Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CISCO

CCIE Security

CCIE-SECURITYCisco Certified Internetwork Expert Security

The CCIE Security certification validates expert-level skills in planning, designing, deploying, operating, and optimizing complex enterprise security networks. It is for experienced security professionals aiming to become technical leaders, demonstrating mastery of context-aware policy enforcement, centralized orchestration, cloud-delivered security, and automation. Earning this credential signals you are among the best in the field, ready to lead security initiatives and drive business outcomes.

2372 practice questions · Updated 2025-01-01

5Domains
56Objectives
498Concepts
2372Questions

CCIE-SECURITY Curriculum

Every domain, objective, and concept the CCIE-SECURITY exam measures.

  1. Routed mode fundamentals
  2. Transparent mode fundamentals
  3. Single context mode
  4. Multi-context mode
  5. Multi-instance mode
  6. Deployment mode selection criteria
  7. Configuration and verification of deployment modes
  1. NAT on Cisco ASA and FTD
  2. NAT order of operation and types
  3. Application inspection engines
  4. Inspection policy and advanced options
  5. Traffic zones on ASA and FTD
  6. Zone-based policy enforcement
  7. Policy-based routing on ASA and FTD
  8. PBR configuration and verification
  9. Traffic redirection to service modules
  10. Redirection methods and verification
  11. Identity firewall concepts
  12. Identity firewall configuration
  1. Application awareness fundamentals
  2. NBAR protocol discovery and classification
  3. Application-based policies and QoS
  4. Zone-based firewall architecture
  5. Configuring zone pairs and policies
  6. ZBFW inspection and stateful filtering
  7. ZBFW logging and monitoring
  8. NAT concepts and types
  9. Configuring NAT on IOS/IOS XE
  10. NAT with zone-based firewall integration
  11. Troubleshooting NAT and ZBFW

1.4 Cisco FMC features

10 concepts · 59 questions
  1. Alerting Configuration
  2. Alert Severity and Thresholds
  3. Alert Destinations
  4. Logging Configuration
  5. Log Retention and Storage
  6. Log Viewing and Filtering
  7. Report Generation
  8. Report Scheduling and Distribution
  9. Dynamic Object Definition
  10. Dynamic Object Usage

1.5 Cisco NGIPS deployment modes

3 concepts · 33 questions
  1. In-line deployment
  2. Passive deployment
  3. TAP deployment

1.6 Cisco NGFW features

11 concepts · 58 questions
  1. SSL inspection fundamentals
  2. SSL decryption methods
  3. SSL inspection policies
  4. SSL certificate handling
  5. User identity sources
  6. User identity enforcement
  7. Geolocation database
  8. Geolocation-based policies
  9. AVC overview
  10. Application identification techniques
  11. AVC policy configuration
  1. DoS/DDoS attack types
  2. DDoS mitigation techniques
  3. Evasion techniques
  4. Evasion detection and countermeasures
  5. Spoofing attacks
  6. Spoofing mitigation
  7. Man-in-the-middle (MITM) attacks
  8. MITM detection and prevention
  9. Botnet architecture and lifecycle
  10. Botnet detection and disruption
  1. ASA Clustering Fundamentals
  2. ASA Cluster Deployment Requirements
  3. ASA Cluster Configuration
  4. ASA Cluster Traffic Handling
  5. ASA Cluster Management and Monitoring
  6. ASA High Availability (Active/Standby)
  7. ASA Active/Active High Availability
  8. FTD High Availability Overview
  9. FTD Failover Configuration
  10. FTD Clustering (if applicable)
  11. High Availability and Clustering Troubleshooting
  1. ASA Access Control Lists (ACLs)
  2. ASA Object Groups
  3. ASA Time-Based ACLs
  4. ASA Modular Policy Framework (MPF)
  5. ASA Inspect and Service Policies
  6. FTD Access Control Policies
  7. FTD Prefilter Policies
  8. FTD Intrusion Prevention Policies
  9. FTD Identity Policies
  10. FTD SSL Decryption Policies
  11. FTD DNS and URL Filtering Policies
  12. FTD QoS Policies
  13. ASA and FTD Rule Ordering and Evaluation
  14. ASA and FTD Logging and Monitoring for Policies
  1. Routing protocol authentication on Cisco IOS
  2. Routing protocol authentication on Cisco ASA
  3. Routing protocol authentication on Cisco FTD
  4. Routing protocol filtering and route filtering
  5. Routing protocol security against attacks
  6. BGP security features
  7. OSPF security features
  8. EIGRP security features
  9. Routing protocol security on virtual routing and forwarding (VRF) instances
  10. Monitoring and troubleshooting routing protocol security
  1. ASA and FTD connectivity overview
  2. Interface configuration for connectivity
  3. IP addressing and routing
  4. NAT and PAT for connectivity
  5. Access control for connectivity
  6. High availability and failover
  7. VPN connectivity
  8. Troubleshooting connectivity
  1. Correlation rules
  2. Correlation rule components
  3. Creating correlation rules
  4. Correlation rule actions
  5. Remediation rules
  6. Remediation rule configuration
  7. Remediation actions
  8. Correlation and remediation integration
  9. Testing and tuning

