Explain how different threat actors operate by describing their motivations, common attack vectors, typical breach and credential-abuse patterns, and the role of the cyber threat intelligence lifecycle in helping organisations understand and track these evolving threats
Describe how structural weaknesses in software and web applications are identified, classified, and prioritised using concepts such as vulnerability classes, OWASP, CVE, and CVSS, and explain how AI/LLM systems extend this landscape with new vulnerability patterns
Explain why humans and identity remain a primary attack vector by describing social-engineering and credential-theft lifecycles and by outlining the key conceptual defense layers that organisations apply to reduce, but not completely remove, identity-driven risk
Describe the main cryptographic building blocks, hashing, symmetric and asymmetric encryption, key exchange, digital signatures, PKI, and encrypted transport protocols, and explain the specific security guarantees and trust assumptions each introduces into an enterprise design
Explain how Zero Trust, defense in depth, and the Cisco SAFE Blueprint framework together turn threat, vulnerability, identity, and cryptographic insights into a coherent security architecture that assumes failure, limits blast radius, and guides technology placement across the environment
Describe why the Layer 2 access network is a foundational security boundary by explaining how segmentation, topology, addressing, neighbor discovery, and edge-port controls work together to prevent local attacks from undermining higher-layer security
Describe how to secure network infrastructure devices by reducing their attack surface, protecting management and control planes as privileged authority channels, and choosing management-plane architectures that create clear, defensible trust boundaries
Explain how to design and operate AAA for infrastructure administration by choosing appropriate protocols, defining AAA and fallback behavior, and systematically troubleshooting AAA failures to restore secure administrative access
Perform Cisco Secure Firewall Threat Defense Basic Setup
Configure access control policy with intrusion policy, file and malware policy to meet given security requirements
Configure secure site-to-site VPN solutions to establish connectivity between remote sites using Cisco Secure Firewall Threat Defense
Configure remote access VPN solutions on Cisco Secure Firewall Threat Defense to provide secure connectivity to the corporate network for remote users
Evaluate cloud security strategies using NIST 800-145 shared responsibility models, security frameworks, and CASB solutions for multicloud environments
Describe cloud workload security strategies encompassing microsegmentation principles, Cisco Secure Workload, Multicloud Defense platforms, and eBPF-based security approaches
Describe DevSecOps and Infrastructure as Code principles and interpret Python scripts to call security appliances API
Describe SASE and SSE architectures and Cisco Secure Access capabilities providing unified, cloud-delivered protection of private applications and the internet across remote and branch environments
Configure cloud-delivered connectivity, identity-aware authentication, and granular access policies to provide secure access to private applications for remote and branch users
Configure connectivity identity, and security controls to provide secure access to the internet and SaaS applications for remote and branch users
Explain how identity, device context, and policy-driven access control work together in secure network access solutions, and describe how Cisco ISE supports differentiated access through AAA, guest access, profiling, and BYOD
Configure wired and wireless network access control with Cisco ISE by implementing 802.1X and MAB, applying Cisco ISE authentication and authorisation policy, selecting appropriate EAP and supplicant approaches, and using RADIUS and CoA to enforce the change access state
Explain how Cisco Duo supports zero-trust principles through strong user verification, device trust, adaptive access policy, and identity-risk visibility with Cisco Identity Intelligence
Explain how Cisco Secure Email Threat Defense is integrated and configured in Microsoft 365-based email environments to provide message visibility, threat analysis, and remediation against phishing, business email compromise, and account takeover
Explain how organisations build, validate, and enforce endpoint trust through device management, asset visibility, compliance and posture assessment, and application control to reduce endpoint security risk
Explain how modern endpoint security, such as Cisco Secure Endpoint with Cisco Secure Malware Analytics, combines prevention, continuous detection, malware analysis, and event-driven investigation by using Endpoint Protection Platform (EPP) and Endpoint Detection and Response (EDR) concepts
Describe how Splunk Enterprise and Splunk Cloud function as data analytics platforms for security operations, explain how Splunk platform components and deployment models support scalable data processing and analytics, construct queries using Splunk Processing Language to search and analyse the ingested data, explain how Cisco security products are integrated into Splunk, and describe how Splunk Enterprise extends the platform with SIEM capabilities
Explain how Splunk SOAR supports SOC operations through orchestration, playbook automation, and case-driven response, and describe how it works with Splunk Enterprise Security and Cisco XDR to automate investigation and response workflows
Explain how XDR unifies threat detection, investigation, and response across multiple security domains, and describe how Cisco XDR provides cross-domain visibility, correlation, prioritisation, investigation, and coordinated and automated response across integrated security controls
There are no prerequisites for this training. However, the knowledge and skills you are recommended to have before attending this training are: