CCNP Security SDSI Practice Exams

300-745 SDSI
⭐ Most popularAdvancedProfessionalSecurity Architect

Designing Cisco Security Infrastructure — the CCNP Security concentration exam covering security architecture design: selecting approaches to protect endpoints, identity and email; adapting designs for hybrid work, IoT, SaaS and multicloud; application, container and microsegmentation security; risk, incident response and compliance frameworks; and the role of AI, automation, and DevSecOps in modern security architecture.

90
minutes
82%
passing score
$300
exam fee

Start preparing today

5 flashcard sets · 5 learning tests · 2 timed exams · 200-question bank

Start Free Practice →

Overview

What this certification is and how the exam works.

The 300-745 SDSI exam — Designing Cisco Security Infrastructure — is a CCNP Security concentration exam that, combined with the 350-701 SCOR core exam, earns the CCNP Security certification. Unlike the product-focused concentrations, SDSI is an architecture exam: it tests the ability to select an approach and justify a design rather than to configure a platform. The blueprint covers secure infrastructure (30%) — choosing protections for endpoints on and off network, identity including MFA, passwordless and continuous trust, and email against phishing, ransomware, business email compromise and spoofing, plus adapting architecture for hybrid work, IoT, SaaS and multicloud, VPN selection, management and control plane protection, and firewall architecture; applications (25%) — selecting solutions from application data and traffic flows, securing cloud-native applications, microservices, containers and microsegmentation, and the impact of generative AI and quantum computing on application security policy; risk, events and requirements (30%) — SOC incident response tooling, modifying designs after an incident, frameworks such as MITRE CAPEC and NIST SP 800-37, and aligning designs to regulatory and compliance obligations; and artificial intelligence, automation and DevSecOps (15%) — API tooling, infrastructure as code, security telemetry, SOAR, and reducing risk in automated deployment pipelines. The exam runs 90 minutes and contains roughly 55 to 65 questions.

Why should I take the exam?

What this credential does for your career.

  • 1Completes CCNP Security when paired with the 350-701 SCOR core exam
  • 2The architecture exam in the track — it tests design judgment rather than platform configuration
  • 3Covers the reasoning senior engineers and architects are actually paid for: selecting an approach and defending it
  • 4Includes the modern agenda — AI, automation, DevSecOps, containers, and quantum readiness — that older blueprints omit
  • 5Framework and compliance content transfers directly to risk and audit conversations outside Cisco environments

Skills measured

What you need to know to pass this exam.

  • Select protection approaches for endpoints on network, off network, and fully remote
  • Design identity security using MFA, passwordless, continuous trust, and identity intelligence
  • Choose email security controls against phishing, ransomware, business email compromise, malware, and spoofing
  • Adapt a security architecture for hybrid work, IoT, SaaS adoption, and multicloud estates
  • Select an appropriate VPN approach and justify it against the access requirement
  • Protect the management and control planes as part of the infrastructure design
  • Choose a firewall architecture appropriate to the placement, traffic, and operational model
  • Select application security solutions from the application's data classification and traffic flows
  • Design security for cloud-native applications, microservices, containers, and microsegmentation
  • Assess the impact of generative AI and quantum computing on application security policy
  • Describe how a SOC uses incident response tooling and how findings feed design change
  • Apply frameworks such as MITRE CAPEC and the NIST SP 800-37 Risk Management Framework
  • Align a security design with regulatory and compliance requirements
  • Select tooling for secure automated infrastructure: APIs, infrastructure as code, telemetry, and SOAR
  • Identify the pipeline controls that reduce risk during automated deployment

About our 300-745 SDSI practice exams

Our CCNP Security SDSI 300-745 SDSI question bank holds 200 exam-style questions with a written explanation on every answer, mapped to the four exam domains published for 300-745 SDSI, covering Secure Infrastructure, Applications, Risk, Events, and Requirements and Artificial Intelligence, Automation, and DevSecOps.

Alongside the bank there are two full-length timed exams at the real 90-minute limit and 82% pass mark, plus five topic-based learning tests for working a single domain at a time. Randomised mock exams are dealt on demand from the full 200-question pool, so you never run out of fresh papers.

Questions
200
Exam domains
4
Timed exams
2
Pass mark
82%

How our practice content is created

Practice questions are independently developed using the official Cisco 300-745 SDSI exam guide and Cisco documentation. Each question is checked for alignment with the current exam objectives and reviewed for technical accuracy before publication.

The 300-745 SDSI bank cites 1 distinct Cisco documentation page, and every question links the source it was written against — so you can check any answer at first hand.

Official 300-745 SDSI exam guide

Cisco is a trademark of its respective owner. This is an independent study resource and is not affiliated with, endorsed by, or authorised by Cisco.

Related certifications

Credentials that pair well with this exam or come next on the path.

Official resources

Provider documentation and study material for this exam.

Start Free Practice →

5 flashcard sets · 5 learning tests · 2 timed exams · 200-question bank