Cisco Certified Network Professional (CCNP) Security
Credential: Cisco Certified Network Professional (CCNP) Security
Credentialing Agency: Cisco Systems, Inc.
Renewal Period: 3 years
The Cisco Certified Network Professional Security (CCNP Security) is a mid-level certification that validates the ability to plan, implement, verify and troubleshoot local and wide-area enterprise networks and work collaboratively with specialists on advanced security, voice, wireless and video solutions. CCNP Security is aligned to the job role of a Cisco Network Security Engineer responsible for security in routers, switches, networking devices and appliances, as well as choosing, deploying, supporting and troubleshooting firewalls, VPNS, and IDS/IPS solutions. Candidates must have a valid CCNA Security certification, or any CCIE Certification to be eligible for CCNP Security, and must successfully pass four examinations.
More information can be found on the certifying agency's website.
Cisco Certified Network Professional (CCNP) Security
MINIMUM REQUIREMENTS
Eligibility Requirements (View Details)
- Credential Prerequisite: CCNA Security or any CCIE certification
- Experience
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for becoming eligible. Listed are the minimum requirements based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
RECERTIFICATION SUMMARY
Renewal Period: 3 years
Credential Pre-requisite REQUIREMENTS
Candidates must hold a valid CCNA Security certification or any CCIE certification to be eligible for CCNP Security.
Other REQUIREMENTS
The Cisco Certified Network Professional (CCNP) Security credential has the following other requirements:
- Candidates must acknowledge the Cisco Career Certifications and Confidentiality Agreement online at the authorized testing center.
-
Candidates must agree to follow the Cisco Candidate Conduct Policy.
Written Exam 300-208 SISAS
-
1.0 Identity Management and Secure Access (33%)
- 1.1 Implement Device Administration
- 1.2 Describe Identity Management
- 1.3 Implement Wired/Wireless 802.1x
- 1.4 Implement MAB
- 1.5 Implement Network Authorization Enforcement
-
2.0 Threat Defense (10%)
- 2.1 Implement firewall
-
3.0 Troubleshooting, Monitoring and Reporting Tools (7%)
- 3.1 Troubleshoot identity management solutions
-
4.0 Threat Defense Architectures (17%)
- 4.1 Design highly secure wireless solution
-
5.0 Identity Management Architectures (33%)
- 5.1 Design AAA security solution
- 5.2 Design profiling security solution
- 5.3 Design posturing security solution
- 5.4 Design BYOD security solution
- 5.5 Design device admin security solution
- 5.6 Design guest services security solution
Written Exam 300-206 SENSS
-
1.0 Threat Defense (25%)
- 1.1 Implement firewall (ASA or IOS depending on which supports the implementation)
- 1.2 Implement Layer 2 Security
- 1.3 Configure device hardening per best practices
-
2.0 Cisco Security Devices GUIs and Secured CLI Management (25%)
- 2.1 Implement SSHv2, HTTPS, and SNMPv3 access on the network devices
- 2.2 Implement RBAC on the ASA/IOS using CLI and ASDM
- 2.3 Describe Cisco Prime Infrastructure
- 2.4 Describe Cisco Security Manager (CSM)
- 2.5 Implement Device Managers
-
3.0 Management Services on Cisco Devices (12%)
- 3.1 Configure NetFlow exporter on Cisco Routers, Switches, and ASA
- 3.2 Implement SNMPv3
- 3.3 Implement logging on Cisco Routers, Switches, and ASA using Cisco best practices
- 3.4 Implement NTP with authentication on Cisco Routers, Switches, and ASA
- 3.5 Describe CDP, DNS, SCP, SFTP, and DHCP
-
4.0 Troubleshooting, Monitoring and Reporting Tools (10%)
- 4.1 Monitor firewall using analysis of packet tracer, packet capture, and syslog
-
5.0 Threat Defense Architectures (16%)
- 5.1 Design a Firewall Solution
- 5.2 Layer 2 Security Solutions
-
6.0 Security Components and Considerations (12%)
- 6.1 Describe security operations management architectures
- 6.2 Describe Data Center security components and considerations
- 6.3 Describe Collaboration security components and considerations
- 6.4 Describe common IPv6 security considerations
Written Exam 300-209 SIMOS
-
1.0 Secure Communications (32%)
- 1.1 Site-to-site VPNs on routers and firewalls
- 1.2 Implement remote access VPNs
-
2.0 Troubleshooting, Monitoring and Reporting Tools (38%)
- 2.1 Troubleshoot VPN using ASDM & CLI
-
3.0 Secure Communications Architectures (30%)
- 3.1 Design site-to-site VPN solutions
- 3.2 Design remote access VPN solutions
- 3.3 Describe encryption, hashing, and Next Generation Encryption (NGE)
Written Exam 300-210 SITCS
-
1.0 Content Security (27%)
- 1.1 Cisco Cloud Web Security (CWS)
- 1.2 Cisco Web Security Appliance (WSA)
- 1.3 Cisco Email Security Appliance
-
2.0 Network Threat Defense (22%)
- 2.1 Cisco Next-Generation Firewall (NGFW) Security Services
- 2.2 Cisco Advanced Malware Protection (AMP)
-
3.0 Cisco FirePOWER Next-Generation IPS (NGIPS) (20%)
- 3.1 Configurations
- 3.2 Describe traffic redirection and capture methods
- 3.3 Deployments
-
4.0 Security Architectures (17%)
- 4.1 Design a web security solution
- 4.2 Design an email security solution
- 4.3 Design Cisco FirePOWER solutions
-
5.0 Troubleshooting, Monitoring and Reporting Tools (14%)
- 5.1 Design a web security solution
- 5.2 Cisco Web Security Appliance (WSA)
- 5.3 Cisco Email Security Appliance (ESA)
- 5.4 Cisco FirePOWER
Exam Preparation Resources
There are a number of resources available to help you prepare for the Cisco Certified Network Professional (CCNP) Security examination:
-
Best Sources
- Cisco Certification Resources
- Cisco Exam Information
- Cisco Learning Partner Lounge Lobby
- Cisco Recertification
- Implementing Cisco Secure Access Solutions (SISAS) 300-208 Exam Overview
- Implementing Cisco Edge Network Security Solutions (SENSS) 300-206 Exam Overview
- Implementing Cisco Secure Mobility Solutions (SIMOS) 300-209 Exam Overview
- Implementing Cisco Threat Control Solutions (SITCS) 300-210 Exam Overview
- General References
Testing Information
Testing for this credential is handled by Pearson VUE. The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
For more information on the Cisco Systems, Inc. testing process, visit the agency website.
RECERTIFICATION
Cisco Certified Network Professional (CCNP) Security
Renewal Period: 3 years