IT Certification and Career Paths

300-207 SITCS

Implementing Cisco Threat Control Solutions

Exam Number 300-207 SITCS
Associated Certifications CCNP Security
Duration 90 minutes (65 - 75 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

The 300-207 Implementing Cisco Threat Control Solutions (SITCS) exam tests a network security engineer on advanced firewall architecture and configuration with Cisco's Next Generation Firewall (NGFW) utilizing access and identity polices. This exam covers integration of Intrusion Prevention System (IPS) and context-aware firewall components, as well as Web (Cloud) and Email Security solutions. Candidates can prepare for this exam by taking the Implementing Cisco Threat Control Solutions (SITCS) course.

Exam Topics

The exam is closed book, and no outside reference materials are allowed. The following topics are general guidelines for the content that is likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines that follow may change at any time without notice.

  • 22%     1.0   Content Security

      • 1.1   Implement Cisco CX
        • 1.1.a   Describe features and functionality
        • 1.1.b   Implement web usage control
        • 1.1.c   Implement AVC
        • 1.1.d   Implement decryption policies
        • 1.1.e   Describe traffic redirection and capture methods
           
      • 1.2   Implement Cisco Cloud Web Security
        • 1.2.a   Describe features and functionality
        • 1.2.b   Implement IOS and ASA connectors
        • 1.2.c   Implement AnyConnect web security module
        • 1.2.d   Describe web usage control
        • 1.2.e   Describe AVC
        • 1.2.f   Describe anti-malware
        • 1.2.g   Describe decryption policies
           
      • 1.3   Implement Cisco WSA
        • 1.3.a   Implement data security
        • 1.3.b   Describe traffic redirection and capture methods
           
      • 1.4   Implement Cisco ESA
        • 1.4.a   Describe features and functionality
        • 1.4.b   Implement email encryption
        • 1.4.c   Implement anti-spam policies
        • 1.4.d   Implement virus outbreak filter
        • 1.4.e   Implement DLP policies
        • 1.4.f   Implement anti-malware
        • 1.4.g   Implement inbound and outbound mail policies
                      and authentication
        • 1.4.h   Describe traffic redirection and capture methods
           
  • 23%     2.0   Threat Defense

      • 2.1   Implement network IPS
        • 2.1.a   Describe traffic redirection and capture methods
        • 2.1.b   Configure network IPS
        • 2.1.c   Describe signatures
        • 2.1.d   Implement event actions
        • 2.1.e   Configure event action overrides
        • 2.1.f   Implement risk ratings
        • 2.1.g   Describe router-based IPS
           
      • 2.2   Configure Device Hardening per Best Practices
        • 2.2.a   IPS
        • 2.2.b   Content Security appliances
           
      • 2.3   Implement Network IPS
        • 2.3.a   Describe signatures
        • 2.3.b   Configure blocking
        • 2.3.c   Implement anomaly detection
           
  • 16%     3.0   Devices GUIs and Secured CLI

      • 3.1   Implement Content Security
         
  • 19%     4.0   Troubleshooting, Monitoring and Reporting
                Tools

      • 4.1   Configure IME and IP logging for IPS
         
      • 4.2   Monitor Content Security
         
      • 4.3   Monitor Cisco Security intelliShield
         
  •   8%     5.0   Threat Defense Architectures

      • 5.1   Design IPS solution
         
  • 12%     6.0   Content Security Architectures

      • 6.1   Design web security solution
         
      • 6.2   Design email security solution
         
      • 6.3   Design application security solution
         
  • The following course is the recommended training for this exam:

    Courses listed are offered by Cisco Learning Partners-the only authorized source for Cisco IT training delivered exclusively by Certified Cisco Instructors. Check the List of Learning Partners for a Cisco Learning Partner nearest you

    A variety of Cisco Press titles may be available for this exam. These titles can be purchased through the Cisco Marketplace Bookstore, directly from Cisco Press.

          Register at Pearson VUE      

    Cisco Learning Network

    Get valuable IT training resources for all Cisco certifications. Access study tools, CCNA practice tests, IT salaries, and find IT jobs.

    Go Now

    Cisco Training Tools

    Use the following tools to assist in your certification journey.

    Cisco Learning Locator Self Assessment Tool Certification Tracking System Certifications & Communities Online Support

    Cisco Learning Labs

    Get hands-on routing / switching lab experience using Cisco IOS on UNIX.

    Learn More