SSCP Certification Cheat Sheet 2026
The 30 highest-yield SSCP Certification facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
125 questions
120 min time limit
70.00% to pass
- In a Delphi risk assessment technique, a group of experts anonymously provide risk estimates in multiple rounds. What is the primary advantage of this approach? → It reduces groupthink and anchoring bias by anonymizing expert opinions
- Which type of analysis involves examining memory dumps, disk images, and network captures after an incident to reconstruct what occurred? → Forensic analysis
- A database administrator can modify any record but a separate auditor must approve deletions. This enforces which principle? → Separation of duties
- Which type of malware hides its presence by modifying the operating system kernel to intercept and falsify system calls? → Rootkit
- What is 'resilience' in the context of business continuity planning? → The organizational capacity to absorb disruptions and rapidly return to normal operations
- Which NIST SP 800-61 incident response lifecycle phase involves activities such as installing patches and improving defenses to prevent recurrence? → Eradication and Recovery
- Which endpoint security technology monitors and controls program execution based on a list of approved applications? → Application whitelisting
- Which of the following is an illustration of hardening physical infrastructure? → Fire suppression system
- Which TLS feature allows a server to include the CA's OCSP response in the TLS handshake, reducing client lookup latency? → OCSP stapling
- What is the purpose of an identity governance and administration (IGA) solution? → Automate identity lifecycle, access requests, and compliance reporting
- Which risk analysis method uses attack trees, scenarios, and threat modeling to systematically identify risk without assigning specific monetary values? → Qualitative risk analysis
- Which network security device inspects traffic at Layer 7 and can block specific application-level threats such as SQL injection in web requests? → Web Application Firewall (WAF)
- An attacker gains admin-level access by exploiting a vulnerability in a low-privilege process. This attack technique is called: → Vertical privilege escalation
- Which fire class involves energized electrical equipment, and which extinguishing agent should be used? → Class C — CO2 or dry chemical
- Recently, Jane discovered a security problem happening on her network. What should she do right now that should be her top priority? → Containment
- An access control system that evaluates policies using attributes of the user, resource, environment, and action is best described as: → ABAC
- What does the term 'object' refer to in the context of access control? → A passive resource such as a file, database, or device being accessed
- Which concept describes the practice of granting users only the permissions necessary to perform their job functions? → Least privilege
- Which mobile security control prevents an application from communicating with a fraudulent server even if the device trusts a rogue CA certificate? → Certificate pinning embedded in the application
- Which of the following best describes 'indicator of compromise' (IoC)? → Forensic artifacts that suggest a system has been breached
- Which incident response phase involves identifying the scope and impact of a security event after it has been detected? → Analysis / Identification
- What is the purpose of a VLAN in network security? → To logically segment a network without requiring additional physical hardware
- Which type of fire suppression system is most appropriate for a data center to minimize equipment damage? → Clean agent (e.g., FM-200) system
- A security team wants to detect malware that uses domain generation algorithms (DGA) for command-and-control. Which tool is MOST useful? → DNS query log analysis with anomaly detection
- What vulnerability does the Electronic Codebook (ECB) mode of operation have? → Identical plaintext blocks produce identical ciphertext blocks, leaking patterns
- What distinguishes a stream cipher from a block cipher? → Stream ciphers encrypt one bit or byte at a time; block ciphers encrypt fixed-size chunks
- Which access control model assigns permissions based on the sensitivity label of an object and the clearance level of a subject? → Mandatory Access Control (MAC)
- In a Clark-Wilson integrity model, what are 'Transformation Procedures' (TPs)? → Well-formed transactions that are the only permitted operations on constrained data
- A security engineer implements time-based one-time passwords (TOTP) for VPN access. Which attack does this MOST effectively mitigate? → Credential replay attacks using stolen static passwords
- What is a 'logic bomb' in the context of malicious code? → Code that executes a malicious payload when a specific condition is met
Turn these facts into recall:
Was this helpful?