Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CCNP,CCIE Security SCOR (350-701) Training Part-2/2
Rating: 4.5 out of 5(511 ratings)
7,874 students

CCNP,CCIE Security SCOR (350-701) Training Part-2/2

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) with Step by Step Lab Workbook
Created byAhmad Ali
Last updated 7/2026
English
English [Auto],Thai [Auto],

What you'll learn

  • Compare common security vulnerabilities
  • Describe functions of the cryptography components
  • Compare site-to-site VPN and remote access VPN deployment types
  • Compare network security solutions that provide intrusion prevention
  • Configure and verify network infrastructure security methods
  • Device hardening of network infrastructure security devices
  • Implement segmentation, access control policies, AVC, URL filtering
  • Implement management options for network security solutions
  • Configure and verify site-to-site VPN and remote access VPN
  • Describe identity management and secure network access
  • common threats against on-premises and cloud environments
  • Configure secure network management of perimeter security
  • Configure AAA for device and network access
  • Identify security solutions for cloud environments

Course content

1 section92 lectures20h 47m total length
  • Before Starting This Course1:22
  • Lecture-95:Configure Initial Working Lab Cisco FTD and Cisco FMC.38:09

    Configure the initial working lab for Cisco FTD and FMC, including objects, security zones, and inside/outside interfaces. Deploy policies, test internet access, and review logs and dashboards on FMC.

  • Lecture-96:Configure and Verify Access Control Policies.13:51

    Configure and verify access control policies from layer 3 to 7, using ACPs to allow, deny, or monitor traffic, with top-to-bottom rule evaluation and application-based controls.

  • Lecture-97:Configure and Verify Pre-Filter Policy in FTD.12:55

    Configure and verify a pre filter policy in FTD to bypass or fast path traffic before deep packet inspection, linking it to the access control policy.

  • Lecture-98:Configure and Verify Intrusion Policy in FTD.10:16

    Configure and verify intrusion policy in FTD by selecting the built-in ips policies, understanding balance security and connectivity, and attaching the intrusion policy to access control rules for deployment.

  • Lecture-99:Configure and Verify SSL Policy in Cisco FTD.16:45

    Configure and verify SSL policy in Cisco FTD to decrypt TLS traffic, deploy self-signed or CA certificates, and integrate with access control policy for monitoring and logging.

  • Lecture-100:Configure and Verify Malware & File Policy in FTD.3:44

    Configure malware and file policy in FTD to inspect all uploads and downloads. Use a three-type policy—clean, unknown, and malware—and cloud lookup to block malicious files.

  • Lecture-101:Configure and Verify DNS Policy in Cisco FTD.8:11

    Configure and verify Cisco FTD's DNS policy using security intelligence feeds, whitelists, blacklists, and sinkhole actions, then attach to access control rules and test.

  • Lecture-102:Introduction and Concept of Security Intelligence in FTD.6:39

    Security intelligence is a threat intelligence database used by Cisco firepower to block malicious domains, IPs, and URLs before access control. It supports blacklists, whitelists, and DNS-based blocking.

  • Lecture-103:Introduction and Concept of IPS and Deployment Modes.14:37

    Explore the differences between intrusion detection and prevention systems, deployment modes like inline, promiscuous, span, and tape, and host-based versus network-based IPS with Cisco firepower.

  • Lecture-104:Install and Add Cisco NGIPS 6.2.3-83 on EVE-NG Lab.7:24

    Deploy Cisco firepower next generation IPS 6.2.3-83 on an Eve-NG lab, using winscp to transfer and unzip the image, rename the files correctly, set permissions, and boot to verify operation.

  • Lecture-105:Cisco Firepower NGIPS First Time Configuration Lab.9:23

    configure and register Cisco firepower ngips for first-time setup, including admin login, password change, ipv4 settings, hostname and dns, deployment mode (inline or passive), and FMC registration for centralized management.

  • Lecture-106:Basic Terminologies Proxy,Forward and Reverse Proxy etc.13:41

    Explore basic terminologies, including proxy concepts and forward, reverse, and full proxy with SSL offloading. Review TCP three-way handshake, HTTP/HTTPS, and the role of TCP/UDP ports and well-known ports.

