
Cisco Certified Network Professional Security
The Cisco Certified Network Professional (CCNP) Security certification validates your ability to design, implement, and operate core security technologies, including network security, cloud security, content security, endpoint protection, and secure network access. It is designed for security engineers and architects who protect enterprise networks and data. Earning this credential demonstrates advanced skills that are essential for securing modern, complex IT environments.
1289 practice questions · Updated 2026-07-30
350-701 Curriculum
Every domain, objective, and concept the 350-701 exam measures.
- On-premises attack vectors
- Hybrid environment attack surfaces
- Cloud-specific threats
- Viruses and trojans
- DoS and DDoS attacks
- Phishing attacks
- Rootkits
- Man-in-the-middle attacks
- Malware categories
- Data breaches
- Insecure APIs
- Compromised credentials
- Post-quantum cryptography (PQC) threats
- AI-related attack threats
- Software Bugs
- Weak and Hardcoded Passwords
- OWASP Top Ten
- Missing Encryption Ciphers
- Buffer Overflow
- Path Traversal
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection
- CVEs and CVSS Scores
- Prompt Injection
- System Prompt Leakage
- Vector and Embedding Weaknesses
- Supply Chain Vulnerabilities in AI/LLM
- Phishing attack vectors
- Phishing attack types
- Social engineering techniques
- Technical controls against phishing
- User awareness and training
- Authentication and verification controls
- Incident response and reporting
- Virtual Tunnel Interfaces (VTI)
- Standards-based IPsec
- SSL VPN
- DMVPN
- FlexVPN
- GETVPN
- Security Intelligence Authoring
- Security Intelligence Sharing
- Security Intelligence Consumption
- Threat Intelligence Feeds
- Indicators of Compromise (IOCs)
- STIX/TAXII
- Intelligence Lifecycle
- Integration with Security Tools
- Zero Trust Architecture Definition
- Zero Trust Pillars
- Zero Trust Components
- Zero Trust Deployment Models
- Zero Trust vs Traditional Security
- Zero Trust Implementation Challenges
- Defense in Depth Principles
- SAFE Architecture Overview
- SAFE Pillars and Places in the Network
- SAFE Design and Implementation
- Mapping Security Controls to SAFE
- API Authentication Methods
- HTTP Methods and Endpoints
- Request and Response Handling
- Error Handling and Status Codes
- Script Structure and Best Practices
- Use Case: Retrieving Security Data
- Use Case: Configuring Security Devices
- Intrusion Prevention Systems (IPS)
- Firewall Technologies
- Deployment Models
- Network Security Solutions Integration
- High Availability and Scalability
- Security Monitoring Fundamentals
- Telemetry Data Sources
- NetFlow and IPFIX
- Syslog and Log Management
- SNMP for Monitoring
- Packet Capture and Analysis
- Threat Intelligence Feeds
- Security Information and Event Management (SIEM)
- Network Traffic Analysis (NTA)
- Endpoint Detection and Response (EDR)
- Orchestration and Automation in Monitoring
- Monitoring Architecture and Deployment
- VLAN Segmentation
- SGT Segmentation
- Layer 2 Security Fundamentals
- Port Security
- DHCP Snooping
- Dynamic ARP Inspection (DAI)
- Storm Control
- MAC Attack Defense
- ARP Attack Defense
- VLAN Hopping Defense
- STP Attack Defense
- Rogue DHCP Defense
- Single vs. multidevice manager
- In-band vs. out-of-band management
- On-premises vs. cloud management
- Cisco Security Cloud Control
- Selecting management options
- CIS Benchmarks Overview
- CIS Benchmark Structure
- CIS Benchmarks for Cisco Secure Firewall (FTD)
- CIS Benchmarks for Cisco IOS XE
- Applying CIS Benchmarks
- Verifying Compliance
- AAA architecture overview
- TACACS+ protocol fundamentals
- RADIUS protocol fundamentals
- TACACS+ vs RADIUS comparison
- AAA configuration for device access
- AAA configuration for network access
- Troubleshooting AAA authentication
- Troubleshooting AAA authorization
- Troubleshooting AAA accounting
- AAA debugging and logging
- AAA server integration and testing
- SNMPv3 configuration
- NetConf and RestConf
- Device APIs
- Secure syslog
- NTP with authentication
- Access Control Policies
- Application Visibility and Control (AVC)
- URL Filtering
- Malware Protection
- Intrusion Prevention System (IPS)
- Integration of Security Features
- Site-to-site VPN fundamentals on FTD
- Configuring site-to-site VPN on FTD
- Remote access VPN fundamentals on FTD
- Configuring remote access VPN on FTD
- Cisco Secure Client deployment and configuration
- VPN troubleshooting on FTD
- VPN tunnel establishment phases
- Common VPN misconfigurations
- Troubleshooting commands and logs
- IKE and IPsec SA negotiation issues
- NAT and routing impact on VPN
- Certificate and authentication problems
- Firewall policy and interface issues
- Cloud Security Capabilities
- Cloud Deployment Models
- Cloud Service Models
- Cloud Security Frameworks
- Cloud Policy Management
- Cloud Deployment Models
- NIST 800-145 Cloud Service Models
- Cloud Security Shared Responsibility Model
- Cloud Access Security Broker (CASB)
- Selecting Security Solutions for Cloud
- Cloud Security Fundamentals
- Network Security in Cloud
- Application Security in Cloud
- Data Security in Cloud
- Cisco Multicloud Defense Overview
- Cisco Multicloud Defense Capabilities
- Cisco Secure Workload Overview
- Cisco Secure Workload Capabilities
- Integration of Solutions
- Splunk data ingestion fundamentals
- Cloud logging and monitoring data sources
- Integration with other security solutions
- Data parsing and field extraction
- Troubleshooting ingestion issues
- Application security concepts
- Workload security concepts
- eBPF overview
- eBPF use cases in security
- Infrastructure as Code (IaC) Security
- CI/CD Pipeline Security
- Container Orchestration Security
- Secure Software Development Lifecycle (SSDLC)
- SSE Definition
- SASE Definition
- SSE vs SASE
- SSE Use Cases
- SASE Use Cases
- Cisco Secure Access Overview
- Secure Internet Access Architecture
- Configuration of Secure Internet Access
- Integration with Identity Providers
- Policy Enforcement for Internet Traffic
- Monitoring and Troubleshooting
- Cisco Secure Access Overview
- Secure Private Access Components
- Configure Secure Private Access Policies
- Integrate with Identity Providers
- Deploy and Manage Connectors
- Monitor and Troubleshoot Secure Private Access
- Data Loss Prevention (DLP) fundamentals
- DLP policy configuration
- DLP integration with secure internet access
- AI guardrails overview
- AI guardrail configuration
- Monitoring and reporting for DLP and AI guardrails
- Investigate scores
- Indicators of compromise
- Score thresholds and risk levels
- Investigate data sources
- Correlating scores with security events
- EPP vs EDR
- EPP Core Capabilities
- EDR Core Capabilities
- EPP and EDR Integration
- MDM Overview
- MDM Features and Capabilities
- Asset Inventory Systems
- Integration of MDM and Asset Inventory
- Endpoint Posture Assessment Overview
- Posture Assessment Components
- Posture Assessment Process
- Posture Assessment Technologies
- Integration with Security Infrastructure
- Remediation and Enforcement
- Cisco Secure Client Overview
- Cisco Secure Client Features
- Cisco Secure Malware Analytics Overview
- Malware Analysis Process
- Integration with Endpoint Protection
- Cisco Secure Endpoint architecture
- Connector installation and configuration
- Policy creation and management
- Malware detection engines
- File trajectory and retrospective analysis
- Advanced malware protection (AMP) cloud integration
- Endpoint isolation and remediation
- Reporting and auditing
- Malware Event Categories
- Event Severity Levels
- Event Details and Artifacts
- Detection Technologies
- Event Lifecycle and Disposition
- Threat Intelligence Integration
- Event Correlation and Triage
- Remediation Actions
- Email Security Threat Defense Overview
- Mail Flow Policies
- Message Filters
- Content Filters
- Outbreak Filters
- Anti-Spam and Anti-Virus Settings
- Email Encryption
- Data Loss Prevention (DLP)
- Reporting and Tracking
- Identity Management Fundamentals
- Guest Services
- Profiling
- Posture Assessment
- BYOD (Bring Your Own Device)
- Device Compliance
- Application Control
- Cisco Compliance and Application Control Technologies
- 802.1X Authentication Flow
- MAB (MAC Authentication Bypass)
- ISE as Authentication Server
- AAA and RADIUS Integration
- ISE Policy Sets and Authorization
- Profiling and Identity Groups
- Troubleshooting 802.1X and MAB
- CoA fundamentals
- CoA message types
- CoA with RADIUS
- CoA use cases
- CoA configuration on Cisco ISE
- CoA configuration on network devices
- CoA troubleshooting
- DNS tunneling
- HTTPS exfiltration
- Email exfiltration
- FTP/SSH/SCP/SFTP exfiltration
- ICMP exfiltration
- Messenger exfiltration
- IRC exfiltration
- NTP exfiltration
- Cloud storage exfiltration
- Telemetry Fundamentals
- Native AI/ML Capabilities
- XDR Overview
- SIEM and SOAR Platforms
- Splunk Integration
- Cisco XDR Integration
- Enforcement Mechanisms
- Cisco Duo Overview in Zero Trust
- Trust Monitor
- Multi-Factor Authentication (MFA)
- Device Trust
- Health Checks
- Adaptive Access Policies
- Single Sign-On (SSO)
- Critical Infrastructure Integration (CII)
- Splunk architecture and components
- Data ingestion and parsing
- Search and investigation
- Dashboards and visualizations
- Alerts and correlation
- Automation and orchestration
- Management and administration
- Security information and event management (SIEM) use cases
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 350-701, so none is invented.