In this Designing Cisco Security Infrastructure course provides a comprehensive introduction to designing, implementing, and evolving security architectures that protect modern enterprise and cloud-based environments. The curriculum begins by defining the purpose of security architecture and examining the core components of security infrastructure, including network, host, application, and management layers. Learners explore foundational security design principles, industry-standard frameworks, and compliance and regulatory considerations, gaining the ability to align technical security controls with organizational risk, governance, and operational requirements.
The course then transitions into practical security approaches used to defend against today’s threat landscape. Topics include network access security, VPN and tunneling technologies, secure control and management planes, next-generation firewalls, web application firewalls, IDS/IPS deployments, host-based and distributed firewalls, and security solutions driven by application and flow telemetry. Learners also examine security architectures for cloud-native applications, microservices, and containerized environments, along with emerging technologies that address evolving application-layer threats.
The final portion of the course focuses on operational security and continuous improvement. Students learn how SOC tools support incident detection, handling, and response, and how security architectures must adapt based on incident findings and risk analysis. DevSecOps integration, secure automation pipelines, and infrastructure-as-code security practices are covered to demonstrate how security can be embedded throughout the development lifecycle. The course concludes with an exploration of AI’s growing role in securing infrastructure, enhancing threat detection, accelerating response, and improving architectural decision-making in complex environments.
How You'll Benefit
This training will help you:
Gain hands-on experience of security architecture design
Qualify for professional and expert-level security job roles
Identify and explain the fundamental concepts of security architecture and how they support the design, building, and maintenance of a secure infrastructure
Identify the layers of security infrastructure, core security technologies, and infrastructure concepts
Explain how security designs principles contribute to secure infrastructure
Identify and discuss security design and management frameworks that can be used for infrastructure security design
Explain the importance of and methods for enforcement of regulatory compliance in security design
Identify tools that enable detection and response to infrastructure security incidents
Explain various strategies that can be implemented to modify traditional security architectures to meet the technical requirements of modern enterprise networks
Implement secure network access methods, such as 802.1X, MAC Authentication Bypass (MAB), and web-based authentication
Describe security technologies that can be applied to enterprise Wide Area Network (WAN) connections
Compare methods to secure network management and control plane traffic
Compare the differences between traditional firewalls and next-gen firewalls (NGFWs) and identify the advanced features that NGFWs provide
Explain how web application firewalls (WAFs) secure web applications from threats
Describe the key features and best practices for deploying intrusion detection system (IDS) and intrusion prevention system (IPS) as part of the enterprise infrastructure security design
Explain how endpoints and services in cloud-native or microservice environments can be protected with host-based or distributed firewalls
Discuss security technologies that address application data and data that is in transit
Identify several security solutions for cloud-native applications, microservices, and containers
Explain how technology advancements allow for improvements in today’s infrastructure security
Identify tools that enable detection and response to infrastructure security incidents
Describe frameworks and controls to access and mitigate security risks for infrastructure
Explain how to make security adjustments following a security incident
Identify DevSecOps integrations that improve security management and response
Discuss how to ensure that automated services are secure
Discuss how AI can aid in threat detection and response
What to Expect in the Exam
Designing Cisco Security Infrastructure (300-745 SDSI) v1.0 is a 90-minute exam associated with the Cisco Certified Specialist - Designing Cisco Security Infrastructure certification and satisfies the core exam requirement for the CCNP Security certification.
This exam tests your knowledge of security architecture design, including: