Career Employer

Your FREE SSCP Flashcards 2026 – 300+ Cards

Realistic, SSCP exam-style flashcards across all 7 ISC2 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer SSCP”

By

Click Study Flashcards above to open the flashcard hub — hundreds of SSCP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the seven official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

SSCP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.

SSCP Flashcard Study Modes

Four ways to work the same 300 cards: Flip for quiet study, Match for a timed race pairing terms with their definitions, Type to read a definition and spell the term back, and Quiz for multiple choice pulled from the deck. Type is where recall gets honest — you see the description and have to produce Kerberos or DAD triad yourself.

Free SSCP flashcards from Career Employer — active recall for the Systems Security Certified Practitioner exam

Why Flashcards Work for the SSCP

Security Concepts & Practices carries 54 cards and ties for the heaviest weight at 16%, so it is the natural opening. These cards drill the vocabulary of governance and foundational security models, separating documents that look alike — Policy, Standard, Procedure and Guideline all appear as distinct fronts — alongside concepts like Due care, the CIA triad and the DAD triad.

Network & Communications Security also sits at 16% with 44 cards covering perimeter devices, segmentation and wireless protection, including WAF, DMZ and WPA3 as well as the IDS and IPS pairing that candidates routinely blur. Access Controls adds 42 cards at 15%, focused on authentication and federation terms such as SAML, RADIUS and TACACS+, plus one-factor and multifactor building blocks like OTP.

Risk Identification, Monitoring & Analysis brings 43 cards for its 15%, mixing measurement and regulation: CVSS and CVE for vulnerability scoring and cataloging, SIEM for monitoring, and privacy and compliance terms including PII, GDPR and HIPAA. Systems & Application Security contributes 46 cards, also 15%, spanning endpoint defenses such as EDR and HIPS, malware types like Worm, and cloud service models IaaS, PaaS and SaaS.

Incident Response & Recovery holds 35 cards at 14% and follows the lifecycle, from the CSIRT that responds through Containment, Eradication and Escalation, then into recovery options like Hot site, Warm site and Cold site. Cryptography closes with 36 cards for 9%, covering algorithms and infrastructure — AES, RSA, ECC, HMAC — plus protocols and key management pieces such as TLS, CRL and HSM.

The SSCP is dense with terminology — access control models, risk formulas, cryptography, networking, and incident response.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

SSCP Flashcards by Domain

The cards are organized by the seven official ISC2 domains. The weights are fairly even, so cover them all — but start with the two heaviest, Security Concepts & Practices and Network & Communications Security:[1]

SSCP flashcards by domain and weight
DomainExam weight
Security Concepts & Practices16%
Network & Communications Security16%
Access Controls15%
Risk Identification, Monitoring & Analysis15%
Systems & Application Security15%
Incident Response & Recovery14%
Cryptography9%

How to Get the Most Out of These Flashcards

  • Start with the foundation. Security Concepts & Practices is 54 cards at 16%; its Policy, Standard, Procedure and Guideline distinctions shape how you read questions in every other domain.
  • Type-drill the lookalikes. Force yourself to produce IDS versus IPS, and Hot site versus Warm site, because multiple choice lets you guess while typing exposes fuzzy recall.
  • Use Match for acronyms. The short cryptography and access control fronts — AES, HMAC, SAML, LDAP — pair fast, and the timer pushes you toward instant recognition instead of reasoning.
  • Switch when recall is clean. Once Quiz runs smooth across Risk Identification, Monitoring & Analysis and Systems & Application Security, move to the practice test for scenario wording and the study guide for depth.
  • Rotate rather than cram. With 300 cards across seven domains, cycle two domains per session and revisit Cryptography and Incident Response & Recovery often, since their 36 and 35 cards fade quickly.

SSCP Flashcards FAQ

Hundreds of free SSCP flashcards, organized across all seven ISC2 domains — Security Concepts & Practices, Access Controls, Risk Identification Monitoring & Analysis, Incident Response & Recovery, Cryptography, Network & Communications Security, and Systems & Application Security. They're free with no account required.

SSCP flashcard bank

All 300 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Security Concepts & Practices (54)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Preventing unauthorized disclosure of data; enforced by encryption and access control.

Integrity
Show answer

Ensuring data is accurate and unaltered except by authorized parties; enforced by hashing and change control.

Availability
Show answer

Ensuring authorized users have timely, reliable access; enforced by redundancy, backups, and fault tolerance.

Accountability
Show answer

Tying actions back to a specific identity through logging and monitoring.

Non-repudiation
Show answer

Assurance a party cannot deny an action; achieved with digital signatures and logging.

Least privilege
Show answer

Granting users and processes only the minimum access needed to do their job.

Need-to-know
Show answer

Limiting access to the specific information a person requires, even within their clearance.

Separation of duties
Show answer

Splitting a sensitive task so no single person can complete it alone.

Dual control
Show answer

Requiring two authorized people to act together to perform one sensitive operation.

Job rotation
Show answer

Periodically moving staff between duties to detect fraud and reduce single-person dependence.

Mandatory vacation
Show answer

Requiring time off so hidden fraudulent activity can surface in an employee's absence.

Defense in depth
Show answer

Layering multiple, overlapping controls so one failure doesn't expose the asset.

Administrative control
Show answer

A managerial control such as a policy, procedure, training, or background check.

Technical (logical) control
Show answer

A control implemented in technology, such as a firewall, encryption, or ACL.

Physical control
Show answer

A control protecting the environment, such as locks, guards, fences, or cameras.

Preventive control
Show answer

A control that stops an incident before it happens (lock, MFA, input validation).

Detective control
Show answer

A control that identifies an incident in progress or after it (logs, IDS, CCTV).

Corrective control
Show answer

A control that fixes or restores after an incident (backups, patches).

Deterrent control
Show answer

A control that discourages an attacker (warning signs, visible cameras).

Compensating control
Show answer

An alternative control used when the primary control isn't feasible (extra monitoring).

Recovery control
Show answer

A control that restores operations after a disruption (disaster recovery, backups).

Due diligence
Show answer

Doing the research and developing the plans/policies needed to protect the organization.

Due care
Show answer

Acting on due diligence by implementing and maintaining reasonable controls (prudent-person rule).

ISC2 Code of Ethics canons
Show answer

Applied in order: (1) protect society and the infrastructure; (2) act honorably; (3) provide diligent service to principals; (4) advance the profession.

Data classification
Show answer

Labeling data by sensitivity (public, confidential, secret) so the right protection is applied.

Data owner
Show answer

The senior business manager accountable for data who sets its classification.

Data custodian
Show answer

The party (usually IT) that implements and maintains the controls protecting data day to day.

Data remanence
Show answer

Residual data left on media after deletion or formatting that may be recoverable.

Clearing (sanitization)
Show answer

Overwriting media so it can be safely reused within the organization.

Purging (sanitization)
Show answer

Degaussing or strong overwrite/crypto-erase so media can be released externally.

Destruction (sanitization)
Show answer

Physically shredding, pulverizing, or incinerating media for the most sensitive data.

Change management
Show answer

A controlled process to request, evaluate, approve, test, and document system changes.

Change control board (CCB)
Show answer

The group that reviews and approves proposed changes before they are implemented.

Baseline (security)
Show answer

A documented minimum required level of security configuration for a system.

Security awareness training
Show answer

Educating users to recognize threats like phishing and follow security policy.

Policy
Show answer

A high-level management statement of security intent and goals (mandatory).

Standard
Show answer

A specific, mandatory requirement that supports a policy (e.g., 'use AES-256').

Procedure
Show answer

Detailed step-by-step instructions to carry out a task (mandatory).

Guideline
Show answer

A recommended, discretionary best practice (the only optional document type).

Asset management lifecycle
Show answer

Tracking assets from acquisition through use, maintenance, and secure disposal.

Social engineering
Show answer

Manipulating people into breaking security (phishing, pretexting, tailgating).

Confidentiality vs. integrity
Show answer

Confidentiality keeps data secret; integrity keeps data accurate and unaltered.

DAD triad
Show answer

Disclosure, Alteration, Destruction — the opposite of (and threats to) the CIA triad.

