ISC2 SSCP Training Course

Training course

This is a free, self-paced reading course for the ISC2 Systems Security Certified Practitioner (SSCP), the credential for the administrators, SOC analysts, and network engineers who implement, monitor, and administer security controls hands-on. The distinction from the CISSP runs through every question on this exam: the CISSP asks how you would design a security program, and the SSCP asks what you would do first, right now, on a live network. This course is written at that altitude, so the material stays on operational decisions rather than governance abstractions.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. Two things about that structure are worth knowing before you start. First, the weight is spread unusually evenly, six of the seven domains sit between 14% and 16%, and only Cryptography drops into single digits, so there is no domain you can safely skip. Second, the outline reflects the October 1, 2025 update, in which ISC2 embedded AI security throughout all seven domains rather than isolating it in one, so material on securing AI service accounts, reading model drift as an indicator of compromise, and protecting training data appears in the modules where it operationally belongs.

SSCP Practitioner level 7 modules Domain-weighted Self-paced Free account

What the course covers

Security Concepts and Practices

Module 1 · 16%

The foundation: the ISC2 Code of Ethics, the CIA triad, control categories and functions, least privilege and separation of duties, the asset and change management lifecycles, awareness training, and coordination with physical security. This domain was retitled from “Security Operations and Administration” in the 2024 refresh, same territory, sharper framing.

Access Controls

Module 2 · 15%

Authentication factors and MFA, single sign-on and federation with SAML, OAuth2, and OpenID Connect, trust architectures including zero trust, the identity lifecycle from proofing through de-provisioning, and the access control models (MAC, DAC, RBAC, rule-based, and ABAC) with the judgment to know which one fits a given scenario.

Risk Identification, Monitoring and Analysis

Module 3 · 15%

The risk process end to end: registers and treatment options, appetite versus tolerance, CVSS read in context rather than in isolation, threat intelligence and MITRE ATT&CK, the vulnerability management lifecycle, and operating the monitoring stack, log integrity, SIEM tuning, baselines, and knowing when to escalate what you find.

Incident Response and Recovery

Module 4 · 14%

The incident response lifecycle and, critically, its order, containment before eradication before recovery. Forensic fundamentals: order of volatility, chain of custody, write blockers, and hashing. Plus the continuity side: the business impact analysis, RTO, RPO, and MTD, backup strategies, recovery site tiers, and plan testing from tabletop through full interruption.

Cryptography

Module 5 · 9%

The lightest domain, but dense: symmetric versus asymmetric selection, hashing and salting, digital signatures versus HMAC, why TLS is a hybrid design, PKI and the key management lifecycle, including revocation as the first move after a compromise, and which algorithm families quantum computing actually threatens.

Network and Communications Security

Module 6 · 16%

The other heavyweight: OSI and TCP/IP reasoning, ports and protocols, firewall rule processing, IDS versus IPS placement, segmentation and micro-segmentation, 802.1X with RADIUS and EAP-TLS, countermeasures for ARP spoofing, DNS poisoning, and DDoS, wireless security through WPA3-Enterprise, plus SD-WAN, CASB, and IoT isolation.

Systems and Application Security

Module 7 · 15%

Malicious code and activity (fileless malware, insider threats, APT behavior) and the endpoint stack that counters them: EDR, application allowlisting, and full-disk encryption with TPM. Rounds out with mobile strategies (MDM versus containerization), the cloud shared responsibility model, and virtualization and container security.

How to use it

Read a module, then test that domain immediately with the SSCP practice exam rather than saving the questions for the end. The flat domain weighting is the reason: on an exam where six of seven domains carry roughly equal weight, an average score hides nothing useful, and the only meaningful measure is whether every domain individually holds up. Pay particular attention to ordering questions (containment before eradication, revocation before reissue, order of volatility in evidence collection) because the SSCP tests sequence far more often than definitions, and the adaptive format gives you no chance to revisit an answer once you have moved on. The course modules themselves require a free Certifym account to open.

For exam logistics, the two-hour window, the 100 to 125 adaptive items, the 700-out-of-1000 scaled cut score, the one-year experience requirement and the Associate of ISC2 route around it, see the SSCP certification guide.

← Back

What the SSCP Is and Who It Is For

4 min read · Free preview

The Systems Security Certified Practitioner (SSCP) is ISC2's credential for the hands-on operator: the person who actually implements, monitors, and administers the controls that a CISSP might design and a CISO might approve. If CISSP is the architect and CGRC is the compliance officer, SSCP is the security administrator sitting at the console, tuning a SIEM rule at 2 a.m. or approving a firewall change ticket at 10 a.m.

What the credential validates

Passing the SSCP tells an employer three things: you understand security concepts well enough to explain why a control exists, you can implement and monitor common technical controls competently, and you can operate within a governance framework instead of freelancing. It is deliberately narrower than CISSP: less architecture, less strategy, more operational depth.

The seven domains

The current Exam Outline (effective October 1, 2025) covers seven domains: Security Concepts and Practices (16 percent), Access Controls (15 percent), Risk Identification/Monitoring/Analysis (15 percent), Incident Response and Recovery (14 percent), Cryptography (9 percent), Network and Communications Security (16 percent), and Systems and Application Security (15 percent). Two domains are tied at 16 percent, so no single area dominates the study plan; instead, weakness in any one domain will bleed into your overall score.

Exam mechanics

As of October 1, 2025, the SSCP is delivered by Computerized Adaptive Testing (CAT) through Pearson VUE. Item count is variable between 100 and 125; total time is 120 minutes; passing score is 700 out of 1000 on ISC2's scaled scoring, not a raw 70 percent. The exam adapts to your demonstrated proficiency, so you cannot skip items and you cannot mark them for review after moving on. Cost is USD 249 in most regions.

The experience requirement

ISC2 requires one year of cumulative full-time paid experience in one or more of the seven SSCP domains before you are granted the SSCP designation. A relevant bachelor's or master's degree can waive that year. If you pass the exam without the required experience, you become an Associate of ISC2 for up to two years while you accrue it.

Where SSCP fits in a career

Typical SSCP-holders sit in roles such as security analyst, network security administrator, systems administrator with security duties, incident responder, or SOC engineer. The credential is officially recognized under U.S. DoD Manual 8140.03 as one of the qualifying certifications for operational cybersecurity positions. Many practitioners use it as a stepping stone toward CISSP once they have five years of experience.

What this course does

This training walks the full CBK domain by domain, at practitioner depth. Each module opens with the concepts you need to reason about a scenario, then moves into the concrete controls, tools, and decisions you will actually be tested on and expected to make on the job. This first lesson is free; the rest of the course is available to Certifym subscribers.

Frequently asked questions about the SSCP training course

Is the SSCP training course free?

Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.

How is the course structured?

One module per official SSCP domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Because SSCP weights are nearly flat, the modules run to similar lengths, only Cryptography, at 9%, is meaningfully shorter than the rest.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative exam outline and sells its own official training and CBK reference material. This course is an independent study companion meant to be read in order alongside practice questions, not a substitute for the official outline, which you should download from isc2.org and check your preparation against.

Do I need experience before starting the course?

Not to read it. The credential itself requires one year of experience in the SSCP domains, but candidates without that year can still sit and pass the exam and hold the Associate of ISC2 designation while they earn it. If you are new to security entirely, the CC course is the step below this one on the same path.

What should I do after finishing the course?

Move to the SSCP practice exam and work in full-length sittings rather than short bursts, until you are clearing 70% in each domain separately. Then book with Pearson VUE.

Is the course current with the October 2025 SSCP update?

The modules are built against the current seven-domain outline, which reflects the October 1, 2025 changes: the move to Computerized Adaptive Testing and the embedding of AI security throughout all seven domains rather than in a single new one. Domain 1’s retitling from “Security Operations and Administration” to “Security Concepts and Practices” in the 2024 refresh is also carried through. ISC2 can revise the outline at any time; download the current version from isc2.org before you sit.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, SSCP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these study materials are intended. The SSCP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and endorsement policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.