  1. AnyConnect Architecture
  2. SSL VPN and IPsec IKEv2 Support
  3. Configuration on Cisco ASA
  4. Configuration on Cisco FTD
  5. Configuration on Cisco Routers
  6. Client Deployment and Profiles
  7. Authentication and Authorization
  8. Dynamic Access Policies (DAP)
  9. Group Policies and Attributes
  10. Split Tunneling and DNS
  11. High Availability and Load Balancing
  12. Troubleshooting AnyConnect VPN
  13. Integration with Security Features
  14. Performance and Optimization
  15. Licensing and Compliance

2.2 Cisco IOS CA for VPN authentication

6 concepts · 49 questions
  1. Cisco IOS CA overview
  2. CA server setup
  3. Certificate enrollment
  4. Certificate revocation
  5. VPN authentication with certificates
  6. Troubleshooting certificate-based VPNs
  1. FlexVPN Architecture
  2. FlexVPN Configuration
  3. FlexVPN Operation and Verification
  4. DMVPN Architecture
  5. DMVPN Configuration
  6. DMVPN Operation and Verification
  7. IPsec L2L Tunnel Fundamentals
  8. IPsec L2L Tunnel Configuration
  9. IPsec L2L Tunnel Verification and Troubleshooting
  10. Comparison of FlexVPN, DMVPN, and IPsec L2L

2.4 VPN high availability methods

7 concepts · 54 questions
  1. Cisco ASA VPN clustering overview
  2. ASA cluster deployment models
  3. ASA cluster configuration and management
  4. ASA cluster failover and load balancing
  5. Dual-hub DMVPN design
  6. Dual-hub DMVPN configuration
  7. Dual-hub DMVPN failover and optimization

2.5 Infrastructure segmentation methods

8 concepts · 16 questions
  1. VLAN Fundamentals
  2. VLAN Configuration and Verification
  3. Private VLAN (PVLAN) Concepts
  4. PVLAN Configuration and Verification
  5. GRE Tunnel Fundamentals
  6. GRE Configuration and Verification
  7. VRF-Lite Concepts
  8. VRF-Lite Configuration and Verification
  1. SFT Overview
  2. SXP Overview
  3. SGT and SGACL Fundamentals
  4. SFT Operation
  5. SXP Operation
  6. SXP Connections and Modes
  7. SXP Hold-Down and Timers
  8. SXP Filtering and Prefix Lists
  9. SXP Password and Security
  10. Integration of SFT and SXP
  11. Troubleshooting SFT and SXP

  1. Control Plane Policing (CoPP)
  2. CoPP Configuration
  3. CoPP Verification and Monitoring
  4. IP Source Routing
  5. Disabling IP Source Routing
  6. Infrastructure Access Control Lists (iACLs)
  7. iACL Design and Implementation
  8. iACL Placement and Verification
  1. CPU protection mechanisms
  2. CPU threshold configuration
  3. Memory thresholding concepts
  4. Memory threshold configuration
  5. Secure device access methods
  6. Management plane access restrictions
  7. Management plane protection best practices

