Cisco Security Cloud Control

This 5-day course provides a complete end-to-end training and lab path for provisioning Cisco Security Cloud Control and Managing Integrations. Managing Cisco Secure Firewall with FMC or Cloud-Delivered FMC, forwarding firewall telemetry to Splunk, investigating events with Cisco XDR, and using AI-Assisted workflows to improve operational efficiency.

Retail Price: $4,495.00

Next Date: 01/25/2027

Course Days: 5


Enroll in Next Date

Request Custom Course


Learners progress from Cloud Control Provisioning and Firewall Onboarding through policy creation, NAT, threat inspection, logging, SIEM integration, XDR correlation, AI-Assisted analysis, change control, troubleshooting, and a final capstone.

The primary audience for this course is as follows:

  • Security Administrators
  • Security Engineers
  • Firewall Administrators
  • Network Administrators
  • Network Engineers
  • SOC Analysts
  • Security Operations (SecOps) Engineers
  • Cisco Partners
  • IT Staff and Managers

Prerequisites

  • Basic understanding of TCP/IP networking fundamentals
  • Familiarity with routing, switching, and network security concepts
  • Experience with Cisco networking technologies (recommended)
  • Basic knowledge of firewalls and security policies
  • Familiarity with Microsoft Active Directory or Microsoft Entra ID (helpful)
  • Hands-on experience with Cisco Secure Firewall or Cisco Security products (preferred)

OUTLINE

Module 1: Cisco Security Cloud Control

Lesson 1: Security Cloud Control Overview

  • Cisco Security Cloud Control Overview
  • Integrations Overview

Lesson 2: Security Cloud Control Provisioning Overview

  • Tenant provisioning concepts
  • Cisco account access
  • Smart Account and Virtual Account relationship
  • Entitlements and licensing
  • Tenant region and organization boundaries

Lesson 3: Provisioning Prerequisites and Planning

  • Cisco account requirements
  • Organization access
  • Smart Account access
  • Virtual Account planning
  • Security Cloud Control entitlement
  • cdFMC entitlement
  • Secure Firewall licenses
  • Administrator role planning
  • SSO/MFA planning
  • Splunk and XDR integration planning

Lesson 4: Tenant Creation and Initial Access

  • Accessing an existing tenant
  • Receiving tenant invitation
  • Validating correct organization
  • Reviewing tenant settings
  • Verifying inventory access
  • Confirming audit or activity logs

Lesson 5: Administrative Access, RBAC, and Identity

  • Least privilege
  • Named administrator accounts
  • Role-based access control
  • SSO and identity provider considerations
  • MFA
  • Break-glass account planning
  • Auditability

Lesson 6: Smart Account, Licensing, and Entitlement Readiness

  • Security Cloud Control entitlement
  • cdFMC entitlement
  • Secure Firewall base license
  • Threat license
  • Malware license
  • URL license
  • RA VPN license, if used
  • XDR entitlement
  • Splunk licensing/storage planning

Lesson 7: cdFMC Service Readiness

  • Launching cdFMC from Security Cloud Control
  • Device management readiness
  • Policy management readiness
  • Object management readiness
  • Event visibility
  • Deployment workflow readiness

Lesson 8: Security, Compliance, and Governance

  • Audit logging
  • Access review
  • Change control
  • Deployment approval
  • Data visibility and retention
  • Regional considerations
  • API and integration governance

Module 2: Configuring Authentication in Cisco Security Cloud Control

Lesson 1: Security Cloud Control Authentication Architecture

  • Security Cloud Control authentication overview
  • Administrative authentication versus network-user authentication
  • Authentication, authorization, and accounting
  • Identity providers and service providers
  • Single sign-on concepts
  • Security Assertion Markup Language
  • Multifactor authentication
  • Active and passive authentication
  • User-to-IP address mapping
  • Directory synchronization
  • Authentication data flow

Lesson 2: Configuring Active Directory Authentication

  • Active Directory integration requirements
  • Domain controllers and Global Catalog servers
  • LDAP and LDAPS communication
  • DNS and Network Time Protocol dependencies
  • Certificate requirements
  • Service account permissions
  • User and group discovery
  • Realm configuration
  • Directory synchronization
  • Nested group considerations
  • Authentication testing
  • Configuration Workflow
  • Troubleshooting

Lesson 3: Configuring Microsoft Entra ID Authentication

  • Microsoft Entra ID authentication models
  • Entra ID application registration
  • Directory tenant identification
  • Application client identifiers
  • Client secrets
  • Microsoft Graph permissions
  • Enterprise applications
  • SAML-based single sign-on
  • User and group assignments
  • Conditional Access
  • Entra ID audit logs
  • Azure Event Hubs
  • Active versus passive authentication
  • Configuration Workflow
  • Troubleshooting

Lesson 4: Configuring Identity and Access Control Policies

  • Identity policy purpose
  • Authentication rules
  • Active authentication
  • Passive authentication
  • Realm selection
  • Authentication fallback
  • Captive portal configuration
  • Certificate requirements
  • User and group conditions
  • Access control rule integration
  • Unknown-user handling
  • Policy deployment

Lesson 5: Cisco Duo Authentication and MFA

  • Cisco Duo architecture
  • Duo Universal Prompt
  • Duo users, groups, and devices
  • Enrollment methods
  • Duo Push and Verified Duo Push
  • Passcodes and hardware tokens
  • Passkeys and security keys
  • Trusted endpoints
  • Remembered devices
  • Authorized networks
  • New-user policies
  • Application policies
  • Authentication policies
  • Duo reporting and authentication logs

Lesson 6: Cisco Identity Intelligence

Module 3: Cisco Security Cloud Control Integrations

Lesson 1: Cisco Security Cloud Control Integrations

  • Security Cloud Control Integration Architecture
  • Integration Categories
  • Integration Data Types
  • Integration Requirements
  • Integration Monitoring

Lesson 2: Integration of Identity Services Engine

  • Cisco ISE Integration Architecture
  • Integration Requirements
  • Configuring ISE Connectivity
  • Identity-Based Policy Enforcement
  • Monitoring and Troubleshooting

Lesson 3: Catalyst SD-WAN Integration

  • Catalyst SD-WAN Integration Architecture
  • Catalyst SD-WAN Integration Prerequisites
  • Catalyst SD-WAN Workflow
  • Catalyst SD-WAN Security Policy Management
  • Catalyst SD-WAN Integration Troubleshooting

Lesson 4: Meraki SD-WAN Integration

  • Meraki SD-WAN Integration Requirements
  • Meraki SD-WAN Integration
  • Firewall Policy Management
  • SCC Co-Management Considerations
  • Meraki SD-WAN Integration Troubleshooting

Lesson 5: Splunk Security Integration

  • Splunk Integration Architecture
  • Integration Use Cases
  • Splunk Data Sources
  • Splunk Enterprise and Splunk Cloud Integration
  • Configuration Components
  • Investigation and Automation
  • Troubleshooting

Lesson 6: Cisco XDR Integration

  • Cisco XDR Integration Architecture
  • Integration Capabilities
  • Tenant Linking
  • Configuring the Integration
  • Event Sharing and Investigation
  • Cisco XDR Automation
  • Troubleshooting

Module 4: Logging, Monitoring, and Event Analysis

Lesson 1: Firewall Event Visibility

  • Connection events
  • Intrusion events
  • File events
  • Malware events
  • URL events
  • VPN events
  • Health events
  • Deployment events
  • Event filtering
  • NAT visibility
  • Rule match analysis

Module 5: Cisco Secure Firewall Platform Overview

Lesson 1: Cisco Secure Firewall Architecture

  • Cisco Secure Firewall portfolio
  • Secure Firewall Threat Defense
  • Physical, virtual, and cloud deployments
  • Enforcement plane vs. management plane
  • Policy lifecycle
  • Threat inspection overview
  • Event generation
  • Cisco Talos intelligence role

Lesson 2: Management - FDM, FMC, cdFMC, and Security Cloud Control

  • Firewall Device Manager
  • On-prem FMC
  • Cloud-delivered FMC
  • Cisco Security Cloud Control
  • Centralized policy management
  • Hybrid management models
  • SaaS-based operations

Lesson 3: Cisco Security Cloud Control Orientation

  • SCC dashboard
  • Tenant concepts
  • Inventory
  • Administrative roles
  • Activity and audit logs
  • Launching cdFMC
  • Operational visibility

Module 6: SCC FMC and cdFMC Architecture

Lesson 1: Firewall Manager Architecture and Policy Flow

  • Manager-to-device relationship
  • Device registration
  • Policy assignment
  • Access control policy
  • NAT policy
  • Intrusion policy
  • File and malware policy
  • URL filtering policy
  • Platform settings
  • Health policies
  • Object model
  • Deployment workflow
  • Event flow

Module 7: SSC Secure Firewall Onboarding

Lesson 1: Device Registration and Licensing

  • Onboarding prerequisites
  • Management interface
  • Registration key
  • NAT ID
  • DNS
  • NTP
  • Smart Licensing
  • Initial access control policy
  • Health monitoring
  • Common onboarding failures

Module 8: Interfaces and Security Zones

Lesson 1: Interface Types and Zone Design

  • Routed interfaces
  • Subinterfaces
  • VLAN tagging
  • Management interface
  • Security zones
  • Zone naming
  • Zone-based policy
  • Common zone mistakes

