Published by Cisco Press (November 9, 2023) © 2024
Omar SantosTrust the best-selling Official Cert Guide series from Cisco Press to help you learn, prepare, and practice for the CCNP and CCIE Security Core SCOR 350-701 exam. Well regarded for its level of detail, study plans, assessment features, and challenging review questions and exercises, CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide, Second Edition helps you master the concepts and techniques that ensure your exam success and is the only self-study resource approved by Cisco. Expert author Omar Santos shares preparation hints and test-taking tips, helping you identify areas of weakness and improve both your conceptual knowledge and hands-on skills.
This complete study package includes
- A test-preparation routine proven to help you pass the exam
- Do I Know This Already? quizzes, which let you decide how much time you need to spend on each section
- Exam Topic lists that make referencing easy
- Chapter-ending exercises, which help you drill on key concepts you must know thoroughly
- The powerful Pearson Test Prep Practice Test software, complete with hundreds of well-reviewed, exam-realistic questions, customization options, and detailed performance reports
- A final preparation chapter, which guides you through tools and resources to help you craft your review and test-taking strategies
- Study plan suggestions and templates to help you organize and optimize your study time
Content Update Program:
This fully updated second edition includes the latest topics and additional information covering changes to the latest CCNP and CCIE Security Core SCOR 350-701 exam. Visit ciscopress.com/newcerts for information on annual digital updates for this book that align to Cisco exam blueprint version changes.
This official study guide helps you master all the topics on the CCNP and CCIE Security Core SCOR 350-701 exam, including
- Network security
- Cloud security
- Content security
- Endpoint protection and detection
- Secure network access
- Visibility and enforcement
Companion Website:
The companion website contains more than 200 unique practice exam questions, practice exercises, and a study planner
Pearson Test Prep online system requirements:
Browsers: Chrome version 73 and above, Safari version 12 and above, Microsoft Edge 44 and above.
Devices: Desktop and laptop computers, tablets running Android v8.0 and above or iPadOS v13 and above, smartphones running Android v8.0 and above or iOS v13 and above with a minimum screen size of 4.7”. Internet access required.
Pearson Test Prep offline system requirements:
Windows 11, Windows 10, Windows 8.1; Microsoft .NET Framework 4.5 Client; Pentium-class 1 GHz processor (or equivalent); 512 MB RAM; 650 MB disk space plus 50 MB for each downloaded practice exam; access to the Internet to register and download exam databases
Also available from Cisco Press for CCNP Advanced Routing study is the CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide Premium Edition eBook and Practice Test, Second Edition This digital-only certification preparation product combines an eBook with enhanced Pearson Test Prep Practice Test.
This integrated learning package
- Enables you to focus on individual topic areas or take complete, timed exams
- Includes direct links from each question to detailed tutorials to help you understand the concepts behind the questions
- Provides unique sets of exam-realistic practice questions
- Tracks your performance and provides feedback on a module-by-module basis, laying out a complete assessment of your knowledge to help you focus your study where it is needed most
Introduction xxxi
Chapter 1 Cybersecurity Fundamentals 2
“Do I Know This Already?” Quiz 3
Foundation Topics 6
Introduction to Cybersecurity 6
Defining What Are Threats, Vulnerabilities, and Exploits 8
Common Software and Hardware Vulnerabilities 31
Confidentiality, Integrity, and Availability 43
Cloud Security Threats 50
IoT Security Threats 54
An Introduction to Digital Forensics and Incident Response 58
Summary 76
Exam Preparation Tasks 76
Review All Key Topics 76
Define Key Terms 78
Review Questions 78
Chapter 2 Cryptography 80
“Do I Know This Already?” Quiz 80
Foundation Topics 82
Introduction to Cryptography 82
Fundamentals of PKI 97
Exam Preparation Tasks 106
Review All Key Topics 106
Define Key Terms 107
Review Questions 107
Chapter 3 Software-Defined Networking Security and Network Programmability 110
“Do I Know This Already?” Quiz 110
Foundation Topics 112
Software-Defined Networking (SDN) and SDN Security 112
Introduction to Network Programmability 136
Exam Preparation Tasks 151
Review All Key Topics 151
Define Key Terms 152
Review Questions 152
Chapter 4 Authentication, Authorization, Accounting (AAA) and Identity Management 156
“Do I Know This Already?” Quiz 157
Foundation Topics 160
Introduction to Authentication, Authorization, and Accounting 160
Authentication 162
Authorization 177
Accounting 179
Infrastructure Access Controls 179
AAA Protocols 182
Cisco Identity Services Engine (ISE) 192
Configuring TACACS+ Access 207
Configuring RADIUS Authentication 213
Additional Cisco ISE Design Tips 222
Exam Preparation Tasks 225
Review All Key Topics 225
Define Key Terms 226
Review Questions 227
Chapter 5 Network Visibility and Segmentation 232
“Do I Know This Already?” Quiz 233
Foundation Topics 236
Introduction to Network Visibility 236
NetFlow 237
IP Flow Information Export (IPFIX) 249
NetFlow Deployment Scenarios 255
Cisco Secure Network Analytics and Cisco Secure Cloud Analytics 263
Cisco Cognitive Intelligence and Cisco Encrypted Traffic Analytics (ETA) 274
NetFlow Collection Considerations and Best Practices 279
Configuring NetFlow in Cisco IOS and Cisco IOS-XE 280
Configuring NetFlow in NX-OS 295
Introduction to Network Segmentation 296
Micro-Segmentation with Cisco ACI 301
Segmentation with Cisco ISE 302
Exam Preparation Tasks 312
Review All Key Topics 312
Define Key Terms 313
Review Questions 314
Chapter 6 Infrastructure Security 316
“Do I Know This Already?” Quiz 317
Foundation Topics 320
Securing Layer 2 Technologies 320
VLAN and Trunking Fundamentals 320
Common Layer 2 Threats and How to Mitigate Them 333
Network Foundation Protection 343
Understanding and Securing the Management Plane 345
Understanding the Control Plane 347
Understanding and Securing the Data Plane 348
Securing Management Traffic 350
Implementing Logging Features 378
Configuring NTP 379
Securing the Network Infrastructure Device Image and Configuration Files 380
Securing the Data Plane in IPv6 381
Securing Routing Protocols and the Control Plane 395
Exam Preparation Tasks 404
Review All Key Topics 404
Define Key Terms 405
Review Questions 405
Chapter 7 Cisco Secure Firewall 410
“Do I Know This Already?” Quiz 410
Foundation Topics 413
Introduction to Cisco Secure Firewall 413
Comparing Network Security Solutions That Provide Firewall Capabilities 435
Deployment Modes of Network Security Solutions and Architectures That Provide Firewall Capabilities 437
High Availability and Clustering 448
Implementing Access Control 452
Cisco Firepower Intrusion Policies 472
Cisco Secure Malware Defense 478
Security Intelligence, Security Updates, and Keeping Firepower Software Up to Date 483
Exam Preparation Tasks 484
Review All Key Topics 485
Define Key Terms 486
Review Questions 486
Chapter 8 Virtual Private Networks (VPNs) 490
“Do I Know This Already?” Quiz 490
Foundation Topics 494
Virtual Private Network (VPN) Fundamentals 494
Deploying and Configuring Site-to-Site VPNs in Cisco Routers 506
Configuring Site-to-Site VPNs in Cisco ASA Firewalls 528
Configuring Remote-Access VPNs in the Cisco ASA 537
Configuring Clientless Remote Access SSL VPNs in the Cisco ASA 540
Configuring Client-Based Remote-Access SSL VPNs in the Cisco ASA 551
Configuring Remote-Access VPNs in Cisco Secure Firewall 556
Configuring Site-to-Site VPNs in the Cisco Secure Firewall 567
Cisco SD-WAN 569
Exam Preparation Tasks 573
Review All Key Topics 573
Define Key Terms 574
Review Questions 575
Chapter 9 Securing the Cloud 578
“Do I Know This Already?” Quiz 579
Foundation Topics 581
What Is Cloud and What Are the Cloud Service Models? 581
DevOps, Continuous Integration (CI), Continuous Delivery (CD), and
Describing the Customer vs. Provider Security Responsibility for the Different Cloud Service Models 605
Cisco Umbrella 608
Cisco Secure Email Threat Defense 614
Cisco Attack Surface Management (Formerly Cisco Secure Cloud Insights) 616
Cisco Secure Cloud Analytics 618
AppDynamics Cloud Monitoring 619
Cisco Secure Workload 622
Cisco XDR 627
Exam Preparation Tasks 632
Review All Key Topics 633
Define Key Terms 634
Review Questions 634
Chapter 10 Content Security 638
“Do I Know This Already?” Quiz 638
Foundation Topics 641
Content Security Fundamentals 641
Cisco Secure Web Appliance 642
Cisco Secure Email 658
Cisco Content Security Management Appliance (SMA) 662
Exam Preparation Tasks 667
Review All Key Topics 668
Define Key Terms 668
Review Questions 669
Chapter 11 Endpoint Protection and Detection 672
“Do I Know This Already?” Quiz 672
Foundation Topics 674
Introduction to Endpoint Protection and Detection 674
Cisco Secure Endpoint 676
Cisco Threat Response 693
Exam Preparation Tasks 693
Review All Key Topics 693
Define Key Terms 694
Review Questions 694
Chapter 12 Final Preparation 696
Hands-on Activities 696
Suggested Plan for Final Review and Study 696
Summary 697
Chapter 13 CCNP and CCIE Security Core SCOR (350-701) Exam Updates 698
The Purpose of This Chapter 698
News about the Next Exam Release 700
Updated Technical Content 700
Appendix A Answers to the “Do I Know This Already?” Quizzes and Q&A
Glossary 714
Online Element
Appendix B Study Planner
9780138221263, TOC, 10/2/23