Click Study Flashcards above to open the flashcard hub — hundreds of SSCP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the seven official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
SSCP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
SSCP Flashcard Study Modes
Four ways to work the same 300 cards: Flip for quiet study, Match for a timed race pairing terms with their definitions, Type to read a definition and spell the term back, and Quiz for multiple choice pulled from the deck. Type is where recall gets honest — you see the description and have to produce Kerberos or DAD triad yourself.

Why Flashcards Work for the SSCP
Security Concepts & Practices carries 54 cards and ties for the heaviest weight at 16%, so it is the natural opening. These cards drill the vocabulary of governance and foundational security models, separating documents that look alike — Policy, Standard, Procedure and Guideline all appear as distinct fronts — alongside concepts like Due care, the CIA triad and the DAD triad.
Network & Communications Security also sits at 16% with 44 cards covering perimeter devices, segmentation and wireless protection, including WAF, DMZ and WPA3 as well as the IDS and IPS pairing that candidates routinely blur. Access Controls adds 42 cards at 15%, focused on authentication and federation terms such as SAML, RADIUS and TACACS+, plus one-factor and multifactor building blocks like OTP.
Risk Identification, Monitoring & Analysis brings 43 cards for its 15%, mixing measurement and regulation: CVSS and CVE for vulnerability scoring and cataloging, SIEM for monitoring, and privacy and compliance terms including PII, GDPR and HIPAA. Systems & Application Security contributes 46 cards, also 15%, spanning endpoint defenses such as EDR and HIPS, malware types like Worm, and cloud service models IaaS, PaaS and SaaS.
Incident Response & Recovery holds 35 cards at 14% and follows the lifecycle, from the CSIRT that responds through Containment, Eradication and Escalation, then into recovery options like Hot site, Warm site and Cold site. Cryptography closes with 36 cards for 9%, covering algorithms and infrastructure — AES, RSA, ECC, HMAC — plus protocols and key management pieces such as TLS, CRL and HSM.
The SSCP is dense with terminology — access control models, risk formulas, cryptography, networking, and incident response.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
SSCP Flashcards by Domain
The cards are organized by the seven official ISC2 domains. The weights are fairly even, so cover them all — but start with the two heaviest, Security Concepts & Practices and Network & Communications Security:[1]
| Domain | Exam weight |
|---|---|
| Security Concepts & Practices | 16% |
| Network & Communications Security | 16% |
| Access Controls | 15% |
| Risk Identification, Monitoring & Analysis | 15% |
| Systems & Application Security | 15% |
| Incident Response & Recovery | 14% |
| Cryptography | 9% |
How to Get the Most Out of These Flashcards
- Start with the foundation. Security Concepts & Practices is 54 cards at 16%; its Policy, Standard, Procedure and Guideline distinctions shape how you read questions in every other domain.
- Type-drill the lookalikes. Force yourself to produce IDS versus IPS, and Hot site versus Warm site, because multiple choice lets you guess while typing exposes fuzzy recall.
- Use Match for acronyms. The short cryptography and access control fronts — AES, HMAC, SAML, LDAP — pair fast, and the timer pushes you toward instant recognition instead of reasoning.
- Switch when recall is clean. Once Quiz runs smooth across Risk Identification, Monitoring & Analysis and Systems & Application Security, move to the practice test for scenario wording and the study guide for depth.
- Rotate rather than cram. With 300 cards across seven domains, cycle two domains per session and revisit Cryptography and Incident Response & Recovery often, since their 36 and 35 cards fade quickly.
SSCP Flashcards FAQ
Hundreds of free SSCP flashcards, organized across all seven ISC2 domains — Security Concepts & Practices, Access Controls, Risk Identification Monitoring & Analysis, Incident Response & Recovery, Cryptography, Network & Communications Security, and Systems & Application Security. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the SSCP's heavy terminology across access controls, cryptography, networking, and operations.
All seven ISC2 domains: Security Concepts & Practices (CIA, ethics, controls), Access Controls (authentication, MFA, models), Risk Identification Monitoring & Analysis, Incident Response & Recovery, Cryptography, Network & Communications Security (OSI, firewalls, IDS/IPS), and Systems & Application Security (malware, cloud, virtualization).
Cover all seven domains, but lead with the two heaviest at 16% each — Security Concepts & Practices and Network & Communications Security. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 exam outline effective October 1, 2025, covering all seven domains in their official proportions.
SSCP flashcard bank
All 300 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Security Concepts & Practices (54)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Preventing unauthorized disclosure of data; enforced by encryption and access control.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered except by authorized parties; enforced by hashing and change control.
