300-715 Skills measured as of Blueprint v1.1
Cisco August 22, 2026 5 min read

Cisco SISE 300-715 Exam Guide 2026 (Identity Services Engine)

Seven domains, none larger than 25 percent, all describing one product. SISE is the most concentrated exam in the CCNP Security track — it lives or dies on how well you know ISE.

Cisco SISE 300-715 Identity Services Engine exam guide

SISE 300-715Implementing and Configuring Cisco Identity Services Engine — is a concentration exam in the CCNP Security track. This brief uses the official blueprint, v1.1.

What SISE certifies

Unlike the core exams, SISE is about a single product. Every domain describes deploying, configuring or operating Cisco ISE — network access control, identity-based policy, guest access, device profiling, BYOD onboarding and posture assessment.

That concentration cuts both ways. There is no breadth to hide behind, but there is also nothing to learn that is not directly useful if ISE is in your environment. It is one of the more immediately applicable Cisco certifications.

Exam format

Exam code300-715
Blueprintv1.1
Duration90 min
Domains7
TrackCCNP Security
Pairs withSCOR 350-701

To complete CCNP Security you need the SCOR 350-701 core exam alongside a concentration such as this one. At 90 minutes, SISE is shorter than the 120-minute core exams.

The seven domains and their weights

Policy Enforcement25%
Web Auth and Guest Services15%
Profiler15%
BYOD15%
Architecture and Deployment10%
Endpoint Compliance10%
Network Access Device Administration10%

Seven domains is a lot for a 90-minute exam, and the distribution is deliberately flat below the top: one domain at 25%, three at 15%, three at 10%. Nothing is negligible.

Why Policy Enforcement dominates

Policy Enforcement at 25% is the largest domain, and that is not arbitrary — it is what ISE fundamentally does. Authentication and authorisation policy, policy sets, conditions and results, and the logic that decides what a device is allowed to do on the network.

Learn policy first, everything else second

Guest services, profiling, BYOD and posture all ultimately feed policy enforcement — they supply the identity, the device classification and the compliance state that policy then acts on. If you learn policy sets properly first, the other four domains become much easier to reason about, because you understand what they are for.

The three 15% domains — guest, profiler, BYOD — are together 45%, nearly half the exam. These are the day-to-day use cases organisations actually deploy ISE for, and they are heavily configuration-oriented. Lab time beats reading here by a wide margin.

The seven domains in practice

Seven domains sounds fragmented until you see how they connect. They describe one flow: a device appears on the network, ISE works out what and who it is, and policy decides what it may do.

DomainIts job in that flowWeight
Architecture and DeploymentThe platform itself — nodes, personas, certificates10%
Network Access Device AdministrationHow switches and routers talk to ISE, and TACACS+ for admin access10%
ProfilerWhat is this device?15%
Web Auth and Guest ServicesWho is this, when they have no supplicant?15%
BYODWho is this, on a personal device, and can we trust it?15%
Endpoint ComplianceIs it healthy enough to be allowed on?10%
Policy EnforcementGiven all of the above, what may it do?25%

Reading it that way explains the weighting. Policy enforcement is the largest domain because it is where every other domain’s output is consumed, and it is why studying policy sets early makes the rest easier rather than harder.

The detail candidates most often miss

Certificates. They sit in the smallest domain and quietly underpin almost everything — EAP-TLS authentication, BYOD onboarding and provisioning, portal trust, and admin access. A surprising number of ISE problems in the real world, and questions on this exam, resolve to a certificate or trust-chain issue rather than a policy one.

A five-week study plan

Week 1
Architecture and deployment (10%). Node types and personas, deployment models, certificates and initial setup. Small domain, but everything else assumes it — do it first.
Week 2
Policy enforcement (25%). Policy sets, authentication and authorisation policies, conditions and results, and how a request actually flows through them. The largest domain and the conceptual spine of the exam.
Week 3
Guest and web auth (15%) plus profiler (15%). Guest flows, sponsor portals, hotspot; then profiling policies, probes and how classification decisions are made.
Week 4
BYOD (15%) plus endpoint compliance (10%). Onboarding flows, certificate provisioning, then posture policies, conditions and remediation.
Week 5
Device administration and rehearsal (10%). TACACS+ for network device administration, then timed practice weighted toward policy enforcement.

If you are working toward CCNP Security, the SCOR 350-701 practice test covers the core exam, and the study-time calculator will plan both around your schedule.

Frequently Asked Questions

What are the SISE 300-715 domains?

Policy Enforcement (25%), Web Auth and Guest Services (15%), Profiler (15%), BYOD (15%), Architecture and Deployment (10%), Endpoint Compliance (10%) and Network Access Device Administration (10%).

How long is the SISE exam?

90 minutes. It is a concentration exam in the CCNP Security track, paired with the SCOR 350-701 core exam.

Is SISE only about Cisco ISE?

Effectively yes. All seven domains describe implementing and configuring Cisco Identity Services Engine, which makes it unusually product-specific even by Cisco standards.

What should I take before SISE?

SISE is a concentration exam, so you also need the SCOR 350-701 core exam to complete CCNP Security. Many candidates sit SCOR first.

Practise SISE Before You Book

500–1,000+ practice questions with worked explanations, written against the current exam objectives.

SISE Practice Test
ExamCert

ExamCert Team

Certified IT professionals tracking the cloud, AI, and security certification landscape. Every exam brief is rebuilt against the official skills-measured document on the date shown above.

Practice Before You Book

500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.