Free knowledge base

Cisco CCNP Security Core (SCOR) 350-701 — key terms, tricks & tips

Everything from the course in one searchable place: 321 entries. Use it to review before a practice test or look up a word you forgot.

321 results · showing first 300, refine your search

Key term

SCOR 350-701

Cisco's core exam for CCNP Security and CCIE Security certifications.

Getting Started: Your SCOR Exam Journey

Key term

Exam Domains

Major technology areas covered by the exam, each with a specific weighting.

Getting Started: Your SCOR Exam Journey

Key term

Cisco Learning Network

Official online community and resource hub for Cisco certification candidates.

Getting Started: Your SCOR Exam Journey

Key term

Passing Score

The minimum score required to pass the exam, not publicly disclosed by Cisco.

Getting Started: Your SCOR Exam Journey

Key term

Simlet/Testlet

Exam question type simulating a network environment for troubleshooting or configuration.

Getting Started: Your SCOR Exam Journey

Key term

CCNP Security

Professional-level Cisco certification focusing on enterprise security solutions.

Getting Started: Your SCOR Exam Journey

Key term

CCIE Security

Expert-level Cisco certification, requiring SCOR as its core component.

Getting Started: Your SCOR Exam Journey

Memory trick

Understanding the CCNP Security Core (SCOR) 350-701 Exam

To remember the main domains, think 'N-C-C-E-S-V': Network, Cloud, Content, Endpoint, Secure Access, Visibility.

Getting Started: Your SCOR Exam Journey

Exam tip

Understanding the CCNP Security Core (SCOR) 350-701 Exam

The official Cisco exam topics document is the single most authoritative source for what will be on the SCOR 350-701 exam. Memorize the main domains and their approximate weightings.

Getting Started: Your SCOR Exam Journey

Common mistake

Understanding the CCNP Security Core (SCOR) 350-701 Exam

Ignoring the official exam topics document and relying solely on third-party study guides.

Getting Started: Your SCOR Exam Journey

Common mistake

Understanding the CCNP Security Core (SCOR) 350-701 Exam

Underestimating the time needed for hands-on practice with Cisco security technologies.

Getting Started: Your SCOR Exam Journey

Common mistake

Understanding the CCNP Security Core (SCOR) 350-701 Exam

Failing to review the performance breakdown on the score report after a failed attempt.

Getting Started: Your SCOR Exam Journey

Key term

Active Recall

Actively retrieving information from memory to strengthen learning.

Getting Started: Your SCOR Exam Journey

Key term

Spaced Repetition

Reviewing material at increasing intervals to improve long-term retention.

Getting Started: Your SCOR Exam Journey

Key term

Learning Style

An individual's preferred way of absorbing, processing, and retaining information.

Getting Started: Your SCOR Exam Journey

Key term

Study Plan

A structured schedule outlining topics, resources, and time allocation for study.

Getting Started: Your SCOR Exam Journey

Key term

Cisco Press

Official publisher of Cisco certification study guides and reference books.

Getting Started: Your SCOR Exam Journey

Key term

Exam Blueprint

Official document outlining all topics covered on a certification exam.

Getting Started: Your SCOR Exam Journey

Key term

Practice Exam

A simulated test used to assess readiness and identify knowledge gaps.

Getting Started: Your SCOR Exam Journey

Key term

Kinesthetic Learner

Learns best through hands-on activities, experiments, and doing.

Getting Started: Your SCOR Exam Journey

Memory trick

Effective Study Strategies & Resource Utilization

To remember the key study steps: 'PLAN-REVISE-PRACTICE-SUCCEED' (Plan your study, Review your material, Practice with labs/exams, Succeed on the exam!).

Getting Started: Your SCOR Exam Journey

Exam tip

Effective Study Strategies & Resource Utilization

The SCOR exam blueprint is your definitive guide. Every topic listed, including specific protocols, technologies, and configuration commands, is fair game. Memorize the exact names of security features and their primary functions as described in Cisco documentation.

Getting Started: Your SCOR Exam Journey

Common mistake

Effective Study Strategies & Resource Utilization

Relying solely on passive learning like re-reading notes without active recall.

Getting Started: Your SCOR Exam Journey

Common mistake

Effective Study Strategies & Resource Utilization

Ignoring the official exam blueprint and studying irrelevant or outdated topics.

Getting Started: Your SCOR Exam Journey

Common mistake

Effective Study Strategies & Resource Utilization

Skipping hands-on labs, leading to a lack of practical understanding for configuration and troubleshooting.

Getting Started: Your SCOR Exam Journey

Key term

CIA Triad

Foundational model for info security: Confidentiality, Integrity, Availability.

Foundational Security Principles

Key term

Confidentiality

Ensuring data is accessed only by authorized individuals.

Foundational Security Principles

Key term

Integrity

Ensuring data is accurate, complete, and untampered.

Foundational Security Principles

Key term

Availability

Ensuring authorized users can access systems when needed.

Foundational Security Principles

Key term

Security Governance

Framework aligning security with business objectives and compliance.

Foundational Security Principles

Key term

CISO

Chief Information Security Officer; leads security strategy.

Foundational Security Principles

Key term

Access Control

Mechanisms to restrict access to resources.

Foundational Security Principles

Key term

DLP

Data Loss Prevention; prevents sensitive data from leaving.

Foundational Security Principles

Memory trick

CIA Triad & Security Governance Fundamentals

CIA: 'C' for 'Covert' (secret), 'I' for 'Intact' (unchanged), 'A' for 'Accessible' (always there).

Foundational Security Principles

Exam tip

CIA Triad & Security Governance Fundamentals

The exam often tests your ability to identify which CIA principle is violated or upheld in a given scenario. Look for keywords like 'unauthorized disclosure' (Confidentiality), 'data alteration' (Integrity), or 'system downtime' (Availability).

Foundational Security Principles

Common mistake

CIA Triad & Security Governance Fundamentals

Confusing integrity with confidentiality: Integrity is about data accuracy, confidentiality is about data secrecy.

