300-715 SISE Lab Guide 2026: The Self-Funded One
Its sibling needs a service contract and a Smart Account. This one needs a free account and a 90-day trial - plus one cheap second-hand switch.
- 300-715Exam
- 90 minTime
- $300Fee
- 7Domains
- Free downloadCheapest lab
- 32 GB hostRAM needed

Table of Contents
The minimum lab
SISE is the quiet win of the CCNP Security track. The identity appliance is downloadable with an ordinary Cisco account and ships a 90-day evaluation that supports enough endpoints for any home lab, so unlike its sibling firewall exam there is no contract to negotiate. What it asks instead is memory and patience: the appliance is a large virtual machine, and identity work is fiddly by nature - every test involves a supplicant, a switch, and a policy that has to agree with both. Note the blueprint is v1.2 and has seven domains, not the six most study material lists.
The switch is the piece people under-rate. It is the authenticator, so it is where you configure 802.1X, MAB and change-of-authorisation, and it is where most of your troubleshooting time goes. The wireless controller is optional but cheap to add and covers the wireless half of the policy domain. Active Directory is not optional - identity stores are examinable and a local user database teaches you nothing about the real thing.
Where to build it
Any hypervisor runs this. The only real question is whether your host has the memory.
| Platform | Good enough? | Cost | What decides it |
|---|---|---|---|
| ESXi, KVM or Workstation | Yes | Free to licensed | The appliance is a normal virtual machine and the download needs only a free Cisco account. Its published evaluation profile is four cores and 16 GB. |
| A used Catalyst access switch | Yes | $40-100 used | The best-value purchase for this exam by a distance. Virtual switches accept the config and do not enforce it - see the walls below. |
| Cisco DevNet Sandbox | Yes | $0 | Free identity sandboxes exist, including one with automation tooling and a RADIUS simulator. The fastest way to see a working policy set. |
| CML-Personal | Not bundled | $199, 20 nodes | Fine for the routers and controller around it, but Cisco states the identity appliance is not included - run it alongside as its own virtual machine. |
| CML-Free | No | $0, 5 nodes | No identity appliance, and five nodes would not hold the topology. |
The appliance runs as its own virtual machine rather than inside a network emulator, so the usual pattern is an emulator for the network and a hypervisor for the appliance, bridged together. That is one more moving part than the other exams in this batch, and it is worth setting up deliberately rather than discovering halfway through.
Images and horsepower
One large node and several small ones - the appliance is the whole budget.
| Component | What it is | Where it comes from |
|---|---|---|
| Identity appliance (virtual) | Policy, profiling, posture and guest - the entire exam | Free Cisco account, with a 90-day evaluation licence. The reason this exam is self-funded |
| A switch that supports 802.1X | The authenticator | An emulator node, or a used access switch |
| Windows Server | Active Directory as the identity source | Evaluation edition. Identity stores are examinable |
| A client with a supplicant | Something to authenticate | A Windows or Linux virtual machine |
| A wireless controller | Optional, for the wireless policy work | The virtual controller from the wireless exam's image set |
The appliance's published evaluation profile is four cores and 16 GB, and practitioner reports line up: 16 GB works, and there are no credible reports of success at 8 to 12 GB. Add Active Directory, a client and the network nodes and 32 GB is the honest host figure. One version caution: that evaluation profile is published for releases 3.3 and 3.4 and is absent from 3.5's requirements, whose smallest listed profile is considerably larger - so if you are labbing the newest release, check before sizing.
The build list
Work top to bottom. Each step is a thing you build and then break on purpose, and each one is tagged with the blueprint domain it covers, so by the end you have touched the parts of the syllabus a lab can reach.
Join it to Active Directory and get a real user inPolicy Enforcement 25%
Identity stores are the foundation of the largest domain. Get a domain user authenticating before you touch anything else, because every later policy references it.
Make 802.1X work on the wirePolicy Enforcement 25%
Switch as authenticator, client as supplicant, appliance as the server. Use a physical switch if you have one - virtual switches take the configuration and often do not enforce it. Then break it three ways, wrong shared secret, missing method, wrong VLAN, and learn to tell them apart from the logs.
Add MAC authentication bypass for the things that cannot speakPolicy Enforcement 25%
Printers and cameras are the standard example and the standard exam scenario. This is also where change-of-authorisation starts to matter.
