Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CISCO

Cisco Certified Network Professional Security

350-701

The Cisco Certified Network Professional (CCNP) Security certification validates your ability to design, implement, and operate core security technologies, including network security, cloud security, content security, endpoint protection, and secure network access. It is designed for security engineers and architects who protect enterprise networks and data. Earning this credential demonstrates advanced skills that are essential for securing modern, complex IT environments.

Exam formatMultiple choice and multiple response
Duration120 minutes
DeliveryPearson VUE
Free questions1289

Content last reviewed 30 July 2026 · Up to date

The certification

What 350-701 proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

6domains
47objectives
319concepts
US $400exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The CCNP Security certification is a professional-level credential that proves your expertise in implementing and operating core security technologies. It covers a broad range of topics, from securing network infrastructure and cloud environments to protecting content, endpoints, and user access. This certification is ideal for security professionals who want to advance their careers and take on more complex security challenges.

Achieving CCNP Security requires passing the 350-701 SCOR exam, which tests your knowledge of network security, cloud security, content security, endpoint protection and detection, secure network access, visibility, and enforcements. The certification also requires passing one concentration exam, allowing you to specialize in areas such as advanced threat protection, identity and access management, or security automation. Earning this credential signals to employers that you have the skills to design and manage robust security solutions.

Who it’s for

This certification is for security engineers, network security architects, and IT professionals who are responsible for designing, implementing, and operating security solutions in enterprise environments. It is also suitable for those who want to validate their skills in core security technologies and advance to expert-level certifications. Candidates typically have several years of experience in network security and are familiar with Cisco security products and solutions. They are comfortable working with firewalls, VPNs, intrusion prevention systems, and cloud security technologies.

Recommended experience

Cisco recommends that candidates have a good understanding of network security concepts and hands-on experience with Cisco security products before attempting the SCOR exam. Hands-on experience with Cisco firewalls, VPNs, and intrusion prevention systems; Knowledge of network security concepts such as access control, threat defense, and secure access; Familiarity with cloud security and content security technologies; Understanding of endpoint protection and detection mechanisms

The syllabus

What you’ll learn

Every domain and objective Cisco measures, with the weight they carry on the exam.

The official Cisco exam outline · checked 30 July 2026 · See the source

Security Concepts
  • 1.1 Explain attack threats against on-premises, hybrid, and cloud environments such as viruses, trojans, DoS/DDoS, phishing, rootkits, man-in-the middle, malware, data breaches, insecure APIs, compromised credentials, PQC, and AI
  • 1.2 Describe security vulnerabilities and exploits such as software bugs, weak and/or hardcoded passwords, OWASP top ten, missing encryption ciphers, buffer overflow, path traversal, cross-site scripting/forgery, SQL injection, and identification and prioritization using CVEs and CVSS scores
  • 1.3 Describe vulnerabilities in AI/LLM models such as prompt injection, system prompt leakage, vector and embedding weaknesses, and supply chain
  • 1.4 Describe the controls used to protect against phishing and social engineering attacks
  • 1.5 Describe cryptography security components such as hashing, encryption, PKI, SSL, TLS, QUIC, MASQUE, IPsec, NAT-T IPv4 for IPsec, preshared key, certificate-based authorization, and post-quantum cryptography
  • 1.6 Describe site-to-site and remote access VPN deployment types such as virtual tunnel interfaces, standards-based IPsec, SSL VPN, DMVPN, FlexVPN, and GETVPN
  • 1.7 Describe security intelligence authoring, sharing, and consumption
  • 1.8 Describe zero trust architecture
  • 1.9 Describe defense in depth strategy such as Secure Architecture for Everyone (SAFE)
  • 1.10 Interpret scripts used to call security appliances APIs in a language such as Python
10 objectives · 308 free questions · 65 pages
Network Security
  • 2.1 Describe network security solutions and deployment models that provide intrusion prevention and firewall capabilities
  • 2.2 Describe security monitoring and telemetry technologies
  • 2.3 Configure network infrastructure security methods (network segmentation using VLANs or SGTs; Layer 2 and port security; DHCP snooping; Dynamic ARP inspection; storm control; and defenses against MAC, ARP, VLAN hopping, STP, and DHCP rogue attacks)
  • 2.4 Select management options for network security solutions (single vs. multidevice manager, in-band vs. out-of-band, on-premises vs. cloud with Cisco Security Cloud Control)
  • 2.5 Describe CIS benchmarks for hardening devices such as Cisco Secure Firewall (FTD) and Cisco IOS XE
  • 2.6 Troubleshoot AAA for device and network access such as TACACS+ and RADIUS
  • 2.7 Configure secure network management of perimeter security and infrastructure devices such as SNMPv3, NetConf, RestConf, APIs, secure syslog, and NTP with authentication
  • 2.8 Implement access control policies, AVC, URL filtering, malware protection, and intrusion prevention using Cisco Secure Firewall (FTD)
  • 2.9 Configure site-to-site and remote access VPN using Cisco Secure Firewall (FTD) and Cisco Secure Client
  • 2.10 Troubleshoot VPN tunnel establishment on Cisco Secure Firewall (FTD)
10 objectives · 259 free questions · 55 pages
Cloud Security
  • 3.1 Describe security responsibility within common Cloud Shared Responsibility Models
  • 3.2 Select security capabilities, deployment models, cloud security frameworks, and policy management to secure the cloud
  • 3.3 Select security solutions for cloud environments (public; private; hybrid; community cloud; NIST 800-145 SaaS, PaaS, and IaaS; and Cloud Access Security Broker)
  • 3.4 Describe network, application, and data security in cloud environments with solutions such as Cisco Multicloud Defense and Cisco Secure Workload
  • 3.5 Configure Splunk to ingest cloud logging and monitoring data from other security solutions
  • 3.6 Describe application and workload security concepts including eBPF
  • 3.7 Describe DevSecOps (Infrastructure as Code security, CI/CD pipeline, container orchestration, and secure software development)
7 objectives · 189 free questions · 40 pages
Secure Service Edge
  • 4.1 Describe Security Service Edge (SSE) and Secure Access Service Edge (SASE)
  • 4.2 Configure Cisco Secure Access Secure Internet Access
  • 4.3 Configure Cisco Secure Access Secure Private Access
  • 4.4 Configure data loss prevention and AI guardrails for secure internet access
  • 4.5 Interpret Cisco Secure Access Investigate scores and indicators
5 objectives · 133 free questions · 29 pages
Endpoint Protection and Detection
  • 5.1 Describe Endpoint Protection Platforms (EPP) and Endpoint Detection and Response (EDR) solutions
  • 5.2 Describe endpoint device management and asset inventory systems such as MDM
  • 5.3 Describe endpoint posture assessment solutions to ensure endpoint security
  • 5.4 Describe endpoint protection and detection security with solutions such as Cisco Secure Client and Cisco Secure Malware Analytics
  • 5.5 Configure endpoint antimalware protection using Cisco Secure Endpoint
  • 5.6 Interpret Cisco Secure Endpoint malware detection events
  • 5.7 Configure email security features with Cisco Security Email Threat Defense
7 objectives · 188 free questions · 39 pages
Network Access, Visibility, and Enforcement
  • 6.1 Describe identity management and secure network access concepts such as guest services, profiling, posture assessment, and BYOD
  • 6.2 Describe device compliance and application control
  • 6.3 Configure network access control mechanisms such as 802.1X and MAB with Cisco Identity Services Engine
  • 6.4 Configure network access with CoA
  • 6.5 Explain exfiltration techniques such as DNS tunneling, HTTPS, email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP, and cloud storage
  • 6.6 Describe network visibility and enforcement using telemetry and native AI/ML capabilities with XDR and SIEM/SOAR platforms such as Splunk and Cisco XDR
  • 6.7 Describe Cisco Duo in a zero-trust security architecture (Trust Monitor, MFA, Device Trust, health checks, Adaptive Access policies, SSO, and CII)
  • 6.8 Describe managing, orchestrating, and automating security information and events with Splunk
8 objectives · 212 free questions · 45 pages
On the day

The exam itself

Everything Cisco publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

Exam code350-701
CertificationCisco Certified Network Professional Security
Exam formatMultiple choice and multiple response
Duration120 minutes
DeliveryPearson VUE
LanguagesEnglish, Japanese
PricingUS $400
Certification levelProfessional
After you pass

Where this credential goes next

The path Cisco lays out, how the credential is kept, and where to book.

Step-by-step path to Cisco Certified Network Professional Security

Cisco Certified Network Professional Security badgeCredential earnedCisco Certified Network Professional Security Professional level certification
Renewal and maintenance

Cisco certifications are valid for three years. You can recertify by passing a qualifying exam or earning Continuing Education (CE) credits. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. Cisco maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by Cisco

Exam registration

Register for the exam through Pearson VUE, Cisco’s authorized testing partner.

Schedule your exam

Visit the official Cisco certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the 350-701 SCOR exam relate to the retired CCNP Security exams?

The 350-701 SCOR exam replaced the previous CCNP Security core exams, such as 300-206 SISAS and 300-208 SISF. It consolidates the core security topics into a single exam that is also the qualifying exam for CCNP Security and CCIE Security.

Do I need to earn a lower-level Cisco certification before taking the 350-701 SCOR exam?

No, there are no mandatory prerequisites for the 350-701 SCOR exam. However, Cisco recommends that candidates have a strong understanding of network security concepts and hands-on experience with Cisco security products.

Is the 350-701 SCOR exam available online?

Yes, the 350-701 SCOR exam is offered both online and at test centers. Online exams are proctored and require a reliable internet connection and a quiet, private testing environment.

What is the retake policy for the 350-701 SCOR exam?

If you fail the exam, you must wait 5 calendar days from the day after your attempt before retaking it. There is no limit on the number of attempts, but each attempt requires a new exam fee.

Can I use Cisco Learning Credits to pay for the 350-701 SCOR exam?

Yes, Cisco Learning Credits can be redeemed for exam vouchers that can be used to pay for the 350-701 SCOR exam.

Does the 350-701 SCOR exam include any hands-on or lab-based components?

No, the 350-701 SCOR exam is a written exam that consists of multiple-choice and multiple-response questions. It does not include a hands-on lab component.

What job roles does the CCNP Security certification map to?

The CCNP Security certification is designed for security engineers, network security architects, and security operations professionals who are responsible for designing, implementing, and managing security solutions.

Can I recertify my CCNP Security by passing a different Cisco exam?

Yes, you can recertify by passing any qualifying Cisco certification exam, including a higher-level exam like CCIE Security, or by earning Continuing Education credits.

How soon will I receive my score report after taking the 350-701 SCOR exam?

You will receive a score report immediately after completing the exam. The report includes your score for each exam section and the passing score for the exam.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 1289 questions, free, no account needed.