350-701 cheat sheet
A one-page reference for the Cisco CCNP Security SCOR (350-701) exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
Cisco
Level
Professional
Questions
90
Time
120 min
Mock pass mark
75%
Domains
6
Practice Qs
146
Code
350-701
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- Cisco Secure Firewall
- Cisco Secure Firewall (formerly Firepower) is Cisco's next-generation firewall providing stateful inspection, IPS, and application control managed by FMC or cloud. SCOR covers firewall and IPS capabilities under network security.
- NGIPS
- A Next-Generation Intrusion Prevention System (NGIPS) inspects traffic against threat signatures and behavioral rules to block attacks inline. SCOR covers comparing intrusion prevention and firewall solutions.
- Snort
- Snort is the open-source intrusion-detection and prevention engine that powers Cisco's IPS with signature-based rules. SCOR references Snort rules as the detection mechanism behind Cisco Secure IPS.
- Cisco Umbrella
- Cisco Umbrella is a cloud-delivered security service that enforces DNS-layer protection before connections are established and adds secure web gateway inspection in the web traffic path. SCOR covers Umbrella's components, capabilities, and benefits for content security.
- Secure Web Appliance
- The Cisco Secure Web Appliance (formerly WSA) is a web proxy that enforces URL filtering, malware scanning, and acceptable-use policy. SCOR covers web proxy redirection, identity, and authentication methods.
- AnyConnect
- Cisco Secure Client (formerly AnyConnect) is the endpoint agent that establishes remote-access VPNs and delivers posture and security modules. SCOR covers remote-access VPN configuration and endpoint security.
- VPN
- A Virtual Private Network (VPN) secures traffic over untrusted networks using encryption, covering site-to-site (IPsec) and remote-access designs. SCOR covers configuring and verifying both VPN types.
- TrustSec
- Cisco TrustSec enforces software-defined segmentation using Security Group Tags (SGTs) instead of IP-based ACLs. SCOR covers segmentation and access-control policies for secure network access.
- ISE
- The Identity Services Engine (ISE) is Cisco's policy engine for authentication, authorization, and network access control using 802.1X, profiling, and posture. SCOR covers AAA and secure network access with ISE.
- AAA
- AAA (authentication, authorization, and accounting) controls who accesses devices and networks and logs their actions, via TACACS+ or RADIUS. SCOR covers configuring AAA for device and network access.
- Posture Assessment
- Posture Assessment evaluates an endpoint's compliance (patches, antimalware, configuration) before granting network access. SCOR covers posture as part of secure network access and endpoint security.
- Cisco Secure Endpoint
- Cisco Secure Endpoint (formerly AMP for Endpoints) provides endpoint antimalware, EDR, and retrospective detection. SCOR covers configuring endpoint antimalware protection and outbreak control.
- EDR
- Endpoint Detection and Response (EDR) continuously monitors endpoints to detect, investigate, and respond to threats, going beyond preventive EPP. SCOR covers comparing EPP and EDR solutions.
- CASB
- A Cloud Access Security Broker (CASB) enforces visibility, compliance, and threat protection for cloud application usage. SCOR covers CASB among the security solutions for cloud environments.
- Cloud Security
- Cloud Security in SCOR covers the shared responsibility model, DevSecOps, and protecting applications and data across IaaS, PaaS, and SaaS. It is the basis of the Securing the Cloud domain.