
CCIE Security
The CCIE Security certification validates expert-level skills in planning, designing, deploying, operating, and optimizing complex enterprise security networks. It is for experienced security professionals aiming to become technical leaders, demonstrating mastery of context-aware policy enforcement, centralized orchestration, cloud-delivered security, and automation. Earning this credential signals you are among the best in the field, ready to lead security initiatives and drive business outcomes.
2372 practice questions · Updated 2025-01-01
CCIE-SECURITY Curriculum
Every domain, objective, and concept the CCIE-SECURITY exam measures.
- Routed mode fundamentals
- Transparent mode fundamentals
- Single context mode
- Multi-context mode
- Multi-instance mode
- Deployment mode selection criteria
- Configuration and verification of deployment modes
- NAT on Cisco ASA and FTD
- NAT order of operation and types
- Application inspection engines
- Inspection policy and advanced options
- Traffic zones on ASA and FTD
- Zone-based policy enforcement
- Policy-based routing on ASA and FTD
- PBR configuration and verification
- Traffic redirection to service modules
- Redirection methods and verification
- Identity firewall concepts
- Identity firewall configuration
- Application awareness fundamentals
- NBAR protocol discovery and classification
- Application-based policies and QoS
- Zone-based firewall architecture
- Configuring zone pairs and policies
- ZBFW inspection and stateful filtering
- ZBFW logging and monitoring
- NAT concepts and types
- Configuring NAT on IOS/IOS XE
- NAT with zone-based firewall integration
- Troubleshooting NAT and ZBFW
- Alerting Configuration
- Alert Severity and Thresholds
- Alert Destinations
- Logging Configuration
- Log Retention and Storage
- Log Viewing and Filtering
- Report Generation
- Report Scheduling and Distribution
- Dynamic Object Definition
- Dynamic Object Usage
- In-line deployment
- Passive deployment
- TAP deployment
- SSL inspection fundamentals
- SSL decryption methods
- SSL inspection policies
- SSL certificate handling
- User identity sources
- User identity enforcement
- Geolocation database
- Geolocation-based policies
- AVC overview
- Application identification techniques
- AVC policy configuration
- DoS/DDoS attack types
- DDoS mitigation techniques
- Evasion techniques
- Evasion detection and countermeasures
- Spoofing attacks
- Spoofing mitigation
- Man-in-the-middle (MITM) attacks
- MITM detection and prevention
- Botnet architecture and lifecycle
- Botnet detection and disruption
- ASA Clustering Fundamentals
- ASA Cluster Deployment Requirements
- ASA Cluster Configuration
- ASA Cluster Traffic Handling
- ASA Cluster Management and Monitoring
- ASA High Availability (Active/Standby)
- ASA Active/Active High Availability
- FTD High Availability Overview
- FTD Failover Configuration
- FTD Clustering (if applicable)
- High Availability and Clustering Troubleshooting
- ASA Access Control Lists (ACLs)
- ASA Object Groups
- ASA Time-Based ACLs
- ASA Modular Policy Framework (MPF)
- ASA Inspect and Service Policies
- FTD Access Control Policies
- FTD Prefilter Policies
- FTD Intrusion Prevention Policies
- FTD Identity Policies
- FTD SSL Decryption Policies
- FTD DNS and URL Filtering Policies
- FTD QoS Policies
- ASA and FTD Rule Ordering and Evaluation
- ASA and FTD Logging and Monitoring for Policies
- Routing protocol authentication on Cisco IOS
- Routing protocol authentication on Cisco ASA
- Routing protocol authentication on Cisco FTD
- Routing protocol filtering and route filtering
- Routing protocol security against attacks
- BGP security features
- OSPF security features
- EIGRP security features
- Routing protocol security on virtual routing and forwarding (VRF) instances
- Monitoring and troubleshooting routing protocol security
- ASA and FTD connectivity overview
- Interface configuration for connectivity
- IP addressing and routing
- NAT and PAT for connectivity
- Access control for connectivity
- High availability and failover
- VPN connectivity
- Troubleshooting connectivity
- Correlation rules
- Correlation rule components
- Creating correlation rules
- Correlation rule actions
- Remediation rules
- Remediation rule configuration
- Remediation actions
- Correlation and remediation integration
- Testing and tuning
- AnyConnect Architecture
- SSL VPN and IPsec IKEv2 Support
- Configuration on Cisco ASA
- Configuration on Cisco FTD
- Configuration on Cisco Routers
- Client Deployment and Profiles
- Authentication and Authorization
- Dynamic Access Policies (DAP)
- Group Policies and Attributes
- Split Tunneling and DNS
- High Availability and Load Balancing
- Troubleshooting AnyConnect VPN
- Integration with Security Features
- Performance and Optimization
- Licensing and Compliance
- Cisco IOS CA overview
- CA server setup
- Certificate enrollment
- Certificate revocation
- VPN authentication with certificates
- Troubleshooting certificate-based VPNs
- FlexVPN Architecture
- FlexVPN Configuration
- FlexVPN Operation and Verification
- DMVPN Architecture
- DMVPN Configuration
- DMVPN Operation and Verification
- IPsec L2L Tunnel Fundamentals
- IPsec L2L Tunnel Configuration
- IPsec L2L Tunnel Verification and Troubleshooting
- Comparison of FlexVPN, DMVPN, and IPsec L2L
- Cisco ASA VPN clustering overview
- ASA cluster deployment models
- ASA cluster configuration and management
- ASA cluster failover and load balancing
- Dual-hub DMVPN design
- Dual-hub DMVPN configuration
- Dual-hub DMVPN failover and optimization
- VLAN Fundamentals
- VLAN Configuration and Verification
- Private VLAN (PVLAN) Concepts
- PVLAN Configuration and Verification
- GRE Tunnel Fundamentals
- GRE Configuration and Verification
- VRF-Lite Concepts
- VRF-Lite Configuration and Verification
- SFT Overview
- SXP Overview
- SGT and SGACL Fundamentals
- SFT Operation
- SXP Operation
- SXP Connections and Modes
- SXP Hold-Down and Timers
- SXP Filtering and Prefix Lists
- SXP Password and Security
- Integration of SFT and SXP
- Troubleshooting SFT and SXP
- Control Plane Policing (CoPP)
- CoPP Configuration
- CoPP Verification and Monitoring
- IP Source Routing
- Disabling IP Source Routing
- Infrastructure Access Control Lists (iACLs)
- iACL Design and Implementation
- iACL Placement and Verification
- CPU protection mechanisms
- CPU threshold configuration
- Memory thresholding concepts
- Memory threshold configuration
- Secure device access methods
- Management plane access restrictions
- Management plane protection best practices
- uRPF fundamentals
- uRPF modes
- uRPF configuration and verification
- QoS classification and marking
- QoS policing and shaping
- QoS for control plane protection
- RTBH fundamentals
- RTBH implementation
- RTBH with BGP
- DAI (Dynamic ARP Inspection)
- IPDT (IP Device Tracking)
- STP Security (Spanning Tree Protocol)
- Port Security
- DHCP Snooping
- RA Guard (Router Advertisement Guard)
- VACL (VLAN Access Control Lists)
- WPA overview
- WPA authentication and encryption
- WPA2 overview
- WPA2 authentication and encryption
- WPA3 overview
- WPA3 features and modes
- TKIP protocol
- TKIP limitations and usage
- AES in wireless security
- AES-CCMP operation
- NetFlow fundamentals
- IPFIX
- NSEL
- SNMP architecture
- SNMP operations
- SYSLOG fundamentals
- SYSLOG configuration and management
- RMON fundamentals
- RMON implementation
- eStreamer fundamentals
- eStreamer configuration and integration
- ISO 27001 Overview
- ISO 27001 Security Controls
- ISO 27001 Compliance Implementation
- RFC 2827 Overview
- Ingress Filtering Implementation
- Egress Filtering and Best Practices
- PCI-DSS Overview
- PCI-DSS Security Requirements
- PCI-DSS Compliance Implementation
- Cisco SAFE model overview
- Places in the Network (PINs)
- Threat identification per PIN
- Mapping security capabilities to PINs
- Validating network security design with SAFE
- SAFE model design principles
- REST API fundamentals
- HTTP action verbs
- HTTP error codes
- HTTP headers and cookies
- JSON payloads
- XML payloads
- API authentication methods
- JSON data encoding
- XML data encoding
- YAML data encoding
- Python scripting for API interaction
- DNAC Northbound API Authentication
- DNAC Northbound API Authorization
- Network Discovery via DNAC APIs
