CiscoSeptember 5, 20268 min read

300-715 SISE Lab Guide 2026: The Self-Funded One

Its sibling needs a service contract and a Smart Account. This one needs a free account and a 90-day trial - plus one cheap second-hand switch.

  • 300-715Exam
  • 90 minTime
  • $300Fee
  • 7Domains
  • Free downloadCheapest lab
  • 32 GB hostRAM needed
300-715 SISE home lab topology diagram

The minimum lab

SISE is the quiet win of the CCNP Security track. The identity appliance is downloadable with an ordinary Cisco account and ships a 90-day evaluation that supports enough endpoints for any home lab, so unlike its sibling firewall exam there is no contract to negotiate. What it asks instead is memory and patience: the appliance is a large virtual machine, and identity work is fiddly by nature - every test involves a supplicant, a switch, and a policy that has to agree with both. Note the blueprint is v1.2 and has seven domains, not the six most study material lists.

RADIUSidentity source802.1XIdentity applianceAD / DNSSwitch (802.1X)WLCClient
Five nodes. The switch is the authenticator, the appliance is the policy brain, and Active Directory is the identity source.

The switch is the piece people under-rate. It is the authenticator, so it is where you configure 802.1X, MAB and change-of-authorisation, and it is where most of your troubleshooting time goes. The wireless controller is optional but cheap to add and covers the wireless half of the policy domain. Active Directory is not optional - identity stores are examinable and a local user database teaches you nothing about the real thing.

Where to build it

Any hypervisor runs this. The only real question is whether your host has the memory.

PlatformGood enough?CostWhat decides it
ESXi, KVM or WorkstationYesFree to licensedThe appliance is a normal virtual machine and the download needs only a free Cisco account. Its published evaluation profile is four cores and 16 GB.
A used Catalyst access switchYes$40-100 usedThe best-value purchase for this exam by a distance. Virtual switches accept the config and do not enforce it - see the walls below.
Cisco DevNet SandboxYes$0Free identity sandboxes exist, including one with automation tooling and a RADIUS simulator. The fastest way to see a working policy set.
CML-PersonalNot bundled$199, 20 nodesFine for the routers and controller around it, but Cisco states the identity appliance is not included - run it alongside as its own virtual machine.
CML-FreeNo$0, 5 nodesNo identity appliance, and five nodes would not hold the topology.
Worth knowing

The appliance runs as its own virtual machine rather than inside a network emulator, so the usual pattern is an emulator for the network and a hypervisor for the appliance, bridged together. That is one more moving part than the other exams in this batch, and it is worth setting up deliberately rather than discovering halfway through.

Images and horsepower

One large node and several small ones - the appliance is the whole budget.

ComponentWhat it isWhere it comes from
Identity appliance (virtual)Policy, profiling, posture and guest - the entire examFree Cisco account, with a 90-day evaluation licence. The reason this exam is self-funded
A switch that supports 802.1XThe authenticatorAn emulator node, or a used access switch
Windows ServerActive Directory as the identity sourceEvaluation edition. Identity stores are examinable
A client with a supplicantSomething to authenticateA Windows or Linux virtual machine
A wireless controllerOptional, for the wireless policy workThe virtual controller from the wireless exam's image set

The appliance's published evaluation profile is four cores and 16 GB, and practitioner reports line up: 16 GB works, and there are no credible reports of success at 8 to 12 GB. Add Active Directory, a client and the network nodes and 32 GB is the honest host figure. One version caution: that evaluation profile is published for releases 3.3 and 3.4 and is absent from 3.5's requirements, whose smallest listed profile is considerably larger - so if you are labbing the newest release, check before sizing.

The build list

Work top to bottom. Each step is a thing you build and then break on purpose, and each one is tagged with the blueprint domain it covers, so by the end you have touched the parts of the syllabus a lab can reach.

  • Join it to Active Directory and get a real user inPolicy Enforcement 25%

    Identity stores are the foundation of the largest domain. Get a domain user authenticating before you touch anything else, because every later policy references it.

  • Make 802.1X work on the wirePolicy Enforcement 25%

    Switch as authenticator, client as supplicant, appliance as the server. Use a physical switch if you have one - virtual switches take the configuration and often do not enforce it. Then break it three ways, wrong shared secret, missing method, wrong VLAN, and learn to tell them apart from the logs.