- Availability
Show answerHide answer
Ensuring authorized users have timely, reliable access; enforced by redundancy, backups, and fault tolerance.
- Accountability
Show answerHide answer
Tying actions back to a specific identity through logging and monitoring.
- Non-repudiation
Show answerHide answer
Assurance a party cannot deny an action; achieved with digital signatures and logging.
- Least privilege
Show answerHide answer
Granting users and processes only the minimum access needed to do their job.
- Need-to-know
Show answerHide answer
Limiting access to the specific information a person requires, even within their clearance.
- Separation of duties
Show answerHide answer
Splitting a sensitive task so no single person can complete it alone.
- Dual control
Show answerHide answer
Requiring two authorized people to act together to perform one sensitive operation.
- Job rotation
Show answerHide answer
Periodically moving staff between duties to detect fraud and reduce single-person dependence.
- Mandatory vacation
Show answerHide answer
Requiring time off so hidden fraudulent activity can surface in an employee's absence.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so one failure doesn't expose the asset.
- Administrative control
Show answerHide answer
A managerial control such as a policy, procedure, training, or background check.
- Technical (logical) control
Show answerHide answer
A control implemented in technology, such as a firewall, encryption, or ACL.
- Physical control
Show answerHide answer
A control protecting the environment, such as locks, guards, fences, or cameras.
- Preventive control
Show answerHide answer
A control that stops an incident before it happens (lock, MFA, input validation).
- Detective control
Show answerHide answer
A control that identifies an incident in progress or after it (logs, IDS, CCTV).
- Corrective control
Show answerHide answer
A control that fixes or restores after an incident (backups, patches).
- Deterrent control
Show answerHide answer
A control that discourages an attacker (warning signs, visible cameras).
- Compensating control
Show answerHide answer
An alternative control used when the primary control isn't feasible (extra monitoring).
- Recovery control
Show answerHide answer
A control that restores operations after a disruption (disaster recovery, backups).
- Due diligence
Show answerHide answer
Doing the research and developing the plans/policies needed to protect the organization.
- Due care
Show answerHide answer
Acting on due diligence by implementing and maintaining reasonable controls (prudent-person rule).
- ISC2 Code of Ethics canons
Show answerHide answer
Applied in order: (1) protect society and the infrastructure; (2) act honorably; (3) provide diligent service to principals; (4) advance the profession.
- Data classification
Show answerHide answer
Labeling data by sensitivity (public, confidential, secret) so the right protection is applied.
- Data owner
Show answerHide answer
The senior business manager accountable for data who sets its classification.
- Data custodian
Show answerHide answer
The party (usually IT) that implements and maintains the controls protecting data day to day.
- Data remanence
Show answerHide answer
Residual data left on media after deletion or formatting that may be recoverable.
- Clearing (sanitization)
Show answerHide answer
Overwriting media so it can be safely reused within the organization.
- Purging (sanitization)
Show answerHide answer
Degaussing or strong overwrite/crypto-erase so media can be released externally.
- Destruction (sanitization)
Show answerHide answer
Physically shredding, pulverizing, or incinerating media for the most sensitive data.
- Change management
Show answerHide answer
A controlled process to request, evaluate, approve, test, and document system changes.
- Change control board (CCB)
Show answerHide answer
The group that reviews and approves proposed changes before they are implemented.
- Baseline (security)
Show answerHide answer
A documented minimum required level of security configuration for a system.
- Security awareness training
Show answerHide answer
Educating users to recognize threats like phishing and follow security policy.
- Policy
Show answerHide answer
A high-level management statement of security intent and goals (mandatory).
- Standard
Show answerHide answer
A specific, mandatory requirement that supports a policy (e.g., 'use AES-256').
- Procedure
Show answerHide answer
Detailed step-by-step instructions to carry out a task (mandatory).
- Guideline
Show answerHide answer
A recommended, discretionary best practice (the only optional document type).
- Asset management lifecycle
Show answerHide answer
Tracking assets from acquisition through use, maintenance, and secure disposal.
- Social engineering
Show answerHide answer
Manipulating people into breaking security (phishing, pretexting, tailgating).
- Confidentiality vs. integrity
Show answerHide answer
Confidentiality keeps data secret; integrity keeps data accurate and unaltered.
- DAD triad
Show answerHide answer
Disclosure, Alteration, Destruction — the opposite of (and threats to) the CIA triad.
- Data lifecycle
Show answerHide answer
Create, store, use, share, archive, and destroy — protect data at each stage.
