350-701 exam domains
The 350-701 exam is weighted across 6 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.
| Exam domain | Exam weight | Practice |
|---|---|---|
| Security Concepts | 25% | Practice this topic |
| Network Security | 20% | Practice this topic |
| Securing the Cloud | 15% | Practice this topic |
| Content Security | 15% | Practice this topic |
| Endpoint Protection and Detection | 10% | Practice this topic |
| Secure Network Access, Visibility, and Enforcement | 15% | Practice this topic |
Sample 350-701 questions
A sample of the 350-701 questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.
- A penetration tester submits an oversized input string to a legacy C-based network daemon running on a company server. The application crashes, and th…View question
- A company wants employees to be able to register and configure their personally owned devices for secure 802.1X access to the corporate WLAN without h…View question
- A security team notices employees are uploading corporate files to numerous unsanctioned SaaS applications discovered from firewall and proxy logs. Le…View question
- A security engineer is deploying a remote access VPN and wants to eliminate the risk of shared or reused credentials. The organization already operate…View question
- A DevSecOps team stores database passwords, API keys, and TLS private keys directly as plaintext variables inside their Jenkins pipeline configuration…View question
- A data center team wants to enforce east-west traffic controls between servers regardless of their IP subnet or VLAN, so that policy remains consisten…View question
- A financial services company migrated its file-sharing workloads to a sanctioned SaaS platform. Compliance requires that employees be prevented from u…View question
- A company is deploying a three-tier application (web, app, database) in a public cloud IaaS environment. Security requires that the database tier only…View question
- A financial services company is migrating a sensitive customer database to an IaaS provider's managed storage service. Regulatory requirements state t…View question
- A security engineer at a company using a public cloud IaaS provider must investigate who deleted a virtual machine and from which source IP the API ca…View question
Key 350-701 terms
Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the 350-701 exam.
350-701 frequently asked questions
What is the 350-701 certification?+
SCOR is the shared core exam for CCNP Security and a qualifying exam for CCIE Security, making it Cisco’s flagship professional security exam.
It spans network, cloud, content, and endpoint security plus automation, so success rewards broad Cisco security knowledge and hands-on configuration.
What topics are on the 350-701 exam?+
The SCOR exam is organised into six weighted domains. The percentages below are Cisco’s official blueprint weightings, so bias your study toward the heaviest domain — Security Concepts is the largest at 25%, followed by Network Security.
Security Concepts (25%)
The largest domain. Covers common threats against on-premises, hybrid, and cloud environments, security intelligence, phishing and social-engineering defenses, SDN north/south-bound APIs, Cisco Catalyst Center (formerly DNA Center) APIs, and interpreting Python scripts that call Cisco security APIs.
Network Security (20%)
Covers comparing intrusion prevention and firewall solutions, NetFlow and Flexible NetFlow, network infrastructure security, segmentation and access-control policies (AVC, URL filtering, malware protection), AAA with TACACS+ and RADIUS, and site-to-site and remote-access VPNs.
Securing the Cloud (15%)
Covers cloud security solutions, the shared responsibility model across service models, DevSecOps (CI/CD, containers, secure software), application and data security in the cloud, cloud logging and monitoring, and workload security.
Content Security (15%)
Covers traffic redirection and capture for web proxy, web proxy identity and authentication, web and email security deployment methods, and the Cisco Umbrella components, capabilities, and benefits.
Endpoint Protection and Detection (10%)
Covers comparing EPP and EDR, configuring Cisco Secure Endpoint antimalware, outbreak control and quarantines, endpoint posture assessment, multifactor authentication, device management/MDM, and patching strategy.
Secure Network Access, Visibility, and Enforcement (15%)
Covers network access with CoA, device compliance and application control, exfiltration techniques, network telemetry benefits, and the capabilities of Cisco identity and access products such as ISE and TrustSec.
Is the 350-701 hard?+
SCOR is hard because it spans Cisco’s entire security portfolio plus core concepts and automation, so you must know many products and how they fit together.
The heavy Security Concepts and Network Security weighting rewards both theory and hands-on configuration of firewalls, VPNs, and AAA. Practical Cisco security experience is decisive.
How many questions are on the 350-701 exam and how long is it?+
SCOR is a 120-minute exam with a mix of multiple-choice and other item types; Cisco does not publish an exact question count, and it is a qualifying exam for both CCNP Security and CCIE Security.
Our full-length practice mock uses a 90-question, 120-minute session so you can rehearse pacing across all six domains before test day.
What score do you need to pass the 350-701?+
Cisco does not publish a fixed passing score for SCOR; scaled cut scores are not disclosed and vary by exam form, so the 75% threshold on our practice mock is our own study checkpoint rather than an official cutline. Because there is no guessing penalty, answer every question.
How much does the 350-701 exam cost?+
The SCOR exam fee is set by Cisco (around US$400) — check the Cisco site for current pricing. The certification is valid for three years. Everything on this hub is free.
Who should take the 350-701?+
SCOR is aimed at security engineers, network security engineers, and security administrators pursuing CCNP or CCIE Security.
Cisco recommends three to five years of security experience, and CCNA-level networking knowledge, before attempting it.
What jobs and salaries can the 350-701 lead to?+
SCOR maps to roles such as network security engineer, security operations engineer, and security consultant.
How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. SCOR is best viewed as proof of professional-level Cisco security skill.
How long does it take to study for the 350-701?+
Candidates with networking experience often need two to four months, with hands-on time on Cisco Secure Firewall, ISE, and VPN configuration.
Review every explanation, including for questions you answered correctly, because SCOR distractors are built from plausible but incorrect security configurations. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.
How should you prepare for the 350-701?+
Study the six domains above, giving the heaviest weight to Security Concepts and Network Security, then drill scenario questions domain by domain while practicing with Cisco security products. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.
When you can configure firewalls, VPNs, and AAA comfortably, move to full-length timed mocks. Use the glossary to keep technologies like Cisco Secure Firewall, Umbrella, ISE, and TrustSec straight, and aim to score consistently above the checkpoint before you book.
Can you take the 350-701 exam online?+
Yes. Cisco delivers 350-701 SCOR through Pearson VUE, so you can test at a physical Pearson VUE centre or online with OnVUE remote proctoring. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.
If you do not pass, Cisco enforces a waiting period of five calendar days before you can retake the same exam.
What certification should you take after the 350-701?+
After SCOR, you complete CCNP Security with a concentration exam (such as SISE), or pursue the CCIE Security lab.
For many, the real next step is defending enterprise networks in production. Pairing SCOR with hands-on security operations is what turns the certificate into a career.