 46 - Compliance training
- 47 - User habits
- 48 - Social engineering
- 49 - Measuring compliance and security posture
12. Physical Security
- 50 - Site and facility design
- 51 - Data center environmental controls
- 52 - Data center environmental protection
- 53 - Physical access control
- 54 - Visitor management
13. Domain 2 - Access Controls
- 55 - Overview of the Access Controls Domain
14. Identity and Access Management
- 56 - Access controls
- 57 - Identification, authentication, and authorization
15. Identification
- 58 - Usernames and access cards
- 59 - Biometrics
- 60 - Registration and identity proofing
16. Authentication
- 61 - Authentication factors
- 62 - Multifactor authentication
- 63 - Something you have
- 64 - Password authentication protocols
- 65 - SSO and federation
- 66 - Internetwork trust architectures
- 67 - Third-party connections
- 68 - Zero-trust network architectures
- 69 - SAML
- 70 - OAuth and OpenID Connect
- 71 - Device authentication
17. Identity Management Lifecycle
- 72 - Understand account and privilege management
- 73 - Account policies
- 74 - Password policies
- 75 - Manage roles
- 76 - Monitoring, reporting, and maintenance
- 77 - Provisioning and deprovisioning
18. Authorization
- 78 - Understand authorization
- 79 - Mandatory access controls
- 80 - Discretionary access controls
- 81 - Access control lists
- 82 - Advanced authorization concepts
19. Domain 3 - Risk Identification, Monitoring, and Analysis
- 83 - Overview of the Risk Identification, Monitoring, and Analysis Domain
20. Risk Management
- 84 - Risk assessment
- 85 - Quantitative risk assessment
- 86 - Risk management
- 87 - Ongoing risk management
- 88 - Risk management frameworks
- 89 - Risk visibility and reporting
21. Threat Modeling
- 90 - Threat intelligence
- 91 - Managing threat indicators
- 92 - Intelligence sharing
- 93 - Identifying threats
- 94 - Automating threat intelligence
- 95 - Threat hunting
- 96 - MITRE ATT&CK
22. Understanding Vulnerability Types
- 97 - Vulnerability impacts
- 98 - Supply chain vulnerabilities
- 99 - Configuration vulnerabilities
- 100 - Architectural vulnerabilities
23. Vulnerability Scanning
- 101 - What is vulnerability management
- 102 - Identifying scan targets
- 103 - Scan configuration
- 104 - Scan perspective
- 105 - SCAP
- 106 - CVSS
- 107 - Interpreting CVSS scores
- 108 - Analyzing scan reports
- 109 - Correlating scan results
24. Legal and Regulatory Concerns
- 110 - Legal and compliance risks
- 111 - Legal definitions
- 112 - Data privacy
- 113 - Data breaches
25. Security Monitoring
- 114 - Monitoring log files
- 115 - Security information and event management
- 116 - Continuous security monitoring
- 117 - Visualization and reporting
- 118 - Compliance monitoring
- 119 - Legal and ethical issues in monitoring
26. Domain 4 - Incident Response and Recovery
- 120 - Overview of the Incident Response and Recovery Domain
27. Incident Management
- 121 - Build an incident response program
- 122 - Creating an incident response team
- 123 - Incident communications plan
- 124 - Incident detection
- 125 - Escalation and notification
- 126 - Mitigation
- 127 - Containment techniques
- 128 - Incident eradication and recovery
- 129 - Validation
- 130 - Post-incident activities
- 131 - Incident response exercises
28. Investigations and Forensics
- 132 - Conducting investigations
- 133 - Evidence types
- 134 - Introduction to forensics
- 135 - System and file forensics
- 136 - Network forensics
- 137 - Software forensics
- 138 - Mobile device forensics
- 139 - Embedded device forensics
- 140 - Chain of custody
- 141 - Reporting and documenting incidents
- 142 - Electronic discovery (ediscovery)
29. Business Continuity
- 143 - Business continuity planning
- 144 - Business continuity controls
- 145 - High availability and fault tolerance
30. Disaster Recovery
- 146 - Disaster recovery planning
- 147 - Backups
- 148 - Restoring backups
- 149 - Disaster recovery sites
- 150 - Testing BC DR plans
- 151 - After action reports
31. Emergency Response
- 152 - Building an emergency response plan
32. Domain 5 - Cryptography
- 153 - Overview of the Cryptography Domain
33. Encryption
- 154 - Understanding encryption
- 155 - Symmetric and asymmetric cryptography
- 156 - Goals of cryptography
- 157 - Codes and ciphers
- 158 - Choosing encryption algorithms
- 159 - The perfect encryption algorithm
- 160 - The cryptographic lifecycle
34. Symmetric Cryptography
- 161 - Data encryption standard
- 162 - 3DES
- 163 - AES, Blowfish, and Twofish
- 164 - RC4
- 165 - Steganography
35. Asymmetric Cryptography
- 166 - Rivest-Shamir-Adleman (RSA)
- 167 - PGP and GnuPG
- 168 - Elliptic curve and quantum cryptography
36. Key Management
- 169 - Cryptographic key security
- 170 - Key exchange
- 171 - Diffie-Hellman
- 172 - Key escrow
- 173 - Key stretching
37. Public Key Infrastructure
- 174 - Trust models
- 175 - PKI and digital certificates
- 176 - Hash functions
- 177 - Digital signatures
- 178 - Create a digital certificate
- 179 - Revoke a digital certificate
- 180 - Certificate stapling
- 181 - Certificate authorities
- 182 - Certificate subjects
- 183 - Certificate types
- 184 - Certificate formats
38. Transport Encryption
- 185 - TLS and SSL
- 186 - IPSec
- 187 - Securing common protocols
- 188 - DKIM
- 189 - Tor and perfect forward secrecy
- 190 - Blockchain
39. Cryptanalytic Attacks
- 191 - Brute-force attacks
- 192 - Knowledge-based attacks
- 193 - Limitations of encryption algorithms
40. Domain 6 - Network and Communications Security
- 194 - Overview of the Network and Communications Security Domain
41. TCP IP Networking
- 195 - Introducing TCP IP
- 196 - IP addressing and DHCP
- 197 - Domain Name System (DNS)
- 198 - Network ports
- 199 - ICMP
- 200 - Network topologies
- 201 - Network relationships
42. Network Security Devices
- 202 - Routers, switches, and bridges
- 203 - Firewalls
- 204 - Proxy servers
- 205 - Load balancers
- 206 - VPNs and VPN concentrators
- 207 - Network intrusion detection and prevention
- 208 - Protocol analyzers
- 209 - Content distribution networks
- 210 - Traffic shaping and WAN optimization
- 211 - Unified threat management
43. Secure Network Design
- 212 - Public and private addressing
- 213 - Subnetting
- 214 - Security zones
- 215 - VLANs and network segmentation
- 216 - Security device placement
- 217 - Software-defined networking (SDN)
- 218 - Transmission media
44. Network Security Technologies
- 219 - Restricting network access
- 220 - Network access control
- 221 - RADIUS and TACACS
- 222 - Firewall rule management
- 223 - Router configuration security
- 224 - Switch configuration security
- 225 - Maintaining network availability
- 226 - Network monitoring
- 227 - SNMP
- 228 - Isolating sensitive systems
45. Remote Network Access
- 229 - Remote network access
- 230 - Desktop and application virtualization
46. Wireless Networking
- 231 - Understanding wireless networking
- 232 - Wireless encryption
- 233 - Wireless authentication
- 234 - Wireless signal propagation
- 235 - Wireless networking equipment
47. Network Attacks
- 236 - Denial of service attacks
- 237 - Eavesdropping attacks
- 238 - DNS attacks
- 239 - Layer 2 attacks
- 240 - Network address spoofing
- 241 - Wireless attacks
- 242 - Propagation attacks
- 243 - Preventing rogues and evil twins
- 244 - Disassociation attacks
- 245 - Understanding Bluetooth and NFC attacks
48. Domain 7 - Systems and Application Security
- 246 - Overview of the Systems and Application Security Domain
49. Malware
- 247 - Comparing viruses, worms, and trojans
- 248 - Malware payloads
- 249 - Understanding backdoors and logic bombs
- 250 - Looking at advanced malware
- 251 - Understanding botnets
- 252 - Code signing
50. Understanding Attackers
- 253 - Cybersecurity adversaries
- 254 - Preventing insider threats
- 255 - Attack vectors
- 256 - Zero-days and the Advanced Persistent Threat
51. Social Engineering Attacks
- 257 - Social engineering
- 258 - Impersonation attacks
- 259 - Identity fraud and pretexting
- 260 - Watering hole attacks
- 261 - Physical social engineering
52. Web Application Attacks
- 262 - OWASP Top Ten
- 263 - Application security
- 264 - Preventing SQL injection
- 265 - Understanding cross-site scripting
- 266 - Request forgery
- 267 - Defending against directory traversal
- 268 - Overflow attacks
- 269 - Explaining cookies and attachments
- 270 - Session hijacking
- 271 - Code execution attacks
53. Host Security
- 272 - Operating system security
- 273 - Malware prevention
- 274 - Application management
- 275 - Host-based network security controls
- 276 - File integrity monitoring
- 277 - Data loss prevention
- 278 - Endpoint monitoring
54. Hardware Security
- 279 - Hardware encryption
- 280 - Hardware and firmware security
- 281 - Peripheral security
55. Mobile Device Security
- 282 - Mobile connection methods
- 283 - Mobile device security
- 284 - Mobile device management
- 285 - Mobile device tracking
- 286 - Mobile application management
- 287 - Mobile security enforcement
- 288 - Bring Your Own Device (BYOD)
- 289 - Mobile deployment models
56. Embedded Systems Security
- 290 - Industrial control systems
- 291 - Internet of Things
- 292 - Securing smart devices
- 293 - Secure networking for smart devices
57. Cloud Computing
- 294 - What is the cloud
- 295 - Cloud activities and the Cloud Reference Architecture
- 296 - Cloud deployment models
- 297 - Cloud service categories
- 298 - Virtualization
- 299 - Cloud compute resources
- 300 - Cloud storage
- 301 - Containers
58. Cloud Issues
- 302 - Security and privacy concerns in the cloud
- 303 - Data sovereignty
- 304 - Cloud access security brokers
- 305 - Operational concerns in the cloud
Conclusion
- 306 - Preparing for the exam