OUTLINE
Module 1: Cisco Security Cloud Control
Lesson 1: Security Cloud Control Overview
- Cisco Security Cloud Control Overview
- Integrations Overview
Lesson 2: Security Cloud Control Provisioning Overview
- Tenant provisioning concepts
- Cisco account access
- Smart Account and Virtual Account relationship
- Entitlements and licensing
- Tenant region and organization boundaries
Lesson 3: Provisioning Prerequisites and Planning
- Cisco account requirements
- Organization access
- Smart Account access
- Virtual Account planning
- Security Cloud Control entitlement
- cdFMC entitlement
- Secure Firewall licenses
- Administrator role planning
- SSO/MFA planning
- Splunk and XDR integration planning
Lesson 4: Tenant Creation and Initial Access
- Accessing an existing tenant
- Receiving tenant invitation
- Validating correct organization
- Reviewing tenant settings
- Verifying inventory access
- Confirming audit or activity logs
Lesson 5: Administrative Access, RBAC, and Identity
- Least privilege
- Named administrator accounts
- Role-based access control
- SSO and identity provider considerations
- MFA
- Break-glass account planning
- Auditability
Lesson 6: Smart Account, Licensing, and Entitlement Readiness
- Security Cloud Control entitlement
- cdFMC entitlement
- Secure Firewall base license
- Threat license
- Malware license
- URL license
- RA VPN license, if used
- XDR entitlement
- Splunk licensing/storage planning
Lesson 7: cdFMC Service Readiness
- Launching cdFMC from Security Cloud Control
- Device management readiness
- Policy management readiness
- Object management readiness
- Event visibility
- Deployment workflow readiness
Lesson 8: Security, Compliance, and Governance
- Audit logging
- Access review
- Change control
- Deployment approval
- Data visibility and retention
- Regional considerations
- API and integration governance
Module 2: Configuring Authentication in Cisco Security Cloud Control
Lesson 1: Security Cloud Control Authentication Architecture
- Security Cloud Control authentication overview
- Administrative authentication versus network-user authentication
- Authentication, authorization, and accounting
- Identity providers and service providers
- Single sign-on concepts
- Security Assertion Markup Language
- Multifactor authentication
- Active and passive authentication
- User-to-IP address mapping
- Directory synchronization
- Authentication data flow
Lesson 2: Configuring Active Directory Authentication
- Active Directory integration requirements
- Domain controllers and Global Catalog servers
- LDAP and LDAPS communication
- DNS and Network Time Protocol dependencies
- Certificate requirements
- Service account permissions
- User and group discovery
- Realm configuration
- Directory synchronization
- Nested group considerations
- Authentication testing
- Configuration Workflow
- Troubleshooting
Lesson 3: Configuring Microsoft Entra ID Authentication
- Microsoft Entra ID authentication models
- Entra ID application registration
- Directory tenant identification
- Application client identifiers
- Client secrets
- Microsoft Graph permissions
- Enterprise applications
- SAML-based single sign-on
- User and group assignments
- Conditional Access
- Entra ID audit logs
- Azure Event Hubs
- Active versus passive authentication
- Configuration Workflow
- Troubleshooting
Lesson 4: Configuring Identity and Access Control Policies
- Identity policy purpose
- Authentication rules
- Active authentication
- Passive authentication
- Realm selection
- Authentication fallback
- Captive portal configuration
- Certificate requirements
- User and group conditions
- Access control rule integration
- Unknown-user handling
- Policy deployment
Lesson 5: Cisco Duo Authentication and MFA
- Cisco Duo architecture
- Duo Universal Prompt
- Duo users, groups, and devices
- Enrollment methods
- Duo Push and Verified Duo Push
- Passcodes and hardware tokens
- Passkeys and security keys
- Trusted endpoints
- Remembered devices
- Authorized networks
- New-user policies
- Application policies
- Authentication policies
- Duo reporting and authentication logs
Lesson 6: Cisco Identity Intelligence
Module 3: Cisco Security Cloud Control Integrations
Lesson 1: Cisco Security Cloud Control Integrations
- Security Cloud Control Integration Architecture
- Integration Categories
- Integration Data Types
- Integration Requirements
- Integration Monitoring
Lesson 2: Integration of Identity Services Engine
- Cisco ISE Integration Architecture
- Integration Requirements
- Configuring ISE Connectivity
- Identity-Based Policy Enforcement
- Monitoring and Troubleshooting
Lesson 3: Catalyst SD-WAN Integration
- Catalyst SD-WAN Integration Architecture
- Catalyst SD-WAN Integration Prerequisites
- Catalyst SD-WAN Workflow
- Catalyst SD-WAN Security Policy Management
- Catalyst SD-WAN Integration Troubleshooting
Lesson 4: Meraki SD-WAN Integration
- Meraki SD-WAN Integration Requirements
- Meraki SD-WAN Integration
- Firewall Policy Management
- SCC Co-Management Considerations
- Meraki SD-WAN Integration Troubleshooting
Lesson 5: Splunk Security Integration
- Splunk Integration Architecture
- Integration Use Cases
- Splunk Data Sources
- Splunk Enterprise and Splunk Cloud Integration
- Configuration Components
- Investigation and Automation
- Troubleshooting
Lesson 6: Cisco XDR Integration
- Cisco XDR Integration Architecture
- Integration Capabilities
- Tenant Linking
- Configuring the Integration
- Event Sharing and Investigation
- Cisco XDR Automation
- Troubleshooting
Module 4: Logging, Monitoring, and Event Analysis
Lesson 1: Firewall Event Visibility
- Connection events
- Intrusion events
- File events
- Malware events
- URL events
- VPN events
- Health events
- Deployment events
- Event filtering
- NAT visibility
- Rule match analysis
Module 5: Cisco Secure Firewall Platform Overview
Lesson 1: Cisco Secure Firewall Architecture
- Cisco Secure Firewall portfolio
- Secure Firewall Threat Defense
- Physical, virtual, and cloud deployments
- Enforcement plane vs. management plane
- Policy lifecycle
- Threat inspection overview
- Event generation
- Cisco Talos intelligence role
Lesson 2: Management - FDM, FMC, cdFMC, and Security Cloud Control
- Firewall Device Manager
- On-prem FMC
- Cloud-delivered FMC
- Cisco Security Cloud Control
- Centralized policy management
- Hybrid management models
- SaaS-based operations
Lesson 3: Cisco Security Cloud Control Orientation
- SCC dashboard
- Tenant concepts
- Inventory
- Administrative roles
- Activity and audit logs
- Launching cdFMC
- Operational visibility
Module 6: SCC FMC and cdFMC Architecture
Lesson 1: Firewall Manager Architecture and Policy Flow
- Manager-to-device relationship
- Device registration
- Policy assignment
- Access control policy
- NAT policy
- Intrusion policy
- File and malware policy
- URL filtering policy
- Platform settings
- Health policies
- Object model
- Deployment workflow
- Event flow
Module 7: SSC Secure Firewall Onboarding
Lesson 1: Device Registration and Licensing
- Onboarding prerequisites
- Management interface
- Registration key
- NAT ID
- DNS
- NTP
- Smart Licensing
- Initial access control policy
- Health monitoring
- Common onboarding failures
Module 8: Interfaces and Security Zones
Lesson 1: Interface Types and Zone Design
- Routed interfaces
- Subinterfaces
- VLAN tagging
- Management interface
- Security zones
- Zone naming
- Zone-based policy
- Common zone mistakes
Module 9: Routing Fundamentals
Lesson 1: Static Routing and Traffic Forwarding
- Routing table
- Default route
- Internal routes
- DMZ routes
- Return path
- Routing and NAT interaction
- Asymmetric routing
Module 10: SCC FW Object Management
Lesson 1: Reusable Objects and Naming Standards
- Network objects
- Host objects
- Port objects
- URL objects
- FQDN objects
- Object groups
- Naming conventions
