300-440 cheat sheet
A one-page reference for the Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
Cisco
Level
Professional
Questions
90
Time
90 min
Mock pass mark
75%
Domains
5
Practice Qs
128
Code
300-440
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- Cloud Connectivity
- Cloud Connectivity is the set of designs and technologies that securely connect an enterprise network to public cloud providers. ENCC is entirely about designing and implementing enterprise-to-cloud connectivity.
- IPsec
- IPsec is the protocol suite that authenticates and encrypts IP traffic, used to build secure site-to-cloud and site-to-site tunnels. ENCC's IPsec Cloud Connectivity domain covers building encrypted tunnels to cloud providers.
- IKEv2
- IKEv2 (Internet Key Exchange version 2) negotiates the security associations and keys that establish an IPsec tunnel. ENCC covers IKEv2 configuration for cloud connectivity tunnels.
- SD-WAN
- SD-WAN (Cisco Catalyst SD-WAN) is an overlay architecture that centrally manages transport-independent connectivity, including to cloud on-ramps. ENCC's SD-WAN Cloud Connectivity domain covers connecting SD-WAN fabrics to cloud.
- Cloud OnRamp
- Cloud OnRamp is the Cisco Catalyst SD-WAN feature that optimizes and automates connectivity to SaaS and IaaS cloud workloads. ENCC covers Cloud OnRamp for connecting branches to cloud applications.
- Transit Gateway
- A Transit Gateway is a cloud-provider hub (such as AWS Transit Gateway) that interconnects VPCs/VNets and on-premises networks. ENCC covers cloud transit constructs when designing enterprise-to-cloud connectivity.
- VPC
- A Virtual Private Cloud (VPC), or VNet in Azure, is an isolated virtual network within a cloud provider where workloads run. ENCC covers connecting enterprise networks into VPCs/VNets securely.
- BGP
- Border Gateway Protocol (BGP) exchanges routing between the enterprise, SD-WAN, and cloud networks over the connectivity tunnels. ENCC covers BGP for dynamic routing across cloud connections.
- Redundancy
- Redundancy is the use of multiple tunnels, paths, or regions so cloud connectivity survives a single failure. ENCC's Design domain covers high-availability and redundant cloud-connectivity architectures.
- SLA
- A Service Level Agreement (SLA) defines the performance and availability targets a cloud-connectivity design must meet. ENCC covers designing to SLA requirements and monitoring against them.
- Telemetry
- Telemetry is the streamed operational data used to monitor and assure cloud-connectivity health and performance. ENCC's Operation domain covers monitoring and troubleshooting connectivity with telemetry.
- Multicloud
- Multicloud describes connecting an enterprise to more than one cloud provider (such as AWS, Azure, and Google Cloud) simultaneously. ENCC covers architecture models for single- and multi-cloud connectivity.
- Architecture Models
- Architecture Models in ENCC are the reference designs for connecting enterprises to cloud — direct IPsec, SD-WAN, colocation, and provider interconnects. This domain frames the connectivity options the rest of the exam implements.
- Private Interconnect
- A Private Interconnect (such as AWS Direct Connect or Azure ExpressRoute) is a dedicated private link between the enterprise and a cloud provider, bypassing the public internet. ENCC covers private interconnects as a connectivity model.
- Encryption
- Encryption protects data in transit across cloud-connectivity tunnels, primarily via IPsec with modern ciphers. ENCC covers encryption as the core security control for enterprise-to-cloud links.