Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SSCP Exam Domains and Weights

Updated 8 min read
Key takeaway

The SSCP outline effective October 1, 2025 has seven domains: Security Concepts and Practices (16%), Access Controls (15%), Risk Identification, Monitoring and Analysis (15%), Incident Response and Recovery (14%), Cryptography (9%), Network and Communications Security (16%), and Systems and Application Security (15%).

  • Weights guide coverage, but each domain remains testable.
On this page12 sections
  1. 1. Security Concepts and Practices : 16%
  2. 2. Access Controls : 15%
  3. 3. Risk Identification, Monitoring and Analysis : 15%
  4. 4. Incident Response and Recovery : 14%
  5. 5. Cryptography : 9%
  6. 6. Network and Communications Security : 16%
  7. 7. Systems and Application Security : 15%
  8. Cross-domain scenario: compromised workstation
  9. Cross-domain scenario: weak control evidence
  10. How to study the outline
  11. Original practice question
  12. Use the domain weights correctly

The percentages below are ISC2 average exam weights, not guaranteed item counts for an individual adaptive exam. Use the current outline rather than older books that still organize SSCP under prior domain names. The exam checks applied knowledge: identify the control, the operational risk, the person authorized to act, and how to verify that the response worked.

Current domainWeight
1. Security Concepts and Practices16%
2. Access Controls15%
3. Risk Identification, Monitoring and Analysis15%
4. Incident Response and Recovery14%
5. Cryptography9%
6. Network and Communications Security16%
7. Systems and Application Security15%
Total100%

1. Security Concepts and Practices : 16%

This domain establishes how a practitioner uses security concepts, codes of ethics, organizational policy and controls in day-to-day work. The outline includes confidentiality, integrity, availability, accountability, non-repudiation, least privilege and segregation of duties. It also asks candidates to identify technical, physical and administrative controls; distinguish deterrent, preventive, detective, corrective and compensating controls; and support asset, change-management, awareness and physical-security processes.

Know why controls exist, who owns them and what evidence supports them. A written policy is administrative, a firewall is technical, and a badge reader is physical; the labels do not prove effectiveness. A compensating control reduces risk when a preferred safeguard cannot be used. A candidate should be able to document a control, review it periodically, and escalate a failure without misrepresenting compliance.

2. Access Controls : 15%

Access Controls covers authentication methods such as MFA, single sign-on, federation and device authentication, plus trust relationships between networks and third parties. The identity lifecycle runs from proofing and authorization through provisioning, monitoring, role changes and deprovisioning. The outline includes mandatory, discretionary, role-based, rule-based and attribute-based access approaches.

The practical principle is to grant the minimum justified rights and remove them when circumstances change. For an employee moving teams, do not simply add the new role and leave all old access. Review inherited rights, privileged membership, approvals and logs. A shared account can reduce accountability; emergency access needs control, monitoring and review. Authentication proves identity; authorization decides what the identity may do.

3. Risk Identification, Monitoring and Analysis : 15%

This domain includes risk concepts and treatment, legal and regulatory concerns, security assessments, vulnerability management, monitoring platforms and analysis of their outputs. Candidates should understand threat context, asset value, risk tolerance and treatment choices: accept, transfer, mitigate or avoid. The outline mentions risk registers, threat intelligence, indicators of compromise, CVSS, frameworks, threat modeling, privacy and jurisdiction.

Monitoring work includes relevant source systems, event types, log integrity and preservation, SIEM configuration, baselines, anomalies, metrics, trends and communication. A high CVSS score does not automatically establish the organization’s top priority: exposure, asset criticality, exploitability and business impact matter. A good analyst validates a signal, correlates available evidence, records the conclusion and escalates according to severity.

4. Incident Response and Recovery : 14%

The incident domain follows preparation; detection and analysis; escalation and communication; containment; eradication; recovery; and post-incident improvement. It includes forensic evidence handling, legal and ethical principles, chain of custody, first response, reporting, business continuity and disaster recovery. Know the purpose of RTO, RPO and maximum tolerable downtime, along with backups, alternate processing and recovery testing.

Order matters. Preserve volatile or legally relevant evidence according to procedure before taking actions that could destroy it. Containment limits damage, eradication removes the cause, and recovery restores operations safely. A backup is useful only if it is protected and tested. During a ransomware event, restoring a compromised host before verifying the environment can reintroduce the threat.

5. Cryptography : 9%

Cryptography is the smallest weighted domain, but it covers several distinct purposes. Understand confidentiality through encryption, integrity through hashing or message authentication, authenticity through certificates and signatures, and key management from generation and storage to rotation, revocation and destruction. The outline includes symmetric and asymmetric encryption, elliptic-curve methods, salt, HMAC, digital signatures, secure protocols, PKI and cryptographic attacks.

