SDSI: Cisco CCNP SDSI (300-745)
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the SDSI Exam
Design enterprise security infrastructure — threat protection, VPN and firewall architecture, application and cloud-native security, emerging tech, risk and compliance, and security automation
The 300-745 SDSI (Designing Cisco Security Infrastructure) is a CCNP Security concentration exam focused on security architecture and design. Unlike the hands-on implementation exams, SDSI puts you in the seat of a security architect making design decisions: selecting the right threat-protection approach for endpoints, identity, and email; modifying an architecture for hybrid work, IoT, SaaS, and multi-cloud; choosing a VPN and tunneling solution; securing the management and control planes; selecting firewall features and architectures (NGFW, WAF, IPS, distributed and eBPF firewalls); designing application and cloud-native security (CNAPP, microsegmentation, containers, serverless); setting design policy for emerging technologies (generative AI and machine learning security, and post-quantum cryptography); designing SOC incident response; applying security frameworks (MITRE ATT&CK and CAPEC, NIST SP 800-37 RMF, NIST CSF 2.0, and Cisco SAFE); mapping regulatory compliance; and integrating AI, security automation, and DevSecOps. Passing SDSI earns the Cisco Certified Specialist - Designing Cisco Security Infrastructure badge and, with the SCOR 350-701 core, the CCNP Security certification. Original practice questions. Not affiliated with, endorsed by, or sourced from Cisco Systems certification exams.
Who Should Take This Exam?
SDSI is designed for security architects, security consultants, network-security engineers, and SecOps leads who design security architectures. Cisco recommends 3-5 years of security-solution experience; a working knowledge of the Cisco Secure portfolio (Secure Firewall, ISE, Duo, Cisco XDR, Secure Network Analytics, Secure Workload, Hypershield) plus the security frameworks (NIST, MITRE, Cisco SAFE) helps a lot. It is a DESIGN exam — you are graded on choosing the right approach and tradeoff, not on CLI syntax.
Typical study time: 6-10 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | 300-745 SDSI |
| Title | Designing Cisco Security Infrastructure |
| Duration | 90 minutes |
| Questions | ~55-65 |
| Pass Score | Cisco scales 300-1000 and does not publish the exact cut score |
| Cost | $300 USD |
| Provider | Pearson VUE |
| Validity | 3 years |
| Question Types | Multiple choice, Multiple response, Drag-and-drop |
Exam Domains & Weights
The SDSI exam covers 4 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| Secure Infrastructure | 30% | 74 |
| Applications | 25% | 62 |
| Risk, Events, and Requirements | 30% | 74 |
| Artificial Intelligence, Automation, and DevSecOps | 15% | 40 |
| Total | 100% | 250 |
💡 Study tip: Secure Infrastructure and Risk, Events, and Requirements each carry 30% — together that is 60% of the exam, so start there. Nail the design boundaries Cisco loves to test: routed vs transparent firewall mode (transparent is a Layer-2 bump-in-the-wire, not a routed hop); GETVPN is for private any-to-any WANs (MPLS) while DMVPN/FlexVPN scale spoke-to-spoke over the internet; MITRE ATT&CK (adversary tactics/techniques) vs CAPEC (attack patterns) vs D3FEND (defensive countermeasures); NIST SP 800-37 RMF has 7 steps and NIST CSF 2.0 has 6 functions (Govern was added in 2.0); and the post-quantum standards FIPS 203 ML-KEM (key encapsulation), FIPS 204 ML-DSA and FIPS 205 SLH-DSA (signatures).
Practice Exam — 250 Questions
Prepare for the SDSI with our 250-question practice exam covering all 4 exam domains. Every question is an original real-world security-architecture design scenario with detailed explanations and maps to the official exam topics (v1.0).
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
Cisco Certification Path
Cisco certs follow: Entry (CCT) → Associate (CCNA) → Professional (CCNP) → Expert (CCIE). CCNP Security requires the SCOR 350-701 core exam plus one concentration — SDSI 300-745 is the security-architecture DESIGN concentration.
Related Cisco Certifications
If you’re studying for the SDSI, you might also be interested in these Cisco certifications:
- SCOR: Cisco CCNP SCOR (350-701) — the CCNP Security core that pairs with SDSI — 200 practice questions
- SCAZT: Designing and Implementing Secure Cloud Access (300-740) — the Secure Cloud Access (SSE/SASE/ZTNA) concentration — 250 practice questions
- SNCF: Securing Networks with Cisco Firewalls (300-710) — the Secure Firewall concentration — 250 practice questions
- SISE: Implementing and Configuring Cisco ISE (300-715) — identity, posture, and access control — 250 practice questions
- CyberOps: Cisco Certified CyberOps Associate (200-201) — SOC operations and monitoring — 200 practice questions
Study Tips
- Start with the 30%-weight domains — Secure Infrastructure and Risk, Events, and Requirements are the backbone of the exam
- Think like an architect — SDSI tests the design DECISION and the tradeoff, not CLI syntax; for each scenario, ask “which control/architecture fits this constraint, and why not the alternatives?”
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Master the current product names — Cisco XDR (not SecureX), Secure Network Analytics (not Stealthwatch), Secure Endpoint (not AMP), Secure Client (not AnyConnect), Security Cloud Control (not CDO)
- Know the frameworks cold — ATT&CK vs CAPEC vs D3FEND, the RMF 7 steps, CSF 2.0’s 6 functions, and how to map a regulation (PCI DSS, HIPAA, GDPR, SOX, FedRAMP) to a scenario
- Simulate exam conditions — use the timed exam mode to practice under pressure