SSCP Master Guide 2026
The ISC2 Systems Security Certified Practitioner (SSCP) exam tests hands-on security administration and operations across seven domains.
- The current exam is CAT, with 100 to 125 variable-length items in two hours and a 700/1,000 scaled passing score.
- Certification separately requires one year of qualifying experience; candidates who pass before qualifying can pursue the Associate of ISC2 route.
On this page16 sections
- A practitioner credential for operating security
- What the exam measures
- The current seven domains and how they connect
- Exam format, CAT, and pacing
- A reliable question routine
- Experience requirement and Associate path
- Registration and scheduling
- Scoring, results and retakes
- A study method that builds retrieval
- A six-week plan for a working candidate
- Worked scenario: suspicious privileged login
- Worked scenario: patch exception
- Original practice item with explanation
- How to judge readiness
- After passing: certification and maintenance
- Choosing whether SSCP fits
A practitioner credential for operating security
SSCP is an ISC2 credential focused on the work that keeps information systems secure in daily operation. Its scope includes access administration, monitoring, incident response, network and communications security, systems and application security, and risk identification. It is useful for people who administer controls, investigate alerts, harden systems, or support security operations. It is not a vendor-specific product exam and does not certify that a person has one particular job title.
The current SSCP outline took effect October 1, 2025. It names seven domains: Security Concepts and Practices; Access Controls; Risk Identification, Monitoring and Analysis; Incident Response and Recovery; Cryptography; Network and Communications Security; and Systems and Application Security. A firewall change affects network controls and access, but also risk and monitoring if it fails.
| Domain | Average exam weight |
|---|---|
| Security Concepts and Practices | 16% |
| Access Controls | 15% |
| Risk Identification, Monitoring and Analysis | 15% |
| Incident Response and Recovery | 14% |
| Cryptography | 9% |
| Network and Communications Security | 16% |
| Systems and Application Security | 15% |
| Total | 100% |
What the exam measures
The exam asks you to apply security principles to operational choices. A question may describe an alert, access request, configuration, policy exception, or incident and ask which action should happen first or best protects the organization. Learn the concepts behind the control, the evidence that shows whether it is working, the owner who should act, and the risk created by a rushed fix.
This emphasis rewards disciplined judgment. In real practice, you may be able to implement a control and also assess it. On an exam question, identify the role implied by the stem: administrator, incident responder, analyst, or security manager. If the task is to preserve evidence, do not jump to a destructive remediation. If the task is to restore a service, do not leave an active compromise contained only on paper.
The current seven domains and how they connect
Security Concepts and Practices covers foundational security principles, policy, governance, ethics, awareness and the practitioner’s role. Access Controls covers identity proofing, authentication, authorization, least privilege, account provisioning, access review and revocation. Risk Identification, Monitoring and Analysis addresses assets, threats, vulnerabilities, risk treatment, security monitoring, event analysis, and communicating findings. Incident Response and Recovery connects preparation, detection, analysis, containment, eradication, recovery, evidence handling and lessons learned. Cryptography covers the proper use of encryption, hashing, digital signatures, key management and secure protocols. Network and Communications Security applies segmentation, secure network architecture, wireless protection, boundary defenses and traffic monitoring. Systems and Application Security concerns secure configuration, vulnerabilities, patching, malware defense and development practices.
The domains carry unequal weights. Security Concepts and Practices, Network and Communications Security, and Systems and Application Security each represent 16%, while Access Controls and Risk Identification, Monitoring and Analysis each represent 15%, Incident Response and Recovery is 14%, and Cryptography is 9%. Use these percentages to distribute revision time, but do not neglect a smaller domain: the outline samples multiple areas and an operational scenario can combine them.
Do not memorize domain names as isolated buckets. Consider an employee leaving the company with an active account: Access Controls frames timely revocation; Risk Identification and Monitoring considers the signal and its significance; Security Concepts and Practices supplies policy and responsibility; and Incident Response applies if the account is used after separation. A question can test the relationship among these areas even when it emphasizes one domain.
Exam format, CAT, and pacing
ISC2 lists the SSCP exam as Computerized Adaptive Testing with 100 to 125 variable-length items and a two-hour limit. The reported score is scaled from 0 to 1,000; 700 is the passing score. Do not translate 700 into 70 percent of questions correct. The scale is not a published raw percentage conversion, and the adaptive selection of items makes a home-made raw cutoff unreliable.
CAT means the exam adapts item selection to responses under the test program’s rules. You should answer the question in front of you carefully rather than trying to infer a hidden difficulty level. Follow the current delivery instructions on screen. Plan to finish within two hours, but keep the pace steady: at 100 items that is 72 seconds per item; at 125 it is about 58 seconds. These are average planning figures, not a guarantee of the exact count.
A reliable question routine
First identify the task word: best, first, most likely, or most effective. Next determine what is known and what remains uncertain. Then identify the asset, threat, control owner, and business impact. Finally eliminate options that skip authorization, destroy evidence, grant excessive access, or treat a symptom while leaving the cause in place.
In operational security, “first” frequently points to validation, triage, containment, or preservation before broader remediation. But it depends on the facts. If an active process is exfiltrating data, prompt containment can be warranted; if the alert is unverified and isolation would interrupt a critical service, rapidly validate and follow the incident playbook. The stem supplies the constraints that distinguish the answer.
Experience requirement and Associate path
You may sit the exam before you have the experience required for the credential. To earn SSCP, ISC2 currently requires one year of cumulative work experience in one or more of the seven SSCP domains. The experience must be relevant security work; merely having an IT job or using security tools as an incidental task does not automatically demonstrate the required domain experience.
ISC2 lists an experience substitution of a degree in a cybersecurity program or an approved pathway, as described in its current experience requirements. Part-time work and internships may count under ISC2’s stated conversion rules, subject to the required duration and documentation. Candidates who pass but do not yet meet the experience requirement may become an Associate of ISC2 and have up to two years to earn the required experience for SSCP. Passing the exam and holding the certification are distinct. Do not use the SSCP designation until ISC2 awards it.
Keep employment dates, duties, supervisor details, and domain mapping while work is fresh. A concise record might say: “Administered role-based access for 240 staff; reviewed privileged accounts quarterly; removed access at separation; escalated unexplained authentication patterns.” This gives a verifier a concrete basis to assess security responsibilities. The exact application, endorsement, and evidence steps are controlled by ISC2.
Registration and scheduling
A candidate purchases or redeems an exam through ISC2 and then schedules an appointment through the linked test-delivery process, currently Pearson VUE. Purchase confirmation and an appointment confirmation are separate: the exam code does not itself reserve a seat. Use the legal name that matches the identification requirements for the selected delivery method. Check the test-center rules before the appointment and keep the confirmation details.
The live scheduler controls actual location, language, and date availability. Availability varies by test center and time. Choose a target date that leaves enough preparation time while allowing room to reschedule if needed. Read the current code expiration, cancellation, and rescheduling terms attached to the purchase. Do not rely on an old forum post for a fee or deadline; the applicable checkout and scheduler terms govern.
Scoring, results and retakes
ISC2 publishes 700/1,000 as the passing scaled score. A pass report means the candidate met the exam standard; it does not certify the work-experience requirement or automatically confer SSCP. A candidate who does not pass should use the score report’s domain feedback to decide what to revisit, while remembering that performance feedback is not a complete diagnosis of every misconception.
ISC2’s general exam policy sets retake intervals and attempt limits. Before booking another attempt, read the current policy for the specific exam and your region. Build the wait into a realistic plan: review weak domains, return to mixed questions after targeted repair, and schedule a second attempt only when performance is stable across topics. Avoid claiming that a fixed practice percentage guarantees success; vendor questions and official exam scoring are not interchangeable.
A study method that builds retrieval
Start with the official outline and make a checklist of tasks, not just nouns. For every item, write what a practitioner would do, what evidence confirms the result, what could go wrong, and which other domain is implicated. This turns “know access control” into concrete goals such as explaining why joiner-mover-leaver changes need an owner, audit trail, and timely revocation.
Use one primary learning resource that follows the current outline, a concise reference for unfamiliar concepts, and a question set that explains distractors. Keep a miss log with four fields: topic, why the selected answer failed, principle that chooses the correct option, and what new detail would change the decision. Revisit the log after a day and again in a mixed set. Re-reading a highlighted chapter can feel productive while leaving recall untested.
A six-week plan for a working candidate
Weeks 1 and 2: map the outline and study two domains per week. Spend short sessions on core terms, then draw simple workflows: account provisioning, firewall change approval, vulnerability remediation, and incident escalation. End each week with a closed-book recall and a mixed practice set.
Weeks 3 and 4: cover the remaining domains and revisit the weakest first-pass topics. For each control, ask who owns it, how it is configured, what log or record proves operation, and what action follows an exception. Practice reading scenarios before looking at options.
Week 5: do timed mixed practice in blocks. Classify every miss as knowledge, misreading, role confusion, or decision-order error. Return to source material for the concept, not to memorize the wording of one question. Rework missed items after a gap.
Week 6: use two or three short sessions to review the miss log and outline. Take one realistic timed session, then stop adding new resources. Confirm logistics and rest. If you cannot explain a control in plain language or choose between two actions by the facts in the stem, continue targeted study rather than chasing a numerical readiness promise.
Worked scenario: suspicious privileged login
A monitoring analyst sees a successful administrator login at 02:10 from an unfamiliar region. The account is used by an on-call engineer. Which action is best first? Preserve the alert and relevant authentication records, validate the login with the on-call process, and follow the incident-response escalation path. If evidence indicates compromise, contain the account or session under the playbook while protecting essential service access.
A weak response immediately deletes the account or wipes the server. That may destroy evidence and disrupt recovery. Another weak response simply asks the engineer by email and closes the alert. A good response validates through a trusted channel, maintains an audit trail, and treats the event as a security signal until resolved. If the scenario explicitly says active exfiltration is confirmed, containment becomes urgent.
Worked scenario: patch exception
A critical server cannot be patched during the approved change window because a vendor application would fail. The security team discovers the server is exposed to a vulnerable service. The best operational response is to document the risk, involve the service owner, apply feasible compensating controls such as restricting network reachability, monitor for exploitation, and schedule a tested remediation window. Do not silently waive the issue or deploy an untested patch to production without change control.
The decision balances availability and security through accountable risk treatment. The exception needs an owner, reason, scope, expiration or review date, and evidence that interim controls are operating. A compensating firewall rule reduces exposure but does not erase the underlying vulnerability.
Original practice item with explanation
A departing employee’s account remains enabled after HR submitted a separation request. The account has not been used since the request. What should the SSCP practitioner do first?
Immediately disable the account using the approved access-removal process, preserve the request and action record, and verify that associated credentials or sessions are revoked as required. Then investigate why the handoff failed and correct the process. Least privilege is not a reason to wait for misuse; a confirmed separation is sufficient authorization to remove access.
Why this is best: the access is no longer justified, so prompt revocation reduces exposure. Preserving the request and action evidence supports accountability. The follow-up control review addresses the workflow defect.
Why the alternatives fail: waiting for a manager to discover use leaves unnecessary access active; deleting logs destroys evidence; changing the password while leaving the identity enabled may leave tokens or other authentication paths intact; and broad disabling of unrelated accounts exceeds the evidence.
How to judge readiness
Readiness is stronger when you can retrieve core principles without notes, apply them to mixed scenarios, and explain why the tempting distractor is wrong. Look for repeatable performance across all domains rather than a single strong score on familiar questions. A useful checkpoint is to take a timed mixed set after a delay, review every miss, then take a different mixed set later and see whether the same reasoning error returns.
If your mistakes cluster in one domain, repair that knowledge. If you know the facts but repeatedly choose a destructive or unauthorized action, practice sequencing and role boundaries. If time pressure causes careless reading, slow down enough to identify the task and constraints before selecting. The goal is flexible judgment, not recognition of a vendor’s phrasing.
After passing: certification and maintenance
Passing the SSCP exam is one milestone. Candidates who already meet experience requirements still complete the ISC2 application and endorsement process and agree to the Code of Ethics before certification is granted. Those who lack experience can pursue the Associate route. Confirm current application deadlines and maintenance conditions directly in the official SSCP experience and member-policy pages because those are credential rules, distinct from the exam outline.
ISC2 credentials require ongoing maintenance. The current member policy describes the CPE cycle, submission, and annual maintenance fee; exact requirements can vary by credential level and are updated by ISC2. Keep a professional record of relevant continuing education and pay the fee on time. Do not assume exam purchase includes lifetime certification or that passing alone carries a post-exam title.
Choosing whether SSCP fits
SSCP is a reasonable target if you want a broad practitioner-level security credential and already work with access, networks, endpoint or server controls, operations, risk monitoring, or incident response. It can also provide a structured study map for someone moving into security operations. The credential is less suitable if your immediate goal is deep specialization in one vendor platform or a role-specific credential with a different experience model.
Compare the exam topics with your current work. If you can connect each domain to a task you have performed or practiced in a lab, the material will be easier to apply. If several domains are entirely new, budget more time to build their foundations. Passing is valuable evidence of exam knowledge, but it is not a substitute for hands-on experience.
Common questions
How many questions are on the SSCP exam?
ISC2 lists 100 to 125 variable-length items in two hours; CAT determines the delivered item count.
What is a passing score for SSCP?
The published passing score is 700 on a 1,000-point scaled scale, not a stated raw percentage.
Can I take SSCP before I have experience?
Yes. Experience is a certification requirement, not a prerequisite to sit. A passing candidate can pursue the Associate of ISC2 route while qualifying.
How much experience does SSCP require?
ISC2 currently requires one year of cumulative work experience in one or more SSCP domains, with listed education and experience pathways.