  • Lecture-107:Introduction to Cisco Ironport WSA, Need and Features.9:17

    Introduce Cisco Web Security Appliance (WSA), formerly Ironport, a web proxy and security appliance that secures http/https traffic, blocks threats, and provides URL filtering, malware protection, DLP, and cloud intelligence.

  • Lecture-108:Introduction to Cisco Ironport WSA Deployment Modes.7:36

    learn the two Cisco Ironport wsa deployment modes—explicit and transparent—and how to configure browsers or gateways to forward http, https, and ftp traffic to the proxy.

  • Lecture-109:Install Cisco Ironport WSA Version 10 on EVE NG Lab.8:56

    Learn to install Cisco Ironport WSA version 10 in the Eve NG lab, configure SFTP access, prepare and import the ready image, then boot and login with default credentials.

  • Lecture-110:Configure Basic Topology for Cisco WSA in EVE NG Lab.21:46

    Configure a basic Cisco WSA topology in an Eve-NG lab, linking a DMZ, internal network, and internet through NAT, DNS, and routing, with management and internet clouds.

  • Lecture-111:Cisco Ironport WSA First Time CLI Configuration Lab.8:24

    Configure the Cisco Web Security Appliance for first-time access, set the management IPv4 address, hostname, enable ssh and http/https, then commit and verify http-to-https redirection.

  • Lecture-112:Configure License Cisco Ironport WSA Version 10 Lab.8:19

    Learn to license the Cisco Ironport WSA Version 10 by connecting over SSH, loading the license via CLI, pasting the license content, pressing Ctrl-D, and accepting the agreement.

  • Lecture-113:Cisco WSA First Time Configuration Setup Wizard Lab.5:26

    Configure the Cisco WSA on first login with the setup wizard, setting DNS, hostname, http server, proxy, security features, and then change administrator password and select explicit or transparent mode.

  • Lecture-114:Traffic Redirection Explicit Mode Cisco Ironport WSA.16:08

    Explore explicit mode for Cisco WSA, configuring each client's proxy settings, routing http and https traffic through the proxy, and validating with logs, dashboards, and policy testing.

  • Lecture-115:Access Policies & Identification Profile in Cisco WSA.17:57

    Explore access policies and identification profiles in Cisco WSA, including how to define IP-based identification, apply URL filtering, and test policies with policy trace and decryption requirements.

  • Lecture-116:Configure and Verify Custom URL Category Cisco in WSA.7:21

    Configure a custom url category in Cisco WSA, block BBC.com via a dedicated policy, commit changes, and verify with policy tracer and logs.

  • Lecture-117:Application Visibility, Objects & Anti-Malware Policies.18:46

    Explore application visibility and control by configuring global and object policies to block specific apps like Facebook and Messenger, set bandwidth limits, and apply https decryption and anti-malware checks.

  • Lecture-118:Traffic Redirection Transparent Mode Cisco Ironport WSA.26:27

    Learn how to deploy transparent mode with Cisco devices using policy-based routing and WCCP to redirect http and https traffic to a proxy, without client-side configuration.

  • Lecture-119:Introduction to Cisco Ironport ESA Features and Functions.13:20

    Explore Cisco Ironport ESA features and functions, including email security, spam and malware protection, reputation filtering, data loss prevention, encryption, and cloud-based threat intelligence for inbound and outbound email.

  • Lecture-120:Basic Terminologies of Cisco Ironport ESA and EMail.12:32

    Learn core email security terminology, including SMTP for sending, IMAP/POP3 for receiving, MX records, MTA and MUA roles, MIME, and common threats like spam, phishing, spoofing, and worms.

  • Lecture-121:Install Cisco Ironport ESA Version 10 on EVE NG.5:06

    Install Cisco Ironport ESA version 10 on EVE-NG by downloading, unzipping, and dragging the ready-made images into EVE-NG, then applying the setup command to boot the appliance.

  • Lecture-122:Configure Basic Topology for Cisco ESA in EVE NG.9:44

    Configure a Cisco ESA topology in EVE-NG with a management-connected core, edge router, DMZ ESR, abc.com, and DNS, routing email per policies.

  • Lecture-123:Cisco Ironport ESA First Time CLI Configuration Lab.5:42

    Perform first-time cli setup of Cisco ironport esa: login with admin/ironport, set management ip 192.168.1.100, hostname esa.abc.com, enable ssh and https, save, commit, and ping the address.

  • Lecture-124:Configure License Cisco Ironport ESA Version 10 Lab.3:01

    License the Cisco Ironport ESA by connecting via ssh—through the console—loading and pasting the license, and pressing ctrl-d to apply; then log in with admin and ironport credentials.

  • Lecture-125:Cisco ESA First Time Configuration Setup Wizard Lab.5:19

    Walks through the Cisco ESA first time configuration using the system setup wizard, configuring host name, email alerts, gateway, DNS, and inbound domain abc.com.

  • Lecture-126:Windows DNS Server Installation and Configuration Lab.12:53

    Install and configure Windows dns server, set static ips, create forward and reverse zones for abc.com and xyz.com, and add imap, smtp, and mx records.

  • Lecture-127:Install, Setup and Configure hMailServer Email Server.11:58

    Install, set up, and configure hmailserver for test labs, create abc.com and xyz.com domains, add admin and user accounts, and configure IP addresses and firewall adjustments.

  • Lecture-128:Install, Setup and Configure Thunderbird Email Client.18:43
  • Lecture-129:Cisco ESA Incoming Content Filters & Email Policies Lab.31:29

    Explore Cisco ESA incoming content filters and email policies in a hands-on lab, configuring DNS SMTP routing, Exchange server delivery, and content filters to block hackers and bomb keywords.

  • Lecture-130:Cisco ESA Outgoing Content Filters & Email Policies Lab.10:57

    Configure outbound email protection with Cisco ESA, including outgoing content filters, mail flow policies, relay groups, sender rules, and logs to test and monitor.

  • Lecture-131:Introduction and Concept of OpenDNS and Cisco Umbrella.18:57

    Trace the origins of OpenDNS and Cisco Umbrella, and learn how cloud-based DNS protection blocks phishing and malicious sites by routing queries through two secure DNS servers.

  • Lecture-132:Introduction and Concept of Endpoint EPP and EDR.6:18

    Learn how endpoint protection platform and endpoint detection and response secure end devices, monitor behavior, prevent known and unknown threats, and provide visibility and rapid response.

  • Lecture-133:Introduction and Concept of Multifactor Authentication.5:20

    Multi-factor authentication requires more than one method to log in, combining something you know with something you are, plus a second factor such as a code sent to mobile.

  • Lecture-134:Introduction and Concept of Mobile Device Management MDM.5:34

    Explore mobile device management (MDM) to secure BYOD with Meraki by enrolling devices, enabling encryption, remote lock and wipe, GPS tracing, and managing apps, profiles, and email access.

  • Lecture-135:Role of The Endpoint Protection from Phishing Attacks.5:34

    Protect endpoints with antivirus, anti-spyware, and endpoint protection agents, firewalls, and email filtering; keep OS, apps, and firmware updated, and enforce MFA to defend against phishing.

  • Lecture-136:Introduction & Concept of Advanced Malware Protection.19:53

    Explore advanced malware protection with Cisco AMP, a cloud-based endpoint security using static and dynamic analysis, threat intelligence, and sandboxing to monitor endpoints from a central dashboard.

  • Lecture-137:Introduction and Concept of Endpoint Patching Strategy.4:52

    Explore the endpoint patching strategy, citing WannaCry, and emphasize keeping all endpoints—Windows, Mac, Linux, servers, printers, laptops, tablets—up to date with patch management.

  • Lecture-138:Interpret Basic Python Scripts Network Automation Lab.28:26

    Explore network automation with Python scripts that automate configuration, management, testing, and deployment across switches, routers, and firewalls, with basics of Python versions 2 and 3 and VLAN lab demos.

  • Lecture-139:Introduction to Application Programming Interface API.6:44

    Discover how an application programming interface (API) acts as a middleman between applications and devices, enabling services like maps, weather, and payments using XML or JSON.

  • Lecture-140:NETCONF Application Programming Interface Theory & Lab.29:17

    Explore netconf and restconf as network configuration apis, showing how netconf uses ssh and port 830 to configure, retrieve, and monitor devices as a southbound api through get-config and edit-config.

