Facebook Pixel
Microsoft Certification Training
Search classes by keyword:
Search classes by category:
Microsoft Certification and Microsoft Training, Cisco Certification and MCSE Certification
Cisco CCNP Security space


Live Cisco CCNP Security Certification Training Course

Cisco CCNP Security

Course Number: #CED-699
Course Length: 12 days
Number of Exams: 2
Cisco Learning Credits: 86
Certifications: Cisco CCNP Security
Cisco Certified Specialist - Security Core
Cisco Certified Specialist - Security Identity Management Implementation

DoD Approved 8570: IAT Level III

Grants (discounts) are available for multiple students for the same or different courses.

Guaranteed to Run Guaranteed to Run


Upcoming Dates Class Times Class Format Quote
10/5 - 10/16, 2026Guaranteed to Run 10:00 AM - 6:00 PM ET
9:00 AM - 5:00 PM CT
7:00 AM - 3:00 PM PT
4:00 AM - 12:00 PM HT
Instructor-Led Instant Quote
12/7 - 12/18, 2026Guaranteed to Run 10:00 AM - 6:00 PM ET
9:00 AM - 5:00 PM CT
7:00 AM - 3:00 PM PT
4:00 AM - 12:00 PM HT
Instructor-Led Instant Quote
 Guaranteed to Run Self-Paced Online Self-Study Instant Quote

Online Self-Study courses allow you to study around your busy schedule, remain working as you train, work at your own pace.


Instructor-Led

  • Cisco Official Courseware
  • Cisco Official Labs
  • Lifetime access to Courseware
  • Practice and Certification exam(s) (with exam pass guarantee)

If you aren't successful with your first attempt at the exam, we have an exam pass guarantee.

You may re-sit the course in its entirety for an additional exam voucher for up to 6 months (must provide proof of a failed exam for an additional exam voucher).

Instant Quote


Online Self-Study

  • Cisco Official Courseware
  • Cisco Official Labs
  • Lifetime access to Courseware
  • Labs are available for 6 months from date of redemption
  • Apply Cost to Instructor-led Training of Same Course

Instant Quote



Can't travel or you want to stay with your family or business. No problem!

Stay in your own city and save the additional expenses of roundtrip airfare, lodging, transportation, and meals and receive the same great instruction live from our instructors in our Live Instructor-Led Remote Classroom Training.

Remote Classroom Training

Our Remote Classroom Training is a live class with students observing the instructor and listening through your computer speakers.

You will see the instructor's computer, slides, notes, etc., just like in the classroom. You will be following along, doing work, labs, and individual assignments.


CED Solutions Rewards Points Program

CED Solutions Rewards Points Program


"The CCNP course offered a lot of hands-on instruction. I actually learned useable skills. The instructor was very knowledgeable. This CCNP boot camp was just the type of training I was looking for."

-Edward Sevillena, Vallejo, CA

Cisco Certified Network Professional Security (CCNP Security) certification program is aligned specifically to the job role of the Cisco Network Security Engineer responsible for Security in Routers, Switches, Networking devices and appliances, as well as choosing, deploying, supporting and troubleshooting Firewalls, VPNS, and IDS/IPS solutions for their networking environments.

The new CCNP Security certification program prepares you for today's professional-level job roles in security technologies. CCNP Security now includes automation and programmability to help you scale your security infrastructure.

Prerequisites

There are no formal prerequisites for CCNP Security, but you should have a good understanding of the exam topics before taking the exam.

CCNP candidates often also have three to five years of experience implementing security solutions.


Cisco CCNP® Security

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)

Implementing and Operating Cisco Security Core Technologies v1.0 (SCOR 350-701) tests a candidate's knowledge of implementing and operating core security technologies including network security, cloud security, content security, endpoint protection and detection, secure network access, visibility and enforcements.

1.0 Security Concepts
  • Explain common threats against on-premises and cloud environments
  • Compare common security vulnerabilities such as software bugs, weak and/or hardcoded passwords, SQL injection, missing encryption, buffer overflow, path traversal, cross-site scripting/forgery
  • Describe functions of the cryptography components such as hashing, encryption, PKI, SSL, IPsec, NAT-T IPv4 for IPsec, pre-shared key and certificate based authorization
  • Compare site-to-site VPN and remote access VPN deployment types such as sVTI, IPsec, Cryptomap, DMVPN, FLEXVPN including high availability considerations, and AnyConnect
  • Describe security intelligence authoring, sharing, and consumption
  • Explain the role of the endpoint in protecting humans from phishing and social engineering attacks
  • Explain North Bound and South Bound APIs in the SDN architecture
  • Explain DNAC APIs for network provisioning, optimization, monitoring, and troubleshooting
  • Interpret basic Python scripts used to call Cisco Security appliances APIs
2.0 Network Security
  • Compare network security solutions that provide intrusion prevention and firewall capabilities
  • Describe deployment models of network security solutions and architectures that provide intrusion prevention and firewall capabilities
  • Describe the components, capabilities, and benefits of NetFlow and Flexible NetFlow records
  • Configure and verify network infrastructure security methods (router, switch, wireless)
  • Implement segmentation, access control policies, AVC, URL filtering, and malware protection
  • Implement management options for network security solutions such as intrusion prevention and perimeter security (Single vs. multidevice manager, in-band vs. out-of-band, CDP, DNS, SCP, SFTP, and DHCP security and risks)
  • Configure AAA for device and network access (authentication and authorization, TACACS+, RADIUS and RADIUS flows, accounting, and dACL)
  • Configure secure network management of perimeter security and infrastructure devices (secure device management, SNMPv3, views, groups, users, authentication, and encryption, secure logging, and NTP with authentication)
  • Configure and verify site-to-site VPN and remote access VPN
3.0 Securing the Cloud
  • Identify security solutions for cloud environments
  • Compare the customer vs. provider security responsibility for the different cloud service models
  • Describe the concept of DevSecOps (CI/CD pipeline, container orchestration, and security
  • Implement application and data security in cloud environments
  • Identify security capabilities, deployment models, and policy management to secure the cloud
  • Configure cloud logging and monitoring methodologies
  • Describe application and workload security concepts
4.0 Content Security
  • Implement traffic redirection and capture methods
  • Describe web proxy identity and authentication including transparent user identification
  • Compare the components, capabilities, and benefits of local and cloud-based email and web solutions (ESA, CES, WSA)
  • Configure and verify web and email security deployment methods to protect on-premises and remote users (inbound and outbound controls and policy management)
  • Configure and verify email security features such as SPAM filtering, antimalware filtering, DLP, blacklisting, and email encryption
  • Configure and verify secure internet gateway and web security features such as blacklisting, URL filtering, malware scanning, URL categorization, web application filtering, and TLS decryption
  • Describe the components, capabilities, and benefits of Cisco Umbrella
  • Configure and verify web security controls on Cisco Umbrella (identities, URL content settings, destination lists, and reporting)
5.0 Endpoint Protection and Detection
  • Compare Endpoint Protection Platforms (EPP) and Endpoint Detection & Response (EDR) solutions
  • Explain antimalware, retrospective security, Indication of Compromise (IOC), antivirus, dynamic file analysis, and endpoint-sourced telemetry
  • Configure and verify outbreak control and quarantines to limit infection
  • Describe justifications for endpoint-based security
  • Describe the value of endpoint device management and asset inventory such as MDM
  • Describe the uses and importance of a multifactor authentication (MFA) strategy
  • Describe endpoint posture assessment solutions to ensure endpoint security
  • Explain the importance of an endpoint patching strategy
6.0 Secure Network Access, Visibility, and Enforcement
  • Describe identity management and secure network access concepts such as guest services, profiling, posture assessment and BYOD
  • Configure and verify network access device functionality such as 802.1X, MAB, WebAuth
  • Describe network access with CoA
  • Describe the benefits of device compliance and application control
  • Explain exfiltration techniques (DNS tunneling, HTTPS, email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP)
  • Describe the benefits of network telemetry
  • Describe the components, capabilities, and benefits of these security products and solutions

[ back to top ]


Implementing and Configuring Cisco Identity Services Engine (SISE 300-715 v1.1)

The Implementing and Configuring Cisco Identity Services Engine (SISE) training teaches you to deploy, configure, and operate Cisco® Identity Services Engine (ISE) as the central platform for identity-based access control. Learning begins with the core architecture and installation and progresses through network access control, identity stores, policy design, and day-to-day operations.

You will learn how to configure authentication and authorization policies, create scalable guest onboarding workflows, integrate network devices, and apply identity-based access decisions across wired and wireless environments. It also covers endpoint profiling, posture assessment, Terminal Access Controller Access Control Server (TACACS+) device administration, TrustSec concepts, certificate management, lifecycle operations, and advanced administration practices.

The labs provide you with practical experience in Cisco ISE personas, certificate-based authentication, TEAP (EAP Chaining), Bring Your Own Device (BYOD) onboarding, device profiling, guest services, and policy enforcement in real-world environments. A wide range of use cases are covered, including 802.1X, MAB, and certificate provisioning.

As a result of this training, you will be able to design, implement, and operate a Cisco ISE deployment that meets modern enterprise requirements for identity, security, visibility, and access control.

This training prepares you for the 300-715 SISE v1.1 exam. If passed, you earn the Cisco Certified Specialist - Security Identity Management Implementation certification and satisfy the concentration exam requirement for the Cisco Certified Network Professional (CCNP) Security certification. This training also earns you 32 Continuing Education (CE) credits toward recertification.

This training will help you:
  • Gain hands-on experience configuring, deploying, and operating Cisco ISE for identity-based access control in enterprise environments.
  • Develop skills to design and implement secure authentication, authorization, guest access, and BYOD onboarding policies for both wired and wireless networks.
  • Learn to integrate Cisco ISE with Active Directory, LDAP, and network devices, as well as configure endpoint profiling and compliance-based access controls.
  • Acquire troubleshooting techniques for authentication and policy issues using practical labs and reporting tools, improving real-world problem-solving abilities.
  • Prepare for the 300-715 SISE v1.1 exam.
What to Expect in the Exam:

Implementing and Configuring Cisco Identity Services Engine (300-715 SISE) v1.1 is a 90-minute exam associated with the Cisco Certified Specialist - Security Identity Management Implementation certification and satisfies the concentration exam requirement for the CCNP Security certification.

This exam tests your knowledge of Cisco ISE, including:

  • Architecture and deployment
  • Policy enforcement
  • Web Auth and guest services
  • Profiler
  • BYOD
  • Endpoint compliance
  • Network access device administration
Prerequisites

There are no prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are:

  • Familiarity with the Cisco IOS® Command-Line Interface (CLI) for wired and wireless network devices
  • Familiarity with Cisco Secure Client
  • Familiarity with Microsoft Windows operating systems
  • Familiarity with 802.1X

These skills can be found in the following Cisco Learning Offering:

  • Implementing and Operating Cisco Security Core Technologies (SCOR)

Who Should Attend

The primary audience for this course is as follows:

  • Network Security Engineers
  • Network Administrators
  • Consulting Security Engineers
  • Technical Solutions Architects
  • Network Managers
  • Sales Engineers
  • Account Managers
Course Objectives

Upon successful completion of this course, students will be able to meet these overall objectives:

  • Describe how Cisco ISE fits into contemporary network security architectures and the main functions, design motivations, and common use cases.
  • Examine the functional roles of Cisco ISE node personas, supported deployment models, licensing considerations, and their implications for design planning and scalability decisions.
  • Implement the installation workflows, platform requirements, and initial setup steps for deploying Cisco ISE on supported virtual and hardware platforms.
  • Evaluate the principles, message flow, and authorization outcomes of 802.1X-based network access, and Cisco ISE's contribution to the security of wired and wireless connections with identity-based controls.
  • Describe how MAB works, including its fallback behavior, flow sequence, and policy application within Cisco ISE, and how MAB provides access to non-802.1X-compatible devices.
  • Establish the role of NADs in Cisco ISE authentication workflows, and provide an outline of the steps required to add, configure, and validate NADs within Cisco ISE to ensure secure policy enforcement.
  • Discuss the role of internal and external identity sources in Cisco ISE, how user and device identities are managed, and how certificates are used for identity-based authentication.
  • Evaluate how to configure Cisco ISE to integrate with Active Directory and LDAP, and outline the key settings and connectivity requirements needed to support external user authentication.
  • Interpret how Cisco ISE selects identity sources during authentication and the logic and conditions that determine identity store sequences, fallback behavior, and identity normalization techniques.
  • Discuss the structure and purpose of policy sets in Cisco ISE, including how global and local constructs interact, how policy sets are matched and evaluated, and how authentication and authorization logic is organized within each policy set.
  • Identify how Cisco ISE evaluates authentication policies using rule conditions, identity store sequences, and dictionaries, as well as how behavior is applied when no rules match.
  • Interpret how Cisco ISE applies authorization policies following authentication, including how rules are constructed using Conditions Studio and matched against user and device attributes to apply appropriate access profiles.
  • Analyze Cisco ISE policies based on logs, RADIUS flow data, and session context to resolve authentication and authorization issues across different access scenarios.
  • Analyze how Cisco ISE provides web-based guest access using CWA, and distinguish between hotspot, self-registration, and sponsored access flows.
  • Establish global guest settings in Cisco ISE to define account lifecycle behavior, credential policies, communication methods, and access types for guests across supported onboarding processes.
  • Configure Cisco ISE guest portals to support different access flows, manage account lifecycles, and implement deployment models that are consistent with organizational policies and scalability requirements.
  • Set up sponsor-driven guest access in Cisco ISE via access roles, linking guest types to sponsor groups, and customizing portal behavior to support account creation and approval.
  • Establish a clear understanding of Cisco ISE's roles in secure and scalable BYOD access: its enterprise use cases, deployment models, policy-based control strategies, key components, Cisco ISE-specific capabilities, and onboarding designs such as single and dual SSIDs for seamless personal device integration into the network.
  • Configure Cisco ISE to deliver supplicants, issue certificates, and enforce policies as part of a complete BYOD onboarding pipeline.
  • Operate post-onboarding workflows using the My Device Portal, including revocation of certificates and device de-registration for lost or stolen endpoints.
  • Explain how Cisco ISE uses profiling to identify endpoints by taking advantage of classification logic, profiler components, data flows, and feed services to provide the foundation for advanced profiling and policy enforcement.
  • Analyze how Cisco ISE collects endpoint data using built-in probes, device sensors, and pxGrid enrichment, and how each method contributes to the accuracy and coverage of profiling.
  • Analyze how the profiling policies in Cisco ISE classify endpoints based on collection attributes, and how logical profiles are created and applied to support the decision-making process for determining access based on identity.
  • Design scalable profiling solutions by aligning design principles, probe selection, and NAD integration with diverse network environments.
  • Maintain visibility of profiling through dashboards and reporting tools, and improve deployment efficiency through optimization techniques.
  • Apply foundational understanding of Cisco ISE posture services, including agent types, flow logic, operational modes, and use cases.
  • Implement Cisco ISE to deliver posture agents and related resources to endpoints by configuring update services, portals, and delivery policies.
  • Administer Cisco ISE policies to ensure secure and compliant network access.
  • Test compliance-based access enforcement by simulating a variety of endpoint scenarios using Cisco AnyConnect.
  • Assess session behavior, interpret posture outcomes, and analyze reporting tools to confirm the effectiveness of posture policy application and remediation.
  • Examine Cisco ISE's use of TACACS+ for securing administrative access, including key AAA concepts and a comparison with RADIUS to illustrate centralized authentication and authorization.
  • Set up Cisco ISE for TACACS+-based device administration by configuring policy elements such as command sets, profiles, and policy sets.
  • Onboard network devices, define access permissions, and set up authentication and authorization rules to control administrator access.
  • Implement advanced TACACS+ authorization logic, implement administrator command access, and implement scalable deployments using proven design guidelines.
  • Compare Cisco's TrustSec core architecture, operation, and design considerations, including its enhancements and planning prerequisites for enterprise deployment.
  • Configure Cisco TrustSec segmentation in Cisco ISE, including SGT classification, SXP propagation, and tag-based policy enforcement.
  • Interpret how to operationalize Cisco ISE through system maintenance, backup and restore procedures, certificate management, and structured upgrades in production environments.

Course Outline:

  • Cisco ISE Evolution, Foundation, and Role
  • Architecture and Design
  • Cisco ISE Installation and Initial Config
  • 802.1X in Cisco ISE
  • MAB in Cisco ISE
  • Network Device Integration with Cisco ISE
  • Identity Sources and Authentication Types
  • Active Directory and LDAP Integration
  • Identity Selection and Resolution Logic
  • Cisco ISE Policy Framework
  • Authentication Policies
  • Authorization Policies
  • Troubleshoot Policies and Sessions
  • Guest Access Overview
  • Guest Access Policies and Settings
  • Guest Portals and Lifecycle Operations
  • Sponsor Portals
  • BYOD Architecture and Use Cases
  • BYOD Onboarding with Native Supplicant Provisioning
  • BYOD Lifecycle Operations
  • Profiling Architecture and Capabilities
  • Probes and Data Collection
  • Profile Policies and Authorization
  • Profile Monitoring and Design
  • Posture Service Flow and Agents
  • Posture Updates and Client Provisioning
  • Posture Policies and Compliance-Based Access
  • Posture Testing and Monitoring
  • AAA and TACACS+
  • TACACS+ Device Administration
  • TACACS+ Command Authorization
  • Cisco TrustSec Overview
  • Cisco TrustSec in Cisco ISE
  • Cisco ISE Administration

[ back to top ]



*Cisco Credits can not be used for travel or expense costs.

CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems® and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this web site are the property of their respective owners.


CED Solutions is your best choice for Cisco CCNP Security, Cisco CCNP Security training, Cisco CCNP Security certification, Cisco CCNP Security boot camp, Cisco CCNP Security certification training, Cisco CCNP Security certification course, Cisco CCNP Security course, Cisco CCNP Security class.



Cisco CCNP Security space
Search classes by keyword:
Search classes by category:


Copyright © 2026 CED Solutions. CED Solutions Refund Policy. All Rights Reserved.