What the ISC2 SSCP is and who it is for
The ISC2 Systems Security Certified Practitioner (SSCP) validates the technical skills to implement, monitor and administer IT infrastructure using security best practices. It covers access controls, security operations, risk identification, incident response, cryptography, network security, and systems and application security. It is approved by the US Department of Defense under DoDM 8140.03, which makes it relevant to many federal and defence contracting roles.
It is for you if you are hands on with systems and networks, as an administrator, analyst or engineer, and want a security credential that reflects operational work rather than management. It is also an obvious choice if a federal or defence role you want lists it as an approved certification.
Full certification needs one year of relevant security experience. If you do not have it yet, you can sit the exam first and become an Associate of ISC2 while you build the experience. The SSCP uses computerised adaptive testing.
ISC2 SSCP at a glance
| Item | Detail |
|---|---|
| Exam code | SSCP |
| Questions | 100 to 125, computerised adaptive testing |
| Time allowed | 120 minutes |
| Passing score | 700 out of 1000 |
| Exam fee | US$249 per attempt |
| Where you sit it | Pearson VUE testing centres only |
| Certification valid for | 3 years |
What is on the exam
Seven domains with very even weights. Six sit between 14% and 16%, and only cryptography is smaller. There is no domain you can safely neglect.
Security concepts and practices (16%). The foundations: confidentiality, integrity and availability, codes of ethics, security controls, asset management, change and configuration management, and security awareness.
Access controls (15%). Authentication methods, trust relationships between systems, identity lifecycle from provisioning to removal, and access control models.
Risk identification, monitoring and analysis (15%). Risk management concepts, security assessments and vulnerability scanning, and monitoring systems and logs to spot problems. You will need to interpret results and decide what they mean for the organisation.
Incident response and recovery (14%). The incident lifecycle, supporting forensic investigations, and business continuity and disaster recovery. Many questions give you a point in an incident and ask for the correct next action.
Cryptography (9%). The smallest domain: the purpose of cryptography, symmetric and asymmetric algorithms, hashing, digital signatures, public key infrastructure and secure protocols. It is small by weight but dense with terms, and weak candidates lose easy marks here.
Network and communications security (16%). Network models and protocols, common network attacks and their countermeasures, network access controls, device security and wireless security. Expect scenario questions about securing a network segment or choosing a control for a specific threat.
Systems and application security (15%). Malicious code and activity, endpoint security, cloud and virtualised environments, and securing applications and data.
Why people fail it
Every failed attempt costs the full US$249 again, and for many candidates the cost is higher than the fee. Because the SSCP is DoDM 8140.03 approved and listed for many federal and defence roles, a failure can delay a start date or cost the job itself.
The adaptive format catches out people who prepared for a fixed exam. The SSCP adjusts to your performance in real time and ends anywhere between 100 and 125 questions, so you cannot pace yourself against a fixed finish line. Candidates who are used to counting down a known number of questions lose their sense of timing, and some panic when the exam keeps going past 100, reading it as a sign that things are going badly.
The even weighting is the other trap. With six domains between 14% and 16%, a gap in any one of them costs you a real share of the exam. Practitioners who work mainly in networks or mainly in identity tend to be strong in their own area and thin everywhere else, and an adaptive exam finds those thin areas quickly.
A study plan that fits the exam
Seven weeks. The weights are nearly equal, so each of the six larger domains gets roughly a week, cryptography shares a week with incident response, and the final week is timed practice.
- Week 1: security concepts and practices. The core principles, controls and management processes that the other domains assume. Try the free SSCP practice questions at the end of the week to see how ISC2 words its scenarios.
- Week 2: access controls. Authentication, identity lifecycle and access control models. Start working the matching questions in the SSCP practice question pack and read every explanation, including why each wrong option is wrong.
- Week 3: network and communications security. Protocols, network attacks and their countermeasures, and wireless security. This is one of the two largest domains, so finish with a full set of its questions.
- Week 4: systems and application security. Malicious code, endpoint protection, cloud and virtualisation, and application and data security.
- Week 5: risk identification, monitoring and analysis. Risk concepts, assessments, scanning and monitoring. Practise interpreting scan and log results rather than just defining terms.
- Week 6: incident response and recovery, then cryptography. The incident lifecycle, forensics and continuity planning for the first half of the week, then algorithms, hashing, PKI and protocols. Make a one page summary of the cryptography terms and review it daily.
- Week 7: timed runs. Use the questions only PDF for sittings against the 120 minute limit. Mix the domains so you get used to switching topic on every question, as the real exam will, and spend the remaining days on your lowest scoring domain.
On exam day
You sit the SSCP at a Pearson VUE testing centre. ISC2 does not offer online proctoring for its exams, so there is no option to take it at home. Plan to arrive early for check in.
You have 120 minutes for somewhere between 100 and 125 questions, and you will not know which until the exam ends. Pace yourself for the upper end so you never run short, and treat the exam ending early or late as meaningless, because it tells you nothing you can act on. Answer each question as if you will not see it again. The passing score is 700 out of 1000, and it is a scaled score, so do not try to track your marks as you go.
Frequently asked questions
Can I take the SSCP without a year of experience?
Yes. Full certification needs one year of relevant security experience, but you can sit the exam first. If you pass without the experience, you become an Associate of ISC2 and can complete the certification once you have it.
What happens if I fail? Can I retake it?
You can, but every attempt costs the full US$249 again. ISC2 publishes its retake policy, including any waiting period between attempts, on its website, so check it before you book. The practice pack is refunded if you fail, but the exam fee is not, so do your timed practice before the first attempt.
Is the practice question pack enough on its own?
No. The pack is 1,074 practice questions with the correct answer, the reasoning and a note on every wrong option, plus a questions only PDF for timed runs. It is one of the largest question banks available for the SSCP and it is good at showing you ISC2’s style and exposing weak domains. It is not a course, and it does not replace an official study guide or real experience with the systems the exam describes.
How does adaptive testing change my preparation?
Mainly pacing and nerves. Practise pacing for 125 questions and get comfortable not knowing where the finish line is. The content is still the seven domains above.
When you are ready to practise, get the 1,074 question SSCP pack for US$39, pass or your money back.