- Data in transit
Show answerHide answer
Data moving across a network; protect it with TLS, IPsec, or a VPN.
- Data at rest
Show answerHide answer
Stored data; protect it with full-disk or database encryption.
- Data in use
Show answerHide answer
Data being processed in memory; the hardest state to protect.
- Acceptable use policy (AUP)
Show answerHide answer
A policy defining how employees may use organizational systems and data.
- Tailgating
Show answerHide answer
Following an authorized person through a secure door without authenticating.
- Pretexting
Show answerHide answer
A social-engineering attack using a fabricated scenario to extract information.
- Background check
Show answerHide answer
An administrative, preventive control that vets personnel before granting access.
- Government data classification
Show answerHide answer
Top Secret, Secret, Confidential, and Unclassified levels.
- Commercial data classification
Show answerHide answer
Labels such as Confidential, Private, Sensitive, and Public.
Access Controls (42)
- AAA
Show answerHide answer
Authentication, Authorization, and Accounting — prove identity, grant access, log activity.
- Identification
Show answerHide answer
A subject claiming an identity (e.g., a username) — the first step of access control.
- Authentication
Show answerHide answer
Proving a claimed identity with a credential (knowledge, possession, or inherence).
- Authorization
Show answerHide answer
Determining what an authenticated identity is permitted to access and do.
- Accounting (accountability)
Show answerHide answer
Logging and tracking what an identity did, for audit and forensics.
- Multi-factor authentication (MFA)
Show answerHide answer
Using two or more factors from different categories (know, have, are).
- Something you know
Show answerHide answer
A knowledge factor: password, PIN, or passphrase.
- Something you have
Show answerHide answer
A possession factor: smart card, hardware token, or phone.
- Something you are
Show answerHide answer
An inherence (biometric) factor: fingerprint, iris, or face.
- False Acceptance Rate (FAR)
Show answerHide answer
How often a biometric wrongly accepts an impostor (Type II error) — the security risk.
- False Rejection Rate (FRR)
Show answerHide answer
How often a biometric wrongly rejects a real user (Type I error) — the usability problem.
- Crossover Error Rate (CER)
Show answerHide answer
The point where FAR equals FRR; a lower CER means a more accurate system.
- Discretionary access control (DAC)
Show answerHide answer
Access decided by the data owner (e.g., file permissions, ACLs).
- Mandatory access control (MAC)
Show answerHide answer
Access enforced by the system from labels and clearances; rigid and high-security.
- Role-based access control (RBAC)
Show answerHide answer
Access granted by job role rather than the individual; scales well in enterprises.
- Attribute-based access control (ABAC)
Show answerHide answer
Access decided by attributes and policy (user, resource, time, location); most granular.
- Rule-based access control
Show answerHide answer
Global rules applied to everyone (e.g., a firewall ruleset or time-of-day limits).
- Single sign-on (SSO)
Show answerHide answer
One authentication that grants access to multiple systems.
- Kerberos
Show answerHide answer
A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).
- SAML
Show answerHide answer
An XML standard for exchanging authentication/authorization data — web SSO and federation.
- OAuth
Show answerHide answer
An open standard for delegated authorization between applications and APIs.
- OpenID Connect (OIDC)
Show answerHide answer
An identity layer on top of OAuth that provides federated authentication.
- RADIUS
Show answerHide answer
A protocol that centralizes authentication, authorization, and accounting for network access.
- TACACS+
Show answerHide answer
A Cisco AAA protocol that separates authentication, authorization, and accounting (encrypts the full payload).
- LDAP
Show answerHide answer
A protocol for querying and modifying a directory of users and resources.
- Federation
Show answerHide answer
Allowing identities from one trusted domain to access resources in another.
- Zero trust
Show answerHide answer
Trusting no user or device by default and verifying every access request continuously.
- Privileged access management (PAM)
Show answerHide answer
Securing, monitoring, and limiting accounts with elevated (admin) privileges.
- Identity lifecycle
Show answerHide answer
Provisioning, periodic review/recertification, and prompt deprovisioning of accounts.
- Deprovisioning
Show answerHide answer
Promptly disabling/removing access when a user leaves to prevent orphan accounts.
- Transitive trust
Show answerHide answer
Trust that flows through a chain — if A trusts B and B trusts C, A may trust C.
- Provisioning
Show answerHide answer
Creating accounts and granting initial access based on role and need.
- Type I vs. Type II error
Show answerHide answer
Type I = false rejection (FRR); Type II = false acceptance (FAR) in biometrics.
- Biometric throughput
Show answerHide answer
How quickly a biometric system can process users (enrollment/verification speed).
- Mandatory access control example
Show answerHide answer
A soldier with Secret clearance cannot open a Top Secret file regardless of the owner.
- Account lockout
Show answerHide answer
Disabling an account after repeated failed logins to deter brute-force attacks.
- Password policy
Show answerHide answer
Rules for length, complexity, age, and reuse that strengthen knowledge factors.
- Token (authentication)
Show answerHide answer
A possession factor that generates or stores one-time or cryptographic credentials.
- OTP
Show answerHide answer
One-Time Password — a code valid for a single login or short window.
- Mutual authentication
Show answerHide answer
Both parties authenticate each other, not just the client to the server.
- Access control list (ACL)
Show answerHide answer
A list specifying which subjects may access an object and what they may do.
- Constrained interface
Show answerHide answer
Restricting what a user can do by limiting the controls they can see/use.
Risk Identification, Monitoring & Analysis (43)
- Risk
Show answerHide answer
The likelihood a threat exploits a vulnerability and the resulting impact on an asset.
- Threat
Show answerHide answer
Any potential event or actor that could cause harm by exploiting a vulnerability.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Exposure factor (EF)
Show answerHide answer
The percentage of an asset's value lost if a specific risk event occurs.
- Single Loss Expectancy (SLE)
Show answerHide answer
Expected loss from one event: SLE = Asset Value × Exposure Factor.
- Annualized Rate of Occurrence (ARO)
Show answerHide answer
The expected number of times a risk event occurs in one year.
- Annualized Loss Expectancy (ALE)
Show answerHide answer
Expected yearly cost of a risk: ALE = SLE × ARO; used to cost-justify controls.
- Qualitative risk analysis
Show answerHide answer
Subjective risk ranking (high/medium/low) — fast, but not in dollars.
- Quantitative risk analysis
Show answerHide answer
Objective, dollar-based risk analysis using SLE, ARO, and ALE.
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls.
- Risk transference
Show answerHide answer
Shifting the financial impact of a risk to a third party, such as insurance.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk and its impact.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; management formally accepts it.
- Risk appetite
Show answerHide answer
The amount and type of risk an organization is willing to accept to meet objectives.
- Risk tolerance
Show answerHide answer
The acceptable variation around the organization's risk appetite.
- Vulnerability scan
Show answerHide answer
An automated check that identifies known weaknesses without exploiting them.
- Penetration test
Show answerHide answer
An authorized, simulated attack that actively exploits weaknesses to prove impact.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a unique identifier for a known vulnerability.
- CVSS
Show answerHide answer
Common Vulnerability Scoring System — a 0–10 standard severity score for a vulnerability.
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs for detection.
- Event vs. incident
Show answerHide answer
An event is any observable occurrence; an incident is an event that harms or threatens security.
- Log correlation
Show answerHide answer
Linking related events across sources to reveal an attack that no single log shows.
- Continuous monitoring
Show answerHide answer
Ongoing collection and analysis of security data to detect issues in near real time.
- Baseline (monitoring)
Show answerHide answer
A picture of normal behavior used to spot anomalies.
- Black-box test
Show answerHide answer
A penetration test with no prior knowledge of the target (simulates an outsider).
- White-box test
Show answerHide answer
A penetration test with full knowledge of the target's internals.
- Gray-box test
Show answerHide answer
A penetration test with partial knowledge of the target.
- Security audit
Show answerHide answer
An independent, systematic evaluation of controls against a standard or policy.
- PII
Show answerHide answer
Personally Identifiable Information — data that can identify a specific individual.
- GDPR
Show answerHide answer
The EU regulation governing the processing and protection of personal data.
- HIPAA
Show answerHide answer
U.S. law protecting the privacy and security of health information (PHI).
- PCI DSS
Show answerHide answer
A security standard for organizations that handle payment card data.
- Total cost of ownership (TCO)
Show answerHide answer
The full lifecycle cost of a control or asset, used in risk decisions.
- Return on security investment
Show answerHide answer
Comparing the cost of a control to the reduction in expected loss (ALE) it provides.
- Inherent risk
Show answerHide answer
The risk present before any controls are applied.
- Control gap
Show answerHide answer
The difference between the current and the desired level of risk reduction.
- False positive (alert)
Show answerHide answer
A benign event wrongly flagged as malicious — wastes analyst time.
- False negative (alert)
Show answerHide answer
A real threat that goes undetected — the more dangerous error.
