SDSI: Cisco CCNP SDSI (300-745)

Expert Cisco Cisco
Browse certifications

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

About the SDSI Exam

Design enterprise security infrastructure — threat protection, VPN and firewall architecture, application and cloud-native security, emerging tech, risk and compliance, and security automation

The 300-745 SDSI (Designing Cisco Security Infrastructure) is a CCNP Security concentration exam focused on security architecture and design. Unlike the hands-on implementation exams, SDSI puts you in the seat of a security architect making design decisions: selecting the right threat-protection approach for endpoints, identity, and email; modifying an architecture for hybrid work, IoT, SaaS, and multi-cloud; choosing a VPN and tunneling solution; securing the management and control planes; selecting firewall features and architectures (NGFW, WAF, IPS, distributed and eBPF firewalls); designing application and cloud-native security (CNAPP, microsegmentation, containers, serverless); setting design policy for emerging technologies (generative AI and machine learning security, and post-quantum cryptography); designing SOC incident response; applying security frameworks (MITRE ATT&CK and CAPEC, NIST SP 800-37 RMF, NIST CSF 2.0, and Cisco SAFE); mapping regulatory compliance; and integrating AI, security automation, and DevSecOps. Passing SDSI earns the Cisco Certified Specialist - Designing Cisco Security Infrastructure badge and, with the SCOR 350-701 core, the CCNP Security certification. Original practice questions. Not affiliated with, endorsed by, or sourced from Cisco Systems certification exams.

Who Should Take This Exam?

SDSI is designed for security architects, security consultants, network-security engineers, and SecOps leads who design security architectures. Cisco recommends 3-5 years of security-solution experience; a working knowledge of the Cisco Secure portfolio (Secure Firewall, ISE, Duo, Cisco XDR, Secure Network Analytics, Secure Workload, Hypershield) plus the security frameworks (NIST, MITRE, Cisco SAFE) helps a lot. It is a DESIGN exam — you are graded on choosing the right approach and tradeoff, not on CLI syntax.

Typical study time: 6-10 weeks of focused study

Exam Quick Facts

DetailValue
Exam Code300-745 SDSI
TitleDesigning Cisco Security Infrastructure
Duration90 minutes
Questions~55-65
Pass ScoreCisco scales 300-1000 and does not publish the exact cut score
Cost$300 USD
ProviderPearson VUE
Validity3 years
Question TypesMultiple choice, Multiple response, Drag-and-drop

Exam Domains & Weights

The SDSI exam covers 4 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.

DomainWeightPractice Qs
Secure Infrastructure30%74
Applications25%62
Risk, Events, and Requirements30%74
Artificial Intelligence, Automation, and DevSecOps15%40
Total100%250

💡 Study tip: Secure Infrastructure and Risk, Events, and Requirements each carry 30% — together that is 60% of the exam, so start there. Nail the design boundaries Cisco loves to test: routed vs transparent firewall mode (transparent is a Layer-2 bump-in-the-wire, not a routed hop); GETVPN is for private any-to-any WANs (MPLS) while DMVPN/FlexVPN scale spoke-to-spoke over the internet; MITRE ATT&CK (adversary tactics/techniques) vs CAPEC (attack patterns) vs D3FEND (defensive countermeasures); NIST SP 800-37 RMF has 7 steps and NIST CSF 2.0 has 6 functions (Govern was added in 2.0); and the post-quantum standards FIPS 203 ML-KEM (key encapsulation), FIPS 204 ML-DSA and FIPS 205 SLH-DSA (signatures).

Practice Exam — 250 Questions

Prepare for the SDSI with our 250-question practice exam covering all 4 exam domains. Every question is an original real-world security-architecture design scenario with detailed explanations and maps to the official exam topics (v1.0).

What you get:

  • ✅ Exam simulation mode with timer
  • ✅ Spaced repetition for weak areas
  • ✅ Detailed explanations for every question
  • ✅ Progress tracking across domains
  • ✅ 20 free questions — no account needed

Cisco Certification Path

Cisco certs follow: Entry (CCT) → Associate (CCNA) → Professional (CCNP) → Expert (CCIE). CCNP Security requires the SCOR 350-701 core exam plus one concentration — SDSI 300-745 is the security-architecture DESIGN concentration.

If you’re studying for the SDSI, you might also be interested in these Cisco certifications:

Study Tips

  1. Start with the 30%-weight domains — Secure Infrastructure and Risk, Events, and Requirements are the backbone of the exam
  2. Think like an architect — SDSI tests the design DECISION and the tradeoff, not CLI syntax; for each scenario, ask “which control/architecture fits this constraint, and why not the alternatives?”
  3. Use our practice exam — try the 20 free questions first to gauge your readiness
  4. Master the current product names — Cisco XDR (not SecureX), Secure Network Analytics (not Stealthwatch), Secure Endpoint (not AMP), Secure Client (not AnyConnect), Security Cloud Control (not CDO)
  5. Know the frameworks cold — ATT&CK vs CAPEC vs D3FEND, the RMF 7 steps, CSF 2.0’s 6 functions, and how to map a regulation (PCI DSS, HIPAA, GDPR, SOX, FedRAMP) to a scenario
  6. Simulate exam conditions — use the timed exam mode to practice under pressure
20 Free Questions Practice Exam $9 →