Cisco SISE 300-715 Exam Guide 2026 (Identity Services Engine)
Seven domains, none larger than 25 percent, all describing one product. SISE is the most concentrated exam in the CCNP Security track — it lives or dies on how well you know ISE.

On this page
SISE 300-715 — Implementing and Configuring Cisco Identity Services Engine — is a concentration exam in the CCNP Security track. This brief uses the official blueprint, v1.1.
What SISE certifies
Unlike the core exams, SISE is about a single product. Every domain describes deploying, configuring or operating Cisco ISE — network access control, identity-based policy, guest access, device profiling, BYOD onboarding and posture assessment.
That concentration cuts both ways. There is no breadth to hide behind, but there is also nothing to learn that is not directly useful if ISE is in your environment. It is one of the more immediately applicable Cisco certifications.
Exam format
To complete CCNP Security you need the SCOR 350-701 core exam alongside a concentration such as this one. At 90 minutes, SISE is shorter than the 120-minute core exams.
The seven domains and their weights
Seven domains is a lot for a 90-minute exam, and the distribution is deliberately flat below the top: one domain at 25%, three at 15%, three at 10%. Nothing is negligible.
Why Policy Enforcement dominates
Policy Enforcement at 25% is the largest domain, and that is not arbitrary — it is what ISE fundamentally does. Authentication and authorisation policy, policy sets, conditions and results, and the logic that decides what a device is allowed to do on the network.
Guest services, profiling, BYOD and posture all ultimately feed policy enforcement — they supply the identity, the device classification and the compliance state that policy then acts on. If you learn policy sets properly first, the other four domains become much easier to reason about, because you understand what they are for.
The three 15% domains — guest, profiler, BYOD — are together 45%, nearly half the exam. These are the day-to-day use cases organisations actually deploy ISE for, and they are heavily configuration-oriented. Lab time beats reading here by a wide margin.
The seven domains in practice
Seven domains sounds fragmented until you see how they connect. They describe one flow: a device appears on the network, ISE works out what and who it is, and policy decides what it may do.
| Domain | Its job in that flow | Weight |
|---|---|---|
| Architecture and Deployment | The platform itself — nodes, personas, certificates | 10% |
| Network Access Device Administration | How switches and routers talk to ISE, and TACACS+ for admin access | 10% |
| Profiler | What is this device? | 15% |
| Web Auth and Guest Services | Who is this, when they have no supplicant? | 15% |
| BYOD | Who is this, on a personal device, and can we trust it? | 15% |
| Endpoint Compliance | Is it healthy enough to be allowed on? | 10% |
| Policy Enforcement | Given all of the above, what may it do? | 25% |
Reading it that way explains the weighting. Policy enforcement is the largest domain because it is where every other domain’s output is consumed, and it is why studying policy sets early makes the rest easier rather than harder.
Certificates. They sit in the smallest domain and quietly underpin almost everything — EAP-TLS authentication, BYOD onboarding and provisioning, portal trust, and admin access. A surprising number of ISE problems in the real world, and questions on this exam, resolve to a certificate or trust-chain issue rather than a policy one.
A five-week study plan
If you are working toward CCNP Security, the SCOR 350-701 practice test covers the core exam, and the study-time calculator will plan both around your schedule.
How SISE fits CCNP Security
SISE is a concentration exam, not a core one. CCNP Security requires the SCOR 350-701 core exam plus one concentration, and SISE is one of several concentration options covering firewalls, email and web security, VPN, and automation alongside identity services.
That structure gives you a choice about ordering. Most candidates sit SCOR first because it is broader and establishes the vocabulary the concentrations assume. But if ISE is what you work with daily, sitting SISE first is a reasonable inversion — you will pass it more easily now than after six months away from the product, and it earns a Cisco Certified Specialist designation on its own.
Concentration exams reward current hands-on exposure far more than core exams do, because they go deep on one product. If your organisation runs ISE, SISE is substantially easier for you than a concentration on a product you would have to learn from scratch — and the certification is identical either way.
Building an ISE lab
SISE is configuration-heavy and difficult to pass on reading alone. Three-quarters of the blueprint — policy enforcement, guest, profiler, BYOD and posture — describes things you configure rather than things you know.
A workable lab needs surprisingly little:
- An ISE instance. Cisco provides evaluation licensing for lab use; check current terms and duration before you plan around it.
- One switch or wireless controller that can speak RADIUS to ISE — enough to see authentication actually succeed and fail.
- Two endpoints, ideally different operating systems, so profiling has something to distinguish and BYOD onboarding has somewhere to go.
- A certificate authority, even a simple internal one. Certificates underpin EAP-TLS, BYOD provisioning and portal trust, and they are the most common source of both real-world and exam confusion.
Work through one complete flow end to end — an endpoint appears, is profiled, authenticates, is assessed for posture, and receives an authorisation result — before optimising any single piece. Seeing the whole chain once explains the blueprint better than studying seven domains separately.
Where to find practice access
If you cannot stand up the lab described above, two routes are worth checking before paying for rack time.
Cisco sandboxes. Cisco publishes reservable lab environments covering many of its platforms, and identity services appear among them periodically. Availability changes, so check the current catalogue rather than assuming one way or the other.
Your own network. If your employer already runs ISE, read-only access to the live deployment teaches more than any simulation — real policy sets, real profiling results, and real authentication failures with real causes behind them. Ask for a viewer account before assuming you need to build something from scratch.
Frequently Asked Questions
What are the SISE 300-715 domains?
Policy Enforcement (25%), Web Auth and Guest Services (15%), Profiler (15%), BYOD (15%), Architecture and Deployment (10%), Endpoint Compliance (10%) and Network Access Device Administration (10%).
How long is the SISE exam?
90 minutes. It is a concentration exam in the CCNP Security track, paired with the SCOR 350-701 core exam.
Is SISE only about Cisco ISE?
Effectively yes. All seven domains describe implementing and configuring Cisco Identity Services Engine, which makes it unusually product-specific even by Cisco standards.
What should I take before SISE?
SISE is a concentration exam, so you also need the SCOR 350-701 core exam to complete CCNP Security. Many candidates sit SCOR first.
Practise SISE Before You Book
500–1,000+ practice questions with worked explanations, written against the current exam objectives.
SISE Practice TestPractice Before You Book
500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.