3.3 Data plane protection techniques

9 concepts · 38 questions
  1. uRPF fundamentals
  2. uRPF modes
  3. uRPF configuration and verification
  4. QoS classification and marking
  5. QoS policing and shaping
  6. QoS for control plane protection
  7. RTBH fundamentals
  8. RTBH implementation
  9. RTBH with BGP

3.4 Layer 2 security techniques

7 concepts · 53 questions
  1. DAI (Dynamic ARP Inspection)
  2. IPDT (IP Device Tracking)
  3. STP Security (Spanning Tree Protocol)
  4. Port Security
  5. DHCP Snooping
  6. RA Guard (Router Advertisement Guard)
  7. VACL (VLAN Access Control Lists)

3.5 Wireless security technologies

10 concepts · 39 questions
  1. WPA overview
  2. WPA authentication and encryption
  3. WPA2 overview
  4. WPA2 authentication and encryption
  5. WPA3 overview
  6. WPA3 features and modes
  7. TKIP protocol
  8. TKIP limitations and usage
  9. AES in wireless security
  10. AES-CCMP operation

3.6 Monitoring protocols

11 concepts · 42 questions
  1. NetFlow fundamentals
  2. IPFIX
  3. NSEL
  4. SNMP architecture
  5. SNMP operations
  6. SYSLOG fundamentals
  7. SYSLOG configuration and management
  8. RMON fundamentals
  9. RMON implementation
  10. eStreamer fundamentals
  11. eStreamer configuration and integration
  1. ISO 27001 Overview
  2. ISO 27001 Security Controls
  3. ISO 27001 Compliance Implementation
  4. RFC 2827 Overview
  5. Ingress Filtering Implementation
  6. Egress Filtering and Best Practices
  7. PCI-DSS Overview
  8. PCI-DSS Security Requirements
  9. PCI-DSS Compliance Implementation
  1. Cisco SAFE model overview
  2. Places in the Network (PINs)
  3. Threat identification per PIN
  4. Mapping security capabilities to PINs
  5. Validating network security design with SAFE
  6. SAFE model design principles
  1. REST API fundamentals
  2. HTTP action verbs
  3. HTTP error codes
  4. HTTP headers and cookies
  5. JSON payloads
  6. XML payloads
  7. API authentication methods
  8. JSON data encoding
  9. XML data encoding
  10. YAML data encoding
  11. Python scripting for API interaction
  1. DNAC Northbound API Authentication
  2. DNAC Northbound API Authorization
  3. Network Discovery via DNAC APIs
  4. Network Device Management via DNAC APIs
  5. Network Host Information via DNAC APIs

  1. ISE Node Personas
  2. Multi-Node Deployment Models
  3. Node Roles and Responsibilities
  4. Scalability Considerations
  5. Node Synchronization and Replication
  6. High Availability and Failover
  7. Load Balancing Across PSNs
  8. Node Administration and Monitoring
  1. AAA Architecture on Cisco Switches and WLCs
  2. Configuring RADIUS on Cisco Switches
  3. Configuring RADIUS on Cisco WLCs
  4. ISE Integration with Switches and WLCs
  5. 802.1X and MAB on Switches
  6. 802.1X and MAB on WLCs
  7. Central Web Authentication (CWA)
  8. Flexible Authentication and Policy Enforcement
  9. Accounting and Reporting
  10. Troubleshooting AAA with ISE
  1. Administrative Access Methods
  2. TACACS+ Integration with ISE
  3. RADIUS for Device Administration
  4. ISE as AAA Server
  5. Device Administration Policy Sets
  6. Command Authorization
  7. Administrative User Authentication
  8. Accounting and Audit Logs
  9. ISE and Device CLI Integration
  10. Troubleshooting Administrative Access
  1. 802.1X authentication flow
  2. MAB (MAC Authentication Bypass)
  3. Cisco ISE as AAA server
  4. AAA policy components
  5. Authorization profiles
  6. Identity sources and groups
  7. RADIUS attributes and AV pairs
  8. Dynamic VLAN assignment
  9. Downloadable ACLs (dACLs)
  10. CoA (Change of Authorization)
  11. Troubleshooting AAA and 802.1X
  1. Guest lifecycle overview
  2. Guest portal configuration
  3. Sponsor workflows
  4. Guest account policies
  5. WLC guest access integration
  6. Guest access authentication
  7. Guest access authorization
  8. Guest account expiration and cleanup
  9. Guest lifecycle monitoring and troubleshooting
  1. BYOD onboarding process
  2. Device onboarding methods
  3. Network access flows for BYOD
  4. Integration with identity management
  5. Policy enforcement in BYOD
  6. Troubleshooting BYOD onboarding
  1. LDAP integration overview
  2. Configuring LDAP identity source
  3. LDAP authentication and authorization
  4. AD integration overview
  5. Configuring AD identity source
  6. AD authentication and authorization
  7. External RADIUS integration overview
  8. Configuring external RADIUS identity source
  9. External RADIUS authentication flow
  10. Comparing external identity sources
  1. AnyConnect provisioning overview
  2. Preparing Cisco ISE for AnyConnect provisioning
  3. Preparing Cisco ASA for AnyConnect provisioning
  4. Integrating ISE with ASA for AnyConnect
  5. Creating and applying AnyConnect client profiles
  6. Deploying AnyConnect via ISE
  7. Deploying AnyConnect via ASA
  8. Verifying AnyConnect provisioning

4.9 Posture assessment with Cisco ISE

8 concepts · 54 questions
  1. Posture assessment overview
  2. Posture policy configuration
  3. Posture conditions and requirements
  4. Posture remediation
  5. Posture agent deployment and management
  6. Posture assessment with client provisioning
  7. Posture assessment with guest and BYOD
  8. Posture assessment reporting and troubleshooting
  1. Endpoint profiling overview
  2. Profiling policies and probes
  3. Profiling feed service
  4. Device sensor configuration
  5. Device sensor attributes and filters
  6. Integration of device sensor with ISE
  7. Endpoint classification and identity groups
  8. Troubleshooting endpoint profiling

4.11 Integration of MDM with Cisco ISE

5 concepts · 30 questions
  1. MDM Integration Overview
  2. MDM Server Configuration in ISE
  3. MDM Compliance and Posture Checks
  4. MDM Integration Workflows
  5. Troubleshooting MDM Integration
  1. Certificate-based authentication overview
  2. Certificate enrollment and provisioning
  3. Certificate validation and trust chain
  4. Certificate authentication policies
  5. Certificate authentication with EAP-TLS
  6. Certificate authentication with PEAP and EAP-FAST
  7. Certificate-based machine and user authentication
  8. Troubleshooting certificate-based authentication

4.13 Authentication methods

8 concepts · 44 questions
  1. EAP Chaining Fundamentals
  2. TEAP (Tunnel Extensible Authentication Protocol)
  3. TEAP Inner Methods and Security
  4. TEAP Deployment and Use Cases
  5. MAR (Machine Access Restriction) Overview
  6. MAR Authentication Flow
  7. MAR Configuration and Enforcement
  8. MAR and EAP Chaining Integration
  1. Identity mapping fundamentals
  2. Identity mapping on Cisco ASA
  3. Identity mapping on Cisco ISE
  4. Identity mapping on Cisco WSA
  5. Identity mapping on Cisco FTD
  6. Comparison of identity mapping implementations
  1. pxGrid architecture and roles
  2. WSA-ISE integration via pxGrid
  3. ISE-FMC integration via pxGrid
  4. WSA-FMC integration via pxGrid
  5. pxGrid configuration steps
  6. pxGrid topics and subscriptions
  7. Policy enforcement using shared context
  8. Troubleshooting pxGrid integrations
  1. MFA integration methods
  2. MFA deployment models
  3. Authentication flow with MFA
  4. Configuration of MFA providers
  5. MFA policy enforcement
  6. Troubleshooting MFA integration
  7. MFA and authorization
  8. MFA with VPN and remote access
  9. MFA with wireless and wired access
  10. MFA with guest and BYOD
  11. MFA and identity lifecycle
  12. MFA reporting and monitoring
  1. DUO authentication methods
  2. DUO enrollment and user management
  3. DUO access policies
  4. DUO single sign-on (SSO) integration
  5. DUO with VPN and remote access
  6. DUO with Cisco AnyConnect
  7. DUO with Active Directory and LDAP
  8. DUO with RADIUS
  9. DUO with web applications
  10. DUO with RDP and SSH
  11. DUO with custom applications
  12. DUO policies for device trust
  13. DUO authentication proxy
  14. DUO universal prompt
  15. DUO administration and reporting
  16. DUO failover and high availability
  17. DUO security best practices
  1. IBNS 2.0 Architecture
  2. C3PL Policy Structure
  3. Authentication Methods
  4. Access Control Enforcement
  5. User Policy Enforcement
  6. Integration with Identity Sources
  7. Troubleshooting IBNS 2.0

  1. AMP for Networks architecture and deployment
  2. AMP for Networks detection and analysis
  3. AMP for Networks policy configuration
  4. AMP for Endpoints architecture and deployment
  5. AMP for Endpoints protection features
  6. AMP for Endpoints management and investigation
  7. AMP for Content Security integration with Cisco ESA
  8. AMP for Content Security integration with Cisco WSA
  9. AMP threat intelligence and retrospective analysis
  10. AMP reporting and troubleshooting
  1. Malware Detection Techniques
  2. Malware Analysis Methods
  3. Malware Incident Response Process
  4. Mitigation Strategies for Malware
  5. Threat Intelligence Integration
  6. Sandboxing and Detonation
  7. Malware Family and Campaign Analysis
  8. Reporting and Documentation
  1. Wireshark capture and analysis
  2. tcpdump capture and analysis
  3. SPAN configuration and use
  4. RSPAN configuration and use
  5. ERSPAN configuration and use
  6. Comparison of capture methods

5.4 Cloud security

10 concepts · 60 questions
  1. Umbrella Virtual Appliance Deployment
  2. DNS Proxy Forwarding
  3. Umbrella DNS Policy Configuration
  4. DNS Policy Enforcement and Reporting
  5. Remote Browser Isolation (RBI) Policy Setup
  6. RBI Policy Application and Tuning
  7. CASB Policy Configuration
  8. CASB Threat Protection and Data Controls
  9. DLP Policy Definition
  10. DLP Policy Implementation and Monitoring
  1. Web filtering on Cisco FTD
  2. User identification on Cisco FTD
  3. Application Visibility and Control (AVC) on Cisco FTD
  4. Web filtering on Cisco WSA
  5. User identification on Cisco WSA
  6. Application Visibility and Control (AVC) on Cisco WSA
  7. Integration of FTD and WSA for web security
  8. Comparison of web filtering and AVC features between FTD and WSA

5.6 WCCP redirection on Cisco devices

9 concepts · 35 questions
  1. WCCP Overview
  2. WCCP Versions and Features
  3. WCCP Service Groups
  4. WCCP Redirection Modes
  5. WCCP Router Configuration
  6. WCCP Cache Engine Configuration
  7. WCCP Security and Authentication
  8. WCCP Load Balancing and Redundancy
  9. WCCP Verification and Troubleshooting

5.7 Email security features

5 concepts · 30 questions
  1. Mail Policies
  2. DLP (Data Loss Prevention)
  3. Quarantine
  4. Email Authentication
  5. Email Encryption
  1. HTTP decryption architecture
  2. Decryption policies and rules
  3. Certificate handling and trust
  4. Inspection of decrypted traffic
  5. Decryption exceptions and bypass
  6. Performance and scalability considerations
  7. Troubleshooting decryption issues
  8. Integration with Cisco Umbrella
  9. Compliance and privacy considerations
  1. SMA deployment modes
  2. SMA integration with email security
  3. SMA integration with web security
  4. Centralized policy management
  5. Centralized reporting and tracking
  6. Centralized quarantine management
  7. SMA administration and user roles
  8. SMA high availability and redundancy
  1. Cisco Stealthwatch integration
  2. Cisco FMC integration
  3. Cisco AMP integration
  4. Cisco CTA integration
  5. Threat Grid integration
  6. Encrypted Traffic Analytics (ETA)
  7. Cisco WSA integration
  8. Cisco SMA integration
  9. Cisco Threat Response integration
  10. Cisco Umbrella integration
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCIE-SECURITY, so none is invented.