  • Add MAC authentication bypass for the things that cannot speakPolicy Enforcement 25%

    Printers and cameras are the standard example and the standard exam scenario. This is also where change-of-authorisation starts to matter.

  • Build a guest portal and sponsor flowWeb Auth and Guest 15%

    Fiddly, heavily examined, and entirely doable with what you already have running. Do the sponsor portal too, not just the guest one.

  • Turn on profiling and watch endpoints classifyProfiler 15%

    Enable probes, then connect different devices and watch the classification change. Profiling is one of those topics that is obvious once seen and opaque when only read.

  • Onboard a device through BYOD, then posture itBYOD 15% / Compliance 10%

    Certificate onboarding through the internal authority, then a posture policy that checks something simple. Two domains, one workflow, and the last two on the blueprint.

What you can and cannot lab

Cisco publishes the domain weightings but not the number of items or the passing score, so treat the percentages as how the paper is built rather than as a target. The column that matters here is the last one.

DomainWeightLabbableNotes
Architecture and Deployment10%PartlyTODO
Policy Enforcement25%PartlyTODO
Web Auth and Guest Services15%PartlyTODO
Profiler15%PartlyTODO
BYOD15%PartlyTODO
Endpoint Compliance10%PartlyTODO
Network Access Device Administration10%PartlyTODO

The walls you will hit

There are fewer walls here than anywhere else in CCNP Security, which is the point of this page.

Cannot be labbed at home

  • Virtual switches accept identity config without enforcing it. This is the important one. Cisco's own platform matrix for group-based policy lists none of the virtual switch images, and engineers report DHCP snooping and MAC authentication bypass configuring cleanly and then not working. You get the syntax and not the behaviour.
  • The virtual Catalyst switch image is beta and heavy. It exists, it is documented as unsupported beta, it wants around 18 GB, and practitioners report authentication bypass simply not working on it. Not a solution to the point above.
  • The evaluation licence expires. Ninety days is ample for exam preparation, but it is a clock - start the appliance when you start studying.
  • The appliance is not bundled with the network emulator. Cisco says so directly, so plan on a separate virtual machine bridged into your topology.
  • Memory, not entitlement. A 16 GB host will not hold the appliance plus a directory server plus a client.

That first wall is why this page recommends spending money on something small: a second-hand access switch for the price of a takeaway makes the authenticator side behave properly, and the authenticator side is where most of your troubleshooting time in this exam actually goes. Everything else here is free. Compared with the firewall exam - service contract, Smart Account, and VPN topics you cannot touch without one - this is the CCNP Security concentration you can genuinely build.

A lab proves you can build it. Questions prove you can pass.

The blueprint is only half the exam — the other half is answering under a clock. Start with the free question sets, then $5.99 unlocks the full 300-715 SISE bank.

Free 300-715 SISE practice test300-715 SISE exam page

FAQ

Can I download the Cisco identity appliance without a service contract?

Yes. It needs only a free Cisco account and comes with a 90-day evaluation licence supporting enough endpoints for a home lab. That is the main practical difference from the SNCF firewall exam, whose images do require a contract.

How many domains does 300-715 SISE have?

Seven, not six. The v1.2 blueprint is Architecture and Deployment 10%, Policy Enforcement 25%, Web Auth and Guest Services 15%, Profiler 15%, BYOD 15%, Endpoint Compliance 10% and Network Access Device Administration 10%. A lot of study material omits the last one and inflates the first.

How much RAM do I need for a SISE lab?

About 32 GB. The identity appliance is a large virtual machine and you also need Active Directory, a client with a supplicant, and a switch acting as authenticator. Dropping the wireless controller is the easiest saving.

Do I need a real switch to practise 802.1X for SISE?

It is the one purchase worth making. Virtual switches accept the identity configuration and frequently do not enforce it - Cisco's group-based policy platform matrix does not list any of the virtual switch images, and practitioners report MAC authentication bypass and DHCP snooping configuring cleanly then failing. A second-hand access switch costs very little and makes the authenticator side behave.

Sources

Exam facts come from Cisco. Lab guidance is marked as official or as practitioner consensus where the two differ:

Checked September 5, 2026. Cisco revises exam topics and changes image licensing without notice — confirm before you spend anything.