ISC2 · Exam reference

About the ISC2 SSCP exam

The SSCP (Systems Security Certified Practitioner) is ISC2's hands-on security credential for the people who actually run the controls — SOC analysts, systems and network administrators, and security engineers. This course covers all seven domains of the exam outline effective 1 October 2025, with practice questions, flashcards and a full study guide.

10

Sample questions

120 min

Exam time limit

70%

Practice pass mark

$249

Exam voucher

The SSCP is the certification for people who operate security rather than write policy about it. Where the CISSP asks how you would design a security programme, the SSCP asks whether you can configure the access control, read the log, contain the incident and get the system back. That makes it the natural next step after CompTIA Security+ and the natural proof of competence for a SOC analyst, systems administrator, network administrator, database administrator or security engineer who has been doing the work for a year or more. ISC2 rewrote how the exam is delivered on 1 October 2025. It is now Computerized Adaptive Testing, the same engine as the CISSP: between 100 and 125 items in two hours, each one selected based on how you answered the last, until the engine is statistically confident about you. You cannot skip, flag or return to a question. Passing is a scaled 700 out of 1000, and the seven domains carry different weights — Security Concepts and Practices and Network and Communications Security at 16% each, Cryptography at just 9%. Adaptive delivery punishes shallow coverage in a specific way. A linear exam lets a weak domain hide in the average; a CAT exam keeps probing where you are uncertain until it has measured exactly how uncertain you are. Cryptography being the smallest domain is not permission to skip it. This course covers all seven domains at their real weights so the thin ones get the attention the engine will give them.

Exam Domains Covered

Security Concepts and Practices · 16%Access Controls · 15%Risk Identification, Monitoring and Analysis · 15%Incident Response and Recovery · 14%Cryptography · 9%Network and Communications Security · 16%Systems and Application Security · 15%

Exam Format & Details

Computerized Adaptive Testing (CAT) since 1 October 2025: 100-125 items in 2 hours, drawn adaptively from all seven domains. Item formats are multiple choice plus advanced item types (drag-and-drop and ordering). Passing score is a scaled 700 out of 1000 points. Booked through Pearson VUE test centres at $249 USD, available in English, Japanese and Spanish. Certification requires one year of cumulative paid work experience in at least one domain; without it you pass as an Associate of ISC2 and have two years to earn the experience. Annual maintenance fee is $135 with 60 CPE credits over the three-year cycle.

Why Practice Questions Matter

SSCP questions are written at the practitioner level: not "what is least privilege" but "which of these four changes enforces least privilege in this situation". Reading about a control does not tell you whether you can pick it out under time pressure, and the adaptive engine gives you no chance to come back to a question once you have answered it. Working through several hundred scenario questions at the real domain weights builds the reflex the exam actually measures, and shows you which of the seven domains is quietly weak before the CAT engine finds it for you.

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 SSCP exam — not actual exam content.

Q1.To stop a line-of-business application crashing, an administrator excludes an entire program directory from antimalware and endpoint telemetry. What is the main security risk?

  • A.Attackers who learn the excluded path gain a blind spot to work from
  • B.Signature updates stop applying to that host
  • C.The agent consumes more processor time scanning elsewhere
  • D.The vendor support agreement becomes invalid

Domain: Systems and Application Security

Q2.Which RAID level stripes data across disks with no redundancy, so that losing any single disk loses the whole array?

  • A.RAID 0
  • B.RAID 1
  • C.RAID 5
  • D.RAID 6

Domain: Incident Response and Recovery

Q3.A user with no session opens a service-provider-initiated SAML application, is redirected to the corporate identity provider, and completes multi-factor authentication successfully. What happens next?

  • A.The identity provider issues a signed assertion that the browser posts to the assertion consumer endpoint
  • B.The identity provider forwards the user's password to the service provider over a back channel
  • C.The service provider queries the identity provider's directory over LDAP for group memberships
  • D.The service provider issues a ticket-granting ticket for the new session

Domain: Access Controls

Q4.Which statement separates least privilege from need to know correctly?

  • A.Least privilege limits what an account can do; need to know limits which records it may see
  • B.Least privilege applies to people while need to know applies to service accounts
  • C.Least privilege is a technical control and need to know is a physical one
  • D.Need to know is a stricter form of least privilege used only for administrators

Domain: Security Concepts and Practices

Q5.Which sequence correctly orders the phases of incident response?

  • A.Preparation, containment, detection and analysis, eradication, recovery, lessons learned
  • B.Preparation, detection and analysis, containment, eradication, recovery, lessons learned
  • C.Preparation, detection and analysis, eradication, containment, recovery, lessons learned
  • D.Detection and analysis, preparation, containment, recovery, eradication, lessons learned

Domain: Incident Response and Recovery

Frequently Asked Questions

What is included in the free ISC2 SSCP sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full ISC2 SSCP course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the ISC2 SSCP course page.

Are these official ISC2 exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.

Which domains does the ISC2 SSCP course cover?

The course covers 7 exam domains: Security Concepts and Practices, Access Controls, Risk Identification, Monitoring and Analysis, Incident Response and Recovery, Cryptography, Network and Communications Security, Systems and Application Security.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.