Leanpub Header

Skip to main content

CCNP Security bundle

Two exams, one certification. The core and the concentration, 672 pages, written in the same voice and built to the same structure.

Bought separately

$30.00

Minimum price

$20.00

$23.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

These books have a total suggested price of $30.00. Get them now for only $20.00!
About

About

About the Bundle

A CCNP Security certification takes two exams: the SCOR 350-701 core, and one concentration. This bundle is the core plus the concentration that follows it most naturally — SSCA 300-740, Designing and Implementing Secure Cloud Access for Users and Endpoints.

Both books are built the same way, so the second one needs no adjustment on your part: every sub-section explains from first principles, shows real configuration with verification steps, carries diagrams where a picture is clearer than a paragraph, and ends with a summary, key takeaways and five exam-style questions whose explanations cover the wrong answers as well as the right one.

  • SCOR 350-701 v2.0 Complete Learning Guide — 348 pages on the core: network, cloud and content security, endpoint protection, secure access and visibility.
  • SSCA 300-740 v2.0 Complete Learning Guide — 324 pages on the concentration: zero trust, identity and Duo, policy and AI security, Cisco Secure Access end to end, Secure Workload microsegmentation, and security operations. 260 practice questions, 48 diagrams, 8 cases from the field.

Where the two overlap — encryption, identity, data loss prevention, the security edge — the treatment is deliberately complementary rather than repeated: the core establishes the ground, the concentration takes it into cloud access and enforcement.

Both are independent, unofficial study guides. Neither is endorsed by or affiliated with Cisco Systems, Inc. Exam topics can change without notice, so confirm the current

Share this bundle

Books

About the Books

SSCA 300-740 v2.0 Complete Learning Guide

SSCA 300-740 v2.0 Complete Learning Guide

Designing and Implementing Secure Cloud Access for Users and Endpoints

The SSCA 300-740 blueprint is unusually wide. It runs from zero-trust theory and cloud platform security, through identity, multifactor authentication and data protection, into AI security, workload microsegmentation and the operations that prove any of it is working. Almost nobody arrives comfortable in all of it. A network engineer knows tunnels and has never read a SAML assertion. A security analyst knows MITRE ATT&CK and has never labelled a workload.

This book is written for both of them, starting from first principles and ending with configuration you could actually deploy.

What's inside
  • 324 pages covering every topic in the published v2.0 blueprint, which became the live exam on 27 August 2026
  • 5 sections, 52 sub-sections, weighted to match the domain percentages Cisco publishes
  • 260 knowledge-check questions — five per sub-section, with explanations of why the plausible wrong answers are wrong, not only why the right one is right
  • 48 diagrams, because some things are easier seen than described
  • 8 cases from the field — cross-domain incident narratives, each naming the sub-sections it draws on
  • glossary of 108 terms and a blueprint-to-sub-section map, so you can check your coverage topic by topic
How each sub-section is built

The structure repeats deliberately, so that after a few pages you know where to find what you need: an explanation from first principles with every term defined at first use, a diagram where the relationship is spatial or sequential, real configuration with verification steps, four kinds of callout (Did you know?Exam TipCommon PitfallFrom the Field), a summary and key takeaways written to work as a standalone revision pass, and five knowledge-check questions.

What it covers
  • Concepts — NIST SP 800-207, the CISA Zero Trust Maturity Model v2.0, MITRE ATT&CK for cloud, IdP and SaaS, public cloud security and operational requirements, private cloud and Kubernetes, and eBPF runtime security with Cilium and Tetragon
  • Identity — identity intelligence, certificate-based authentication, Cisco Duo, phishing-resistant multifactor, endpoint posture and device trust, SAML for web and mobile, SCIM provisioning, and an ordered method for troubleshooting the identity path
  • Policies — encryption in transit and at rest, IPS and malware protection, data loss prevention design, Cisco AI Defense, AI Access and AI Guardrails, web application firewalls and DDoS, the Secure Access policy model, Secure Firewall and SD-WAN enforcement, and the full Cisco Secure Workload microsegmentation lifecycle
  • Access — Secure Access architecture and onboarding, DNS security, the secure web gateway, DLP and CASB configuration, resource connectors and IPsec backhaul, branch connectivity, VPN as a service with ISE, client-based and clientless zero-trust access with QUIC and MASQUE, ThousandEyes, and an ordered method for troubleshooting the access path
  • Operations — choosing the right visibility and enforcement tool, reading telemetry against a baseline, compliance evidence that survives an audit, the Secure Access dashboards, and the Cisco XDR and Splunk Enterprise integrations
Who it's for

Engineers preparing for SSCA 300-740 as a CCNP Security concentration, and anyone implementing Cisco Secure Access who wants the reasoning as well as the configuration. It assumes CCNA-level networking, basic familiarity with TLS and certificates, and general awareness of what a public cloud is. Everything else is built from the ground up.