Foundational Security Principles

Common mistake

CIA Triad & Security Governance Fundamentals

Underestimating the importance of availability: Downtime can be as damaging as a data breach.

Foundational Security Principles

Common mistake

CIA Triad & Security Governance Fundamentals

Believing security governance is purely an IT responsibility: It requires organization-wide commitment and executive support.

Foundational Security Principles

Key term

Risk Management

Process of identifying, assessing, and controlling threats to assets.

Foundational Security Principles

Key term

Threat Intelligence

Actionable knowledge about existing or emerging cyber threats.

Foundational Security Principles

Key term

Security Operations (SecOps)

People, processes, and tech for monitoring and responding to threats.

Foundational Security Principles

Key term

Risk Assessment

Analyzing the likelihood and impact of identified risks.

Foundational Security Principles

Key term

Risk Mitigation

Reducing the likelihood or impact of a risk.

Foundational Security Principles

Key term

Risk Transfer

Shifting financial burden of risk to another party.

Foundational Security Principles

Key term

SOC (Security Operations Center)

Centralized unit for security monitoring and incident response.

Foundational Security Principles

Key term

SIEM (Security Information and Event Management)

System for collecting, analyzing, and managing security logs.

Foundational Security Principles

Memory trick

Risk Management, Threat Intelligence & Operations

To remember the four risk treatment strategies, think 'AAMT': Accept, Avoid, Mitigate, Transfer. It's like deciding how to deal with a scary 'Aunt' Mildred!

Foundational Security Principles

Exam tip

Risk Management, Threat Intelligence & Operations

The exam often tests the definitions and differences between risk treatment strategies (acceptance, avoidance, mitigation, transfer). Also, be prepared to distinguish between strategic, tactical, and operational threat intelligence. Know the core functions of a SOC.

Foundational Security Principles

Common mistake

Risk Management, Threat Intelligence & Operations

Confusing risk mitigation with risk avoidance; mitigation reduces impact/likelihood, avoidance eliminates the risk-causing activity.

Foundational Security Principles

Common mistake

Risk Management, Threat Intelligence & Operations

Believing that all risks must be eliminated; risk management aims for an acceptable level of risk.

Foundational Security Principles

Common mistake

Risk Management, Threat Intelligence & Operations

Failing to integrate threat intelligence into daily security operations, making defenses reactive instead of proactive.

Foundational Security Principles

Key term

Security Policy

High-level, mandatory statement of security objectives.

Foundational Security Principles

Key term

Security Standard

Specific, mandatory requirements for implementing policies.

Foundational Security Principles

Key term

Security Guideline

Recommended best practices for achieving security objectives.

Foundational Security Principles

Key term

NIST CSF

Framework for improving critical infrastructure cybersecurity.

Foundational Security Principles

Key term

ISO/IEC 27001

International standard for Information Security Management Systems (ISMS).

Foundational Security Principles

Key term

GDPR

EU regulation protecting personal data and privacy.

Foundational Security Principles

Key term

HIPAA

US law protecting patient health information.

Foundational Security Principles

Key term

PCI DSS

Standard for organizations handling credit card data.

Foundational Security Principles

Memory trick

Security Policies, Frameworks & Legal Compliance

P-S-G: Policies Set Goals, Standards Specify Steps, Guidelines Give Guidance.

Foundational Security Principles

Exam tip

Security Policies, Frameworks & Legal Compliance

The exam often tests your ability to distinguish between policies, standards, and guidelines. Remember that policies are 'what' to do, standards are 'how' to do it mandatorily, and guidelines are 'how' to do it optionally.

Foundational Security Principles

Common mistake

Security Policies, Frameworks & Legal Compliance

Confusing guidelines with mandatory standards.

Foundational Security Principles

Common mistake

Security Policies, Frameworks & Legal Compliance

Assuming a framework is a 'one-size-fits-all' solution without tailoring.

Foundational Security Principles

Common mistake

Security Policies, Frameworks & Legal Compliance

Underestimating the legal and financial penalties of non-compliance.

Foundational Security Principles

Key term

Best Practices

Established guidelines for effective security.

Foundational Security Principles

Key term

Defense in Depth

Layered security approach with multiple controls.

Foundational Security Principles

Key term

Security Awareness

Employee education on security risks and policies.

Foundational Security Principles

Key term

Security Audit

Systematic evaluation of security posture and controls.

Foundational Security Principles

Key term

Vulnerability Assessment

Identifies weaknesses in systems and applications.

Foundational Security Principles

Key term

Penetration Testing

Simulated attack to find exploitable vulnerabilities.

Foundational Security Principles

Key term

Security Metrics

Quantifiable measures of security program effectiveness.

Foundational Security Principles

Key term

MTTD/MTTR

Mean Time To Detect/Respond to incidents.

Foundational Security Principles

Memory trick

Best Practices, Awareness, Audits & Metrics

To remember the cycle of security improvement, think 'A.C.E.S.': Awareness, Controls, Evaluations (Audits), and Stats (Metrics).

Foundational Security Principles

Exam tip

Best Practices, Awareness, Audits & Metrics

The exam often tests your understanding of the *purpose* of security awareness and audits. Remember that awareness targets human vulnerabilities, while audits verify compliance and effectiveness of controls. Know the difference between a vulnerability assessment (identify) and penetration test (exploit).

Foundational Security Principles

Common mistake

Best Practices, Awareness, Audits & Metrics

Believing technology alone can solve all security problems; human factors are critical.

Foundational Security Principles

Common mistake

Best Practices, Awareness, Audits & Metrics

Treating security awareness as a one-time event instead of an ongoing process.

Foundational Security Principles

Common mistake

Best Practices, Awareness, Audits & Metrics

Collecting metrics without a clear purpose or failing to act on the insights they provide.

Foundational Security Principles

Key term

Least Privilege

Granting minimum necessary access rights.

Core Network Security Technologies

Key term

Defense-in-Depth

Layering multiple security controls for protection.

Core Network Security Technologies

Key term

Malware

Malicious software like viruses, worms, ransomware.

Core Network Security Technologies

Key term

Phishing

Social engineering to trick users into revealing info.

Core Network Security Technologies

Key term

DDoS

Overwhelming a system with traffic to deny service.

Core Network Security Technologies

Key term

Technical Control

Hardware/software-based security mechanism.

Core Network Security Technologies

Key term

Administrative Control

Policy or procedure-based security mechanism.

Core Network Security Technologies

Memory trick

Network Security Fundamentals & Design Principles

To remember the CIA Triad: 'C' is for 'Covert' (keeping secrets), 'I' is for 'Intact' (keeping things whole), 'A' is for 'Always Available' (keeping things running).

Core Network Security Technologies

Exam tip

Network Security Fundamentals & Design Principles

The exam frequently tests your understanding of the CIA Triad and its application. Be ready to identify which principle is violated in a given scenario or which control addresses a specific principle. Keywords like 'unauthorized disclosure' point to Confidentiality, 'unauthorized modification' to Integrity, and 'service interruption' to Availability.

Core Network Security Technologies

Common mistake

Network Security Fundamentals & Design Principles

Confusing confidentiality with integrity: Confidentiality is about secrecy, integrity is about accuracy.

Core Network Security Technologies

Common mistake

Network Security Fundamentals & Design Principles

Forgetting that insider threats are a major risk, not just external attackers.

Core Network Security Technologies

Common mistake

Network Security Fundamentals & Design Principles

Believing that a single security product will solve all security problems; layered defense is crucial.

Core Network Security Technologies

Key term

Firewall

A network security device that monitors and filters incoming and outgoing network traffic.

Core Network Security Technologies

Key term

Stateful Firewall

A firewall that tracks the state of active network connections to make filtering decisions.

Core Network Security Technologies

Key term

NAT (Network Address Translation)

A method of remapping IP address space by modifying IP address information in packet headers.

Core Network Security Technologies

Key term

PAT (Port Address Translation)

A type of NAT that allows multiple private IP addresses to share a single public IP using port numbers.

Core Network Security Technologies

Key term

ACL (Access Control List)

A sequential list of permit/deny statements used to filter network traffic based on criteria.

Core Network Security Technologies

Key term

VPN (Virtual Private Network)

A secure, encrypted connection over a public network, providing confidentiality and integrity.

Core Network Security Technologies

Key term

IPsec

A suite of protocols for securing IP communications by authenticating and encrypting each IP packet.

Core Network Security Technologies

Key term

IKE (Internet Key Exchange)

The protocol used to set up a Security Association (SA) in the IPsec protocol suite.

Core Network Security Technologies

Memory trick

Firewalls, NAT, ACLs & VPN Implementations

For VPN security, remember 'CIA': Confidentiality, Integrity, Authenticity. These are the three pillars IPsec provides!

Core Network Security Technologies

Exam tip

Firewalls, NAT, ACLs & VPN Implementations

The exam frequently tests the differences between stateful and stateless firewalls, the function of PAT for address conservation, and the two phases of IPsec (IKE Phase 1 and Phase 2). Pay close attention to the order of operations for ACLs and the implicit deny.

Core Network Security Technologies

Common mistake

Firewalls, NAT, ACLs & VPN Implementations

Forgetting the implicit 'deny any' at the end of an ACL, leading to unexpected traffic blocking.

Core Network Security Technologies

Common mistake

Firewalls, NAT, ACLs & VPN Implementations

Confusing Static NAT with PAT; Static NAT is 1:1, PAT is many:1.

Core Network Security Technologies

Common mistake

Firewalls, NAT, ACLs & VPN Implementations

Not understanding the distinct roles of IKE Phase 1 (control channel) and Phase 2 (data channel) in IPsec.

Core Network Security Technologies

Key term

IDS

Intrusion Detection System; monitors for suspicious activity and alerts.

Core Network Security Technologies

Key term

IPS

Intrusion Prevention System; monitors, detects, and actively blocks threats.

Core Network Security Technologies

Key term

Signature-based

Detection method matching known attack patterns.

Core Network Security Technologies

Key term

Anomaly-based

Detection method identifying deviations from normal behavior.

Core Network Security Technologies

Key term

In-line

Deployment where all traffic passes through the device.

Core Network Security Technologies

Key term

Out-of-band

Deployment where a copy of traffic is monitored.

Core Network Security Technologies

Key term

Zero-day attack

An attack exploiting an unknown vulnerability.

Core Network Security Technologies

Key term

NGFW

Next-Generation Firewall; integrates advanced security features.

Core Network Security Technologies

Memory trick

IDS/IPS & Threat Prevention

IDS is for 'I Detect Silently,' IPS is for 'I Prevent Swiftly.'

Core Network Security Technologies

Exam tip

IDS/IPS & Threat Prevention

The exam often tests the fundamental difference between IDS and IPS, particularly their deployment modes (in-line vs. out-of-band) and their actions (alert vs. block). Memorize these core distinctions.

Core Network Security Technologies

Common mistake

IDS/IPS & Threat Prevention

Confusing IDS (detection only) with IPS (prevention).

Core Network Security Technologies

Common mistake

IDS/IPS & Threat Prevention

Underestimating the performance impact or latency introduced by an in-line IPS.

Core Network Security Technologies

Common mistake

IDS/IPS & Threat Prevention

Relying solely on signature-based detection, leaving systems vulnerable to zero-day attacks.

Core Network Security Technologies

Key term

NDP (Neighbor Discovery Protocol)

IPv6 protocol for address resolution, router discovery, and redirection.

Core Network Security Technologies

Key term

SLAAC (Stateless Address Autoconfiguration)

Allows IPv6 devices to automatically configure addresses without a DHCP server.

Core Network Security Technologies

Key term

WPA3 (Wi-Fi Protected Access 3)

Latest security standard for Wi-Fi networks, offering enhanced encryption.