Build a guest portal and sponsor flowWeb Auth and Guest 15%
Fiddly, heavily examined, and entirely doable with what you already have running. Do the sponsor portal too, not just the guest one.
Turn on profiling and watch endpoints classifyProfiler 15%
Enable probes, then connect different devices and watch the classification change. Profiling is one of those topics that is obvious once seen and opaque when only read.
Onboard a device through BYOD, then posture itBYOD 15% / Compliance 10%
Certificate onboarding through the internal authority, then a posture policy that checks something simple. Two domains, one workflow, and the last two on the blueprint.
What you can and cannot lab
Cisco publishes the domain weightings but not the number of items or the passing score, so treat the percentages as how the paper is built rather than as a target. The column that matters here is the last one.
| Domain | Weight | Labbable | Notes |
|---|---|---|---|
| Architecture and Deployment | 10% | Partly | TODO |
| Policy Enforcement | 25% | Partly | TODO |
| Web Auth and Guest Services | 15% | Partly | TODO |
| Profiler | 15% | Partly | TODO |
| BYOD | 15% | Partly | TODO |
| Endpoint Compliance | 10% | Partly | TODO |
| Network Access Device Administration | 10% | Partly | TODO |
The walls you will hit
There are fewer walls here than anywhere else in CCNP Security, which is the point of this page.
Cannot be labbed at home
- Virtual switches accept identity config without enforcing it. This is the important one. Cisco's own platform matrix for group-based policy lists none of the virtual switch images, and engineers report DHCP snooping and MAC authentication bypass configuring cleanly and then not working. You get the syntax and not the behaviour.
- The virtual Catalyst switch image is beta and heavy. It exists, it is documented as unsupported beta, it wants around 18 GB, and practitioners report authentication bypass simply not working on it. Not a solution to the point above.
- The evaluation licence expires. Ninety days is ample for exam preparation, but it is a clock - start the appliance when you start studying.
- The appliance is not bundled with the network emulator. Cisco says so directly, so plan on a separate virtual machine bridged into your topology.
- Memory, not entitlement. A 16 GB host will not hold the appliance plus a directory server plus a client.
That first wall is why this page recommends spending money on something small: a second-hand access switch for the price of a takeaway makes the authenticator side behave properly, and the authenticator side is where most of your troubleshooting time in this exam actually goes. Everything else here is free. Compared with the firewall exam - service contract, Smart Account, and VPN topics you cannot touch without one - this is the CCNP Security concentration you can genuinely build.
A lab proves you can build it. Questions prove you can pass.
The blueprint is only half the exam — the other half is answering under a clock. Start with the free question sets, then $5.99 unlocks the full 300-715 SISE bank.
Free 300-715 SISE practice test300-715 SISE exam pageFAQ
Can I download the Cisco identity appliance without a service contract?
Yes. It needs only a free Cisco account and comes with a 90-day evaluation licence supporting enough endpoints for a home lab. That is the main practical difference from the SNCF firewall exam, whose images do require a contract.
How many domains does 300-715 SISE have?
Seven, not six. The v1.2 blueprint is Architecture and Deployment 10%, Policy Enforcement 25%, Web Auth and Guest Services 15%, Profiler 15%, BYOD 15%, Endpoint Compliance 10% and Network Access Device Administration 10%. A lot of study material omits the last one and inflates the first.
How much RAM do I need for a SISE lab?
About 32 GB. The identity appliance is a large virtual machine and you also need Active Directory, a client with a supplicant, and a switch acting as authenticator. Dropping the wireless controller is the easiest saving.
Do I need a real switch to practise 802.1X for SISE?
It is the one purchase worth making. Virtual switches accept the identity configuration and frequently do not enforce it - Cisco's group-based policy platform matrix does not list any of the virtual switch images, and practitioners report MAC authentication bypass and DHCP snooping configuring cleanly then failing. A second-hand access switch costs very little and makes the authenticator side behave.
Sources
Exam facts come from Cisco. Lab guidance is marked as official or as practitioner consensus where the two differ:
- https://learningcontent.cisco.com/documents/marketing/exam-topics/300-715-SISE-v1.2.pdf
- https://www.cisco.com/site/us/en/learn/training-certifications/exams/policies.html
- https://developer.cisco.com/site/sandbox/
- https://developer.cisco.com/docs/modeling-labs/vm-images-for-cml-labs/
Checked September 5, 2026. Cisco revises exam topics and changes image licensing without notice — confirm before you spend anything.