Module 9: Routing Fundamentals

Lesson 1: Static Routing and Traffic Forwarding

  • Routing table
  • Default route
  • Internal routes
  • DMZ routes
  • Return path
  • Routing and NAT interaction
  • Asymmetric routing

Module 10: SCC FW Object Management

Lesson 1: Reusable Objects and Naming Standards

  • Network objects
  • Host objects
  • Port objects
  • URL objects
  • FQDN objects
  • Object groups
  • Naming conventions
  • Object governance

Module 11: Access Control Policy

Lesson 1: Access Control Rule Design

  • Access control policy structure
  • Rule order
  • Source/destination zones
  • Source/destination networks
  • Ports
  • Applications
  • URLs
  • Users
  • Default action
  • Logging
  • Deployment

Module 12: NAT Policy

Lesson 1: Outbound and Inbound NAT

  • Dynamic PAT
  • Dynamic NAT
  • Static NAT
  • Identity NAT
  • Policy NAT
  • NAT rule order
  • NAT and access control interaction

Module 13: Application Control

Lesson 1: Application-Aware Firewall Policy

  • Port-based vs. application-aware control
  • Application detection
  • Encrypted traffic limitations
  • Application categories
  • Rule placement
  • Event visibility

Module 14: URL Filtering

Lesson 1: URL Category and Reputation Controls

  • URL categories
  • Reputation filtering
  • Custom URL objects
  • HTTPS visibility
  • Licensing
  • Cloud intelligence lookups
  • URL event review

Module 15: Intrusion Prevention

Lesson 1: Applying IPS Inspection

  • Intrusion policy overview
  • Balanced Security and Connectivity
  • Security over Connectivity
  • Connectivity over Security
  • Rule recommendations
  • Event priority
  • Tuning considerations

Module 16: File and Malware Inspection

Lesson 1: File Policy and Malware Defense

  • File detection
  • File blocking
  • Malware cloud lookup
  • Retrospective analysis where supported
  • File event review
  • Licensing
  • Encrypted traffic considerations

Module 17: Cloud-Delivered Firewall Operations

Lesson 1: Operating Firewalls Through Cloud-Delivered Management

  • cdFMC use cases
  • SCC operations
  • Distributed firewall management
  • SaaS lifecycle benefits
  • Hybrid management
  • Cloud connectivity
  • Tenant boundaries
  • Licensing
  • Audit logging
  • Data visibility and retention

Module 18: AI-Assisted Operations in Cisco Security Cloud Control

Lesson 1: AI-Assisted Security Operations Overview

  • AI-assisted operations concepts
  • AI as an operational assistant, not an autonomous administrator
  • Common firewall and SOC use cases
  • Human validation requirements
  • Risk and limitation awareness
  • Change-control requirements

Lesson 2: AI Use Cases in Cisco Security Cloud Control

Lesson 3: Prompting for Firewall Operations

Example prompt patterns:

  • “Summarize the intent of this access control policy.”
  • “What should I check if inside users cannot reach HTTPS destinations?”
  • “Explain why this traffic was blocked based on the event fields.”
  • “Create a change summary for this firewall rule update.”
  • “Generate a validation checklist for this NAT change.”
  • “Summarize these Splunk firewall events for SOC handoff.”
  • “Create investigation notes from this XDR observable summary.”

Lesson 4: AI Validation and Governance

  • Validate recommendations against FMC/cdFMC configuration
  • Confirm policy impact before deployment
  • Avoid broad allow rules without review
  • Use least privilege
  • Use deployment preview
  • Maintain audit trail
  • Record AI-assisted recommendations separately from final administrator decisions
  • Do not expose sensitive credentials, secrets, or private data in prompts

Lesson 5: AI-Assisted Documentation

  • Change summaries
  • Troubleshooting notes
  • Capstone evidence summaries
  • SOC handoff summaries
  • Executive summaries
  • Lessons learned

Module 19: Change Management and Deployment Discipline

Lesson 1: Safe Firewall Change Workflow

  • Define business requirement.
  • Identify affected traffic.
  • Identify affected devices.
  • Create or modify objects.
  • Update policy.
  • Review pending changes.
  • Validate deployment target.
  • Deploy during approved window.
  • Test traffic.
  • Review events.
  • Document outcome.

Module 20: Troubleshooting SCC with Secure Firewall, Splunk, XDR, and Workflows

Lesson 1: Structured Troubleshooting Methodology

  • Define symptom.
  • Identify expected behavior.
  • Verify firewall path.
  • Check interfaces and zones.
  • Check routing.
  • Check NAT.
  • Check access control.
  • Review events.
  • Make smallest required fix.
  • Deploy and validate.
Course Dates Course Times (EST) Delivery Mode GTR
1/25/2027 - 1/29/2027 10:00 AM - 6:00 PM Virtual Enroll
3/29/2027 - 4/2/2027 10:00 AM - 6:00 PM Virtual Enroll