350-701 cheat sheet

A one-page reference for the Cisco CCNP Security SCOR (350-701) exam: the format, how the domains are weighted, and the glossary terms for this exam.

Exam at a glance

Vendor
Cisco
Level
Professional
Questions
90
Time
120 min
Mock pass mark
75%
Domains
6
Practice Qs
146
Code
350-701

Domain weightings

How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.

Key terms

Cisco Secure Firewall
Cisco Secure Firewall (formerly Firepower) is Cisco's next-generation firewall providing stateful inspection, IPS, and application control managed by FMC or cloud. SCOR covers firewall and IPS capabilities under network security.
NGIPS
A Next-Generation Intrusion Prevention System (NGIPS) inspects traffic against threat signatures and behavioral rules to block attacks inline. SCOR covers comparing intrusion prevention and firewall solutions.
Snort
Snort is the open-source intrusion-detection and prevention engine that powers Cisco's IPS with signature-based rules. SCOR references Snort rules as the detection mechanism behind Cisco Secure IPS.
Cisco Umbrella
Cisco Umbrella is a cloud-delivered security service that enforces DNS-layer protection before connections are established and adds secure web gateway inspection in the web traffic path. SCOR covers Umbrella's components, capabilities, and benefits for content security.
Secure Web Appliance
The Cisco Secure Web Appliance (formerly WSA) is a web proxy that enforces URL filtering, malware scanning, and acceptable-use policy. SCOR covers web proxy redirection, identity, and authentication methods.
AnyConnect
Cisco Secure Client (formerly AnyConnect) is the endpoint agent that establishes remote-access VPNs and delivers posture and security modules. SCOR covers remote-access VPN configuration and endpoint security.
VPN
A Virtual Private Network (VPN) secures traffic over untrusted networks using encryption, covering site-to-site (IPsec) and remote-access designs. SCOR covers configuring and verifying both VPN types.
TrustSec
Cisco TrustSec enforces software-defined segmentation using Security Group Tags (SGTs) instead of IP-based ACLs. SCOR covers segmentation and access-control policies for secure network access.
ISE
The Identity Services Engine (ISE) is Cisco's policy engine for authentication, authorization, and network access control using 802.1X, profiling, and posture. SCOR covers AAA and secure network access with ISE.
AAA
AAA (authentication, authorization, and accounting) controls who accesses devices and networks and logs their actions, via TACACS+ or RADIUS. SCOR covers configuring AAA for device and network access.
Posture Assessment
Posture Assessment evaluates an endpoint's compliance (patches, antimalware, configuration) before granting network access. SCOR covers posture as part of secure network access and endpoint security.
Cisco Secure Endpoint
Cisco Secure Endpoint (formerly AMP for Endpoints) provides endpoint antimalware, EDR, and retrospective detection. SCOR covers configuring endpoint antimalware protection and outbreak control.
EDR
Endpoint Detection and Response (EDR) continuously monitors endpoints to detect, investigate, and respond to threats, going beyond preventive EPP. SCOR covers comparing EPP and EDR solutions.
CASB
A Cloud Access Security Broker (CASB) enforces visibility, compliance, and threat protection for cloud application usage. SCOR covers CASB among the security solutions for cloud environments.
Cloud Security
Cloud Security in SCOR covers the shared responsibility model, DevSecOps, and protecting applications and data across IaaS, PaaS, and SaaS. It is the basis of the Securing the Cloud domain.