Core Network Security Technologies

Key term

Rogue AP

Unauthorized access point connected to a network, posing a security risk.

Core Network Security Technologies

Key term

Shared Responsibility Model

Defines security duties between cloud provider and customer based on service model.

Core Network Security Technologies

Key term

CASB (Cloud Access Security Broker)

Software that sits between users and cloud apps to enforce security policies.

Core Network Security Technologies

Key term

Evil Twin Attack

A rogue AP mimicking a legitimate one to trick users into connecting.

Core Network Security Technologies

Memory trick

Advanced Network Security: IPv6, Wireless & Cloud

For Cloud responsibility, think 'I PAss SAAfely': IaaS (Infrastructure), PaaS (Platform), SaaS (Software) – each adds more provider responsibility.

Core Network Security Technologies

Exam tip

Advanced Network Security: IPv6, Wireless & Cloud

The exam often tests your understanding of the shared responsibility model in cloud computing. Memorize which security aspects fall under the customer's responsibility for IaaS, PaaS, and SaaS. Keywords to spot: 'customer responsibility', 'provider responsibility', 'IaaS', 'PaaS', 'SaaS'.

Core Network Security Technologies

Common mistake

Advanced Network Security: IPv6, Wireless & Cloud

Assuming IPv4 security controls automatically apply to IPv6 without verification.

Core Network Security Technologies

Common mistake

Advanced Network Security: IPv6, Wireless & Cloud

Neglecting to secure wireless guest networks, creating a backdoor into the corporate network.

Core Network Security Technologies

Common mistake

Advanced Network Security: IPv6, Wireless & Cloud

Misunderstanding the shared responsibility model in the cloud, leading to critical security gaps.

Core Network Security Technologies

Key term

IaaS

Infrastructure as a Service; customer manages OS, apps, data.

Securing Cloud Environments

Key term

PaaS

Platform as a Service; customer manages apps, data.

Securing Cloud Environments

Key term

SaaS

Software as a Service; customer manages user access, data.

Securing Cloud Environments

Key term

Public Cloud

Third-party owned, shared resources over the internet.

Securing Cloud Environments

Key term

Private Cloud

Dedicated to one organization, on-prem or hosted.

Securing Cloud Environments

Key term

Hybrid Cloud

Combines public and private cloud environments.

Securing Cloud Environments

Key term

Multi-Cloud

Using multiple public cloud providers simultaneously.

Securing Cloud Environments

Memory trick

Cloud Security Fundamentals & Architecture Design

IaaS, PaaS, SaaS: I Always Secure Software. (IaaS: Infrastructure, you secure more. PaaS: Platform, you secure apps. SaaS: Software, you secure least.)

Securing Cloud Environments

Exam tip

Cloud Security Fundamentals & Architecture Design

The exam frequently tests the nuances of the Shared Responsibility Model. Memorize what the provider is responsible for ('security OF the cloud') versus the customer ('security IN the cloud') for IaaS, PaaS, and SaaS. Keywords like 'physical security' or 'hypervisor' point to provider responsibility, while 'data encryption' or 'application configuration' point to customer responsibility.

Securing Cloud Environments

Common mistake

Cloud Security Fundamentals & Architecture Design

Assuming the cloud provider is solely responsible for all security aspects in a SaaS model; customer data and access management are still critical responsibilities.

Securing Cloud Environments

Common mistake

Cloud Security Fundamentals & Architecture Design

Confusing the responsibilities between IaaS and PaaS, particularly regarding operating system and runtime environment management.

Securing Cloud Environments

Common mistake

Cloud Security Fundamentals & Architecture Design

Failing to implement least privilege, leading to overly permissive access policies that increase risk.

Securing Cloud Environments

Key term

Security Group

Stateful virtual firewall for cloud instances.

Securing Cloud Environments

Key term

NACL (Network Access Control List)

Stateless packet filtering for subnets.

Securing Cloud Environments

Key term

Virtual Firewall Appliance

Third-party firewall software in cloud VM.

Securing Cloud Environments

Key term

Site-to-Site VPN

Secure connection between two networks.

Securing Cloud Environments

Key term

Client-to-Site VPN

Secure connection for individual users.

Securing Cloud Environments

Key term

Stateless Firewall

Filters packets based on rules, no session tracking.

Securing Cloud Environments

Memory trick

Cloud Security Technologies: Firewalls & VPNs

Imagine a 'VPN' as a 'Very Private Network' tunnel, and 'Firewalls' as 'Fences' around your cloud resources.

Securing Cloud Environments

Exam tip

Cloud Security Technologies: Firewalls & VPNs

The exam often distinguishes between stateful (Security Groups) and stateless (NACLs) cloud firewalls. Remember that Security Groups apply to instances/ENIs, while NACLs apply to subnets. Look for keywords like 'instance-level' vs. 'subnet-level' filtering.

Securing Cloud Environments

Common mistake

Cloud Security Technologies: Firewalls & VPNs

Confusing stateless (NACLs) with stateful (Security Groups) firewall behavior, especially regarding return traffic.

Securing Cloud Environments

Common mistake

Cloud Security Technologies: Firewalls & VPNs

Overlooking the need for both ingress and egress rules in cloud firewall configurations.

Securing Cloud Environments

Common mistake

Cloud Security Technologies: Firewalls & VPNs

Failing to consider VPN throughput limitations when designing hybrid cloud architectures.

Securing Cloud Environments

Key term

IAM

Identity and Access Management; controls who can do what.

Securing Cloud Environments

Key term

WAF

Web Application Firewall; protects web apps from exploits.

Securing Cloud Environments

Key term

SIEM

Security Information and Event Management; centralizes log analysis.

Securing Cloud Environments

Key term

CSPM

Cloud Security Posture Management; checks cloud configurations.

Securing Cloud Environments

Key term

MFA

Multi-Factor Authentication; adds extra login security.

Securing Cloud Environments

Memory trick

Cloud Access Control, Threat Prevention & Monitoring

For IAM, think 'I Am Managed': Identities are Managed, Access is Managed.

Securing Cloud Environments

Exam tip

Cloud Access Control, Threat Prevention & Monitoring

The exam frequently tests your understanding of the Shared Responsibility Model. Remember: the cloud provider secures the infrastructure (OF the cloud), while the customer secures their data and configurations (IN the cloud). Keywords like 'customer responsibility' or 'provider's duty' often point to this concept.

Securing Cloud Environments

Common mistake

Cloud Access Control, Threat Prevention & Monitoring

Over-privileging IAM users or roles, granting more access than is actually required.

Securing Cloud Environments

Common mistake

Cloud Access Control, Threat Prevention & Monitoring

Neglecting to enable logging and monitoring services, making incident investigation impossible.

Securing Cloud Environments

Common mistake

Cloud Access Control, Threat Prevention & Monitoring

Assuming the cloud provider handles all security aspects, ignoring the customer's responsibilities in the Shared Responsibility Model.

Securing Cloud Environments

Key term

Infrastructure as Code (IaC)

Managing and provisioning infrastructure through machine-readable definition files.

Securing Cloud Environments

Key term

DevSecOps

Integrating security practices into every phase of the DevOps software development lifecycle.

Securing Cloud Environments

Key term

Cloud Security Posture Management (CSPM)

Tools that identify and remediate misconfigurations and compliance risks in cloud environments.

Securing Cloud Environments

Key term

Continuous Compliance

Automated and ongoing monitoring to ensure adherence to regulatory standards.

Securing Cloud Environments

Key term

Security Orchestration, Automation, and Response (SOAR)

Platform that collects security alerts and automates incident response workflows.

Securing Cloud Environments

Key term

Configuration Drift

When cloud resource configurations deviate from their intended or baseline state.

Securing Cloud Environments

Memory trick

Cloud Security Operations, Automation & Best Practices

For 'Compliance Frameworks': Think 'HIPAA-GDPR-PCI-SOC' as a 'Hasty General Protects Critical Systems'.

Securing Cloud Environments

Exam tip

Cloud Security Operations, Automation & Best Practices

The exam often tests your understanding of the shared responsibility model. Remember: the cloud provider secures the underlying infrastructure (physical security, hypervisor), while the customer is responsible for securing their data, applications, and network configurations within the cloud.

Securing Cloud Environments

Common mistake

Cloud Security Operations, Automation & Best Practices

Assuming cloud providers handle all security responsibilities, neglecting the customer's role in the shared responsibility model.

Securing Cloud Environments

Common mistake

Cloud Security Operations, Automation & Best Practices

Failing to integrate security into CI/CD pipelines, leading to security issues being discovered late in the development cycle.

Securing Cloud Environments

Common mistake

Cloud Security Operations, Automation & Best Practices

Over-relying on manual security checks in dynamic cloud environments, which are prone to human error and cannot keep up with changes.

Securing Cloud Environments

Key term

Content Security

Protecting digital content from threats and policy violations.

Protecting Data in Transit and at Rest

Key term

Deep Packet Inspection (DPI)

Examines data payload of network packets for content analysis.

Protecting Data in Transit and at Rest

Key term

Signature-based Inspection

Compares content against known threat patterns.

Protecting Data in Transit and at Rest

Key term

Heuristic Analysis

Detects threats by identifying suspicious behaviors or characteristics.

Protecting Data in Transit and at Rest

Key term

Sandboxing

Executes suspicious files in an isolated environment to observe behavior.

Protecting Data in Transit and at Rest

Key term

Secure Web Gateway (SWG)

Filters web traffic to enforce policies and block threats.

Protecting Data in Transit and at Rest

Key term

Secure Email Gateway (SEG)

Filters email traffic to protect against spam, malware, and phishing.

Protecting Data in Transit and at Rest

Memory trick

Content Security Fundamentals

Cisco's Content Security uses SANDS: Signatures, Anomalies, Network data, Deep inspection, and Sandboxing.

Protecting Data in Transit and at Rest

Exam tip

Content Security Fundamentals

The exam often tests your understanding of where different content security technologies fit within a network and their primary function. Keywords like 'inspecting HTTP/HTTPS,' 'email attachments,' or 'sensitive data patterns' should direct you to the correct solution (e.g., SWG, SEG, DLP).

Protecting Data in Transit and at Rest

Common mistake

Content Security Fundamentals

Confusing content security with basic firewall packet filtering; content security goes deeper than just IP/port.

Protecting Data in Transit and at Rest

Common mistake

Content Security Fundamentals

Underestimating the importance of threat intelligence; without it, even advanced systems are quickly outdated.

Protecting Data in Transit and at Rest

Common mistake

Content Security Fundamentals

Believing one content security solution is sufficient; a layered approach is always necessary.

Protecting Data in Transit and at Rest

Key term

Email Security Gateway (ESG)

Filters email for spam, malware, and policy violations.

Protecting Data in Transit and at Rest

Key term

URL Filtering

Blocks access to websites based on categories or reputation.

Protecting Data in Transit and at Rest

Key term

Sandbox Analysis

Executes suspicious files in an isolated environment.

Protecting Data in Transit and at Rest

Key term

Advanced Threat Protection (ATP)

Uses advanced techniques to detect zero-day and sophisticated threats.

Protecting Data in Transit and at Rest

Key term

SSL/TLS Decryption

Unencrypts traffic for inspection at a security gateway.

Protecting Data in Transit and at Rest

Key term

DMARC

Email authentication protocol to detect and prevent spoofing.

Protecting Data in Transit and at Rest

Memory trick

Email & Web Security Solutions Implementation

To remember the core functions of a Secure Web Gateway, think 'SWG blocks Bad Sites and Malware'.

Protecting Data in Transit and at Rest

Exam tip

Email & Web Security Solutions Implementation

The exam often tests your understanding of the *functions* and *deployment models* of ESGs and SWGs. Pay attention to how they differ and what specific threats each is designed to mitigate. Keywords to spot include 'anti-spam', 'URL filtering', 'DLP', 'sandboxing', and 'cloud-based security'.

Protecting Data in Transit and at Rest

Common mistake

Email & Web Security Solutions Implementation

Assuming basic firewalls provide sufficient email/web security; they lack deep content inspection capabilities.

Protecting Data in Transit and at Rest

Common mistake

Email & Web Security Solutions Implementation

Neglecting to decrypt SSL/TLS traffic on SWGs, leaving a blind spot for encrypted threats.

Protecting Data in Transit and at Rest

Common mistake

Email & Web Security Solutions Implementation

Failing to regularly update threat intelligence feeds and software on security gateways.

Protecting Data in Transit and at Rest

Key term

Data Loss Prevention (DLP)

Technologies preventing sensitive data from unauthorized exfiltration.

Protecting Data in Transit and at Rest

Key term

Data in Use

Data currently being processed by an application or user.

Protecting Data in Transit and at Rest

Key term

Data in Motion

Data actively being transmitted over a network.

Protecting Data in Transit and at Rest

Key term

Data at Rest

Data stored on a physical or digital medium.

Protecting Data in Transit and at Rest

Key term

Threat Prevention

Proactive measures to stop cyberattacks before they succeed.

Protecting Data in Transit and at Rest

Key term

Signature-Based Detection

Identifies threats by matching known patterns or signatures.

Protecting Data in Transit and at Rest

Key term

Behavioral-Based Detection

Identifies threats by detecting anomalous system or network activity.

Protecting Data in Transit and at Rest

Key term

Zero-Day Exploit

A cyberattack exploiting a previously unknown vulnerability.

Protecting Data in Transit and at Rest

Memory trick

Data Loss Prevention (DLP) & Threat Prevention

DLP: Don't Let 'P'ersonal data out! (P for Personal, but also for Prevention)

Protecting Data in Transit and at Rest

Exam tip

Data Loss Prevention (DLP) & Threat Prevention

The exam often tests your understanding of DLP components (network, endpoint, cloud) and their respective functions. Be prepared to differentiate between signature-based and behavioral-based threat detection methods and know when each is most effective.

Protecting Data in Transit and at Rest

Common mistake

Data Loss Prevention (DLP) & Threat Prevention

Confusing DLP with encryption: While DLP might use encryption, its primary role is policy enforcement and monitoring, not just scrambling data.

Protecting Data in Transit and at Rest

Common mistake

Data Loss Prevention (DLP) & Threat Prevention

Assuming signature-based detection is sufficient for all threats: It's excellent for known threats but fails against new, unknown attacks.

Protecting Data in Transit and at Rest

Common mistake

Data Loss Prevention (DLP) & Threat Prevention

Overlooking the importance of policy definition: DLP is only as effective as the policies configured to protect the data.

Protecting Data in Transit and at Rest

Key term

False Positive

Legitimate content or activity incorrectly identified as malicious or unwanted.

Protecting Data in Transit and at Rest

Key term

False Negative

Malicious content or activity that bypasses security controls undetected.

Protecting Data in Transit and at Rest

Key term

Message Tracking

Feature on email security gateways to follow an email's path and status.

Protecting Data in Transit and at Rest

Key term

Access Logs

Records of user attempts to access resources, including web traffic.

Protecting Data in Transit and at Rest

Key term

Policy Conflict

When two or more security rules contradict each other, leading to unpredictable behavior.

Protecting Data in Transit and at Rest

Key term

Root Cause Analysis

A systematic process for identifying the underlying cause of a problem.

Protecting Data in Transit and at Rest

Memory trick

Content Security Monitoring & Troubleshooting

To troubleshoot, remember D-G-A-T-V-D: Define, Gather, Analyze, Test, Verify, Document. It's a systematic approach to any problem!

Protecting Data in Transit and at Rest

Exam tip

Content Security Monitoring & Troubleshooting

The exam expects you to know how to interpret logs from Cisco Secure Email Appliance (ESA) and Cisco Secure Web Appliance (WSA) to diagnose common issues like blocked emails or web access problems. Focus on understanding the different log types and what information they provide.

Protecting Data in Transit and at Rest

Common mistake

Content Security Monitoring & Troubleshooting

Jumping to conclusions without checking logs: Always verify symptoms with data.

Protecting Data in Transit and at Rest

Common mistake

Content Security Monitoring & Troubleshooting

Making multiple changes at once: Change one thing, test, then move on.

Protecting Data in Transit and at Rest

Common mistake

Content Security Monitoring & Troubleshooting

Not documenting troubleshooting steps: This prevents repeating mistakes and aids future investigations.

Protecting Data in Transit and at Rest

Key term

Endpoint

Any device connected to a network, like laptops, servers, or mobile phones.

Endpoint Protection & Secure Access

Key term

Endpoint Security

Protecting end-user devices from cyber threats.

Endpoint Protection & Secure Access

Key term

Antivirus (AV)

Software detecting and removing known malware.

Endpoint Protection & Secure Access

Key term

Endpoint Detection and Response (EDR)

Monitors endpoints for threats and enables rapid response.

Endpoint Protection & Secure Access

Key term

Attack Vector

Method or path used by attackers to gain unauthorized access.

Endpoint Protection & Secure Access

Key term

Patch Management

Process of applying software updates to fix vulnerabilities.

Endpoint Protection & Secure Access

Key term

Host-based Firewall

Software firewall running on an individual endpoint.

Endpoint Protection & Secure Access

Memory trick

Endpoint Security Fundamentals & Technologies

To remember core endpoint tech: 'A.P.E. D.F.L.' - Antivirus, Patching, EDR, DLP, Firewall, Logging (for EDR telemetry).

Endpoint Protection & Secure Access

Exam tip

Endpoint Security Fundamentals & Technologies

The exam often tests your understanding of the *purpose* and *function* of different endpoint security technologies. Keywords like 'detection and response,' 'data exfiltration prevention,' or 'vulnerability patching' should immediately trigger associations with EDR, DLP, and patch management, respectively. Know what each technology aims to achieve.

Endpoint Protection & Secure Access

Common mistake

Endpoint Security Fundamentals & Technologies

Relying solely on traditional antivirus: Modern threats bypass signature-based detection.

Endpoint Protection & Secure Access

Common mistake

Endpoint Security Fundamentals & Technologies

Neglecting patch management: Unpatched vulnerabilities are a primary entry point for attackers.

Endpoint Protection & Secure Access

Common mistake

Endpoint Security Fundamentals & Technologies

Ignoring mobile devices: Mobile endpoints are just as vulnerable and require specific protection strategies.

Endpoint Protection & Secure Access

Key term

NGAV

Next-Generation Antivirus; uses AI/ML for advanced threat detection.

Endpoint Protection & Secure Access

Key term

EDR

Endpoint Detection and Response; monitors, detects, and responds to threats.

Endpoint Protection & Secure Access

Key term

Endpoint IPS

Intrusion Prevention System protecting an individual endpoint.

Endpoint Protection & Secure Access

Key term

Posture Assessment

Evaluating an endpoint's security state before granting access.

Endpoint Protection & Secure Access

Key term

IOC

Indicator of Compromise; evidence of a security breach.

Endpoint Protection & Secure Access

Key term

Lateral Movement

Attacker moving between systems within a network.

Endpoint Protection & Secure Access

Memory trick

Endpoint Threat Prevention & Access Control

EDR: Every Device Reacts. Think of EDR as having a tiny security guard on every device, always watching, ready to act.

Endpoint Protection & Secure Access

Exam tip

Endpoint Threat Prevention & Access Control

The exam often tests your understanding of EDR capabilities beyond traditional antivirus. Focus on EDR's role in continuous monitoring, threat hunting, and automated response capabilities. Also, differentiate between host-based and network-based access control mechanisms.

Endpoint Protection & Secure Access

Common mistake

Endpoint Threat Prevention & Access Control

Confusing traditional antivirus with EDR; EDR goes beyond simple signature detection.

Endpoint Protection & Secure Access

Common mistake

Endpoint Threat Prevention & Access Control

Underestimating the importance of host-based firewalls, even with network firewalls present.

Endpoint Protection & Secure Access

Common mistake

Endpoint Threat Prevention & Access Control

Not understanding that device posture assessment is a key component of network access control.

Endpoint Protection & Secure Access

Key term

Supplicant

The client device requesting network access.

Endpoint Protection & Secure Access

Key term

Authenticator

Network device controlling port access (e.g., switch, AP).

Endpoint Protection & Secure Access

Key term

Authentication Server

Verifies credentials and applies network policies.

Endpoint Protection & Secure Access

Key term

802.1X

IEEE standard for port-based network access control.

Endpoint Protection & Secure Access

Key term

EAP

Extensible Authentication Protocol; used for authentication exchanges.

Endpoint Protection & Secure Access

Key term

RADIUS

Remote Authentication Dial-In User Service; common AAA protocol.

Endpoint Protection & Secure Access

Key term

Cisco ISE

Cisco Identity Services Engine; a leading SNA platform.

Endpoint Protection & Secure Access

Memory trick

Secure Network Access (SNA) Design & Implementation

Remember 'SAA' for the core components: Supplicant, Authenticator, Authentication Server. They 'SAA-ve' your network!

Endpoint Protection & Secure Access

Exam tip

Secure Network Access (SNA) Design & Implementation

The exam frequently tests your understanding of the roles of the Supplicant, Authenticator, and Authentication Server in an 802.1X deployment. Be able to identify which device performs which function.

Endpoint Protection & Secure Access

Common mistake

Secure Network Access (SNA) Design & Implementation

Forgetting to configure the Authenticator (switch/AP) to communicate with the Authentication Server (RADIUS/ISE).

Endpoint Protection & Secure Access

Common mistake

Secure Network Access (SNA) Design & Implementation

Not planning for fallback authentication methods if the primary server is unreachable.

Endpoint Protection & Secure Access

Common mistake

Secure Network Access (SNA) Design & Implementation

Implementing 802.1X without proper certificate management for EAP-TLS deployments.

Endpoint Protection & Secure Access

Key term

Live Logs

Real-time authentication and authorization events in Cisco ISE.

Endpoint Protection & Secure Access

Key term

NAD

Network Access Device; a switch or WLC enforcing access policies.

Endpoint Protection & Secure Access

Key term

Posture Policy

Rules defining endpoint health and compliance requirements.

Endpoint Protection & Secure Access

Key term

Authorization Profile

Defines access permissions (VLAN, ACLs) granted after authorization.

Endpoint Protection & Secure Access

Key term

Profiler

Cisco ISE service identifying and categorizing connected devices.

Endpoint Protection & Secure Access

Memory trick

SNA Operations, Monitoring & Troubleshooting

To remember SNA troubleshooting steps: 'GIVE PAC-MAN'. Gather Info, Verify Basics, Examine Logs, Packet Capture, Analyze Policy, Correct, Monitor, ANalyze (again).

Endpoint Protection & Secure Access

Exam tip

SNA Operations, Monitoring & Troubleshooting

For the SCOR exam, memorize the order of operations for 802.1X authentication (Supplicant, Authenticator, Authentication Server). Be prepared to interpret basic ISE Live Logs output to identify the cause of an authentication or authorization failure.

Endpoint Protection & Secure Access

Common mistake

SNA Operations, Monitoring & Troubleshooting

Overlooking basic network connectivity issues before diving into complex ISE configurations.

Endpoint Protection & Secure Access

Common mistake

SNA Operations, Monitoring & Troubleshooting

Not checking ISE's Live Logs first; they provide the most direct information about access attempts.

Endpoint Protection & Secure Access

Common mistake

SNA Operations, Monitoring & Troubleshooting

Assuming a user issue is solely an ISE problem without verifying the identity source (e.g., Active Directory).

Endpoint Protection & Secure Access

Key term

IoT Security

Protecting interconnected physical devices from cyber threats.

Endpoint Protection & Secure Access

Key term

SDN

Software-Defined Networking; separates control plane from data plane.

Endpoint Protection & Secure Access

Key term

Micro-segmentation

Dividing a network into small, isolated segments for security.

Endpoint Protection & Secure Access

Key term

Automation

Using technology to perform tasks with minimal human intervention.

Endpoint Protection & Secure Access

Key term

Application Whitelisting

Only allowing explicitly approved applications to run.

Endpoint Protection & Secure Access

Key term

Trusted Platform Module (TPM)

Hardware component providing cryptographic functions and secure boot.

Endpoint Protection & Secure Access

Key term

UEBA

User and Entity Behavior Analytics; detects anomalies in behavior.

Endpoint Protection & Secure Access

Memory trick

Advanced Endpoint & SNA: IoT, SDN & Automation

Imagine a 'SNAKE' guarding your network: **S**DN for control, **N**AC for access, **A**utomation for speed, **K**eeping **E**ndpoints safe (and IoT too!).

Endpoint Protection & Secure Access

Exam tip

Advanced Endpoint & SNA: IoT, SDN & Automation

The exam often tests your understanding of *why* these technologies are important for security, not just what they are. Focus on the security benefits and challenges of IoT, SDN, and automation, and how they integrate with existing security frameworks like NAC.

Endpoint Protection & Secure Access

Common mistake

Advanced Endpoint & SNA: IoT, SDN & Automation

Underestimating the security risks of unmanaged IoT devices.

Endpoint Protection & Secure Access

Common mistake

Advanced Endpoint & SNA: IoT, SDN & Automation

Failing to secure the SDN controller, making it a single point of failure.

Endpoint Protection & Secure Access

Common mistake

Advanced Endpoint & SNA: IoT, SDN & Automation

Implementing automation without proper testing, leading to unintended network disruptions.

Endpoint Protection & Secure Access

Key term

Visibility

Ability to see and understand network traffic and activity.

Monitoring & Enforcing Security Policies

Key term

Enforcement

Applying security policies and taking action based on visibility.

Monitoring & Enforcing Security Policies

Key term

SPAN Port

Switched Port Analyzer; mirrors traffic from one or more ports.

Monitoring & Enforcing Security Policies

Key term

NetFlow

Cisco protocol providing IP traffic flow information for analysis.

Monitoring & Enforcing Security Policies

Key term

IPFIX

IP Flow Information Export; IETF standard based on NetFlow v9.

Monitoring & Enforcing Security Policies

Key term

NAC

Network Access Control; controls device access based on policy.

Monitoring & Enforcing Security Policies

Memory trick

Visibility & Enforcement Fundamentals & Tools

To remember visibility tools: 'SPAN NETs TAP into the FLOW of data for SIEM.'

Monitoring & Enforcing Security Policies

Exam tip

Visibility & Enforcement Fundamentals & Tools

The exam frequently tests your understanding of what each visibility tool (e.g., NetFlow, SPAN, taps) provides and where it's best utilized. Know the difference between full packet capture and flow data.

Monitoring & Enforcing Security Policies

Common mistake

Visibility & Enforcement Fundamentals & Tools

Relying on a single visibility tool, leading to blind spots.

Monitoring & Enforcing Security Policies

Common mistake

Visibility & Enforcement Fundamentals & Tools

Collecting too much data without a plan for analysis, causing 'data overload'.

Monitoring & Enforcing Security Policies

Common mistake

Visibility & Enforcement Fundamentals & Tools

Implementing enforcement without proper visibility, leading to false positives or blocking legitimate traffic.

Monitoring & Enforcing Security Policies

Key term

Security Monitoring

Continuous observation of IT infrastructure for security events.

Monitoring & Enforcing Security Policies

Key term

Logging

Systematic recording of events for audit and analysis.

Monitoring & Enforcing Security Policies

Key term

Event Correlation

Analyzing multiple events to identify patterns or incidents.

Monitoring & Enforcing Security Policies

Key term

Log Aggregation

Collecting and consolidating logs from various sources.

Monitoring & Enforcing Security Policies

Key term

Normalization

Standardizing diverse log formats for consistent analysis.

Monitoring & Enforcing Security Policies

Key term

Dwell Time

The period an attacker remains undetected in a network.

Monitoring & Enforcing Security Policies

Key term

Forensic Analysis

Investigating security incidents to determine cause and impact.

Monitoring & Enforcing Security Policies

Memory trick

Security Monitoring, Logging & Event Management

To remember SIEM functions: 'CAN Do': **C**ollect, **A**ggregate, **N**ormalize, **D**etect (**O**rchestrate).

Monitoring & Enforcing Security Policies

Exam tip

Security Monitoring, Logging & Event Management

The exam expects you to differentiate between various log types (e.g., firewall, IDS/IPS, server) and understand the core functions of a SIEM system, especially aggregation, normalization, and correlation. Memorize that SIEMs are central to proactive threat detection and compliance.

Monitoring & Enforcing Security Policies

Common mistake

Security Monitoring, Logging & Event Management

Not centralizing logs: Distributes data across many systems, making analysis impossible.

Monitoring & Enforcing Security Policies

Common mistake

Security Monitoring, Logging & Event Management

Ignoring low-severity alerts: Can miss early indicators of a larger attack.

Monitoring & Enforcing Security Policies

Common mistake

Security Monitoring, Logging & Event Management

Insufficient log retention: Prevents thorough forensic investigation and compliance.

Monitoring & Enforcing Security Policies

Common mistake

Security Monitoring, Logging & Event Management

Lack of correlation rules: Leads to an overwhelming number of individual alerts without context.

Monitoring & Enforcing Security Policies

Key term

DAC (Discretionary Access Control)

Resource owner grants/revokes permissions.

Monitoring & Enforcing Security Policies