- Patch / config audit
Show answerHide answer
Verifying systems are patched and configured to the secure baseline.
- Threat modeling
Show answerHide answer
Systematically identifying and prioritizing threats to a system during design.
- Risk register
Show answerHide answer
A documented inventory of identified risks, owners, and treatments.
- SOC 2 report
Show answerHide answer
An independent audit of an organization's security/availability controls.
Incident Response & Recovery (35)
- Incident response lifecycle
Show answerHide answer
Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident (NIST 800-61).
- Preparation (IR)
Show answerHide answer
Building the policy, the CSIRT, tooling, and training before an incident happens.
- Detection & analysis
Show answerHide answer
Identifying and confirming a real incident from events; determining scope and severity.
- Containment
Show answerHide answer
Limiting the spread and damage of an incident (short-term then long-term).
- Eradication
Show answerHide answer
Removing the threat — malware, compromised accounts, and the root cause.
- Recovery (IR)
Show answerHide answer
Restoring systems to validated normal operation and monitoring for recurrence.
- Lessons learned
Show answerHide answer
The post-incident review that improves detection, controls, and the plan.
- CSIRT
Show answerHide answer
Computer Security Incident Response Team — the group that handles security incidents.
- Chain of custody
Show answerHide answer
Documentation of who handled evidence and when, preserving its integrity for legal use.
- Order of volatility
Show answerHide answer
Collect evidence by how fast it disappears — memory before disk before backups.
- Digital forensics
Show answerHide answer
The collection, preservation, and analysis of digital evidence.
- Business continuity plan (BCP)
Show answerHide answer
A plan to keep critical business functions operating during and after a disruption.
- Disaster recovery (DR)
Show answerHide answer
Processes and procedures to restore IT systems after a disruptive event.
- Business Impact Analysis (BIA)
Show answerHide answer
Identifies critical functions and sets recovery objectives (MTD, RTO, RPO).
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The longest a function can be unavailable before unacceptable harm occurs.
- Recovery Time Objective (RTO)
Show answerHide answer
The target time to restore a function after a disruption; must be shorter than MTD.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable data loss measured backward in time; drives backup frequency.
- Hot site
Show answerHide answer
A fully equipped recovery site with near-real-time failover — fastest, most expensive.
- Warm site
Show answerHide answer
A recovery site with hardware and connectivity; data restored on demand — moderate.
- Cold site
Show answerHide answer
An empty recovery space with power/cooling only — cheapest, slowest to bring online.
- Full backup
Show answerHide answer
A backup of all selected data; fastest to restore (one set).
- Incremental backup
Show answerHide answer
Backs up changes since the last backup of any type; fast backup, slow restore.
- Differential backup
Show answerHide answer
Backs up changes since the last full backup; slower backup, faster restore.
- 3-2-1 backup rule
Show answerHide answer
Keep three copies of data, on two media types, with one stored off-site.
- Tabletop exercise
Show answerHide answer
A discussion-based walkthrough of the incident or recovery plan.
- Escalation
Show answerHide answer
Raising an incident to higher-level responders or management as severity grows.
- First responder action
Show answerHide answer
After detection, the typical first technical step is containment — stop the spread.
- Eradication vs. recovery
Show answerHide answer
Eradication removes the threat and root cause; recovery restores normal operations.
- Tabletop vs. full-interruption test
Show answerHide answer
Tabletop is a discussion; full-interruption actually fails over to recovery systems.
- Work Recovery Time (WRT)
Show answerHide answer
Time to verify and restore data/functionality after systems are back online.
- Evidence integrity (hashing)
Show answerHide answer
Hashing collected evidence proves it has not changed since collection.
- Write blocker
Show answerHide answer
A forensic tool that allows reading a drive without altering its contents.
- Mean time to recover (MTTR)
Show answerHide answer
The average time to restore a system after a failure.
- Playbook (IR)
Show answerHide answer
A predefined set of steps for responding to a specific type of incident.
- Recovery site selection
Show answerHide answer
Choose hot/warm/cold based on the RTO and budget the BIA produced.
Cryptography (36)
- Symmetric encryption
Show answerHide answer
One shared secret key for both encrypt and decrypt (AES); fast, hard to distribute.
- Asymmetric encryption
Show answerHide answer
A public/private key pair (RSA, ECC); slower, solves key exchange, enables signatures.
- AES
Show answerHide answer
The current symmetric block cipher standard (128/192/256-bit keys).
- RSA
Show answerHide answer
A widely used asymmetric algorithm for encryption and digital signatures.
- Diffie-Hellman
Show answerHide answer
An asymmetric method for two parties to agree on a shared secret over an insecure channel.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest to verify integrity (SHA-256).
- SHA-2 / SHA-3
Show answerHide answer
Current secure hash algorithm families; use these instead of broken MD5/SHA-1.
- HMAC
Show answerHide answer
A keyed hash providing both integrity and authenticity of a message.
- Salting
Show answerHide answer
Adding random data to a password before hashing so identical passwords differ.
- Key stretching
Show answerHide answer
Slowing password hashing with bcrypt, PBKDF2, scrypt, or Argon2 to resist cracking.
- Digital signature
Show answerHide answer
A hash of a message encrypted with the sender's private key; gives integrity, authenticity, non-repudiation.
- Encrypt vs. sign
Show answerHide answer
Encrypt with the recipient's PUBLIC key (confidentiality); sign with YOUR PRIVATE key (authenticity).
- Hybrid cryptography
Show answerHide answer
Using asymmetric crypto to exchange a fast symmetric session key (e.g., TLS).
- Public Key Infrastructure (PKI)
Show answerHide answer
The framework of CAs, certificates, and policies that manages public keys and trust.
- Certificate Authority (CA)
Show answerHide answer
A trusted entity that issues and signs digital certificates.
- Digital certificate (X.509)
Show answerHide answer
A document binding a public key to a verified identity, signed by a CA.
- CRL
Show answerHide answer
Certificate Revocation List — a published list of certificates no longer trusted.
- OCSP
Show answerHide answer
Online Certificate Status Protocol — a real-time check of a certificate's revocation status.
- Key escrow
Show answerHide answer
Storing a copy of a key with a trusted third party for recovery or legal access.
- HSM
Show answerHide answer
Hardware Security Module — a tamper-resistant device that generates and stores keys.
- TLS
Show answerHide answer
The protocol that secures application traffic (HTTPS) using hybrid cryptography.
- IPsec
Show answerHide answer
A protocol suite that secures IP traffic at Layer 3 (AH for integrity, ESP for confidentiality).
- SSH
Show answerHide answer
A protocol for secure remote administration and file transfer.
- Birthday attack
Show answerHide answer
An attack that exploits hash collision probability to find two inputs with the same digest.
- Man-in-the-middle (crypto)
Show answerHide answer
An attacker secretly relays/alters communication between two parties.
- Rainbow table
Show answerHide answer
A precomputed table of hashes used to crack unsalted password hashes quickly.
- Block vs. stream cipher
Show answerHide answer
Block ciphers encrypt fixed-size blocks (AES); stream ciphers encrypt bit/byte by byte.
- ECB vs. CBC mode
Show answerHide answer
ECB encrypts blocks independently (insecure patterns); CBC chains blocks for security.
- GCM mode
Show answerHide answer
An authenticated encryption mode providing both confidentiality and integrity.
- 3DES
Show answerHide answer
A legacy symmetric cipher applying DES three times; now deprecated for AES.
- ECC
Show answerHide answer
Elliptic Curve Cryptography — asymmetric crypto with strong security at small key sizes.
- Perfect forward secrecy
Show answerHide answer
Session keys aren't compromised even if a long-term key is later exposed.
- Key management lifecycle
Show answerHide answer
Generate, distribute, store, rotate, and destroy keys securely.
- Nonce
Show answerHide answer
A number used once to prevent replay and ensure uniqueness in crypto operations.
- Steganography
Show answerHide answer
Hiding data within other data (e.g., inside an image) rather than encrypting it.
- Replay attack
Show answerHide answer
Capturing and re-sending valid data to gain unauthorized access; nonces/timestamps defend.
Network & Communications Security (44)
- OSI model
Show answerHide answer
Seven layers: Physical, Data Link, Network, Transport, Session, Presentation, Application.
- Layer 1 — Physical
Show answerHide answer
Cables, signals, and hubs — raw bit transmission.
- Layer 2 — Data Link
Show answerHide answer
MAC addresses and switches; frames between adjacent nodes.
- Layer 3 — Network
Show answerHide answer
IP addressing and routers; IPsec operates here.
- Layer 4 — Transport
Show answerHide answer
TCP and UDP; ports and end-to-end delivery.
- TCP vs. UDP
Show answerHide answer
TCP is connection-oriented and reliable; UDP is connectionless and fast.
- Switch
Show answerHide answer
A Layer 2 device that forwards frames by MAC address.
- Router
Show answerHide answer
A Layer 3 device that forwards packets between networks by IP address.
- Firewall
Show answerHide answer
A device/software that filters network traffic against a rule set.
- Packet-filter firewall
Show answerHide answer
Inspects each packet in isolation against rules; no memory of sessions.
- Stateful firewall
Show answerHide answer
Tracks the state of active connections; allows return traffic for known sessions.
- Proxy firewall
Show answerHide answer
Terminates and inspects traffic at the application layer on behalf of clients.
- WAF
Show answerHide answer
Web Application Firewall — protects web apps from attacks like SQL injection and XSS.
- IDS
Show answerHide answer
Intrusion Detection System — monitors and alerts but does not block (passive).
- IPS
Show answerHide answer
Intrusion Prevention System — sits inline and can block malicious traffic (active).
- Signature-based detection
Show answerHide answer
Detects threats by matching known attack patterns.
- Anomaly-based detection
Show answerHide answer
Detects threats by flagging deviations from a normal baseline.
- HIDS vs. NIDS
Show answerHide answer
HIDS runs on a host; NIDS watches network traffic.
- VPN
Show answerHide answer
A Virtual Private Network — an encrypted tunnel over an untrusted network.
- DMZ
Show answerHide answer
A screened subnet hosting public-facing services, isolated from the internal network.
- VLAN
Show answerHide answer
A logically segmented broadcast domain on a switch for isolation.
- Network access control (NAC)
Show answerHide answer
Checks a device's identity and posture before allowing it onto the network.
- NAT / PAT
Show answerHide answer
Network/Port Address Translation — maps private addresses to public ones.
- DoS / DDoS
Show answerHide answer
Attacks that overwhelm a target to deny service; DDoS uses many sources.
- ARP poisoning
Show answerHide answer
Falsifying ARP replies to redirect traffic on a LAN (enables MITM).
- DNS poisoning
Show answerHide answer
Corrupting DNS data to redirect users to a malicious address.
- Spoofing
Show answerHide answer
Forging a source address or identity to impersonate a trusted entity.
- WPA3
Show answerHide answer
The current Wi-Fi security standard with strong encryption and offline-attack protection.
- 802.1X / EAP
Show answerHide answer
A framework for port-based network access control and authentication.
- Rogue access point
Show answerHide answer
An unauthorized wireless AP that creates an unsecured entry into the network.
- Evil twin
Show answerHide answer
A malicious AP impersonating a legitimate one to capture traffic.
- IoT security
Show answerHide answer
Hardening internet-connected devices that often ship insecure by default.
- Secure protocol swaps
Show answerHide answer
Replace HTTP→HTTPS, FTP/Telnet→SFTP/SSH, WEP→WPA3, SNMPv1/2→SNMPv3.
- Layer 5 — Session
Show answerHide answer
Establishes, manages, and terminates sessions between applications.
- Layer 6 — Presentation
Show answerHide answer
Translates, encrypts, and compresses data (TLS sits around 6/7).
- Layer 7 — Application
Show answerHide answer
Where user-facing protocols live: HTTP, DNS, SMTP, FTP.
- TCP three-way handshake
Show answerHide answer
SYN, SYN-ACK, ACK — establishes a TCP connection.
- Port (well-known)
Show answerHide answer
HTTPS 443, HTTP 80, SSH 22, DNS 53, RDP 3389.
- Subnetting
Show answerHide answer
Dividing a network into smaller segments to improve control and isolation.
- Reverse proxy
Show answerHide answer
A proxy that sits in front of servers, handling and filtering inbound requests.
- Honeypot
Show answerHide answer
A decoy system used to detect, deflect, or study attackers.
- MAC filtering
Show answerHide answer
Allowing only known hardware addresses onto a network (weak on its own).
- Sniffing (eavesdropping)
Show answerHide answer
Capturing network traffic to read unencrypted data; encryption defends against it.
- Air gap
Show answerHide answer
Physically isolating a system from untrusted networks for high security.
Systems & Application Security (46)
- Malware
Show answerHide answer
Malicious software: viruses, worms, trojans, ransomware, rootkits, spyware, logic bombs.
- Virus
Show answerHide answer
Malware that attaches to a file and needs a user to run it to spread.
- Worm
Show answerHide answer
Self-replicating malware that spreads across networks with no user action.
- Trojan
Show answerHide answer
Malware disguised as legitimate software to deliver a hidden payload.
- Ransomware
Show answerHide answer
Malware that encrypts a victim's data and demands payment for the key.
- Rootkit
Show answerHide answer
Malware with deep, privileged access that hides its presence from the OS.
- Spyware
Show answerHide answer
Malware that secretly collects information about a user or system.
- Logic bomb
Show answerHide answer
Malicious code that stays dormant until a trigger condition is met.
- Fileless malware
Show answerHide answer
Malware that runs in memory using legitimate tools, leaving little on disk.
- Phishing
Show answerHide answer
A social-engineering attack using fraudulent messages to steal data or deliver malware.
- Spear phishing
Show answerHide answer
A targeted phishing attack aimed at a specific person or organization.
- Advanced persistent threat (APT)
Show answerHide answer
A stealthy, long-term, well-resourced intrusion, often state-sponsored.
- EDR
Show answerHide answer
Endpoint Detection and Response — continuously monitors endpoints to detect and respond.
- Antivirus / anti-malware
Show answerHide answer
Software that detects and removes malicious code on endpoints.
- Application allowlisting
Show answerHide answer
Permitting only approved programs to run; blocks everything else by default.
- Patch management
Show answerHide answer
Acquiring, testing, and applying software updates to fix vulnerabilities.
- System hardening
Show answerHide answer
Reducing the attack surface via secure config, removing unneeded services, and patching.
- Host-based firewall
Show answerHide answer
A firewall running on an individual endpoint to filter its traffic.
- Mobile device management (MDM)
Show answerHide answer
Software enforcing security policy on mobile devices (passcode, encryption, remote wipe).
- BYOD
Show answerHide answer
Bring Your Own Device — using personal devices for work; needs containerization/policy.
- Containerization (mobile)
Show answerHide answer
Isolating work data and apps from personal data on a device.
- Remote wipe
Show answerHide answer
Erasing a lost or stolen device's data remotely to protect it.
- Shared responsibility model
Show answerHide answer
Cloud provider secures the infrastructure; the customer always owns its data and access.
- IaaS
Show answerHide answer
Infrastructure as a Service — customer secures the OS, apps, and data.
- PaaS
Show answerHide answer
Platform as a Service — customer secures apps and data; provider manages OS/runtime.
- SaaS
Show answerHide answer
Software as a Service — provider secures most; customer manages data, access, settings.
- Cloud misconfiguration
Show answerHide answer
A leading cloud breach cause (e.g., a public storage bucket) — on the customer's side.
- CASB
Show answerHide answer
Cloud Access Security Broker — enforces policy between users and cloud services.
- Hypervisor
Show answerHide answer
Software that creates and runs VMs; Type 1 runs on bare metal, Type 2 on a host OS.
- VM escape
Show answerHide answer
An attack that breaks out of a guest VM to reach the hypervisor or other VMs.
- VM sprawl
Show answerHide answer
Uncontrolled growth of unmanaged virtual machines, increasing risk.
- Container (technology)
Show answerHide answer
A lightweight, isolated package of an app and its dependencies sharing the host OS kernel.
- Input validation
Show answerHide answer
Checking and sanitizing all user input to prevent injection attacks.
- SQL injection
Show answerHide answer
Inserting malicious SQL through unvalidated input to read or alter a database.
- Drive-by download
Show answerHide answer
Malware that installs simply by visiting a compromised or malicious web page.
- Watering-hole attack
Show answerHide answer
Compromising a site a target group frequently visits to infect them.
- Zero-day
Show answerHide answer
A vulnerability exploited before a patch exists; no signature yet to detect it.
- Backdoor
Show answerHide answer
A hidden method to bypass normal authentication and gain access.
- Botnet
Show answerHide answer
A network of compromised machines controlled by an attacker (often for DDoS).
- HIPS
Show answerHide answer
Host Intrusion Prevention System — blocks malicious activity on an endpoint.
- Secure baseline image
Show answerHide answer
A hardened, approved OS image deployed to ensure consistent, secure configuration.
- Least functionality
Show answerHide answer
Configuring systems to provide only essential capabilities, reducing attack surface.
- Type 1 vs. Type 2 hypervisor
Show answerHide answer
Type 1 runs on bare metal; Type 2 runs as an app on a host OS.
- Snapshot risk
Show answerHide answer
VM snapshots may contain sensitive data and can revert security patches if restored.
- Sandboxing
Show answerHide answer
Running untrusted code in an isolated environment to contain any harm.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting malicious scripts into a web page viewed by other users.
References
- 1.ISC2. “SSCP Certification Exam Outline (effective October 1, 2025).” isc2.org. ↑
- 2.ISC2. “SSCP — Systems Security Certified Practitioner.” isc2.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