  • Lecture-141:RESTCONF Application Programming Interface Theory & Lab.12:06

    Explore restconf as a lightweight api alternative to netconf, using http/https and json messages to retrieve and configure devices with get, post, put, patch, and delete.

  • Lecture-142:Introduction and Concept of Software Defined Networking.15:08

    Explore software defined networking concepts, including central controller architecture, three planes (application, control, data), and how a controller centralizes routing decisions for all devices.

  • Lecture-143:Introduction to North Bound API and South Bound API.4:46

    Explain northbound api and southbound api roles in a network stack, showing how rest-based api links applications to the controller and netconf/restconf links the controller to devices.

  • Lecture-144:Introduction & Concept of Cisco DNA Center (Cisco DNAC).14:25

    Cisco DNA Center serves as a central device and cloud-based platform that unites all network devices for design, provisioning, policy, and health assurance from a single dashboard.

  • Lecture-145:Introduction to Cloud and Different Types of Cloud.23:25

    Explore cloud concepts by contrasting on premises with cloud and define private, public, hybrid, and community clouds. Assess pay-as-you-go models, scalability, and security implications for organizations.

  • Lecture-146:Introduction and Concept of Cloud Service Models.13:17

    Explore cloud service models—software as a service, platform as a service, and infrastructure as a service—where providers host apps like Google Docs and Google Drive.

  • Lecture-147:Introduction and Concept of Cloud Patch Management.7:36

    Understand cloud patch management, updating end devices, servers, OS, and applications to prevent vulnerabilities, and explore IaaS, PaaS, and SaaS responsibilities with practical update steps.

  • Lecture-148:Introduction to Security Assessment in the Cloud.4:54

    Learn to perform security assessment in the cloud by evaluating documentation, access controls, MFA, disaster recovery, and SLAs, just as you assess a house before buying.

  • Lecture-149:Introduction to Cloud Access Security Brokder (CASB).5:24

    Explore how a cloud access security broker (casb) sits between users and cloud services to provide visibility, compliance, data security, data loss prevention, and threat protection.

  • Lecture-150:Introduction and Concept of DevOps and DevSecOps.14:33

    Define how devops unites development and operations to speed delivery through continuous development, testing, integration, deployment, and monitoring, and how devsecops embeds security across every stage with ten practices.

  • Lecture-151:Introduction and Concept of CI/CD Pipeline in DevOps.9:30

    Learn about ci cd in devops, including continuous integration, continuous delivery, and continuous deployment, and how a ci cd pipeline automates build, test, and production deployment.

  • Lecture-152:Concept of Docker, Container & Container Orchestration.15:31

    Explore Docker, containers, and container orchestration, explaining how containers replace virtual machines for lightweight, portable applications, and how Kubernetes orchestrates deployment, scaling, and networking.

  • Lecture-153:Cloud Logging and Monitoring Secure Cloud Analytics.6:55

    Explore cloud logging and monitoring with Cisco Secure Cloud Analytics, aka steel watch cloud, using NetFlow, telemetry, and VPC flow logs to detect threats in real time across public clouds.

  • Lecture-154:Introduction to Cisco Identity Services Engine (ISE).16:30

    Explore Cisco ISE as a centralized policy control point that uses identity and context to authenticate, posture, profile, and authorize access across wired, wireless, and VPN networks.

  • Lecture-155:Install and Configure Cisco ISE on VMware Workstation.17:56

    Install and configure Cisco ISE on VMware Workstation by importing the virtual evaluation package, adjusting network interfaces, and setting IP, DNS, and admin credentials to access the GUI.

  • Lecture-156:Add, Install and Configure Cisco ISE on EVE-NG.17:18

    Install Cisco ISE on Eve-ng or VMware, set RAM to 8 to 10 gb, add a 200 gb drive, import the 16 gb image, and configure gig0 IP.

  • Lecture-157:Cisco Identity Services Engine (ISE) CLI Commands.8:03

    Explore Cisco identity services engine (ISE) cli commands and navigation, mirroring Cisco ios router and switch syntax, including config mode, show commands, backups, and basic management tasks.

  • Lecture-158:Cisco Identity Services Engine Dashboard Walkthrough.15:09

    Explore the Cisco Identity Services Engine dashboard after login, featuring widgets for system summary, alarms, authentication, and endpoint details, with admin, monitoring, and policy services personas.

  • Lecture-159:Cisco Identity Services Engine Basic Terminologies.9:46

    Explore Cisco ISE terminology: identity and identity store (local or external such as Active Directory or LDAP), nodes as virtual appliances, plus admin, policy, and monitoring personas.

  • Lecture-160:Cisco Identity Services Engine Three Persona Theory.12:41

    Explore Cisco ISE three personas—monitoring node, policy administration node, and policy service node—and how each handles logs, reporting, administration, and policy provisioning, with the work center consolidating related tasks.

  • Lecture-161:Cisco Identity Services Engine Deployment Options.13:38

    Explore Cisco ISE deployment options, from stand-alone to fully distributed, dividing administration, monitoring, and policy services across devices to ensure redundancy and high availability.

  • Lecture-162:Introduction to Device Administration & Network Access.11:05

    Configure network devices from a centralized Cisco ISE platform to manage device administration and enforce network access through authentication and authorization for multiple devices and users.

  • Lecture-163:Introduction, Theory and Concept of AAA Server.14:59
  • Lecture-164:Introduction to AAA Options TACACS+ and RADIUS Protocols.6:40

    Compare tacacs+ and radius for aaa, detailing tcp vs udp transport, encryption of communications, and the differences in authentication, authorization, and accounting; explain use for network access versus device administration.

  • Lecture-165:Introduction and Concept of 802.1X (Dot1x) & Components.13:53

    Explain 802.1x dot1x port-based authentication, its EAPOL flow, and the roles of supplicant, authenticator, and authentication server in wired and wireless networks with Cisco ISE.

  • Lecture-166:Introduction to 802.1X (Dot1x) Port States and Host Modes.11:26

    Discover 802.1x port states auto, force authorized, and unauthorized on Cisco switches, and learn host modes single host, multi-host, multi-domain, and multi-authentication.

  • Lecture-167:Configure and Verify AAA 802.1X (Dot1x) Lab.36:14

    Configure and verify a dot1x 802.1X lab using a Cisco switch as authenticator, Windows 7 as supplicant, and Cisco ISE with radius for authentication, authorization, and accounting.

  • Lecture-168:Introduction to Media Access Control Authentication Bypass.7:03

    Explore media access control authentication bypass, using mac addresses stored in a database as username and password to authenticate devices without 802.1x via Cisco ISE.

  • Lecture-169:Configure Media Access Control Authentication Bypass Lab.21:25

    Learn how to implement mac address authentication bypass using the map command with 802.1x and radius on Cisco ISE, configure the interface map, register endpoints, and verify sessions.

  • Lecture-170:Introduction and Concept of Downloadable ACL (DACL).5:36

    Learn how downloadable ACLs (decal) simplify policy management across hundreds of switches by centralizing dynamic ACLs in Cisco ISE and automatically downloading them to network devices.

  • Lecture-171:Configure and Verify Downloadable ACL (DACL) Lab.27:01

    Configure and verify downloadable ACLs (DACL) with policy sets and authorization profiles, delivering dynamic per-user access controls downloaded to Cisco switches to restrict access to a server.

  • Lecture-172:Introduction and Concept of Dynamic VLAN (DVLAN).4:04

    Learn how dynamic vlan automatically assigns interfaces to vlans based on identity, mac address, or authentication via mab and ise, contrasting with static vlan configuration.

  • Lecture-173:Configure and Verify Dynamic VLAN (DVLAN) Lab.11:16
  • Lecture-174:Introduction to Central Web Authentication (CWA).6:59

    Learn central web authentication (CWA) that redirects users to a web portal for login, enabling guest access, temporary credentials, and automatic guest vlan assignment via Cisco ISE.

  • Lecture-175:Configure and Verify Central Web Authentication Lab.42:22

    Explore configuring central web authentication in a Cisco switch and ISE lab, creating authentication and authorization policies and downloadable ACLs for web portal redirection.