- Object governance
Module 11: Access Control Policy
Lesson 1: Access Control Rule Design
- Access control policy structure
- Rule order
- Source/destination zones
- Source/destination networks
- Ports
- Applications
- URLs
- Users
- Default action
- Logging
- Deployment
Module 12: NAT Policy
Lesson 1: Outbound and Inbound NAT
- Dynamic PAT
- Dynamic NAT
- Static NAT
- Identity NAT
- Policy NAT
- NAT rule order
- NAT and access control interaction
Module 13: Application Control
Lesson 1: Application-Aware Firewall Policy
- Port-based vs. application-aware control
- Application detection
- Encrypted traffic limitations
- Application categories
- Rule placement
- Event visibility
Module 14: URL Filtering
Lesson 1: URL Category and Reputation Controls
- URL categories
- Reputation filtering
- Custom URL objects
- HTTPS visibility
- Licensing
- Cloud intelligence lookups
- URL event review
Module 15: Intrusion Prevention
Lesson 1: Applying IPS Inspection
- Intrusion policy overview
- Balanced Security and Connectivity
- Security over Connectivity
- Connectivity over Security
- Rule recommendations
- Event priority
- Tuning considerations
Module 16: File and Malware Inspection
Lesson 1: File Policy and Malware Defense
- File detection
- File blocking
- Malware cloud lookup
- Retrospective analysis where supported
- File event review
- Licensing
- Encrypted traffic considerations
Module 17: Cloud-Delivered Firewall Operations
Lesson 1: Operating Firewalls Through Cloud-Delivered Management
- cdFMC use cases
- SCC operations
- Distributed firewall management
- SaaS lifecycle benefits
- Hybrid management
- Cloud connectivity
- Tenant boundaries
- Licensing
- Audit logging
- Data visibility and retention
Module 18: AI-Assisted Operations in Cisco Security Cloud Control
Lesson 1: AI-Assisted Security Operations Overview
- AI-assisted operations concepts
- AI as an operational assistant, not an autonomous administrator
- Common firewall and SOC use cases
- Human validation requirements
- Risk and limitation awareness
- Change-control requirements
Lesson 2: AI Use Cases in Cisco Security Cloud Control
Lesson 3: Prompting for Firewall Operations
Example prompt patterns:
- “Summarize the intent of this access control policy.”
- “What should I check if inside users cannot reach HTTPS destinations?”
- “Explain why this traffic was blocked based on the event fields.”
- “Create a change summary for this firewall rule update.”
- “Generate a validation checklist for this NAT change.”
- “Summarize these Splunk firewall events for SOC handoff.”
- “Create investigation notes from this XDR observable summary.”
Lesson 4: AI Validation and Governance
- Validate recommendations against FMC/cdFMC configuration
- Confirm policy impact before deployment
- Avoid broad allow rules without review
- Use least privilege
- Use deployment preview
- Maintain audit trail
- Record AI-assisted recommendations separately from final administrator decisions
- Do not expose sensitive credentials, secrets, or private data in prompts
Lesson 5: AI-Assisted Documentation
- Change summaries
- Troubleshooting notes
- Capstone evidence summaries
- SOC handoff summaries
- Executive summaries
- Lessons learned
Module 19: Change Management and Deployment Discipline
Lesson 1: Safe Firewall Change Workflow
- Define business requirement.
- Identify affected traffic.
- Identify affected devices.
- Create or modify objects.
- Update policy.
- Review pending changes.
- Validate deployment target.
- Deploy during approved window.
- Test traffic.
- Review events.
- Document outcome.
Module 20: Troubleshooting SCC with Secure Firewall, Splunk, XDR, and Workflows
Lesson 1: Structured Troubleshooting Methodology
- Define symptom.
- Identify expected behavior.
- Verify firewall path.
- Check interfaces and zones.
- Check routing.
- Check NAT.
- Check access control.
- Review events.
- Make smallest required fix.
- Deploy and validate.