| Section | Weight | Objectives |
| Threat Defense, Content Security and Automation | 20% | - Advanced threat protection
- 1. AMP for endpoints & networks
- 2. ESA, WSA, Umbrella
- Automation & evolving technologies
- 1. Network programmability
- 2. Cloud security concepts
|
| Identity Services and Access Control | 20% | - Network access control
- 1. TrustSec, SGT segmentation
- 2. 802.1X, MAB, WebAuth
- Cisco ISE
- 1. Authentication & authorization
- 2. Profiling, posture, guest services
|
| Firewall and Intrusion Prevention Technologies | 20% | - Cisco ASA and FTD
- 1. NAT, policy, inspection
- 2. Deployment modes
- Intrusion Prevention System
- 1. IPS policies & signatures
- 2. Threat detection & mitigation
|
| Infrastructure, Connectivity, Communications, and Network Security | 20% | - Infrastructure security
- 1. AAA, TACACS+, RADIUS
- 2. ACLs, CoPP, uRPF
- 3. Device hardening
- Networking fundamentals
- 1. OSI model, TCP/UDP/IP
- 2. IPv4/IPv6 addressing
- 3. VLAN, trunking, spanning tree
- 4. Routing protocols & security
|
| Security Protocols, Cryptography, and VPN Technologies | 20% | - Virtual Private Networks
- 1. Remote access SSL VPN
- 2. DMVPN, GETVPN
- 3. Site-to-site IPsec VPN
- Cryptography
- 1. SSL/TLS, IPsec
- 2. Hashing, encryption, PKI
|