ISC2 · Practice exam

Free ISC2 SSCP Practice Questions

The ISC2 SSCP exam is up to 125 questions in 120 minutes, and the voucher costs $249. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 7 exam domains, each with a full explanation. Free to try, no account required.

No account · No card · Pass or refund

Try one · Systems and Application Security

To stop a line-of-business application crashing, an administrator excludes an entire program directory from antimalware and endpoint telemetry. What is the main security risk?

Practice questions
400
Exam time limit
120 min
Practice pass mark
70%
Exam voucher
$249

In the full course

What you get

  • 400 exam-style questions, each with a full explanation
  • 20 performance-based tasks, marked with partial credit
  • 200 flashcards, filtered by domain
  • The full study guide, 25 chapters
  • Timed mock exams matched to the real exam length
  • A readiness score weighted by the official exam blueprint

Get full access to ISC2 SSCP

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

Until 30 November

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

More free samples

Marked, and passed

Real feedback from people who passed

“I failed my CISSP on the first attempt with another platform. Switched to CertCrush, focused on my weak domains using the tracking feature, and passed three months later. The explanations for wrong answers are genuinely useful, not just 'A is correct because A is correct'.”
MTMarcus T.ISC² CISSP
“Honestly wasn't expecting much but this is probably the best ten bucks I've spent on exam prep. Did 20–30 questions every morning before work for 6 weeks. Passed with a comfortable margin. The timed exam mode is what really got me comfortable with the pressure.”
PSPriya S.CompTIA Security+
“The flashcards are underrated. I used them during my commute and it made a huge difference for the theory-heavy ITIL questions. Passed first try. Already using it again for CISM.”
JRJames R.ITIL 5 Foundation

The SSCP (Systems Security Certified Practitioner) is ISC2's hands-on security credential for the people who actually run the controls — SOC analysts, systems and network administrators, and security engineers. This course covers all seven domains of the exam outline effective 1 October 2025, with practice questions, flashcards and a full study guide.

Practice content last updated · Independently written and aligned to ISC2’s published exam objectives.

About the ISC2 SSCP Exam

The SSCP is the certification for people who operate security rather than write policy about it. Where the CISSP asks how you would design a security programme, the SSCP asks whether you can configure the access control, read the log, contain the incident and get the system back. That makes it the natural next step after CompTIA Security+ and the natural proof of competence for a SOC analyst, systems administrator, network administrator, database administrator or security engineer who has been doing the work for a year or more. ISC2 rewrote how the exam is delivered on 1 October 2025. It is now Computerized Adaptive Testing, the same engine as the CISSP: between 100 and 125 items in two hours, each one selected based on how you answered the last, until the engine is statistically confident about you. You cannot skip, flag or return to a question. Passing is a scaled 700 out of 1000, and the seven domains carry different weights — Security Concepts and Practices and Network and Communications Security at 16% each, Cryptography at just 9%. Adaptive delivery punishes shallow coverage in a specific way. A linear exam lets a weak domain hide in the average; a CAT exam keeps probing where you are uncertain until it has measured exactly how uncertain you are. Cryptography being the smallest domain is not permission to skip it. This course covers all seven domains at their real weights so the thin ones get the attention the engine will give them.

Exam Domains Covered

  • Security Concepts and Practices16%
  • Access Controls15%
  • Risk Identification, Monitoring and Analysis15%
  • Incident Response and Recovery14%
  • Cryptography9%
  • Network and Communications Security16%
  • Systems and Application Security15%

Exam Format & Details

Computerized Adaptive Testing (CAT) since 1 October 2025: 100-125 items in 2 hours, drawn adaptively from all seven domains. Item formats are multiple choice plus advanced item types (drag-and-drop and ordering). Passing score is a scaled 700 out of 1000 points. Booked through Pearson VUE test centres at $249 USD, available in English, Japanese and Spanish. Certification requires one year of cumulative paid work experience in at least one domain; without it you pass as an Associate of ISC2 and have two years to earn the experience. Annual maintenance fee is $135 with 60 CPE credits over the three-year cycle.

Why Practice Questions Matter

SSCP questions are written at the practitioner level: not "what is least privilege" but "which of these four changes enforces least privilege in this situation". Reading about a control does not tell you whether you can pick it out under time pressure, and the adaptive engine gives you no chance to come back to a question once you have answered it. Working through several hundred scenario questions at the real domain weights builds the reflex the exam actually measures, and shows you which of the seven domains is quietly weak before the CAT engine finds it for you.

Try 2 performance tasks free

Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real ISC2 SSCP exam, marked with partial credit.

Start free

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 SSCP exam, not actual exam content.

Q1.To stop a line-of-business application crashing, an administrator excludes an entire program directory from antimalware and endpoint telemetry. What is the main security risk?

  • A.Attackers who learn the excluded path gain a blind spot to work from
  • B.Signature updates stop applying to that host
  • C.The agent consumes more processor time scanning elsewhere
  • D.The vendor support agreement becomes invalid

Domain: Systems and Application Security

Q2.Which RAID level stripes data across disks with no redundancy, so that losing any single disk loses the whole array?

  • A.RAID 0
  • B.RAID 1
  • C.RAID 5
  • D.RAID 6

Domain: Incident Response and Recovery

Q3.A user with no session opens a service-provider-initiated SAML application, is redirected to the corporate identity provider, and completes multi-factor authentication successfully. What happens next?

  • A.The identity provider issues a signed assertion that the browser posts to the assertion consumer endpoint
  • B.The identity provider forwards the user's password to the service provider over a back channel
  • C.The service provider queries the identity provider's directory over LDAP for group memberships
  • D.The service provider issues a ticket-granting ticket for the new session

Domain: Access Controls

Q4.Which statement separates least privilege from need to know correctly?

  • A.Least privilege limits what an account can do; need to know limits which records it may see
  • B.Least privilege applies to people while need to know applies to service accounts
  • C.Least privilege is a technical control and need to know is a physical one
  • D.Need to know is a stricter form of least privilege used only for administrators

Domain: Security Concepts and Practices

Q5.Which sequence correctly orders the phases of incident response?

  • A.Preparation, containment, detection and analysis, eradication, recovery, lessons learned
  • B.Preparation, detection and analysis, containment, eradication, recovery, lessons learned
  • C.Preparation, detection and analysis, eradication, containment, recovery, lessons learned
  • D.Detection and analysis, preparation, containment, recovery, eradication, lessons learned

Domain: Incident Response and Recovery

Q6.Seven years of confidential case files are archived out of a live system onto a low-cost unencrypted file share to save money. What is wrong with this?

  • A.Archived data keeps its classification and its protection requirements
  • B.Archiving is not permitted for confidential records
  • C.The files should have been destroyed rather than archived
  • D.Archives must stay on the live system to remain retrievable

Domain: Security Concepts and Practices

Q7.An access list contains, in order, a permit from any source to 10.0.5.0/24 on TCP 3389, then a deny from the guest range 10.9.0.0/16 to that subnet. Guests still reach remote desktop. Why?

  • A.The two rules conflict, so the device falls through to the implicit deny
  • B.Deny rules require an explicit logging keyword before they take effect
  • C.The broad permit matches guest traffic first, so the deny is never reached
  • D.The guest range must be written as a /24 before a deny will match it

Domain: Network and Communications Security

Q8.A monitoring team decides not to record every denied packet at the perimeter, only volumes above a set rate, because ordinary denials bury the interesting events. What is the point below which nothing is recorded called?

  • A.The clipping level
  • B.The threshold
  • C.The baseline
  • D.The tolerance

Domain: Risk Identification, Monitoring and Analysis

Q9.Two regional firms of similar size agree to host each other's operations if either suffers an outage. What is the principal weakness of this arrangement?

  • A.A regional event affects both parties at the same time
  • B.It costs more than maintaining a warm site of one's own
  • C.It cannot be documented in a continuity plan for audit purposes
  • D.It requires identical hardware and software at both firms

Domain: Incident Response and Recovery

Q10.An on-path attacker blocks a client's access to the certificate authority's OCSP responder, and the browser loads the site anyway. What is the security consequence?

  • A.Revocation checking is effectively disabled for that connection
  • B.The connection falls back to a certificate revocation list automatically
  • C.The browser downgrades the connection to TLS 1.0
  • D.The certificate is treated as expired and the connection is refused

Domain: Cryptography

ISC2 SSCP guides & exam news

Frequently Asked Questions

Does the ISC2 SSCP course include performance-based questions?

Yes. The ISC2 SSCP course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.

What is included in the free ISC2 SSCP sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full ISC2 SSCP course?

The full ISC2 SSCP course includes 400 practice questions and 20 performance-based tasks, covering all 7 exam domains. Every question carries a full explanation for the right answer and the wrong ones.

Are these official ISC2 exam questions?

No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.

Which domains does the ISC2 SSCP course cover?

The course covers 7 exam domains: Security Concepts and Practices, Access Controls, Risk Identification, Monitoring and Analysis, Incident Response and Recovery, Cryptography, Network and Communications Security, Systems and Application Security.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.

Start with 10 free questions

No account, no card. The full ISC2 SSCP course is $9.99, once.

Start freeBuy · $9.99