300-440 cheat sheet

A one-page reference for the Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
Cisco
Level
Professional
Questions
90
Time
90 min
Mock pass mark
75%
Domains
5
Practice Qs
128
Code
300-440

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

Cloud Connectivity
Cloud Connectivity is the set of designs and technologies that securely connect an enterprise network to public cloud providers. ENCC is entirely about designing and implementing enterprise-to-cloud connectivity.
IPsec
IPsec is the protocol suite that authenticates and encrypts IP traffic, used to build secure site-to-cloud and site-to-site tunnels. ENCC's IPsec Cloud Connectivity domain covers building encrypted tunnels to cloud providers.
IKEv2
IKEv2 (Internet Key Exchange version 2) negotiates the security associations and keys that establish an IPsec tunnel. ENCC covers IKEv2 configuration for cloud connectivity tunnels.
SD-WAN
SD-WAN (Cisco Catalyst SD-WAN) is an overlay architecture that centrally manages transport-independent connectivity, including to cloud on-ramps. ENCC's SD-WAN Cloud Connectivity domain covers connecting SD-WAN fabrics to cloud.
Cloud OnRamp
Cloud OnRamp is the Cisco Catalyst SD-WAN feature that optimizes and automates connectivity to SaaS and IaaS cloud workloads. ENCC covers Cloud OnRamp for connecting branches to cloud applications.
Transit Gateway
A Transit Gateway is a cloud-provider hub (such as AWS Transit Gateway) that interconnects VPCs/VNets and on-premises networks. ENCC covers cloud transit constructs when designing enterprise-to-cloud connectivity.
VPC
A Virtual Private Cloud (VPC), or VNet in Azure, is an isolated virtual network within a cloud provider where workloads run. ENCC covers connecting enterprise networks into VPCs/VNets securely.
BGP
Border Gateway Protocol (BGP) exchanges routing between the enterprise, SD-WAN, and cloud networks over the connectivity tunnels. ENCC covers BGP for dynamic routing across cloud connections.
Redundancy
Redundancy is the use of multiple tunnels, paths, or regions so cloud connectivity survives a single failure. ENCC's Design domain covers high-availability and redundant cloud-connectivity architectures.
SLA
A Service Level Agreement (SLA) defines the performance and availability targets a cloud-connectivity design must meet. ENCC covers designing to SLA requirements and monitoring against them.
Telemetry
Telemetry is the streamed operational data used to monitor and assure cloud-connectivity health and performance. ENCC's Operation domain covers monitoring and troubleshooting connectivity with telemetry.
Multicloud
Multicloud describes connecting an enterprise to more than one cloud provider (such as AWS, Azure, and Google Cloud) simultaneously. ENCC covers architecture models for single- and multi-cloud connectivity.
Architecture Models
Architecture Models in ENCC are the reference designs for connecting enterprises to cloud — direct IPsec, SD-WAN, colocation, and provider interconnects. This domain frames the connectivity options the rest of the exam implements.
Private Interconnect
A Private Interconnect (such as AWS Direct Connect or Azure ExpressRoute) is a dedicated private link between the enterprise and a cloud provider, bypassing the public internet. ENCC covers private interconnects as a connectivity model.
Encryption
Encryption protects data in transit across cloud-connectivity tunnels, primarily via IPsec with modern ciphers. ENCC covers encryption as the core security control for enterprise-to-cloud links.