-
The training provides you with the skills to design and implement cloud security architecture, user and device security, network and cloud security, cloud application and data security, cloud visibility and security, and cloud threat response. You will gain knowledge of protocols, solutions and designs to take a professional and expert role in the development and implementation of cloud solutions.
-
Course Contents
-
- Compare NIST, CISA, and DISA security frameworks and understand the value of standardized cybersecurity models
- Describe the Cisco Security Reference Architecture and its five core components
- Identify common use cases and recommend integrated security capabilities. Explain the Cisco SAFE architecture
- Understand certificate-based authentication for users and devices
- Enable and configure Duo MFA from the Duo Admin Portal for application login
- Install Cisco Duo and implement MFA for remote access VPN
- Configure endpoint compliance
- Demonstrate understanding of Stateful Switchover (SSO) using SAML or OpenID Connect with Duo
- Describe Cisco SD-WAN on-box and integrated threat prevention and content filtering services
- Explain Cisco Umbrella Secure Internet Gateway (SIG) features like DNS Security, Cloud-Delivered Firewall, IPS, and SD-WAN integration
- Introduce reverse proxy for internet-facing app protection
- Explore Umbrella SIG use cases for securing cloud app access, including benefits, limitations, and discovery/control features
- Explore Cisco ThousandEyes for SD-WAN monitoring
- Address SaaS access challenges and explore SD-WAN Cloud OnRamp for SaaS with direct or centralized internet access
- Introduce Cisco Secure Firewall platforms, use cases, and capabilities
- Demonstrate understanding of web application firewalls
- Understand Cisco Secure Workload capabilities, deployment, agents, connectors, application dependency mapping, and policy discovery
- Identify common cloud attack tactics and mitigation strategies
- Understand multicloud security needs and policy capabilities
- Address public cloud security issues and explore visibility and assurance tools
- Introduce Cisco Secure Network Analytics and Cisco Security Analytics and Logging
- Describe Cisco Attack Surface Management
- Explain how APIs and automation assist in troubleshooting cloud policy misconfigurations
- Demonstrate appropriate responses to cloud threats and how automation supports detection and response
You will receive the original course documentation from Cisco in English language as a Cisco E-Book. In the Cisco Digital Learning Version, the content of the courseware is integrated into the learning interface instead.
-
Target Group
-
- Network Engineers
- Network Security Engineers
- Network Architects
- Sales/Presales Engineers
-
Knowledge Prerequisites
-
You should have the following knowledge and skills before attending this training course:
- Basic understanding of enterprise routing
- Basic understanding of WAN networks
- Basic understanding of Cisco SD-WAN
- Basic understanding of public cloud services
This knowledge can be found in the following Cisco learning offerings:
- CCNA - Implementing and Administering Cisco Solutions
- ENSDWI - Implementing Cisco SD-WAN Solutions
- SDWFND - Cisco SD-WAN Operation and Deployment
-
Course Objective
-
The course prepares you for the SCAZT exam. Upon passing, you will receive certification as a Cisco Certified Specialist – Secure Cloud Access. Combine this multicloud specialist exam with the Cisco Core Professional exam SCOR to also fulfill the certification requirements for CCNP Security.
-
Complementary and Continuative Courses
-
SCOR – Implementing and Operating Cisco Security Core Technologies
SFWIPF – Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention
SISE – Implementing and Configuring Cisco Identity Services Engine
SESA – Securing Email with Cisco Email Security Appliance
SWSA – Securing the Web with Cisco Web Security Appliance
SVPN – Implementing Secure Solutions with Virtual Private Networks
SAUI – Implementing Automation for Cisco Security Solutions
SFWIPA – Advanced Techniques for Cisco Firewall Threat Defense and Intrusion Prevention
| Outline |
| Industry Security Frameworks* |
| Cisco Security Reference Architecture Fundamentals* |
| Cisco Security Reference Architecture Common Use Cases* |
| Cisco SAFE Architecture* |
| Certificate-Based User and Device Authentication |
| Cisco Duo Multifactor Authentication for Application Protection |
| Cisco Duo with AnyConnect VPN for Remote Access |
| Introducing Cisco ISE Endpoint Compliance Services |
| SSO using SAML or OpenID Connect |
| Deploying On-Premises Threat Prevention |
| Examining Content Filtering |
| Exploring Cisco Umbrella SIG |
| Reverse Proxy |
| Securing Cloud Application with Cisco Umbrella SIG |
| Exploring Cisco SD-WAN ThousandEyes* |
| Optimizing SaaS Applications |
| Security Policies for Remote Access VPN |
| Cisco Secure Access |
| Cisco Secure Firewall |
| Web Application Firewall |
| Cisco Secure Workload Deployments, Agents, and Connectors |
| Cisco Secure Workload Structure and Policy |
| Cloud Security Attacks and Mitigations |
| Multicloud Security Policies |
| Cloud Visibility and Assurance |
| Cisco Secure Network Analytics and Cisco Secure Analytics and Logging |
| Cisco XDR |
| Cisco Attack Surface Management |
| Cloud Applications and Data Access Verifications |
| Automation of Cloud Policy* |
| Response to Cloud Threats* |
| Automation of Cloud Threat Detection and Response* |
| * This section is self-study material that can be done at your own pace if you are taking the instructor-led version of this course. |
| Lab outline |
| Explore Cisco SecureX |
| Windows Client BYOD Onboarding Interactive Activity |
| Use Cisco Duo MFA to Protect the Splunk Application |
| Integrate the Cisco Duo Authentication Proxy to Implement MFA for Cisco Security Secure Firewall AnyConnect Remote Access VPN |
| Configure Cisco ISE Compliance Services |
| Configure Threat Prevention |
| Implement Web Security |
| Deploy DIA Security with Unified Security Policy |
| Configure Cisco Umbrella DNS Policies |
| Deploy Cisco Umbrella Secure Internet Gateway |
| Implement CASB Security |
| Microsoft 365 SaaS Testing by Using Cisco ThousandEyes |
| Configure Remote Access VPN on the Cisco Secure Firewall Threat Defense |
| Configure Cisco Secure Firewall Policies |
| Explore Cisco Secure Workload |
| Explore the ATT&CK Matrix Cloud-Based Techniques |
| Explore Cisco Secure Network Analytics |
| Explore Cisco XDR Incident Response Tasks |
Certification as CCNP Security Certification
-
Classroom training
- Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!
-
Hybrid training
- Hybrid training means that online participants can additionally attend a classroom course. The dynamics of a real seminar are maintained, and the online participants are able to benefit from that. Online participants of a hybrid course use a collaboration platform, such as WebEx Training Center or Saba Meeting. To do this, a PC with browser and Internet access is required, as well as a headset and ideally a Web cam. In the seminar room, we use specially developed and customized audio- and video-technologies. This makes sure that the communication between all persons involved works in a convenient and fault-free way.
-
Online training
- You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.
-
Cisco Digital Learning
- This course is available in the Cisco Digital Learning Library. These recently developed, multi-modal training events include HD videos moderated by lecturers with stored searchable text and subtitles, as well as a exercises, labs, and explanatory text and graphics. We provide this offer to you via our myExperTeach learning portal. Effective of the activation of the account, access to the courses will be granted for a duration of 6 months. In the case of packet solutions (Cisco Digital Learning Subscriptions), this time period will amount to 12 months.
-
Tailor-made courses
-
You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
-
The training provides you with the skills to design and implement cloud security architecture, user and device security, network and cloud security, cloud application and data security, cloud visibility and security, and cloud threat response. You will gain knowledge of protocols, solutions and designs to take a professional and expert role in the development and implementation of cloud solutions.
-
Course Contents
-
- Compare NIST, CISA, and DISA security frameworks and understand the value of standardized cybersecurity models
- Describe the Cisco Security Reference Architecture and its five core components
- Identify common use cases and recommend integrated security capabilities. Explain the Cisco SAFE architecture
- Understand certificate-based authentication for users and devices
- Enable and configure Duo MFA from the Duo Admin Portal for application login
- Install Cisco Duo and implement MFA for remote access VPN
- Configure endpoint compliance
- Demonstrate understanding of Stateful Switchover (SSO) using SAML or OpenID Connect with Duo
- Describe Cisco SD-WAN on-box and integrated threat prevention and content filtering services
- Explain Cisco Umbrella Secure Internet Gateway (SIG) features like DNS Security, Cloud-Delivered Firewall, IPS, and SD-WAN integration
- Introduce reverse proxy for internet-facing app protection
- Explore Umbrella SIG use cases for securing cloud app access, including benefits, limitations, and discovery/control features
- Explore Cisco ThousandEyes for SD-WAN monitoring
- Address SaaS access challenges and explore SD-WAN Cloud OnRamp for SaaS with direct or centralized internet access
- Introduce Cisco Secure Firewall platforms, use cases, and capabilities
- Demonstrate understanding of web application firewalls
- Understand Cisco Secure Workload capabilities, deployment, agents, connectors, application dependency mapping, and policy discovery
- Identify common cloud attack tactics and mitigation strategies
- Understand multicloud security needs and policy capabilities
- Address public cloud security issues and explore visibility and assurance tools
- Introduce Cisco Secure Network Analytics and Cisco Security Analytics and Logging
- Describe Cisco Attack Surface Management
- Explain how APIs and automation assist in troubleshooting cloud policy misconfigurations
- Demonstrate appropriate responses to cloud threats and how automation supports detection and response
You will receive the original course documentation from Cisco in English language as a Cisco E-Book. In the Cisco Digital Learning Version, the content of the courseware is integrated into the learning interface instead.
-
Target Group
-
- Network Engineers
- Network Security Engineers
- Network Architects
- Sales/Presales Engineers
-
Knowledge Prerequisites
-
You should have the following knowledge and skills before attending this training course:
- Basic understanding of enterprise routing
- Basic understanding of WAN networks
- Basic understanding of Cisco SD-WAN
- Basic understanding of public cloud services
This knowledge can be found in the following Cisco learning offerings:
- CCNA - Implementing and Administering Cisco Solutions
- ENSDWI - Implementing Cisco SD-WAN Solutions
- SDWFND - Cisco SD-WAN Operation and Deployment
-
Course Objective
-
The course prepares you for the SCAZT exam. Upon passing, you will receive certification as a Cisco Certified Specialist – Secure Cloud Access. Combine this multicloud specialist exam with the Cisco Core Professional exam SCOR to also fulfill the certification requirements for CCNP Security.
-
Complementary and Continuative Courses
-
SCOR – Implementing and Operating Cisco Security Core Technologies
SFWIPF – Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention
SISE – Implementing and Configuring Cisco Identity Services Engine
SESA – Securing Email with Cisco Email Security Appliance
SWSA – Securing the Web with Cisco Web Security Appliance
SVPN – Implementing Secure Solutions with Virtual Private Networks
SAUI – Implementing Automation for Cisco Security Solutions
SFWIPA – Advanced Techniques for Cisco Firewall Threat Defense and Intrusion Prevention
| Outline |
| Industry Security Frameworks* |
| Cisco Security Reference Architecture Fundamentals* |
| Cisco Security Reference Architecture Common Use Cases* |
| Cisco SAFE Architecture* |
| Certificate-Based User and Device Authentication |
| Cisco Duo Multifactor Authentication for Application Protection |
| Cisco Duo with AnyConnect VPN for Remote Access |
| Introducing Cisco ISE Endpoint Compliance Services |
| SSO using SAML or OpenID Connect |
| Deploying On-Premises Threat Prevention |
| Examining Content Filtering |
| Exploring Cisco Umbrella SIG |
| Reverse Proxy |
| Securing Cloud Application with Cisco Umbrella SIG |
| Exploring Cisco SD-WAN ThousandEyes* |
| Optimizing SaaS Applications |
| Security Policies for Remote Access VPN |
| Cisco Secure Access |
| Cisco Secure Firewall |
| Web Application Firewall |
| Cisco Secure Workload Deployments, Agents, and Connectors |
| Cisco Secure Workload Structure and Policy |
| Cloud Security Attacks and Mitigations |
| Multicloud Security Policies |
| Cloud Visibility and Assurance |
| Cisco Secure Network Analytics and Cisco Secure Analytics and Logging |
| Cisco XDR |
| Cisco Attack Surface Management |
| Cloud Applications and Data Access Verifications |
| Automation of Cloud Policy* |
| Response to Cloud Threats* |
| Automation of Cloud Threat Detection and Response* |
| * This section is self-study material that can be done at your own pace if you are taking the instructor-led version of this course. |
| Lab outline |
| Explore Cisco SecureX |
| Windows Client BYOD Onboarding Interactive Activity |
| Use Cisco Duo MFA to Protect the Splunk Application |
| Integrate the Cisco Duo Authentication Proxy to Implement MFA for Cisco Security Secure Firewall AnyConnect Remote Access VPN |
| Configure Cisco ISE Compliance Services |
| Configure Threat Prevention |
| Implement Web Security |
| Deploy DIA Security with Unified Security Policy |
| Configure Cisco Umbrella DNS Policies |
| Deploy Cisco Umbrella Secure Internet Gateway |
| Implement CASB Security |
| Microsoft 365 SaaS Testing by Using Cisco ThousandEyes |
| Configure Remote Access VPN on the Cisco Secure Firewall Threat Defense |
| Configure Cisco Secure Firewall Policies |
| Explore Cisco Secure Workload |
| Explore the ATT&CK Matrix Cloud-Based Techniques |
| Explore Cisco Secure Network Analytics |
| Explore Cisco XDR Incident Response Tasks |
Certification as CCNP Security Certification
-
Classroom training
- Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!
-
Hybrid training
- Hybrid training means that online participants can additionally attend a classroom course. The dynamics of a real seminar are maintained, and the online participants are able to benefit from that. Online participants of a hybrid course use a collaboration platform, such as WebEx Training Center or Saba Meeting. To do this, a PC with browser and Internet access is required, as well as a headset and ideally a Web cam. In the seminar room, we use specially developed and customized audio- and video-technologies. This makes sure that the communication between all persons involved works in a convenient and fault-free way.
-
Online training
- You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.
-
Cisco Digital Learning
- This course is available in the Cisco Digital Learning Library. These recently developed, multi-modal training events include HD videos moderated by lecturers with stored searchable text and subtitles, as well as a exercises, labs, and explanatory text and graphics. We provide this offer to you via our myExperTeach learning portal. Effective of the activation of the account, access to the courses will be granted for a duration of 6 months. In the case of packet solutions (Cisco Digital Learning Subscriptions), this time period will amount to 12 months.
-
Tailor-made courses
-
You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
