Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

18h 10mIntermediate2025-01-28

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

This course provides an in-depth exploration of the ISC2 Systems Security Certified Practitioner (SSCP) exam domains, equipping you with the cybersecurity skills you need to tackle the official exam. Instructor Mike Chapple covers the seven core domains of the exam: Security Concepts and Practices; Access Controls; Risk Identification, Monitoring, and Analysis; Incident Response and Recovery; Cryptography; Network and Communications Security; and Systems and Application Security. Ideal for experienced cybersecurity and cloud computing professionals tasked with managing and mitigating security risks, this course is designed to help prepare you for the SSCP exam.

Skills covered

Network SecurityIncident ResponseCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Earning your SSCP

1. The SSCP Exam

  • 02 - The SSCP exam
  • 03 - Is the SSCP right for you
  • 04 - Careers in information security
  • 05 - Value of certification
  • 06 - Study resources

2. Inside the SSCP Exam

  • 07 - Registering for the exam
  • 08 - Exam environment
  • 09 - Question types
  • 10 - Passing the SSCP exam

3. Preparing for the Exam

  • 11 - Exam tips
  • 12 - Meeting the experience requirement
  • 13 - Continuing education requirements

4. Domain 1 - Security Concepts and Practices

  • 14 - Overview of the Security Concepts and Practices Domain

5. Security Concepts

  • 15 - The goals of information security
  • 16 - Confidentiality
  • 17 - Integrity
  • 18 - Availability
  • 19 - Accountability
  • 20 - Need to know and least privilege
  • 21 - Segregation of duties (SoD)
  • 22 - Privacy compliance
  • 23 - Employee privacy
  • 24 - Ethics

6. Resource Security

  • 25 - Physical asset management
  • 26 - Software licensing
  • 27 - Change and configuration management

7. Data Security

  • 28 - Understanding data security
  • 29 - Data security policies
  • 30 - Data security roles
  • 31 - Limiting data collection
  • 32 - The data lifecycle

8. Security Standards

  • 33 - Developing security baselines
  • 34 - Leveraging industry standards
  • 35 - Customizing security standards

9. Security Controls

  • 36 - Security control selection and implementation
  • 37 - Control and risk frameworks
  • 38 - Security policy framework
  • 39 - DevOps and DevSecOps

10. Assessing Security Controls

  • 40 - Collect security process data
  • 41 - Management review
  • 42 - Security metrics
  • 43 - Audits and assessments
  • 44 - Control management

11. Awareness and Training

  • 45 - Security awareness and training
  • 46 - Compliance training
  • 47 - User habits
  • 48 - Social engineering
  • 49 - Measuring compliance and security posture

12. Physical Security

  • 50 - Site and facility design
  • 51 - Data center environmental controls
  • 52 - Data center environmental protection
  • 53 - Physical access control
  • 54 - Visitor management

13. Domain 2 - Access Controls

  • 55 - Overview of the Access Controls Domain

14. Identity and Access Management

  • 56 - Access controls
  • 57 - Identification, authentication, and authorization

15. Identification

  • 58 - Usernames and access cards
  • 59 - Biometrics
  • 60 - Registration and identity proofing

16. Authentication

  • 61 - Authentication factors
  • 62 - Multifactor authentication
  • 63 - Something you have
  • 64 - Password authentication protocols
  • 65 - SSO and federation
  • 66 - Internetwork trust architectures
  • 67 - Third-party connections
  • 68 - Zero-trust network architectures
  • 69 - SAML
  • 70 - OAuth and OpenID Connect
  • 71 - Device authentication

17. Identity Management Lifecycle

  • 72 - Understand account and privilege management
  • 73 - Account policies
  • 74 - Password policies
  • 75 - Manage roles
  • 76 - Monitoring, reporting, and maintenance
  • 77 - Provisioning and deprovisioning

18. Authorization

  • 78 - Understand authorization
  • 79 - Mandatory access controls
  • 80 - Discretionary access controls
  • 81 - Access control lists
  • 82 - Advanced authorization concepts

19. Domain 3 - Risk Identification, Monitoring, and Analysis

  • 83 - Overview of the Risk Identification, Monitoring, and Analysis Domain

20. Risk Management

  • 84 - Risk assessment
  • 85 - Quantitative risk assessment
  • 86 - Risk management
  • 87 - Ongoing risk management
  • 88 - Risk management frameworks
  • 89 - Risk visibility and reporting

21. Threat Modeling

  • 90 - Threat intelligence
  • 91 - Managing threat indicators
  • 92 - Intelligence sharing
  • 93 - Identifying threats
  • 94 - Automating threat intelligence
  • 95 - Threat hunting
  • 96 - MITRE ATT&CK

22. Understanding Vulnerability Types

  • 97 - Vulnerability impacts
  • 98 - Supply chain vulnerabilities
  • 99 - Configuration vulnerabilities
  • 100 - Architectural vulnerabilities

23. Vulnerability Scanning

  • 101 - What is vulnerability management
  • 102 - Identifying scan targets
  • 103 - Scan configuration
  • 104 - Scan perspective
  • 105 - SCAP
  • 106 - CVSS
  • 107 - Interpreting CVSS scores
  • 108 - Analyzing scan reports
  • 109 - Correlating scan results

24. Legal and Regulatory Concerns

  • 110 - Legal and compliance risks
  • 111 - Legal definitions
  • 112 - Data privacy
  • 113 - Data breaches

25. Security Monitoring

  • 114 - Monitoring log files
  • 115 - Security information and event management
  • 116 - Continuous security monitoring
  • 117 - Visualization and reporting
  • 118 - Compliance monitoring
  • 119 - Legal and ethical issues in monitoring

26. Domain 4 - Incident Response and Recovery

  • 120 - Overview of the Incident Response and Recovery Domain

27. Incident Management

  • 121 - Build an incident response program
  • 122 - Creating an incident response team
  • 123 - Incident communications plan
  • 124 - Incident detection
  • 125 - Escalation and notification
  • 126 - Mitigation
  • 127 - Containment techniques
  • 128 - Incident eradication and recovery
  • 129 - Validation
  • 130 - Post-incident activities
  • 131 - Incident response exercises

28. Investigations and Forensics

  • 132 - Conducting investigations
  • 133 - Evidence types
  • 134 - Introduction to forensics
  • 135 - System and file forensics
  • 136 - Network forensics
  • 137 - Software forensics
  • 138 - Mobile device forensics
  • 139 - Embedded device forensics
  • 140 - Chain of custody
  • 141 - Reporting and documenting incidents
  • 142 - Electronic discovery (ediscovery)

29. Business Continuity

  • 143 - Business continuity planning
  • 144 - Business continuity controls
  • 145 - High availability and fault tolerance

30. Disaster Recovery

  • 146 - Disaster recovery planning
  • 147 - Backups
  • 148 - Restoring backups
  • 149 - Disaster recovery sites
  • 150 - Testing BC DR plans
  • 151 - After action reports

31. Emergency Response

  • 152 - Building an emergency response plan

32. Domain 5 - Cryptography

  • 153 - Overview of the Cryptography Domain

33. Encryption

  • 154 - Understanding encryption
  • 155 - Symmetric and asymmetric cryptography
  • 156 - Goals of cryptography
  • 157 - Codes and ciphers
  • 158 - Choosing encryption algorithms
  • 159 - The perfect encryption algorithm
  • 160 - The cryptographic lifecycle

34. Symmetric Cryptography

  • 161 - Data encryption standard
  • 162 - 3DES
  • 163 - AES, Blowfish, and Twofish
  • 164 - RC4
  • 165 - Steganography

35. Asymmetric Cryptography

  • 166 - Rivest-Shamir-Adleman (RSA)
  • 167 - PGP and GnuPG
  • 168 - Elliptic curve and quantum cryptography

36. Key Management

  • 169 - Cryptographic key security
  • 170 - Key exchange
  • 171 - Diffie-Hellman
  • 172 - Key escrow
  • 173 - Key stretching

37. Public Key Infrastructure

  • 174 - Trust models
  • 175 - PKI and digital certificates
  • 176 - Hash functions
  • 177 - Digital signatures
  • 178 - Create a digital certificate
  • 179 - Revoke a digital certificate
  • 180 - Certificate stapling
  • 181 - Certificate authorities
  • 182 - Certificate subjects
  • 183 - Certificate types
  • 184 - Certificate formats

38. Transport Encryption

  • 185 - TLS and SSL
  • 186 - IPSec
  • 187 - Securing common protocols
  • 188 - DKIM
  • 189 - Tor and perfect forward secrecy
  • 190 - Blockchain

39. Cryptanalytic Attacks

  • 191 - Brute-force attacks
  • 192 - Knowledge-based attacks
  • 193 - Limitations of encryption algorithms

40. Domain 6 - Network and Communications Security

  • 194 - Overview of the Network and Communications Security Domain

41. TCP IP Networking

  • 195 - Introducing TCP IP
  • 196 - IP addressing and DHCP
  • 197 - Domain Name System (DNS)
  • 198 - Network ports
  • 199 - ICMP
  • 200 - Network topologies
  • 201 - Network relationships

42. Network Security Devices

  • 202 - Routers, switches, and bridges
  • 203 - Firewalls
  • 204 - Proxy servers
  • 205 - Load balancers
  • 206 - VPNs and VPN concentrators
  • 207 - Network intrusion detection and prevention
  • 208 - Protocol analyzers
  • 209 - Content distribution networks
  • 210 - Traffic shaping and WAN optimization
  • 211 - Unified threat management

43. Secure Network Design

  • 212 - Public and private addressing
  • 213 - Subnetting
  • 214 - Security zones
  • 215 - VLANs and network segmentation
  • 216 - Security device placement
  • 217 - Software-defined networking (SDN)
  • 218 - Transmission media

44. Network Security Technologies

  • 219 - Restricting network access
  • 220 - Network access control
  • 221 - RADIUS and TACACS
  • 222 - Firewall rule management
  • 223 - Router configuration security
  • 224 - Switch configuration security
  • 225 - Maintaining network availability
  • 226 - Network monitoring
  • 227 - SNMP
  • 228 - Isolating sensitive systems

45. Remote Network Access

  • 229 - Remote network access
  • 230 - Desktop and application virtualization

46. Wireless Networking

  • 231 - Understanding wireless networking
  • 232 - Wireless encryption
  • 233 - Wireless authentication
  • 234 - Wireless signal propagation
  • 235 - Wireless networking equipment

47. Network Attacks

  • 236 - Denial of service attacks
  • 237 - Eavesdropping attacks
  • 238 - DNS attacks
  • 239 - Layer 2 attacks
  • 240 - Network address spoofing
  • 241 - Wireless attacks
  • 242 - Propagation attacks
  • 243 - Preventing rogues and evil twins
  • 244 - Disassociation attacks
  • 245 - Understanding Bluetooth and NFC attacks

48. Domain 7 - Systems and Application Security

  • 246 - Overview of the Systems and Application Security Domain

49. Malware

  • 247 - Comparing viruses, worms, and trojans
  • 248 - Malware payloads
  • 249 - Understanding backdoors and logic bombs
  • 250 - Looking at advanced malware
  • 251 - Understanding botnets
  • 252 - Code signing

50. Understanding Attackers

  • 253 - Cybersecurity adversaries
  • 254 - Preventing insider threats
  • 255 - Attack vectors
  • 256 - Zero-days and the Advanced Persistent Threat

51. Social Engineering Attacks

  • 257 - Social engineering
  • 258 - Impersonation attacks
  • 259 - Identity fraud and pretexting
  • 260 - Watering hole attacks
  • 261 - Physical social engineering

52. Web Application Attacks

  • 262 - OWASP Top Ten
  • 263 - Application security
  • 264 - Preventing SQL injection
  • 265 - Understanding cross-site scripting
  • 266 - Request forgery
  • 267 - Defending against directory traversal
  • 268 - Overflow attacks
  • 269 - Explaining cookies and attachments
  • 270 - Session hijacking
  • 271 - Code execution attacks

53. Host Security

  • 272 - Operating system security
  • 273 - Malware prevention
  • 274 - Application management
  • 275 - Host-based network security controls
  • 276 - File integrity monitoring
  • 277 - Data loss prevention
  • 278 - Endpoint monitoring

54. Hardware Security

  • 279 - Hardware encryption
  • 280 - Hardware and firmware security
  • 281 - Peripheral security

55. Mobile Device Security

  • 282 - Mobile connection methods
  • 283 - Mobile device security
  • 284 - Mobile device management
  • 285 - Mobile device tracking
  • 286 - Mobile application management
  • 287 - Mobile security enforcement
  • 288 - Bring Your Own Device (BYOD)
  • 289 - Mobile deployment models

56. Embedded Systems Security

  • 290 - Industrial control systems
  • 291 - Internet of Things
  • 292 - Securing smart devices
  • 293 - Secure networking for smart devices

57. Cloud Computing

  • 294 - What is the cloud
  • 295 - Cloud activities and the Cloud Reference Architecture
  • 296 - Cloud deployment models
  • 297 - Cloud service categories
  • 298 - Virtualization
  • 299 - Cloud compute resources
  • 300 - Cloud storage
  • 301 - Containers

58. Cloud Issues

  • 302 - Security and privacy concerns in the cloud
  • 303 - Data sovereignty
  • 304 - Cloud access security brokers
  • 305 - Operational concerns in the cloud

Conclusion

  • 306 - Preparing for the exam

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal