Cisco 300-740 SCAZT Secure Cloud Access Practice Exam
Cover the full 300-740 v1.0 blueprint — cloud security architecture, user and device security, network and cloud security, application and data security, visibility and assurance, and threat response — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.
Start 24-hour free trial →300-740 exam at a glance
- Vendor
- Cisco
- Exam code
- 300-740 (SCAZT)
- Full name
- Designing and Implementing Secure Cloud Access for Users and Endpoints
- Level
- Professional
- Blueprint
- v1.0
- Duration
- 90 minutes
- Scope
- Both design and implementation of secure cloud access
- Role in CCNP
- CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
- Also earns
- Cisco Certified Specialist – Security Secure Cloud Access
- Domains
- Six, with published weights (see below); they sum to 100%
- Prerequisites
- None formally required; familiarity with Cisco security products (Duo, Umbrella, Secure Firewall, ISE, Secure Workload) is recommended
- Delivery
- Pearson VUE; test center or online proctored
Sources: Cisco — SCAZT (300-740) exam page · Cisco — official SCAZT v1.0 exam topics (PDF). Verify current details with Cisco before scheduling.
About the Cisco 300-740 SCAZT exam
The 300-740 SCAZT exam validates the skills to design and implement secure cloud access for users and endpoints — the modern zero-trust and SASE approach to letting people reach SaaS, hybrid, and multicloud applications safely. It spans architecture (Cisco Security Reference Architecture, SAFE), identity and device trust, network/cloud enforcement, application and data protection, visibility, and threat response. For how certification exams work generally, see the certification study guides in our Learning Hub.
SCAZT is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SCAZT being the cloud-access option. Passing SCAZT on its own also earns the Cisco Certified Specialist – Security Secure Cloud Access credential. Its closest relative is the security-design concentration SDSI (300-745); identity work overlaps heavily with SISE (300-715).
Every PowerKram practice question maps to one of the six weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.
300-740 exam domains and weights (v1.0)
Cisco publishes six weighted domains for the 300-740 exam, and they sum to 100%. Application and Data Security is the single heaviest at 25%, with User and Device Security and Network and Cloud Security close behind at 20% each — so weight your study toward enforcement and protection, not just architecture. Confirm the current weights on Cisco’s exam topics before scheduling.
The Cisco Security Reference Architecture and its components; integrated-architecture use cases (common identity, converged multicloud policy, SASE, ZTNA); industry frameworks (NIST, CISA, DISA); and the Cisco SAFE framework, Places in the Network, and Secure Domains.
Implementing user/device authentication with identity certificates; multifactor authentication; endpoint posture policies; and configuring SAML/SSO and OIDC via an identity provider, including device trust for mobile and web apps.
Endpoint access policies for cloud and SaaS apps (URL/DNS filtering, app control, protocol blocking, direct internet access, WAF, reverse proxy); remote-user policies (VPN or app-based); and security-edge enforcement (SSE, Cisco Secure Firewall).
MITRE ATT&CK and attacker-defense mitigation; cloud attack tactics and mitigations; WAF protection against DDoS; application enforcement with Cisco Secure Workload (lateral-movement prevention, microsegmentation); and hybrid/multicloud platform policy across AWS, Azure, and Google Cloud.
Cisco XDR; visibility/assurance automation; logging and telemetry tools (SIEM, OpenTelemetry, Secure Network Analytics); validating traffic flow and telemetry for baseline/compliance; and diagnosing user/application/workload access issues.
Response-automation use cases; determining actions from telemetry and security-audit reports; and responding to user or application compromise — contain, report, remediate, and reinstantiate.
Source: Cisco — official SCAZT v1.0 (300-740) exam topics (PDF). Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.
Who the 300-740 exam is for
SCAZT is aimed at engineers securing cloud and SaaS access for a modern, distributed workforce:
- Cloud security engineers designing and implementing secure access to SaaS, hybrid, and multicloud applications.
- Security and network engineers building zero-trust / SASE access for users and endpoints.
- Identity and endpoint specialists implementing MFA, posture, and SAML/OIDC-based trust.
- CCNP Security candidates choosing the cloud-access concentration alongside the SCOR 350-701 core.
Pair cloud-access skills with the broader security-design concentration SDSI (300-745), deepen identity with SISE (300-715), or add secure remote access with SVPN (300-730). For where cloud-security skills lead, see the cybersecurity career paths in our Career Hub.
What this 300-740 practice exam delivers
Learn mode
Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for the design-and-implement mix, where the right control depends on the requirement.
