Cisco FirePOWER NGIPS and Cisco AMP Now Included
Prepare for the latest in network security with CCNP Security.
Cisco Certified Network Professional Security (CCNP Security) certification program is aligned specifically to the job role of the Cisco Network Security Engineer responsible for Security in Routers, Switches, Networking devices and appliances, as well as choosing, deploying, supporting and troubleshooting Firewalls, VPNS, and IDS/IPS solutions for their networking environments.
Exams & Recommended Training
For a complete list of available network security training, visit the Security training page.
- Implementing Cisco Secure Access Solutions (SISAS) v1.0
- Implementing Cisco Edge Network Security Solutions (SENSS) v1.0
- Implementing Cisco Secure Mobility Solutions (SIMOS) v1.0
- Implementing Cisco Threat Control Solutions (SITCS) v1.5
- CCNP Security Tech Seminars
A comprehensive list of study materials is also available.
Cisco Learning Network resources
Get all your CCNP Security questions answered.
Learning partner content
The best way to prepare for the CCNP Security certification is to take the Cisco-approved training:
This five-day course prepares network security engineers with the skills and knowledge needed to deploy the Cisco Identity Services Engine (ISE) and 802.1X secure network access and to implement and manage network access security by using the Cisco ISE appliance product solution.
This five-day course prepares network security engineers with the skills and knowledge needed to configure Cisco perimeter edge security solutions utilizing Cisco switches, Cisco routers, and Cisco Adaptive Security Appliance (ASA) firewalls and to implement and manage security on Cisco ASA firewalls, Cisco routers with the firewall feature set, and Cisco switches.
This five-day course prepares network security engineers with the knowledge and skills needed to protect data traversing a public or shared infrastructure such as the Internet by implementing and maintaining Cisco VPN solutions and troubleshooting remote-access and site-to-site VPN solutions, using Cisco ASA adaptive security appliances and Cisco IOS routers.
This five-day course prepares network security engineers with the knowledge and skills to implement Ciscos FirePOWER Next-Generation IPS, AMP, as well as Web Security, Email Security and Cloud Web Security. You will gain hands-on experience with configuring various advance Cisco security solutions for mitigating outside threats and securing traffic traversing the firewall.
To earn the Cisco CCNP security certification, you must pass the following exams:
The 300-208 Implementing Cisco Secure Access Solutions (SISAS) exam tests validates a network security engineer knowledge of the components and architecture of secure access by utilizing 802.1X and Cisco TrustSec, including the Cisco Identity Services Engine (ISE) architecture, solution, and components as an overall network threat mitigation and endpoint control solution. It also validates the knowledge of the fundamental concepts of BYOD using the posture and profiling services of the Cisco ISE. Candidates can prepare for this exam by taking the Implementing Cisco Secure Access Solutions (SISAS) course.
The 300-206 Implementing Cisco Edge Network Security Solutions (SENSS) exam validates the knowledge of a network security engineer to configure and implement security on Cisco network perimeter edge devices such as a Cisco switch, Cisco router, or Cisco ASA firewall. The exam focuses on the technologies used to strengthen the security of a network perimeter such as Network Address Translation (NAT), Cisco ASA policy and application inspection, and a zone-based firewall on Cisco routers. Candidates can prepare for this exam by taking the Implementing Cisco Edge Network Security Solutions (SENSS) course.
The 300-209 Implementing Cisco Secure Mobility Solutions (SIMOS) exam tests a network security engineer on the variety of virtual private network (VPN) solutions that Cisco has available on the Cisco ASA firewall and Cisco IOS Software platforms. In addition, the exam validates the knowledge necessary to properly implement highly secure remote communications through VPN technology, such as remote-access SSLVPN and site-to-site VPN (DMVPN, FlexVPN). Candidates can prepare for this exam by taking the Implementing Cisco Secure Mobility Solutions (SIMOS) course.
This exam tests a network security engineer on advanced firewall architecture and configuration with the Cisco next-generation firewall, utilizing access and identity policies. Some older technologies have been removed and includes coverage for both Cisco Firepower NGIPS and Cisco AMP (Advanced Malware Protection). This exam covers integration of Intrusion Prevention System (IPS) and context-aware firewall components, as well as Web (Cloud) and Email Security solutions. Candidates can prepare for this exam by taking the Implementing Cisco Threat Control Solutions (SITCS) course.
Cisco Professional-level certifications (CCDP, CCNP Cloud, CCNP Collaboration, CCNP Data Center, CCNP Routing and Switching, CCNP Security, CCNP Service Provider, and CCNP Wireless) are valid for three years.
To recertify, pass ONE of the following before the certification expiration date:
- Pass any current 642-XXX Professional-level or any 300-XXX Professional-level exam, or
- Pass any current CCIE Written Exam, or
- Pass the current CCDE Written Exam OR current CCDE Practical Exam, or
- Pass the Cisco Certified Architect (CCAr) interview AND the CCAr board review to extend lower certifications.
Achieving or recertifying any of the certifications above automatically extends your active Associate and Professional level certification(s) up to the point of expiration of the last certification achieved.
For more information, access the How to Recertify page.