Choose a mechanism for its purpose. A hash can help detect change but does not conceal a file. Encryption protects confidentiality but does not prove who created a message by itself. A digital signature supports integrity and signer authenticity when certificate trust is valid. If a private key is compromised, rotating passwords alone does not fix certificate trust or signed-data exposure.

6. Network and Communications Security : 16%

The network domain covers networking models and topology, client-server and peer relationships, wired and wireless media, software-defined networking, ports and protocols, attacks, network access control, remote access, segmentation and network appliances. Know the role of firewalls, proxies, IDS/IPS, NAC, DLP, UTM, routers, switches, WAFs, wireless authentication and encryption, IoT isolation and firmware management.

Security design layers controls. Segmentation limits reach; it does not make a vulnerable system safe. A firewall rule should be narrow, justified, monitored and removed when no longer needed. Wireless security includes strong authentication, current encryption and separation of guest devices. Remote access should authenticate users and devices and restrict the paths they can reach. IoT devices require inventory, constrained connectivity and an end-of-life plan.

7. Systems and Application Security : 15%

This domain includes malicious code and activity, malware countermeasures, social engineering, behavior analytics, endpoint controls, mobile-device administration and cloud security. The outline names host-based detection and prevention, host firewalls, application allowlisting, endpoint encryption, TPM, secure browsing, EDR, MDM, containerization and cloud-security concepts. Current outline tasks also address administration of systems that host AI applications; focus on system controls and operational responsibilities that the outline actually names.

For application security, understand secure configurations, patching, vulnerability handling and software-security practices. An endpoint alert may require isolation, evidence preservation, malware analysis and a recovery plan. A mobile device lost outside the organization raises identity, encryption, remote-wipe and data-handling questions. Cloud security does not remove the customer’s responsibility for identity, data and configuration; identify the service boundary before assigning ownership.

Cross-domain scenario: compromised workstation

A user reports a spreadsheet with payroll data was sent to an external address. The workstation shows an unfamiliar browser extension and unusual authentication events. A practitioner should preserve the relevant email, endpoint and identity logs, report through the incident process, assess exposure and scope, and contain the account or endpoint as directed by the playbook. The response spans access controls, monitoring, incident handling, systems/application security and possibly legal or privacy review.

The best next action depends on the question’s timing. If asked to preserve evidence, do not wipe the device first. If the stem confirms active data exfiltration, containment may be the immediate priority while evidence is preserved. A blanket password reset without session revocation or token review can leave an attacker’s access active.

Cross-domain scenario: weak control evidence

A quarterly privileged-access review is recorded as “complete,” but the reviewer did not inspect membership and no exceptions were tracked. This is a control operation and assurance problem, not merely a documentation typo. The practitioner should establish what was reviewed, identify current unauthorized privilege, remediate through the approved process, preserve the evidence, and improve the review procedure. That connects access controls with security concepts, operations, risk and monitoring.

How to study the outline

For each objective, create a small operational case. Ask what is at risk, what the control is meant to do, who may act, which records prove the action, and what exception should be escalated. Practice distinguishing closely related choices: authentication versus authorization, containment versus eradication, encryption versus hashing, vulnerability severity versus business risk.

Use the weights to allocate extra retrieval practice to the 16% areas, but cover every domain. The 9% cryptography domain is not a safe omission: it contains foundational distinctions that recur in network, data and identity scenarios. Build a one-page comparison table from concepts you can explain, not from copied glossary definitions.

Original practice question

A small company detects that a contractor’s account remains active two weeks after the contract ended. The account has not logged in since. Which action is the best immediate response?

Disable the account through the approved deprovisioning process, confirm any active sessions or credentials are revoked as required, preserve the access request and action record, and investigate the handoff failure. The unused account is still an unnecessary path into the environment.

Why not wait for a login? Least privilege and access lifecycle controls require removing access when the business need ends. Why not delete all audit records? Evidence supports accountability and process improvement. Why not disable every contractor account? The facts establish one terminated contract, not a wider authorization.

Use the domain weights correctly

Weights are useful for planning, not prediction. At 16% each, Security Concepts and Practices, Network and Communications Security, and Systems and Application Security deserve consistent review. Access Controls and Risk Identification, Monitoring and Analysis are each 15%, Incident Response and Recovery is 14%, and Cryptography is 9%. ISC2’s adaptive blueprint still covers all domains; no candidate receives a promise of exactly 16 items in a 100-item exam.

Common questions

How many SSCP domains are there?

Seven domains, under the outline effective October 1, 2025.

Which SSCP domain has the largest weight?

Security Concepts and Practices, Network and Communications Security, and Systems and Application Security each have a 16% average weight.

What is the smallest SSCP domain?

Cryptography is weighted at 9%, but remains examinable and supports other domains.

Are SSCP domain weights exact question counts?

No. They are average blueprint weights, not a guaranteed number of items on an individual CAT exam.