A note on what this is

This is an independent, unofficial study guide. It is not endorsed by, affiliated with or produced in cooperation with Cisco Systems, Inc. All configurations are illustrative and should be tested in an environment you control. Cisco may revise exam topics at any time — always confirm the current blueprint before booking.

Free sample

The free sample runs to 40 pages: the complete front matter, the contents of the whole book, and the first four sub-sections of Section 1 in full — including diagrams, callouts and 20 knowledge-check questions. Download it and see whether the style suits you before buying.

SCOR 350-701 v2.0 Complete Learning Guide

SCOR 350-701 v2.0 Complete Learning Guide

Implementing and Operating Cisco Security Core Technologies v2.0

The SCOR 350-701 exam moved to the v2.0 blueprint, and most study material still teaches v1.1.

The parts that changed are exactly the parts the new exam leans on. An entire domain — Secure Service Edge — is new. AI appears twice: once as a threat, and once as a set of vulnerabilities in the models organisations now run themselves. Post-quantum cryptography, QUIC, and MASQUE join the cryptography topic. Splunk appears three times.

Meanwhile, appliance-era web and email content has quietly disappeared. Study the old blueprint and you will revise material that is no longer tested while missing roughly a third of what is. This guide was written from the v2.0 blueprint itself, topic by topic, in the order Cisco published them.

What is inside

Six chapters, one per exam domain, with 47 sub-sections mapped one-to-one onto the numbered blueprint topics. Sub-section 3.4 in the book is blueprint topic 3.4. Nothing merged, nothing skipped. Page counts proportional to the exam weightings, so the time you spend tracks the marks on offer.

235 exam-style questions — five after every topic — with an explanation of why each wrong option is wrong, not just which one is right. 34 original diagrams: the FTD policy evaluation order, the IKEv2 failure decision tree, the shared responsibility matrix, an LLM application's injection points, the posture-to-CoA flow, and more.

Worked configurations and real output: IOS XE Layer 2 hardening, 802.1X and MAB with ISE, SNMPv3 and authenticated NTP, Splunk inputs and correlation searches, Python that calls a security API. Exam Tips, Common Pitfalls, and From the Field boxes on every topic — how it is tested, the mistake people make, and how it behaves in a real network.

Appendix A: what changed from v1.1 to v2.0 — what to study, what to stop revising, and the traps for anyone carrying over old knowledge.

Appendix B: command and verification quick reference.

Appendix C: a practice lab you can actually build from free and evaluation software.

Appendix D: exam-day strategy. Plus a full glossary. An eight-week study plan that weights your effort by domain, and Key Takeaways blocks designed to be your final-week revision layer.

Who it is for

Network and security engineers preparing for the 350-701 SCOR v2.0 exam as the core of CCNP Security or CCIE Security. Engineers moving from routing and switching into security who know how a network behaves but have not worked with ISE, Secure Firewall policy, or a cloud security edge. Practising security engineers wanting a structured refresh across the whole domain. And anyone who studied the v1.1 material and needs to know exactly what changed. You are assumed to be comfortable with IP networking to roughly CCNA level. No prior security certification is required — every security concept is built from first principles before it is applied.

How it is written

v2.0 is a scenario exam. Its questions describe a situation and ask which technology fits, which step comes next, or why something failed. Memorised answers do not survive that format; understanding does. So every topic explains the mechanism first, then shows it working, then tests it — and the explanations are longer than the questions on purpose.

An honest note

This is an independent, unofficial publication. It is not affiliated with, authorised by, or endorsed by Cisco Systems, Inc. It contains no real exam questions and no Cisco courseware — every explanation, diagram, configuration, and question is original. Cisco can change exam topics without notice, so verify the current blueprint before you book. 352 pages. Written for the exam you are actually going to sit.

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub