Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

ISC2 · Free, ad-free audio course

ISC2 SSCP

A structured, audio-first learning route for ISC2 SSCP, designed for focused review and practical understanding.

Every Bare Metal Cyber audio course is free and 100% ad-free.

PUT IT INTO PRACTICE

Practice SSCP concepts

Try 50 original BMC questions, review every explanation, and return to the lessons behind the answer. No login is required. Earn Challenge achievements and share your progress as you go.

50 original questionsExplanation after every answerAchievements and sharing

Independent BMC learning practice—not official exam items, a full mock exam, or an exam-readiness score.

Certification practice in the BMC Cyber Challenge

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

70 lessons available

S01E01Transcript

Getting Started

Decode the SSCP Exam Landscape and Requirements

Success on the SSCP begins with seeing the whole playing field clearly. This episode explains how the exam blueprint maps to core domains, how items are weighted, and what “job-task” orientation means for the kinds of questions you will face.…

Transcript availableNovember 11, 2025
S01E02Transcript

Getting Started

Build a Practical, Realistic SSCP Study Path

A study plan is only effective if it fits real life and the exam’s domain weights. We begin by translating the blueprint into a calendar, balancing heavier domains with spaced repetition and short daily reviews for lighter areas.…

Transcript availableNovember 11, 2025
S01E03Transcript

Getting Started

Understand Exam Rules, Policies, and Test Logistics

Clarity on rules and logistics protects your focus on test day. This episode explains registration steps, identification requirements, reschedule policies, accommodation requests, and the professional ethics you agree to when you sit for the exam.…

Transcript availableNovember 11, 2025
S01E04Transcript

Domain 1 · Security Operations and Administration

Live the Code of Ethics in Daily Decisions

The SSCP Code of Ethics is more than a pledge—it is a decision framework that shows up in questions and real work. We unpack the canon, its priorities, and how it interacts with organizational policy, law, and contractual duties.…

Transcript availableNovember 11, 2025
S01E05Transcript

Domain 1 · Security Operations and Administration

Master Confidentiality, Integrity, Availability and Accountability

CIA plus accountability forms the backbone of control selection and exam reasoning. We define confidentiality safeguards that restrict unauthorized disclosure, integrity measures that prevent unauthorized alteration, and availability protections that keep services dependable.…

Transcript availableNovember 11, 2025
S01E06Transcript

Domain 1 · Security Operations and Administration

Implement Technical Security Controls That Actually Work

Technical controls only deliver value when they are mapped to clear objectives and verified in operation. This episode frames control selection around threats, assets, and required assurance levels, then ties each control to the pillar it primarily supports.…

Transcript availableNovember 11, 2025
S01E09Transcript

Domain 1 · Security Operations and Administration

Document Functional Control Types With Real Examples

Understanding control types helps you choose the most effective safeguard and justify it clearly. We distinguish preventive, detective, and corrective controls; physical, technical, and administrative forms; and compensating controls used when preferred options are not feasible.…

Transcript availableNovember 11, 2025
S01E10Transcript

Domain 1 · Security Operations and Administration

Manage the Full Asset Inventory and Lifecycle

Accurate asset inventories make every other control possible. We define assets broadly—hardware, software, data, services, identities—and explain lifecycle stages from procurement and onboarding to maintenance, reassignment, and secure disposal.…

Transcript availableNovember 11, 2025
S01E12Transcript

Domain 1 · Security Operations and Administration

Run Change and Configuration Management Without Chaos

Change and configuration management prevent outages and security regressions, and the exam expects you to know their purpose and artifacts.…

Transcript availableNovember 11, 2025
S01E13Transcript

Domain 1 · Security Operations and Administration

Drive Engaging Security Awareness Programs People Remember

Awareness programs succeed when they change behavior, not just deliver slides. This episode explains how to align messages with real threats, job roles, and measurable outcomes.…

Transcript availableNovember 11, 2025
S01E15Transcript

Domain 1 · Security Operations and Administration

Recap Core Security Concepts for Rapid Retention

Midway through preparation, a structured recap boosts confidence and reveals gaps. This episode consolidates foundational ideas—risk, threats, vulnerabilities, controls, and assurance—into a compact mental model you can apply under time pressure.…

Transcript availableNovember 11, 2025
S01E17Transcript

Domain 2 · Access Controls

Leverage Single Sign-On and Federation for Usability

Single Sign-On (SSO) and federation reduce password sprawl while improving control, and exam items often test whether you can match the right protocol and trust model to a scenario.…

Transcript availableNovember 11, 2025
S01E19Transcript

Domain 2 · Access Controls

Secure Third-Party Connectivity and External Integrations

Third-party links expand capability and risk, and the exam expects you to reason across legal, technical, and operational safeguards. We start by framing integration types—site-to-site VPNs, partner portals, API exchanges, managed service access—and the minimum controls each requires.…

Transcript availableNovember 11, 2025
S01E20Transcript

Domain 2 · Access Controls

Orchestrate Identity Lifecycle From Proofing to Deprovisioning

Identity lifecycle management turns policy into predictable access outcomes, and exam scenarios frequently hinge on whether accounts follow a controlled birth-to-death path.…

Transcript availableNovember 11, 2025
S01E21Transcript

Domain 2 · Access Controls

Apply Access Control Models to Real-World Scenarios

Access control models translate policy into predictable, auditable decisions, and the SSCP exam often tests whether you can pick the simplest model that truly fits the scenario.…

Transcript availableNovember 11, 2025
S01E22Transcript

Domain 2 · Access Controls

Refresh Access Control Essentials and Common Pitfalls

Strong access control depends on clean identities, clear roles, and consistent enforcement, and the exam probes whether you can spot weak links.…

Transcript availableNovember 11, 2025
S01E23Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Frame Organizational Risk Using Recognized Standards

Exams reward candidates who can structure risk discussions with shared language, and organizations depend on that structure to make decisions.…

Transcript availableNovember 11, 2025
S01E24Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Set Risk Appetite and Choose Effective Treatments

Risk appetite expresses how much uncertainty an organization is willing to accept to achieve its goals, and the exam requires you to know how that statement guides control choices.…

Transcript availableNovember 11, 2025
S01E25Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Report Risks Persuasively to Business Stakeholders

Risk reporting succeeds when it enables decisions, not when it merely lists problems, and the SSCP exam looks for candidates who can bridge security language with business outcomes.…

Transcript availableNovember 11, 2025
S01E26Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Navigate Legal, Regulatory, and Privacy Responsibilities

Legal and privacy obligations define the guardrails within which security operates, and the SSCP exam expects familiarity with how they influence control decisions. This episode outlines key concepts: due care, due diligence, compliance, liability, and accountability.…

Transcript availableNovember 11, 2025
S01E27Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Plan Security Testing Strategies That Truly Add Value

Security testing provides assurance that controls perform as intended, and the SSCP exam focuses on differentiating types and objectives of testing.…

Transcript availableNovember 11, 2025
S01E28Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Run a Full Vulnerability Management Lifecycle End-to-End

Vulnerability management is a continuous process, and the exam expects understanding beyond simple scanning. This episode walks through each stage—discovery, assessment, prioritization, remediation, verification, and reporting—and connects them to policy and risk frameworks.…

Transcript availableNovember 11, 2025
S01E29Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Operate SIEM Platforms and Manage Log Pipelines

Security Information and Event Management (SIEM) systems convert data into situational awareness, and exam questions often test whether you can choose the right collection, correlation, and response approach.…

Transcript availableNovember 11, 2025
S01E30Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Analyze Events, Triage Alerts, and Escalate Confidently

Efficient analysis turns signal into action, and exam scenarios often test whether you can prioritize correctly under pressure.…

Transcript availableNovember 11, 2025
S01E31Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Review Risk Posture and Continuous Monitoring Insights

Continuous monitoring transforms static compliance into living assurance, and the SSCP exam emphasizes how to interpret its results. This episode defines key elements—data feeds, metrics, thresholds, and escalation paths—that make ongoing oversight credible.…

Transcript availableNovember 11, 2025
S01E32Transcript

Domain 3 · Risk Identification, Monitoring and Analysis

Exam Acronyms: Quick Audio Reference for Fast Recall

Acronyms dominate cybersecurity language, and this episode helps you translate shorthand into meaning you can recall instantly under test conditions.…

Transcript availableNovember 11, 2025
S01E33Transcript

Domain 4 · Incident Response and Recovery

Prepare Incident Response Programs That Actually Work

An effective incident response (IR) program defines who acts, how quickly, and with what authority, ensuring chaos becomes coordination. This episode covers IR policy, plan, playbooks, and communication structures that exam scenarios often reference.…

Transcript availableNovember 11, 2025
S01E34Transcript

Domain 4 · Incident Response and Recovery

Detect Incidents, Analyze Indicators, and Escalate Early

Early detection prevents minor issues from becoming major breaches. This episode explains how indicators of compromise (IOCs) and anomaly patterns are recognized, validated, and escalated within monitoring ecosystems.…

Transcript availableNovember 11, 2025
S01E36Transcript

Domain 4 · Incident Response and Recovery

Preserve Digital Evidence and Maintain Chain of Custody

Proper evidence handling determines whether findings hold up under legal or disciplinary review, and the SSCP exam regularly checks understanding of this process.…

Transcript availableNovember 11, 2025
S01E37Transcript

Domain 4 · Incident Response and Recovery

Report Findings Lawfully, Ethically, and Effectively

Incident reporting closes the accountability loop and ensures that lessons lead to improvement, not blame. This episode explains how to prepare reports that meet legal, ethical, and operational expectations.…

Transcript availableNovember 11, 2025
S01E38Transcript

Domain 4 · Incident Response and Recovery

Build and Validate Business Continuity and Disaster Recovery

Business Continuity (BC) and Disaster Recovery (DR) ensure that essential services survive disruption, a major exam theme. We define BC as maintaining operations during adverse events and DR as restoring systems afterward.…

Transcript availableNovember 11, 2025
S01E39Transcript

Domain 4 · Incident Response and Recovery

Rehearse Response and Recovery With Realistic Drills

Exercises transform theory into readiness, and the SSCP exam expects you to know how testing validates plans. We define exercise types—tabletop, functional, and full-scale—and describe their purpose: measuring coordination, timing, and decision quality.…

Transcript availableNovember 11, 2025
S01E40Transcript

Domain 5 · Cryptography

Justify Cryptography Choices by Data Sensitivity and Risk

Cryptography protects confidentiality, integrity, and authenticity, but the SSCP exam tests whether you can match algorithms and implementations to the right purpose and sensitivity level.…

Transcript availableNovember 11, 2025
S01E42Transcript

Domain 5 · Cryptography

Apply Hashing for Integrity, Authenticity, Nonrepudiation

Hashing provides proof that data has not been altered, making it a cornerstone of exam questions on integrity and authenticity. This episode defines a cryptographic hash as a one-way mathematical function that produces a fixed-length digest unique to input data.…

Transcript availableNovember 11, 2025
S01E43Transcript

Domain 5 · Cryptography

Gauge Algorithm Suitability, Key Strength, and Threats

Selecting an algorithm or key length isn’t guesswork; it’s risk-based decision-making tested heavily on the SSCP exam. This episode explains factors influencing cryptographic strength: algorithm design, key size, implementation, and operational controls.…

Transcript availableNovember 11, 2025
S01E44Transcript

Domain 5 · Cryptography

Deploy TLS, IPsec, and S/MIME the Right Way

Secure communication protocols feature prominently in SSCP domain questions, and this episode clarifies where each applies.…

Transcript availableNovember 11, 2025
S01E45Transcript

Domain 5 · Cryptography

Administer PKI, Certificates, and Practical Trust Models

Public Key Infrastructure (PKI) enables scalable trust, and exam questions often probe its components and lifecycle. We define certification authorities (CAs), registration authorities (RAs), certificate repositories, and revocation mechanisms like CRLs and OCSP.…

Transcript availableNovember 11, 2025
S01E47Transcript

Domain 6 · Network and Communications Security

Map OSI and TCP/IP Models to Security Controls

The OSI and TCP/IP models organize communication, and the SSCP exam tests your ability to connect each layer to its security controls.…

Transcript availableNovember 11, 2025
S01E48Transcript

Domain 6 · Network and Communications Security

Recognize Ports, Protocols, and Software-Defined Networking

Ports and protocols are the vocabulary of connectivity, and SSCP candidates must interpret them quickly. This episode reviews common ports—HTTP 80, HTTPS 443, DNS 53, SMTP 25, SSH 22—and protocol roles in securing or exposing data.…

Transcript availableNovember 11, 2025
S01E49Transcript

Domain 6 · Network and Communications Security

Identify Network Attack Patterns and Adversary Tactics

Recognizing attack patterns lets defenders predict behavior instead of merely reacting, a key skill tested in the SSCP exam.…

Transcript availableNovember 11, 2025
S01E50Transcript

Domain 6 · Network and Communications Security

Counter DDoS, Man-in-the-Middle, and Poisoning Attacks

Network attacks often exploit trust and scale, and the SSCP exam assesses how well you can neutralize them. This episode explains the mechanics of Distributed Denial of Service (DDoS), man-in-the-middle (MITM), and poisoning attacks like ARP, DNS, and cache corruption.…

Transcript availableNovember 11, 2025
S01E53Transcript

Domain 6 · Network and Communications Security

Configure Firewalls, WAFs, and Core Security Services

Firewalls and related technologies enforce boundaries between zones, a fundamental competency for SSCP professionals. This episode explains packet-filtering, stateful, and next-generation firewalls, emphasizing rule evaluation order, implicit denies, and policy documentation.…

Transcript availableNovember 11, 2025
S01E54Transcript

Domain 6 · Network and Communications Security

Optimize DLP, UTM, NAC, and Quality of Service

Modern enterprises combine multiple protective systems, and the SSCP exam expects you to understand how these integrate without conflict.…

Transcript availableNovember 11, 2025
S01E55Transcript

Domain 6 · Network and Communications Security

Secure Wi-Fi and Wireless Access From End to End

Wireless networks extend enterprise reach—and risk—and the SSCP exam stresses understanding their protections. This episode describes core wireless security standards: WPA3 with SAE authentication, enterprise 802.1X integration, and encryption protocols that protect data in transit.…

Transcript availableNovember 11, 2025
S01E56Transcript

Domain 6 · Network and Communications Security

Protect and Monitor Internet of Things Deployments

Internet of Things (IoT) ecosystems expand the attack surface by introducing diverse, often constrained devices that run long-lived firmware and communicate over specialized protocols.…

Transcript availableNovember 11, 2025
S01E58Transcript

Domain 7 · Systems and Application Security

Identify Malicious Code, TTPs, and Host Artifacts

Malware analysis on the SSCP exam focuses on recognizing behaviors and artifacts rather than reverse-engineering internals.…

Transcript availableNovember 11, 2025
S01E59Transcript

Domain 7 · Systems and Application Security

Counter Social Engineering With Behavior-Aware Defenses

Social engineering exploits attention, trust, and time pressure, so defenses must combine technology, process, and human habits.…

Transcript availableNovember 11, 2025
S01E60Transcript

Domain 7 · Systems and Application Security

Harden Hosts Using HIPS, HIDS, and Host Firewalls

Host protections remain a last, critical line of defense, and the SSCP exam expects you to differentiate prevention, detection, and containment on endpoints.…

Transcript availableNovember 11, 2025
S01E63Transcript

Domain 7 · Systems and Application Security

Understand Cloud Deployment and Service Models Clearly

Cloud topics appear across SSCP domains, and clarity on models is essential. We define deployment models—public, private, community, and hybrid—and service models—Infrastructure as a Service, Platform as a Service, and Software as a Service.…

Transcript availableNovember 11, 2025
S01E64Transcript

Domain 7 · Systems and Application Security

Navigate Cloud Legal Duties and Shared Responsibilities

Legal and contractual duties do not vanish in the cloud; they shift and require careful mapping. This episode explains shared responsibility: providers secure the infrastructure they run, while customers configure and govern what they deploy.…

Transcript availableNovember 11, 2025
S01E65Transcript

Domain 7 · Systems and Application Security

Manage Cloud Data Protections, SLAs, and Provider Risk

Protecting data in the cloud means aligning technical safeguards with service-level commitments and third-party risk oversight.…

Transcript availableNovember 11, 2025
S01E66Transcript

Domain 7 · Systems and Application Security

Operate Secure Virtualization Platforms and Services Safely

Virtualization concentrates risk and enables resilience, so the SSCP exam expects you to understand both the power and the pitfalls. This episode clarifies core concepts—hypervisors (type 1 vs.…

Transcript availableNovember 11, 2025
S01E69Transcript

Exam Strategy and Review

Essential Terms: Plain-Language Glossary for the SSCP

Fast recall of precise meanings accelerates problem solving on exam day, so this episode presents a plain-language mini-glossary woven into context rather than alphabet soup.…

Transcript availableNovember 11, 2025
S01E70Transcript

Exam Strategy and Review

Triage the Adaptive Exam With Proven Tactics

The SSCP’s adaptive format rewards steady decision-making and penalizes wasted time, so tactics matter as much as knowledge. We explain how adaptive scoring selects items near your current ability estimate, why early stability helps, and how to pace without clock anxiety.…

Transcript availableNovember 11, 2025

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.