Data lifecycle
Show answer

Create, store, use, share, archive, and destroy — protect data at each stage.

Data in transit
Show answer

Data moving across a network; protect it with TLS, IPsec, or a VPN.

Data at rest
Show answer

Stored data; protect it with full-disk or database encryption.

Data in use
Show answer

Data being processed in memory; the hardest state to protect.

Acceptable use policy (AUP)
Show answer

A policy defining how employees may use organizational systems and data.

Tailgating
Show answer

Following an authorized person through a secure door without authenticating.

Pretexting
Show answer

A social-engineering attack using a fabricated scenario to extract information.

Background check
Show answer

An administrative, preventive control that vets personnel before granting access.

Government data classification
Show answer

Top Secret, Secret, Confidential, and Unclassified levels.

Commercial data classification
Show answer

Labels such as Confidential, Private, Sensitive, and Public.

Access Controls (42)

AAA
Show answer

Authentication, Authorization, and Accounting — prove identity, grant access, log activity.

Identification
Show answer

A subject claiming an identity (e.g., a username) — the first step of access control.

Authentication
Show answer

Proving a claimed identity with a credential (knowledge, possession, or inherence).

Authorization
Show answer

Determining what an authenticated identity is permitted to access and do.

Accounting (accountability)
Show answer

Logging and tracking what an identity did, for audit and forensics.

Multi-factor authentication (MFA)
Show answer

Using two or more factors from different categories (know, have, are).

Something you know
Show answer

A knowledge factor: password, PIN, or passphrase.

Something you have
Show answer

A possession factor: smart card, hardware token, or phone.

Something you are
Show answer

An inherence (biometric) factor: fingerprint, iris, or face.

False Acceptance Rate (FAR)
Show answer

How often a biometric wrongly accepts an impostor (Type II error) — the security risk.

False Rejection Rate (FRR)
Show answer

How often a biometric wrongly rejects a real user (Type I error) — the usability problem.

Crossover Error Rate (CER)
Show answer

The point where FAR equals FRR; a lower CER means a more accurate system.

Discretionary access control (DAC)
Show answer

Access decided by the data owner (e.g., file permissions, ACLs).

Mandatory access control (MAC)
Show answer

Access enforced by the system from labels and clearances; rigid and high-security.

Role-based access control (RBAC)
Show answer

Access granted by job role rather than the individual; scales well in enterprises.

Attribute-based access control (ABAC)
Show answer

Access decided by attributes and policy (user, resource, time, location); most granular.

Rule-based access control
Show answer

Global rules applied to everyone (e.g., a firewall ruleset or time-of-day limits).

Single sign-on (SSO)
Show answer

One authentication that grants access to multiple systems.

Kerberos
Show answer

A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).

SAML
Show answer

An XML standard for exchanging authentication/authorization data — web SSO and federation.

OAuth
Show answer

An open standard for delegated authorization between applications and APIs.

OpenID Connect (OIDC)
Show answer

An identity layer on top of OAuth that provides federated authentication.

RADIUS
Show answer

A protocol that centralizes authentication, authorization, and accounting for network access.

TACACS+
Show answer

A Cisco AAA protocol that separates authentication, authorization, and accounting (encrypts the full payload).

LDAP
Show answer

A protocol for querying and modifying a directory of users and resources.

Federation
Show answer

Allowing identities from one trusted domain to access resources in another.

Zero trust
Show answer

Trusting no user or device by default and verifying every access request continuously.

Privileged access management (PAM)
Show answer

Securing, monitoring, and limiting accounts with elevated (admin) privileges.

Identity lifecycle
Show answer

Provisioning, periodic review/recertification, and prompt deprovisioning of accounts.

Deprovisioning
Show answer

Promptly disabling/removing access when a user leaves to prevent orphan accounts.

Transitive trust
Show answer

Trust that flows through a chain — if A trusts B and B trusts C, A may trust C.

Provisioning
Show answer

Creating accounts and granting initial access based on role and need.

Type I vs. Type II error
Show answer

Type I = false rejection (FRR); Type II = false acceptance (FAR) in biometrics.

Biometric throughput
Show answer

How quickly a biometric system can process users (enrollment/verification speed).

Mandatory access control example
Show answer

A soldier with Secret clearance cannot open a Top Secret file regardless of the owner.

Account lockout
Show answer

Disabling an account after repeated failed logins to deter brute-force attacks.

Password policy
Show answer

Rules for length, complexity, age, and reuse that strengthen knowledge factors.

Token (authentication)
Show answer

A possession factor that generates or stores one-time or cryptographic credentials.

OTP
Show answer

One-Time Password — a code valid for a single login or short window.

Mutual authentication
Show answer

Both parties authenticate each other, not just the client to the server.

Access control list (ACL)
Show answer

A list specifying which subjects may access an object and what they may do.

Constrained interface
Show answer

Restricting what a user can do by limiting the controls they can see/use.

Risk Identification, Monitoring & Analysis (43)

Risk
Show answer

The likelihood a threat exploits a vulnerability and the resulting impact on an asset.

Threat
Show answer

Any potential event or actor that could cause harm by exploiting a vulnerability.

Vulnerability
Show answer

A weakness in a system, process, or control that a threat can exploit.

Exposure factor (EF)
Show answer

The percentage of an asset's value lost if a specific risk event occurs.

Single Loss Expectancy (SLE)
Show answer

Expected loss from one event: SLE = Asset Value × Exposure Factor.

Annualized Rate of Occurrence (ARO)
Show answer

The expected number of times a risk event occurs in one year.

Annualized Loss Expectancy (ALE)
Show answer

Expected yearly cost of a risk: ALE = SLE × ARO; used to cost-justify controls.

Qualitative risk analysis
Show answer

Subjective risk ranking (high/medium/low) — fast, but not in dollars.

Quantitative risk analysis
Show answer

Objective, dollar-based risk analysis using SLE, ARO, and ALE.

Risk mitigation
Show answer

Reducing risk to an acceptable level by implementing controls.

Risk transference
Show answer

Shifting the financial impact of a risk to a third party, such as insurance.

Risk avoidance
Show answer

Eliminating a risk by ceasing the activity that creates it.

Risk acceptance
Show answer

A documented, management-approved decision to tolerate a risk and its impact.

Residual risk
Show answer

The risk that remains after controls are applied; management formally accepts it.

Risk appetite
Show answer

The amount and type of risk an organization is willing to accept to meet objectives.

Risk tolerance
Show answer

The acceptable variation around the organization's risk appetite.

Vulnerability scan
Show answer

An automated check that identifies known weaknesses without exploiting them.

Penetration test
Show answer

An authorized, simulated attack that actively exploits weaknesses to prove impact.

CVE
Show answer

Common Vulnerabilities and Exposures — a unique identifier for a known vulnerability.

CVSS
Show answer

Common Vulnerability Scoring System — a 0–10 standard severity score for a vulnerability.

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs for detection.

Event vs. incident
Show answer

An event is any observable occurrence; an incident is an event that harms or threatens security.

Log correlation
Show answer

Linking related events across sources to reveal an attack that no single log shows.

Continuous monitoring
Show answer

Ongoing collection and analysis of security data to detect issues in near real time.

Baseline (monitoring)
Show answer

A picture of normal behavior used to spot anomalies.

Black-box test
Show answer

A penetration test with no prior knowledge of the target (simulates an outsider).

White-box test
Show answer

A penetration test with full knowledge of the target's internals.

Gray-box test
Show answer

A penetration test with partial knowledge of the target.

Security audit
Show answer

An independent, systematic evaluation of controls against a standard or policy.

PII
Show answer

Personally Identifiable Information — data that can identify a specific individual.

GDPR
Show answer

The EU regulation governing the processing and protection of personal data.

HIPAA
Show answer

U.S. law protecting the privacy and security of health information (PHI).

PCI DSS
Show answer

A security standard for organizations that handle payment card data.

Total cost of ownership (TCO)
Show answer

The full lifecycle cost of a control or asset, used in risk decisions.

Return on security investment
Show answer

Comparing the cost of a control to the reduction in expected loss (ALE) it provides.

Inherent risk
Show answer

The risk present before any controls are applied.

Control gap
Show answer

The difference between the current and the desired level of risk reduction.

False positive (alert)
Show answer

A benign event wrongly flagged as malicious — wastes analyst time.

False negative (alert)
Show answer

A real threat that goes undetected — the more dangerous error.

Patch / config audit
Show answer

Verifying systems are patched and configured to the secure baseline.

Threat modeling
Show answer

Systematically identifying and prioritizing threats to a system during design.

Risk register
Show answer

A documented inventory of identified risks, owners, and treatments.

SOC 2 report
Show answer

An independent audit of an organization's security/availability controls.

Incident Response & Recovery (35)

Incident response lifecycle
Show answer

Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident (NIST 800-61).

Preparation (IR)
Show answer

Building the policy, the CSIRT, tooling, and training before an incident happens.

Detection & analysis
Show answer

Identifying and confirming a real incident from events; determining scope and severity.

Containment
Show answer

Limiting the spread and damage of an incident (short-term then long-term).

Eradication
Show answer

Removing the threat — malware, compromised accounts, and the root cause.

Recovery (IR)
Show answer

Restoring systems to validated normal operation and monitoring for recurrence.

Lessons learned
Show answer

The post-incident review that improves detection, controls, and the plan.

CSIRT
Show answer

Computer Security Incident Response Team — the group that handles security incidents.

Chain of custody
Show answer

Documentation of who handled evidence and when, preserving its integrity for legal use.

Order of volatility
Show answer

Collect evidence by how fast it disappears — memory before disk before backups.

Digital forensics
Show answer

The collection, preservation, and analysis of digital evidence.

Business continuity plan (BCP)
Show answer

A plan to keep critical business functions operating during and after a disruption.

Disaster recovery (DR)
Show answer

Processes and procedures to restore IT systems after a disruptive event.

Business Impact Analysis (BIA)
Show answer

Identifies critical functions and sets recovery objectives (MTD, RTO, RPO).

Maximum Tolerable Downtime (MTD)
Show answer

The longest a function can be unavailable before unacceptable harm occurs.

Recovery Time Objective (RTO)
Show answer

The target time to restore a function after a disruption; must be shorter than MTD.

Recovery Point Objective (RPO)
Show answer

The maximum acceptable data loss measured backward in time; drives backup frequency.

Hot site
Show answer

A fully equipped recovery site with near-real-time failover — fastest, most expensive.

Warm site
Show answer

A recovery site with hardware and connectivity; data restored on demand — moderate.

Cold site
Show answer

An empty recovery space with power/cooling only — cheapest, slowest to bring online.

Full backup
Show answer

A backup of all selected data; fastest to restore (one set).

Incremental backup
Show answer

Backs up changes since the last backup of any type; fast backup, slow restore.

Differential backup
Show answer

Backs up changes since the last full backup; slower backup, faster restore.

3-2-1 backup rule
Show answer

Keep three copies of data, on two media types, with one stored off-site.

Tabletop exercise
Show answer

A discussion-based walkthrough of the incident or recovery plan.

Escalation
Show answer

Raising an incident to higher-level responders or management as severity grows.

First responder action
Show answer

After detection, the typical first technical step is containment — stop the spread.

Eradication vs. recovery
Show answer

Eradication removes the threat and root cause; recovery restores normal operations.

Tabletop vs. full-interruption test
Show answer

Tabletop is a discussion; full-interruption actually fails over to recovery systems.

Work Recovery Time (WRT)
Show answer

Time to verify and restore data/functionality after systems are back online.

Evidence integrity (hashing)
Show answer

Hashing collected evidence proves it has not changed since collection.

Write blocker
Show answer

A forensic tool that allows reading a drive without altering its contents.

Mean time to recover (MTTR)
Show answer

The average time to restore a system after a failure.

Playbook (IR)
Show answer

A predefined set of steps for responding to a specific type of incident.

Recovery site selection
Show answer

Choose hot/warm/cold based on the RTO and budget the BIA produced.

Cryptography (36)

Symmetric encryption
Show answer

One shared secret key for both encrypt and decrypt (AES); fast, hard to distribute.

Asymmetric encryption
Show answer

A public/private key pair (RSA, ECC); slower, solves key exchange, enables signatures.

AES
Show answer

The current symmetric block cipher standard (128/192/256-bit keys).

RSA
Show answer

A widely used asymmetric algorithm for encryption and digital signatures.

Diffie-Hellman
Show answer

An asymmetric method for two parties to agree on a shared secret over an insecure channel.

Hashing
Show answer

A one-way function producing a fixed-length digest to verify integrity (SHA-256).

SHA-2 / SHA-3
Show answer

Current secure hash algorithm families; use these instead of broken MD5/SHA-1.

HMAC
Show answer

A keyed hash providing both integrity and authenticity of a message.

Salting
Show answer

Adding random data to a password before hashing so identical passwords differ.

Key stretching
Show answer

Slowing password hashing with bcrypt, PBKDF2, scrypt, or Argon2 to resist cracking.

Digital signature
Show answer

A hash of a message encrypted with the sender's private key; gives integrity, authenticity, non-repudiation.

Encrypt vs. sign
Show answer

Encrypt with the recipient's PUBLIC key (confidentiality); sign with YOUR PRIVATE key (authenticity).

Hybrid cryptography
Show answer

Using asymmetric crypto to exchange a fast symmetric session key (e.g., TLS).

Public Key Infrastructure (PKI)
Show answer

The framework of CAs, certificates, and policies that manages public keys and trust.

Certificate Authority (CA)
Show answer

A trusted entity that issues and signs digital certificates.

Digital certificate (X.509)
Show answer

A document binding a public key to a verified identity, signed by a CA.

CRL
Show answer

Certificate Revocation List — a published list of certificates no longer trusted.

OCSP
Show answer

Online Certificate Status Protocol — a real-time check of a certificate's revocation status.

Key escrow
Show answer

Storing a copy of a key with a trusted third party for recovery or legal access.

HSM
Show answer

Hardware Security Module — a tamper-resistant device that generates and stores keys.

TLS
Show answer

The protocol that secures application traffic (HTTPS) using hybrid cryptography.

IPsec
Show answer

A protocol suite that secures IP traffic at Layer 3 (AH for integrity, ESP for confidentiality).

SSH
Show answer

A protocol for secure remote administration and file transfer.

Birthday attack
Show answer

An attack that exploits hash collision probability to find two inputs with the same digest.

Man-in-the-middle (crypto)
Show answer

An attacker secretly relays/alters communication between two parties.

Rainbow table
Show answer

A precomputed table of hashes used to crack unsalted password hashes quickly.

Block vs. stream cipher
Show answer

Block ciphers encrypt fixed-size blocks (AES); stream ciphers encrypt bit/byte by byte.

ECB vs. CBC mode
Show answer

ECB encrypts blocks independently (insecure patterns); CBC chains blocks for security.

GCM mode
Show answer

An authenticated encryption mode providing both confidentiality and integrity.

3DES
Show answer

A legacy symmetric cipher applying DES three times; now deprecated for AES.

ECC
Show answer

Elliptic Curve Cryptography — asymmetric crypto with strong security at small key sizes.

Perfect forward secrecy
Show answer

Session keys aren't compromised even if a long-term key is later exposed.

Key management lifecycle
Show answer

Generate, distribute, store, rotate, and destroy keys securely.

Nonce
Show answer

A number used once to prevent replay and ensure uniqueness in crypto operations.

Steganography
Show answer

Hiding data within other data (e.g., inside an image) rather than encrypting it.

Replay attack
Show answer

Capturing and re-sending valid data to gain unauthorized access; nonces/timestamps defend.

Network & Communications Security (44)

OSI model
Show answer

Seven layers: Physical, Data Link, Network, Transport, Session, Presentation, Application.

Layer 1 — Physical
Show answer

Cables, signals, and hubs — raw bit transmission.

Layer 2 — Data Link
Show answer

MAC addresses and switches; frames between adjacent nodes.

Layer 3 — Network
Show answer

IP addressing and routers; IPsec operates here.

Layer 4 — Transport
Show answer

TCP and UDP; ports and end-to-end delivery.

TCP vs. UDP
Show answer

TCP is connection-oriented and reliable; UDP is connectionless and fast.

Switch
Show answer

A Layer 2 device that forwards frames by MAC address.

Router
Show answer

A Layer 3 device that forwards packets between networks by IP address.

Firewall
Show answer

A device/software that filters network traffic against a rule set.

Packet-filter firewall
Show answer

Inspects each packet in isolation against rules; no memory of sessions.

Stateful firewall
Show answer

Tracks the state of active connections; allows return traffic for known sessions.

Proxy firewall
Show answer

Terminates and inspects traffic at the application layer on behalf of clients.

WAF
Show answer

Web Application Firewall — protects web apps from attacks like SQL injection and XSS.

IDS
Show answer

Intrusion Detection System — monitors and alerts but does not block (passive).

IPS
Show answer

Intrusion Prevention System — sits inline and can block malicious traffic (active).

Signature-based detection
Show answer

Detects threats by matching known attack patterns.

Anomaly-based detection
Show answer

Detects threats by flagging deviations from a normal baseline.

HIDS vs. NIDS
Show answer

HIDS runs on a host; NIDS watches network traffic.

VPN
Show answer

A Virtual Private Network — an encrypted tunnel over an untrusted network.

DMZ
Show answer

A screened subnet hosting public-facing services, isolated from the internal network.

VLAN
Show answer

A logically segmented broadcast domain on a switch for isolation.

Network access control (NAC)
Show answer

Checks a device's identity and posture before allowing it onto the network.

NAT / PAT
Show answer

Network/Port Address Translation — maps private addresses to public ones.

DoS / DDoS
Show answer

Attacks that overwhelm a target to deny service; DDoS uses many sources.

ARP poisoning
Show answer

Falsifying ARP replies to redirect traffic on a LAN (enables MITM).

DNS poisoning
Show answer

Corrupting DNS data to redirect users to a malicious address.

Spoofing
Show answer

Forging a source address or identity to impersonate a trusted entity.

WPA3
Show answer

The current Wi-Fi security standard with strong encryption and offline-attack protection.

802.1X / EAP
Show answer

A framework for port-based network access control and authentication.

Rogue access point
Show answer

An unauthorized wireless AP that creates an unsecured entry into the network.

Evil twin
Show answer

A malicious AP impersonating a legitimate one to capture traffic.

IoT security
Show answer

Hardening internet-connected devices that often ship insecure by default.

Secure protocol swaps
Show answer

Replace HTTP→HTTPS, FTP/Telnet→SFTP/SSH, WEP→WPA3, SNMPv1/2→SNMPv3.

Layer 5 — Session
Show answer

Establishes, manages, and terminates sessions between applications.

Layer 6 — Presentation
Show answer

Translates, encrypts, and compresses data (TLS sits around 6/7).

Layer 7 — Application
Show answer

Where user-facing protocols live: HTTP, DNS, SMTP, FTP.

TCP three-way handshake
Show answer

SYN, SYN-ACK, ACK — establishes a TCP connection.

Port (well-known)
Show answer

HTTPS 443, HTTP 80, SSH 22, DNS 53, RDP 3389.

Subnetting
Show answer

Dividing a network into smaller segments to improve control and isolation.

Reverse proxy
Show answer

A proxy that sits in front of servers, handling and filtering inbound requests.

Honeypot
Show answer

A decoy system used to detect, deflect, or study attackers.

MAC filtering
Show answer

Allowing only known hardware addresses onto a network (weak on its own).

Sniffing (eavesdropping)
Show answer

Capturing network traffic to read unencrypted data; encryption defends against it.

Air gap
Show answer

Physically isolating a system from untrusted networks for high security.

Systems & Application Security (46)

Malware
Show answer

Malicious software: viruses, worms, trojans, ransomware, rootkits, spyware, logic bombs.

Virus
Show answer

Malware that attaches to a file and needs a user to run it to spread.

Worm
Show answer

Self-replicating malware that spreads across networks with no user action.

Trojan
Show answer

Malware disguised as legitimate software to deliver a hidden payload.

Ransomware
Show answer

Malware that encrypts a victim's data and demands payment for the key.

Rootkit
Show answer

Malware with deep, privileged access that hides its presence from the OS.

Spyware
Show answer

Malware that secretly collects information about a user or system.

Logic bomb
Show answer

Malicious code that stays dormant until a trigger condition is met.

Fileless malware
Show answer

Malware that runs in memory using legitimate tools, leaving little on disk.

Phishing
Show answer

A social-engineering attack using fraudulent messages to steal data or deliver malware.

Spear phishing
Show answer

A targeted phishing attack aimed at a specific person or organization.

Advanced persistent threat (APT)
Show answer

A stealthy, long-term, well-resourced intrusion, often state-sponsored.

EDR
Show answer

Endpoint Detection and Response — continuously monitors endpoints to detect and respond.

Antivirus / anti-malware
Show answer

Software that detects and removes malicious code on endpoints.

Application allowlisting
Show answer

Permitting only approved programs to run; blocks everything else by default.

Patch management
Show answer

Acquiring, testing, and applying software updates to fix vulnerabilities.

System hardening
Show answer

Reducing the attack surface via secure config, removing unneeded services, and patching.

Host-based firewall
Show answer

A firewall running on an individual endpoint to filter its traffic.

Mobile device management (MDM)
Show answer

Software enforcing security policy on mobile devices (passcode, encryption, remote wipe).

BYOD
Show answer

Bring Your Own Device — using personal devices for work; needs containerization/policy.

Containerization (mobile)
Show answer

Isolating work data and apps from personal data on a device.

Remote wipe
Show answer

Erasing a lost or stolen device's data remotely to protect it.

Shared responsibility model
Show answer

Cloud provider secures the infrastructure; the customer always owns its data and access.

IaaS
Show answer

Infrastructure as a Service — customer secures the OS, apps, and data.

PaaS
Show answer

Platform as a Service — customer secures apps and data; provider manages OS/runtime.

SaaS
Show answer

Software as a Service — provider secures most; customer manages data, access, settings.

Cloud misconfiguration
Show answer

A leading cloud breach cause (e.g., a public storage bucket) — on the customer's side.

CASB
Show answer

Cloud Access Security Broker — enforces policy between users and cloud services.

Hypervisor
Show answer

Software that creates and runs VMs; Type 1 runs on bare metal, Type 2 on a host OS.

VM escape
Show answer

An attack that breaks out of a guest VM to reach the hypervisor or other VMs.

VM sprawl
Show answer

Uncontrolled growth of unmanaged virtual machines, increasing risk.

Container (technology)
Show answer

A lightweight, isolated package of an app and its dependencies sharing the host OS kernel.

Input validation
Show answer

Checking and sanitizing all user input to prevent injection attacks.

SQL injection
Show answer

Inserting malicious SQL through unvalidated input to read or alter a database.

Drive-by download
Show answer

Malware that installs simply by visiting a compromised or malicious web page.

Watering-hole attack
Show answer

Compromising a site a target group frequently visits to infect them.

Zero-day
Show answer

A vulnerability exploited before a patch exists; no signature yet to detect it.

Backdoor
Show answer

A hidden method to bypass normal authentication and gain access.

Botnet
Show answer

A network of compromised machines controlled by an attacker (often for DDoS).

HIPS
Show answer

Host Intrusion Prevention System — blocks malicious activity on an endpoint.

Secure baseline image
Show answer

A hardened, approved OS image deployed to ensure consistent, secure configuration.

Least functionality
Show answer

Configuring systems to provide only essential capabilities, reducing attack surface.

Type 1 vs. Type 2 hypervisor
Show answer

Type 1 runs on bare metal; Type 2 runs as an app on a host OS.

Snapshot risk
Show answer

VM snapshots may contain sensitive data and can revert security patches if restored.

Sandboxing
Show answer

Running untrusted code in an isolated environment to contain any harm.

Cross-site scripting (XSS)
Show answer

Injecting malicious scripts into a web page viewed by other users.

References

  1. 1.ISC2. “SSCP Certification Exam Outline (effective October 1, 2025).” isc2.org. ↑
  2. 2.ISC2. “SSCP — Systems Security Certified Practitioner.” isc2.org. ↑
  3. 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.