  • Lecture-176:Configure and Verify Device Administration Lab.41:18
  • Lecture-177:Introduction and Concept of Guest Services in ISE.26:57

    Learn how Cisco ISE implements guest services, including hotspot and sponsor portals, self-register and lobby ambassador options, diverse guest types, and central or local web authentication to isolate guest networks.

  • Lecture-178:Introduction and Concept of BYOD in Cisco ISE.8:07

    Learn how BYOD integrates with Cisco ISE, registering personal devices via a portal, applying MDM policies, and enforcing authentication and authorization to access corporate resources securely.

  • Lecture-179:Introduction and Concept of Change of Authorization CoA.9:38

    Change of authorization (CoA) lets Cisco ISE re-authenticate an authenticated endpoint when policies change. Configure globally or per-profile to trigger re-authentication or port bounce.

  • Lecture-180:Introduction to Profiling, Profiler Services & Probes.27:16

    Explore how Cisco ISE profiling uses profiler services and probes to classify endpoints with profiles, using MAC addresses, hostnames, and network data to differentiate Windows, Apple, and more.

  • Lecture-181:Configure and Verify Profiling using ISE Probes Lab.29:33

    Configure and verify endpoint profiling in Cisco ISE using multiple probes, including radius, dhcp, and snmp, to assign accurate endpoint profiles like Windows 7 or Apple devices.

  • Lecture-182:Introduction and Concept of Posture in Cisco ISE.5:07

    Posture in Cisco ISE checks antivirus, service packs, OS updates, firewall, and registry keys to gauge endpoint health before network access, using web agent or Cisco AnyConnect.

  • Lecture-183:Introduction to Endpoint Compliance in Cisco ISE.13:00

    Learn how endpoint compliance in Cisco ISE uses posture assessment and health checks to classify devices as compliant, non-compliant, or unknown, and govern access via client provisioning.

  • Lecture-184:Introduction and Concept of Network Telemetry.8:14

    Explore network telemetry, a real-time push data method that replaces polling, streaming json-encoded data via yang models with netconf and restconf for live device visibility.

  • Lecture-185:Introduction and Concept of Data Ex-filtration.14:46

    Data exfiltration means unauthorized copying or transferring data from a computer or network. Cyber criminals use DNS tunneling, ICMP tunneling, HTTPS, FTP, SFTP, SSH, SCP, and email to exfiltrate data.

Requirements

  • Basic IP and security knowledge is nice to have.
  • Students need to understand basic networking.
  • CCNA routing and Switching Knowledge
  • Students needs to understand Networking Fundamentals.
  • Describe the concept of DevSecOps

Description

Master Cisco Security Technologies and prepare for the Cisco Implementing and Operating Cisco Security Core Technologies (350-701 SCOR) exam through comprehensive hands-on labs, real-world scenarios, and enterprise security deployments.

This course is designed for network engineers, cybersecurity professionals, security administrators, SOC analysts, and Cisco certification candidates who want to build a strong foundation in modern enterprise security technologies.

Starting with fundamental security concepts, you'll progress through advanced topics including network security, Zero Trust architecture, identity management, VPN technologies, cloud security, Cisco Secure solutions, automation, APIs, and security operations.

Every topic is explained with detailed theory, practical demonstrations, enterprise deployment examples, and troubleshooting exercises to help you develop real-world cybersecurity skills.

What You'll Learn

Security Fundamentals

  • Understand the CIA Triad and security principles

  • Identify common threats targeting enterprise and cloud environments

  • Understand malware, ransomware, phishing, insider threats, and advanced persistent threats (APTs)

  • Apply security best practices using defense-in-depth and Zero Trust principles

Network Security

  • Configure and verify network infrastructure security

  • Secure Layer 2 and Layer 3 networks

  • Configure secure device management

  • Implement Access Control Lists (ACLs)

  • Configure network segmentation and micro-segmentation

  • Configure Cisco TrustSec concepts

  • Understand Application Visibility and Control (AVC)

Identity and Access Management

  • Configure AAA using TACACS+ and RADIUS

  • Configure Authentication, Authorization, and Accounting

  • Understand Identity Management concepts

  • Implement secure network access policies

  • Understand Multi-Factor Authentication (MFA) concepts

  • Implement Role-Based Access Control (RBAC)

VPN Technologies

  • Configure Site-to-Site IPsec VPNs

  • Configure Remote Access VPNs

  • Understand VPN security best practices

  • Verify and troubleshoot VPN connectivity

Cisco Security Solutions

  • Cisco Secure Firewall fundamentals

  • Cisco Secure Firewall Threat Defense (FTD)

  • Cisco Secure Firewall Management Center (FMC)

  • Cisco Secure Endpoint concepts

  • Cisco Secure Email

  • Cisco Secure Web Appliance

  • Cisco Umbrella

  • Cisco Secure Access concepts

  • Cisco Secure Network Analytics concepts

Intrusion Prevention and Threat Protection

  • Understand Next-Generation Firewall (NGFW)

  • Configure Intrusion Prevention Systems (IPS)

  • Understand malware protection

  • Configure content filtering

  • Understand DNS-layer security

  • Explore threat intelligence and security analytics

Cloud Security

  • Understand cloud security principles

  • Compare SaaS, PaaS, and IaaS service models

  • Learn the shared responsibility model

  • Secure public, private, and hybrid cloud environments

  • Perform security assessments in cloud environments

  • Understand cloud patch management

  • Implement cloud security best practices

SDN and Network Automation

  • Understand Software-Defined Networking (SDN)

  • Compare Northbound and Southbound APIs

  • Learn automation fundamentals

  • Understand Cisco security APIs

  • Interpret basic Python scripts for Cisco security automation

  • Explore REST APIs and JSON

Visibility, Monitoring, and Telemetry

  • Understand network telemetry

  • Configure logging and monitoring

  • Implement traffic capture and redirection

  • Analyze security events

  • Generate reports and dashboards

  • Improve visibility across enterprise networks

DevSecOps and Modern Security Operations

  • Understand DevSecOps principles

  • Integrate security into CI/CD pipelines

  • Automate security validation

  • Learn secure application deployment concepts

This Course Includes

  • Complete SCOR (350-701) coverage

  • Enterprise security architecture

  • Step-by-step configuration demonstrations

  • Hands-on lab exercises

  • Real-world enterprise scenarios

  • VPN implementation

  • AAA configuration

  • Cloud security concepts

  • Security automation

  • API demonstrations

  • Python automation examples

  • Downloadable lab files and study materials

  • Practical troubleshooting exercises

  • Lifetime course updates

Why Learn Cisco Security Technologies?

Organizations today require security professionals who can protect enterprise networks, cloud environments, applications, users, and devices against constantly evolving cyber threats.

The Cisco Security Core (SCOR) certification validates the knowledge and practical skills required to implement modern enterprise security solutions, making it one of the most valuable certifications for cybersecurity professionals.

The technologies covered in this course are widely used by enterprises, financial institutions, government agencies, healthcare organizations, telecommunications providers, and cloud service providers.

Who This Course Is For

  • Cisco 350-701 SCOR certification candidates

  • CCNP Security candidates

  • CCIE Security candidates

  • Network Security Engineers

  • Cybersecurity Engineers

  • Security Administrators

  • SOC Analysts

  • Network Engineers

  • System Administrators

  • Cloud Security Engineers

  • IT Professionals interested in enterprise security

Prerequisites

To get the most from this course, you should have:

  • Basic networking knowledge

  • Understanding of TCP/IP

  • Familiarity with routing and switching

  • Basic knowledge of firewalls and security concepts is helpful but not required

No previous Cisco Security experience is required. Every concept is explained from the fundamentals through practical demonstrations.

By the End of This Course

By completing this course, you will confidently understand and implement modern Cisco security technologies used to protect enterprise networks and cloud environments. You will gain practical knowledge of identity management, network segmentation, VPNs, AAA, cloud security, Cisco Secure solutions, network automation, APIs, DevSecOps, and security operations.

Whether your goal is to earn the Cisco 350-701 SCOR certification, prepare for CCNP Security or CCIE Security, or build the practical skills required for a career in enterprise cybersecurity, this course provides the knowledge and hands-on experience needed to succeed.

Who this course is for:

  • Course has been designed for anyone who wants to start learning Security
  • This course is for students trying to obtain the CCNP and CCIE SCOR
  • This course is for students trying to learn the CCNP Security
  • Any Network or Security Engineer want to learn or polish their Skills.