Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CISCO

CCIE Security

Cisco Certified Internetwork Expert Security

The CCIE Security certification validates expert-level skills in planning, designing, deploying, operating, and optimizing complex enterprise security networks. It is for experienced security professionals aiming to become technical leaders, demonstrating mastery of context-aware policy enforcement, centralized orchestration, cloud-delivered security, and automation. Earning this credential signals you are among the best in the field, ready to lead security initiatives and drive business outcomes.

Exam formatMultiple-choice written qualifier (350-701 SCOR) + 8-hour hands-on lab exam
Duration120 minutes
DeliveryPearson VUE
Free questions2372

Content last reviewed 1 January 2025 · Up to date

The certification

What CCIE Security proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
56objectives
498concepts
US $1,600 (lab exam) + US $400 (written qualifier)exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

Includes a hands-on lab exam

Beyond the written/multiple-choice exam, this certification also requires a separate hands-on lab (or practical) exam on live equipment. Practice here prepares the written qualifying exam — the lab itself needs real hands-on experience, not just study.

About this certification

The CCIE Security certification is Cisco's expert-level credential for security professionals who design, deploy, operate, and optimize complex enterprise security solutions. It validates end-to-end lifecycle skills across network, cloud, and content security, with a strong emphasis on context-aware policy enforcement, centralized orchestration, and automation. Achieving this certification demonstrates that you can lead technical teams and architect security solutions that protect modern IT infrastructures.

Candidates for CCIE Security are typically seasoned IT security practitioners with five to seven years of experience. The certification requires passing both a core exam and a hands-on lab exam, ensuring a balance of theoretical knowledge and practical expertise. Earning the CCIE Security certification positions you as a technical leader, opening doors to senior roles such as security architect, security analyst, and IT security officer.

Who it’s for

This certification is for experienced security professionals who design, deploy, operate, and optimize complex enterprise security solutions. It is ideal for those aiming for senior-level or leadership positions, such as security architect, security analyst, or IT security officer, and who want to validate their expert-level skills. Candidates typically have five to seven years of experience in IT security and are comfortable with advanced concepts like policy orchestration, cloud-delivered security, and automation. They are ready to lead security initiatives and drive organizational security strategy.

Recommended experience

Cisco recommends five to seven years of experience designing, deploying, operating, and optimizing security technologies and solutions. Designing and deploying complex enterprise security networks; Operating and optimizing security solutions in production environments; Implementing context-aware security policies and rapid threat containment; Orchestrating security policies from a central management point; Deploying cloud-delivered security services such as DNS layer security, Firewall as a Service, and Secure Web Gateway; Automating security configurations using APIs and Python scripting

The syllabus

What you’ll learn

Every domain and objective Cisco measures, with the weight they carry on the exam.

The official Cisco exam outline · checked 1 January 2025 · See the source

1.0 Perimeter Security and Intrusion Prevention
  • 1.1 Deployment modes on Cisco ASA and Cisco FTD
  • 1.2 Firewall features on Cisco ASA and FTD
  • 1.3 Security features on Cisco IOS/IOS XE
  • 1.4 Cisco FMC features
  • 1.5 Cisco NGIPS deployment modes
  • 1.6 Cisco NGFW features
  • 1.7 Detect and mitigate common types of attacks
  • 1.8 Clustering and high availability features on Cisco ASA and Cisco FTD
  • 1.9 Policies and rules for traffic control on Cisco ASA and Cisco FTD
  • 1.10 Routing protocols security on Cisco IOS, Cisco ASA, and Cisco FTD
  • 1.11 Network connectivity through Cisco ASA and Cisco FTD
  • 1.12 Correlation and remediation rules on Cisco FMC
12 objectives · 553 free questions · 115 pages
2.0 Secure Connectivity and Segmentation
  • 2.1 Cisco AnyConnect client-based, remote-access VPN technologies on Cisco ASA, Cisco FTD, and Cisco routers
  • 2.2 Cisco IOS CA for VPN authentication
  • 2.3 FlexVPN, DMVPN, and IPsec L2L tunnels
  • 2.4 VPN high availability methods
  • 2.5 Infrastructure segmentation methods
  • 2.6 Microsegmentation with Cisco TrustSec using SFT and SXP
6 objectives · 250 free questions · 53 pages
3.0 Security Infrastructure
  • 3.1 Device hardening techniques and control plane protection methods
  • 3.2 Management plane protection techniques
  • 3.3 Data plane protection techniques
  • 3.4 Layer 2 security techniques
  • 3.5 Wireless security technologies
  • 3.6 Monitoring protocols
  • 3.7 Security features to comply with organizational security policies, procedures, and standards BCP 38
  • 3.8 Cisco SAFE model to validate network security design and to identify threats to different PINs
  • 3.9 Interaction with network devices through APIs using basic Python scripts
  • 3.10 Cisco DNAC Northbound APIs use cases
10 objectives · 399 free questions · 84 pages
4.0 Identity Management, Information Exchange, and Access Control
  • 4.1 Cisco ISE scalability using multiple nodes and personas
  • 4.2 Cisco switches and Cisco Wireless LAN Controllers for network access AAA with Cisco ISE
  • 4.3 Cisco devices for administrative access with Cisco ISE
  • 4.4 AAA for network access with 802.1X and MAB using Cisco ISE
  • 4.5 Guest lifecycle management using Cisco ISE and Cisco WLC
  • 4.6 BYOD on-boarding and network access flows
  • 4.7 Cisco ISE integration with external identity sources
  • 4.8 Provisioning Cisco AnyConnect with Cisco ISE and Cisco ASA
  • 4.9 Posture assessment with Cisco ISE
  • 4.10 Endpoint profiling using Cisco ISE and Cisco network infrastructure including device sensor
  • 4.11 Integration of MDM with Cisco ISE
  • 4.12 Certification-based authentication using Cisco ISE
  • 4.13 Authentication methods
  • 4.14 Identity mapping on Cisco ASA, Cisco ISE, Cisco WSA, and Cisco FTD
  • 4.15 pxGrid integration between security devices Cisco WSA, Cisco ISE, and Cisco FMC
  • 4.16 Integration of Cisco ISE with multifactor authentication
  • 4.17 Access control and single sign-on using Cisco DUO security technology
  • 4.18 Cisco IBNS 2.0 (C3PL) for authentication, access control, and user policy enforcement
18 objectives · 760 free questions · 158 pages
5.0 Advanced Threat Protection and Content Security
  • 5.1 Cisco AMP for networks, Cisco AMP for endpoints, and Cisco AMP for content security (Cisco ESA, and Cisco WSA)
  • 5.2 Detect, analyze, and mitigate malware incidents
  • 5.3 Perform packet capture and analysis using Wireshark, tcpdump, SPAN, ERSPAN, and RSPAN
  • 5.4 Cloud security
  • 5.5 Web filtering, user identification, and Application Visibility and Control (AVC) on Cisco FTD and Cisco WSA
  • 5.6 WCCP redirection on Cisco devices
  • 5.7 Email security features
  • 5.8 HTTP decryption and inspection on Cisco FTD, Cisco WSA, and Cisco Umbrella
  • 5.9 Cisco SMA for centralized content security management
  • 5.10 Cisco advanced threat solutions and their integration: Cisco Stealthwatch, Cisco FMC, Cisco AMP, Cisco CTA, Threat Grid, ETA, Cisco WSA, Cisco SMA, Cisco Threat Response, and Cisco Umbrella
10 objectives · 410 free questions · 84 pages
On the day

The exam itself

Everything Cisco publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationCCIE Security
Exam formatMultiple-choice written qualifier (350-701 SCOR) + 8-hour hands-on lab exam
Duration120 minutes
DeliveryPearson VUE
LanguagesEnglish, Japanese
PricingUS $1,600 (lab exam) + US $400 (written qualifier)
After you pass

Where this credential goes next

The path Cisco lays out, how the credential is kept, and where to book.

Step-by-step path to CCIE Security

Renewal and maintenance

The CCIE Security certification is valid for three years. You can renew by earning Continuing Education credits or by retaking the required exams before expiration. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. Cisco maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by Cisco

Exam registration

Register for the exam through Pearson VUE, Cisco’s authorized testing partner.

Schedule your exam

Visit the official Cisco certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How do I prepare for the SCOR written qualifying exam?

The written qualifying exam for this CCIE is 350-701 SCOR, the same exam as CCNP Security (350-701 SCOR). Practice the full SCOR question bank on its Examers page to prepare the written portion. The 8-hour hands-on lab exam is a separate, live-equipment exam that cannot be prepared with practice questions alone — it requires real lab experience.

How does the CCIE Security certification relate to the CCNP Security certification?

CCNP Security is a Professional-level certification that validates advanced security skills, while CCIE Security is the Expert-level certification. Earning CCNP Security is not a formal prerequisite for CCIE Security, but it provides a strong foundation. Passing the CCIE Security core exam (350-701 SCOR) also earns you the Cisco Certified Specialist - Security Core certification.

Do I need to earn a lower-level Cisco certification before attempting CCIE Security?

No. Cisco states there are no formal prerequisites for the CCIE Security certification. However, five to seven years of experience is recommended, and many candidates hold CCNP Security or other advanced certifications.

Is the CCIE Security lab exam hands-on?

Yes. The CCIE Security Lab Exam v6.1 is a hands-on lab exam that tests your ability to design, deploy, operate, and optimize end-to-end security of an enterprise-level dual stack (IPv4 and IPv6) network.

What is the retake policy for the CCIE Security exams?

Cisco's standard retake policy applies: you must wait 24 hours after a first failed attempt, and 14 days before each subsequent attempt. There is no annual cap on attempts.

What job roles does the CCIE Security certification map to?

The certification prepares you for senior security roles such as security architect, security analyst, and IT security officer, where you design, build, and maintain enterprise security systems.

Can I recertify by passing a different Cisco exam?

Yes. You can renew your CCIE Security certification by earning Continuing Education credits or by retaking the required exams before expiration. Passing a higher-level exam may also renew lower-level certifications.

Are there any regional differences in exam delivery for CCIE Security?

Cisco exams are delivered globally through Pearson VUE, with both online proctored and test center options. Availability may vary by region, and some languages may not be offered in all locations.

Information freshness · Content last reviewed on 2025-01-01 Up to date
Practice free questions 2372 questions, free, no account needed.