- Network Device Management via DNAC APIs
- Network Host Information via DNAC APIs
- ISE Node Personas
- Multi-Node Deployment Models
- Node Roles and Responsibilities
- Scalability Considerations
- Node Synchronization and Replication
- High Availability and Failover
- Load Balancing Across PSNs
- Node Administration and Monitoring
- AAA Architecture on Cisco Switches and WLCs
- Configuring RADIUS on Cisco Switches
- Configuring RADIUS on Cisco WLCs
- ISE Integration with Switches and WLCs
- 802.1X and MAB on Switches
- 802.1X and MAB on WLCs
- Central Web Authentication (CWA)
- Flexible Authentication and Policy Enforcement
- Accounting and Reporting
- Troubleshooting AAA with ISE
- Administrative Access Methods
- TACACS+ Integration with ISE
- RADIUS for Device Administration
- ISE as AAA Server
- Device Administration Policy Sets
- Command Authorization
- Administrative User Authentication
- Accounting and Audit Logs
- ISE and Device CLI Integration
- Troubleshooting Administrative Access
- 802.1X authentication flow
- MAB (MAC Authentication Bypass)
- Cisco ISE as AAA server
- AAA policy components
- Authorization profiles
- Identity sources and groups
- RADIUS attributes and AV pairs
- Dynamic VLAN assignment
- Downloadable ACLs (dACLs)
- CoA (Change of Authorization)
- Troubleshooting AAA and 802.1X
- Guest lifecycle overview
- Guest portal configuration
- Sponsor workflows
- Guest account policies
- WLC guest access integration
- Guest access authentication
- Guest access authorization
- Guest account expiration and cleanup
- Guest lifecycle monitoring and troubleshooting
- BYOD onboarding process
- Device onboarding methods
- Network access flows for BYOD
- Integration with identity management
- Policy enforcement in BYOD
- Troubleshooting BYOD onboarding
- LDAP integration overview
- Configuring LDAP identity source
- LDAP authentication and authorization
- AD integration overview
- Configuring AD identity source
- AD authentication and authorization
- External RADIUS integration overview
- Configuring external RADIUS identity source
- External RADIUS authentication flow
- Comparing external identity sources
- AnyConnect provisioning overview
- Preparing Cisco ISE for AnyConnect provisioning
- Preparing Cisco ASA for AnyConnect provisioning
- Integrating ISE with ASA for AnyConnect
- Creating and applying AnyConnect client profiles
- Deploying AnyConnect via ISE
- Deploying AnyConnect via ASA
- Verifying AnyConnect provisioning
- Posture assessment overview
- Posture policy configuration
- Posture conditions and requirements
- Posture remediation
- Posture agent deployment and management
- Posture assessment with client provisioning
- Posture assessment with guest and BYOD
- Posture assessment reporting and troubleshooting
- Endpoint profiling overview
- Profiling policies and probes
- Profiling feed service
- Device sensor configuration
- Device sensor attributes and filters
- Integration of device sensor with ISE
- Endpoint classification and identity groups
- Troubleshooting endpoint profiling
- MDM Integration Overview
- MDM Server Configuration in ISE
- MDM Compliance and Posture Checks
- MDM Integration Workflows
- Troubleshooting MDM Integration
- Certificate-based authentication overview
- Certificate enrollment and provisioning
- Certificate validation and trust chain
- Certificate authentication policies
- Certificate authentication with EAP-TLS
- Certificate authentication with PEAP and EAP-FAST
- Certificate-based machine and user authentication
- Troubleshooting certificate-based authentication
- EAP Chaining Fundamentals
- TEAP (Tunnel Extensible Authentication Protocol)
- TEAP Inner Methods and Security
- TEAP Deployment and Use Cases
- MAR (Machine Access Restriction) Overview
- MAR Authentication Flow
- MAR Configuration and Enforcement
- MAR and EAP Chaining Integration
- Identity mapping fundamentals
- Identity mapping on Cisco ASA
- Identity mapping on Cisco ISE
- Identity mapping on Cisco WSA
- Identity mapping on Cisco FTD
- Comparison of identity mapping implementations
- pxGrid architecture and roles
- WSA-ISE integration via pxGrid
- ISE-FMC integration via pxGrid
- WSA-FMC integration via pxGrid
- pxGrid configuration steps
- pxGrid topics and subscriptions
- Policy enforcement using shared context
- Troubleshooting pxGrid integrations
- MFA integration methods
- MFA deployment models
- Authentication flow with MFA
- Configuration of MFA providers
- MFA policy enforcement
- Troubleshooting MFA integration
- MFA and authorization
- MFA with VPN and remote access
- MFA with wireless and wired access
- MFA with guest and BYOD
- MFA and identity lifecycle
- MFA reporting and monitoring
- DUO authentication methods
- DUO enrollment and user management
- DUO access policies
- DUO single sign-on (SSO) integration
- DUO with VPN and remote access
- DUO with Cisco AnyConnect
- DUO with Active Directory and LDAP
- DUO with RADIUS
- DUO with web applications
- DUO with RDP and SSH
- DUO with custom applications
- DUO policies for device trust
- DUO authentication proxy
- DUO universal prompt
- DUO administration and reporting
- DUO failover and high availability
- DUO security best practices
- IBNS 2.0 Architecture
- C3PL Policy Structure
- Authentication Methods
- Access Control Enforcement
- User Policy Enforcement
- Integration with Identity Sources
- Troubleshooting IBNS 2.0
- AMP for Networks architecture and deployment
- AMP for Networks detection and analysis
- AMP for Networks policy configuration
- AMP for Endpoints architecture and deployment
- AMP for Endpoints protection features
- AMP for Endpoints management and investigation
- AMP for Content Security integration with Cisco ESA
- AMP for Content Security integration with Cisco WSA
- AMP threat intelligence and retrospective analysis
- AMP reporting and troubleshooting
- Malware Detection Techniques
- Malware Analysis Methods
- Malware Incident Response Process
- Mitigation Strategies for Malware
- Threat Intelligence Integration
- Sandboxing and Detonation
- Malware Family and Campaign Analysis
- Reporting and Documentation
- Wireshark capture and analysis
- tcpdump capture and analysis
- SPAN configuration and use
- RSPAN configuration and use
- ERSPAN configuration and use
- Comparison of capture methods
- Umbrella Virtual Appliance Deployment
- DNS Proxy Forwarding
- Umbrella DNS Policy Configuration
- DNS Policy Enforcement and Reporting
- Remote Browser Isolation (RBI) Policy Setup
- RBI Policy Application and Tuning
- CASB Policy Configuration
- CASB Threat Protection and Data Controls
- DLP Policy Definition
- DLP Policy Implementation and Monitoring
- Web filtering on Cisco FTD
- User identification on Cisco FTD
- Application Visibility and Control (AVC) on Cisco FTD
- Web filtering on Cisco WSA
- User identification on Cisco WSA
- Application Visibility and Control (AVC) on Cisco WSA
- Integration of FTD and WSA for web security
- Comparison of web filtering and AVC features between FTD and WSA
- WCCP Overview
- WCCP Versions and Features
- WCCP Service Groups
- WCCP Redirection Modes
- WCCP Router Configuration
- WCCP Cache Engine Configuration
- WCCP Security and Authentication
- WCCP Load Balancing and Redundancy
- WCCP Verification and Troubleshooting
- Mail Policies
- DLP (Data Loss Prevention)
- Quarantine
- Email Authentication
- Email Encryption
- HTTP decryption architecture
- Decryption policies and rules
- Certificate handling and trust
- Inspection of decrypted traffic
- Decryption exceptions and bypass
- Performance and scalability considerations
- Troubleshooting decryption issues
- Integration with Cisco Umbrella
- Compliance and privacy considerations
- SMA deployment modes
- SMA integration with email security
- SMA integration with web security
- Centralized policy management
- Centralized reporting and tracking
- Centralized quarantine management
- SMA administration and user roles
- SMA high availability and redundancy
- Cisco Stealthwatch integration
- Cisco FMC integration
- Cisco AMP integration
- Cisco CTA integration
- Threat Grid integration
- Encrypted Traffic Analytics (ETA)
- Cisco WSA integration
- Cisco SMA integration
- Cisco Threat Response integration
- Cisco Umbrella integration
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCIE-SECURITY, so none is invented.