Exam mode
Timed, full-length simulation spanning all six domains at the real 90-minute pace — so test day feels familiar.
Source-linked explanations
Every answer links to Cisco’s own SCAZT exam material, so you can verify each cloud-access design and implementation choice against the source.
Score by weighted domain
Results break down across the six weighted domains so you can see whether it’s architecture, user/device, network/cloud, application/data, visibility, or threat response that needs more work.
Sample 300-740 practice questions
Ten free questions across the 300-740 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.
Which model converges networking and security into a cloud-delivered service that enforces policy close to the user, wherever they are?
- SASE (Secure Access Service Edge)
- A single on-premises perimeter firewall
- A local print server
- A spanning-tree redesign
Show answer & explanation
Correct: A. SASE converges SD-WAN networking with cloud-delivered security (SWG, CASB, ZTNA, FWaaS) to enforce policy near the user regardless of location — a core SCAZT architecture concept for a distributed workforce.
Why not the others: a single on-prem perimeter firewall (B) is the location-bound model SASE replaces; a print server (C) and a spanning-tree redesign (D) are unrelated to cloud-access architecture.
Source: Cisco — SCAZT: cloud security architecture → Further reading: PowerKram — SDSI (300-745) →To let users sign in to a web application with their corporate identity provider, which protocol is commonly configured for federated single sign-on?
- SMTP
- SAML (Security Assertion Markup Language)
- ICMP
- NTP
Show answer & explanation
Correct: B. SAML enables federated SSO by passing signed assertions between an identity provider and a service provider, so users authenticate once with the corporate IdP — explicitly part of SCAZT’s user/device security domain (alongside OIDC).
Why not the others: SMTP (A) is email transport; ICMP (C) is network diagnostics; NTP (D) is time sync — none provide federated SSO.
Source: Cisco — SCAZT: user & device security (SAML/SSO) → Further reading: PowerKram — SISE (300-715) →Before granting a laptop access to resources, a design must check that it has disk encryption and a required patch installed. Which control enforces this?
- Increasing the VPN timeout
- A DNS A record
- An endpoint posture policy
- A louder alert sound
Show answer & explanation
Correct: C. An endpoint posture policy evaluates device health (encryption, patches, running services) before granting access, and can quarantine or remediate non-compliant endpoints — a named SCAZT user/device security task.
Why not the others: a VPN timeout (A) governs session length, not device health; a DNS record (B) resolves names; an alert sound (D) does nothing for posture.
Source: Cisco — SCAZT: endpoint posture →Which control blocks connections to malicious or risky destinations at the DNS layer before a session is even established?
- A longer DHCP lease
- Jumbo frames
- DNS-layer security (e.g. Cisco Umbrella)
- A second monitor
Show answer & explanation
Correct: C. DNS-layer security (Cisco Umbrella) resolves and filters DNS requests, blocking connections to malicious domains and C2 infrastructure before a connection is made — protecting users on and off network. It maps to SCAZT’s URL/DNS filtering objective.
Why not the others: a DHCP lease (A), jumbo frames (B), and a second monitor (D) provide no DNS-layer threat blocking.
Source: Cisco — SCAZT: network & cloud security (DNS/URL filtering) → Further reading: PowerKram — SVPN (300-730) →A design must give a specific SaaS app (e.g. Office 365) a trusted, high-performance path while still enforcing security policy. Which approach fits?
- Blocking all SaaS traffic outright
- Direct internet access for trusted business applications, with security policy applied at the edge
- Sending all traffic through a single distant data center with no exceptions
- Disabling TLS for that app
Show answer & explanation
Correct: B. Direct internet access (DIA) for trusted apps, combined with edge security enforcement, gives sanctioned SaaS a performant path without abandoning policy — exactly the SCAZT network/cloud objective for controlling access to apps like Office 365.
Why not the others: blocking all SaaS (A) breaks the business; backhauling everything to one distant DC (C) hurts performance and is what DIA avoids; disabling TLS (D) removes confidentiality.
Source: Cisco — SCAZT: SaaS access policy →Which Cisco solution enforces microsegmentation and prevents lateral movement between workloads based on application behavior?
- Cisco Secure Workload
- Cisco Webex
- Cisco Jabber
- A network time server
Show answer & explanation
Correct: A. Cisco Secure Workload discovers application dependencies and enforces microsegmentation policy to contain lateral movement between workloads — named explicitly in SCAZT’s application-and-data-security domain.
Why not the others: Webex (B) and Jabber (C) are collaboration tools; a time server (D) syncs clocks — none enforce workload microsegmentation.
Source: Cisco — SCAZT: application enforcement (Secure Workload) → Further reading: PowerKram — SDSI (300-745) →A team wants a common language to describe adversary tactics and techniques when planning application defenses. Which framework fits?
- The OSI seven-layer model
- MITRE ATT&CK
- The DHCP option list
- The VLAN database
Show answer & explanation
Correct: B. MITRE ATT&CK catalogs real-world adversary tactics and techniques, giving defenders a shared framework to map attacks to mitigations — called out directly in SCAZT’s application-and-data-security domain.
Why not the others: the OSI model (A) describes networking layers; the DHCP option list (C) and VLAN database (D) are configuration constructs, not threat frameworks.
Source: Cisco — SCAZT: MITRE ATT&CK & mitigations →A design must enforce consistent policy for the same application running in both AWS and Azure. Which capability is required?
- A single on-prem-only ACL
- A louder SOC alarm
- A longer power cord to the rack
- Hybrid/multicloud platform security policy based on application connectivity requirements
Show answer & explanation
Correct: D. Consistent protection across AWS and Azure requires hybrid/multicloud platform policy driven by application connectivity requirements, so the same app is governed uniformly regardless of provider — a named SCAZT objective.
Why not the others: an on-prem-only ACL (A) can’t span cloud providers; a SOC alarm (B) and a power cord (C) don’t enforce multicloud policy.
Source: Cisco — SCAZT: multicloud platform policy →Which Cisco solution correlates telemetry across email, endpoints, network, and cloud to speed detection and investigation?
- A spreadsheet of IP addresses
- A desk phone
- A label printer
- Cisco XDR (Extended Detection and Response)
Show answer & explanation
Correct: D. Cisco XDR correlates and enriches telemetry across multiple security domains (email, endpoint, network, cloud) to accelerate detection, investigation, and response — the lead solution in SCAZT’s visibility-and-assurance domain.
Why not the others: a spreadsheet (A), a desk phone (B), and a label printer (C) provide no cross-domain detection and correlation.
Source: Cisco — SCAZT: visibility & assurance (XDR) →After confirming an endpoint is compromised, which sequence best reflects the SCAZT threat-response approach?
- Ignore it and hope it resolves
- Email everyone and take no technical action
- Contain, report, remediate, and reinstantiate
- Immediately rebuild the entire data center
Show answer & explanation
Correct: C. SCAZT frames response to a compromise as contain, report, remediate, and reinstantiate — isolate the threat, document it, fix the affected system, and restore it to a known-good state. That ordered set is drawn straight from the objectives.
Why not the others: ignoring it (A) lets the compromise spread; emailing with no action (B) doesn’t contain anything; rebuilding the whole data center (D) is a disproportionate overreaction to a single endpoint.
Source: Cisco — SCAZT: threat response →Keep going: Learning & Career resources
SCAZT is the cloud-access concentration in the CCNP Security track. Two PowerKram hubs back this exam.
Deep dive: zero trust & SASE, the CCNP Security path, and study strategy
Design and implement — zero trust for cloud access
SCAZT is about letting users and devices reach cloud and SaaS applications securely, using zero-trust principles: verify identity and device posture, enforce least-privilege access at a cloud-delivered edge (SASE/SSE), protect the applications and data behind it, and watch everything with strong telemetry. Unlike the design-only SDSI, SCAZT includes hands-on implementation objectives (MFA, SAML/OIDC, posture, policy). See SDSI (300-745) →
How SCAZT fits CCNP Security
CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SCAZT is the cloud-access concentration; the security-design concentration SDSI (300-745), identity via SISE (300-715), and secure access via SVPN (300-730) are related options. Passing SCAZT alone also earns Cisco Certified Specialist – Security Secure Cloud Access. See SISE (300-715) →
Realistic study path
Weight your time toward Application and Data Security (25%) and the two 20% domains (User/Device and Network/Cloud). Get familiar with the Cisco Security Reference Architecture and SAFE, and with the named products — Duo, Umbrella, Secure Firewall, ISE, Secure Workload, XDR — because questions reference them directly. Finish with objective-mapped practice and at least one timed 90-minute run. Confirm the current blueprint on Cisco’s exam topics. See SVPN (300-730) →
Frequently asked questions
What is the 300-740 SCAZT exam?
Is 300-740 a CCNP exam by itself?
What are the exam domains and weights?
How long is the exam?
How is SCAZT different from SDSI?
Start your free 24-hour 300-740 practice trial
Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all six SCAZT domains. No credit card required.
Start free trial →