Cisco · Practice Exam · Professional · CCNP Security · Updated for 2026

Cisco 300-740 SCAZT Secure Cloud Access Practice Exam

Cover the full 300-740 v1.0 blueprint — cloud security architecture, user and device security, network and cloud security, application and data security, visibility and assurance, and threat response — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
Exam name: 300-740 SCAZT is “Designing and Implementing Secure Cloud Access for Users and Endpoints” — a CCNP Security concentration. It covers both design and implementation of zero-trust-style secure cloud access (SASE, ZTNA, identity, posture, and cloud workload security), across users, devices, and multicloud.
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

300-740 exam at a glance

Vendor
Cisco
Exam code
300-740 (SCAZT)
Full name
Designing and Implementing Secure Cloud Access for Users and Endpoints
Level
Professional
Blueprint
v1.0
Duration
90 minutes
Scope
Both design and implementation of secure cloud access
Role in CCNP
CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
Also earns
Cisco Certified Specialist – Security Secure Cloud Access
Domains
Six, with published weights (see below); they sum to 100%
Prerequisites
None formally required; familiarity with Cisco security products (Duo, Umbrella, Secure Firewall, ISE, Secure Workload) is recommended
Delivery
Pearson VUE; test center or online proctored

Sources: Cisco — SCAZT (300-740) exam page · Cisco — official SCAZT v1.0 exam topics (PDF). Verify current details with Cisco before scheduling.

About the Cisco 300-740 SCAZT exam

The 300-740 SCAZT exam validates the skills to design and implement secure cloud access for users and endpoints — the modern zero-trust and SASE approach to letting people reach SaaS, hybrid, and multicloud applications safely. It spans architecture (Cisco Security Reference Architecture, SAFE), identity and device trust, network/cloud enforcement, application and data protection, visibility, and threat response. For how certification exams work generally, see the certification study guides in our Learning Hub.

SCAZT is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SCAZT being the cloud-access option. Passing SCAZT on its own also earns the Cisco Certified Specialist – Security Secure Cloud Access credential. Its closest relative is the security-design concentration SDSI (300-745); identity work overlaps heavily with SISE (300-715).

Every PowerKram practice question maps to one of the six weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.

300-740 exam domains and weights (v1.0)

Cisco publishes six weighted domains for the 300-740 exam, and they sum to 100%. Application and Data Security is the single heaviest at 25%, with User and Device Security and Network and Cloud Security close behind at 20% each — so weight your study toward enforcement and protection, not just architecture. Confirm the current weights on Cisco’s exam topics before scheduling.

Cloud Security Architecture

The Cisco Security Reference Architecture and its components; integrated-architecture use cases (common identity, converged multicloud policy, SASE, ZTNA); industry frameworks (NIST, CISA, DISA); and the Cisco SAFE framework, Places in the Network, and Secure Domains.

10%
User and Device Security

Implementing user/device authentication with identity certificates; multifactor authentication; endpoint posture policies; and configuring SAML/SSO and OIDC via an identity provider, including device trust for mobile and web apps.

20%
Network and Cloud Security

Endpoint access policies for cloud and SaaS apps (URL/DNS filtering, app control, protocol blocking, direct internet access, WAF, reverse proxy); remote-user policies (VPN or app-based); and security-edge enforcement (SSE, Cisco Secure Firewall).

20%
Application and Data Security

MITRE ATT&CK and attacker-defense mitigation; cloud attack tactics and mitigations; WAF protection against DDoS; application enforcement with Cisco Secure Workload (lateral-movement prevention, microsegmentation); and hybrid/multicloud platform policy across AWS, Azure, and Google Cloud.

25%Heaviest domain
Visibility and Assurance

Cisco XDR; visibility/assurance automation; logging and telemetry tools (SIEM, OpenTelemetry, Secure Network Analytics); validating traffic flow and telemetry for baseline/compliance; and diagnosing user/application/workload access issues.

15%
Threat Response

Response-automation use cases; determining actions from telemetry and security-audit reports; and responding to user or application compromise — contain, report, remediate, and reinstantiate.

10%

Source: Cisco — official SCAZT v1.0 (300-740) exam topics (PDF). Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.

Who the 300-740 exam is for

SCAZT is aimed at engineers securing cloud and SaaS access for a modern, distributed workforce:

  • Cloud security engineers designing and implementing secure access to SaaS, hybrid, and multicloud applications.
  • Security and network engineers building zero-trust / SASE access for users and endpoints.
  • Identity and endpoint specialists implementing MFA, posture, and SAML/OIDC-based trust.
  • CCNP Security candidates choosing the cloud-access concentration alongside the SCOR 350-701 core.

Pair cloud-access skills with the broader security-design concentration SDSI (300-745), deepen identity with SISE (300-715), or add secure remote access with SVPN (300-730). For where cloud-security skills lead, see the cybersecurity career paths in our Career Hub.

What this 300-740 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for the design-and-implement mix, where the right control depends on the requirement.

Exam mode

Timed, full-length simulation spanning all six domains at the real 90-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own SCAZT exam material, so you can verify each cloud-access design and implementation choice against the source.

Score by weighted domain

Results break down across the six weighted domains so you can see whether it’s architecture, user/device, network/cloud, application/data, visibility, or threat response that needs more work.

Sample 300-740 practice questions

Ten free questions across the 300-740 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.

Question 1 · Cloud Security Architecture (10%)

Which model converges networking and security into a cloud-delivered service that enforces policy close to the user, wherever they are?

  1. SASE (Secure Access Service Edge)
  2. A single on-premises perimeter firewall
  3. A local print server
  4. A spanning-tree redesign
Show answer & explanation

Correct: A. SASE converges SD-WAN networking with cloud-delivered security (SWG, CASB, ZTNA, FWaaS) to enforce policy near the user regardless of location — a core SCAZT architecture concept for a distributed workforce.

Why not the others: a single on-prem perimeter firewall (B) is the location-bound model SASE replaces; a print server (C) and a spanning-tree redesign (D) are unrelated to cloud-access architecture.

Source: Cisco — SCAZT: cloud security architecture → Further reading: PowerKram — SDSI (300-745) →
Question 2 · User and Device Security (20%)

To let users sign in to a web application with their corporate identity provider, which protocol is commonly configured for federated single sign-on?

  1. SMTP
  2. SAML (Security Assertion Markup Language)
  3. ICMP
  4. NTP
Show answer & explanation

Correct: B. SAML enables federated SSO by passing signed assertions between an identity provider and a service provider, so users authenticate once with the corporate IdP — explicitly part of SCAZT’s user/device security domain (alongside OIDC).

Why not the others: SMTP (A) is email transport; ICMP (C) is network diagnostics; NTP (D) is time sync — none provide federated SSO.

Source: Cisco — SCAZT: user & device security (SAML/SSO) → Further reading: PowerKram — SISE (300-715) →
Question 3 · User and Device Security (20%)

Before granting a laptop access to resources, a design must check that it has disk encryption and a required patch installed. Which control enforces this?

  1. Increasing the VPN timeout
  2. A DNS A record
  3. An endpoint posture policy
  4. A louder alert sound
Show answer & explanation

Correct: C. An endpoint posture policy evaluates device health (encryption, patches, running services) before granting access, and can quarantine or remediate non-compliant endpoints — a named SCAZT user/device security task.

Why not the others: a VPN timeout (A) governs session length, not device health; a DNS record (B) resolves names; an alert sound (D) does nothing for posture.

Source: Cisco — SCAZT: endpoint posture →
Question 4 · Network and Cloud Security (20%)

Which control blocks connections to malicious or risky destinations at the DNS layer before a session is even established?

  1. A longer DHCP lease
  2. Jumbo frames
  3. DNS-layer security (e.g. Cisco Umbrella)
  4. A second monitor
Show answer & explanation

Correct: C. DNS-layer security (Cisco Umbrella) resolves and filters DNS requests, blocking connections to malicious domains and C2 infrastructure before a connection is made — protecting users on and off network. It maps to SCAZT’s URL/DNS filtering objective.

Why not the others: a DHCP lease (A), jumbo frames (B), and a second monitor (D) provide no DNS-layer threat blocking.

Source: Cisco — SCAZT: network & cloud security (DNS/URL filtering) → Further reading: PowerKram — SVPN (300-730) →
Question 5 · Network and Cloud Security (20%)

A design must give a specific SaaS app (e.g. Office 365) a trusted, high-performance path while still enforcing security policy. Which approach fits?

  1. Blocking all SaaS traffic outright
  2. Direct internet access for trusted business applications, with security policy applied at the edge
  3. Sending all traffic through a single distant data center with no exceptions
  4. Disabling TLS for that app
Show answer & explanation

Correct: B. Direct internet access (DIA) for trusted apps, combined with edge security enforcement, gives sanctioned SaaS a performant path without abandoning policy — exactly the SCAZT network/cloud objective for controlling access to apps like Office 365.

Why not the others: blocking all SaaS (A) breaks the business; backhauling everything to one distant DC (C) hurts performance and is what DIA avoids; disabling TLS (D) removes confidentiality.

Source: Cisco — SCAZT: SaaS access policy →
Question 6 · Application and Data Security (25%)

Which Cisco solution enforces microsegmentation and prevents lateral movement between workloads based on application behavior?

  1. Cisco Secure Workload
  2. Cisco Webex
  3. Cisco Jabber
  4. A network time server
Show answer & explanation

Correct: A. Cisco Secure Workload discovers application dependencies and enforces microsegmentation policy to contain lateral movement between workloads — named explicitly in SCAZT’s application-and-data-security domain.

Why not the others: Webex (B) and Jabber (C) are collaboration tools; a time server (D) syncs clocks — none enforce workload microsegmentation.

Source: Cisco — SCAZT: application enforcement (Secure Workload) → Further reading: PowerKram — SDSI (300-745) →
Question 7 · Application and Data Security (25%)

A team wants a common language to describe adversary tactics and techniques when planning application defenses. Which framework fits?

  1. The OSI seven-layer model
  2. MITRE ATT&CK
  3. The DHCP option list
  4. The VLAN database
Show answer & explanation

Correct: B. MITRE ATT&CK catalogs real-world adversary tactics and techniques, giving defenders a shared framework to map attacks to mitigations — called out directly in SCAZT’s application-and-data-security domain.

Why not the others: the OSI model (A) describes networking layers; the DHCP option list (C) and VLAN database (D) are configuration constructs, not threat frameworks.

Source: Cisco — SCAZT: MITRE ATT&CK & mitigations →
Question 8 · Application and Data Security (25%)

A design must enforce consistent policy for the same application running in both AWS and Azure. Which capability is required?

  1. A single on-prem-only ACL
  2. A louder SOC alarm
  3. A longer power cord to the rack
  4. Hybrid/multicloud platform security policy based on application connectivity requirements
Show answer & explanation

Correct: D. Consistent protection across AWS and Azure requires hybrid/multicloud platform policy driven by application connectivity requirements, so the same app is governed uniformly regardless of provider — a named SCAZT objective.

Why not the others: an on-prem-only ACL (A) can’t span cloud providers; a SOC alarm (B) and a power cord (C) don’t enforce multicloud policy.

Source: Cisco — SCAZT: multicloud platform policy →
Question 9 · Visibility and Assurance (15%)

Which Cisco solution correlates telemetry across email, endpoints, network, and cloud to speed detection and investigation?

  1. A spreadsheet of IP addresses
  2. A desk phone
  3. A label printer
  4. Cisco XDR (Extended Detection and Response)
Show answer & explanation

Correct: D. Cisco XDR correlates and enriches telemetry across multiple security domains (email, endpoint, network, cloud) to accelerate detection, investigation, and response — the lead solution in SCAZT’s visibility-and-assurance domain.

Why not the others: a spreadsheet (A), a desk phone (B), and a label printer (C) provide no cross-domain detection and correlation.

Source: Cisco — SCAZT: visibility & assurance (XDR) →
Question 10 · Threat Response (10%)

After confirming an endpoint is compromised, which sequence best reflects the SCAZT threat-response approach?

  1. Ignore it and hope it resolves
  2. Email everyone and take no technical action
  3. Contain, report, remediate, and reinstantiate
  4. Immediately rebuild the entire data center
Show answer & explanation

Correct: C. SCAZT frames response to a compromise as contain, report, remediate, and reinstantiate — isolate the threat, document it, fix the affected system, and restore it to a known-good state. That ordered set is drawn straight from the objectives.

Why not the others: ignoring it (A) lets the compromise spread; emailing with no action (B) doesn’t contain anything; rebuilding the whole data center (D) is a disproportionate overreaction to a single endpoint.

Source: Cisco — SCAZT: threat response →

Keep going: Learning & Career resources

SCAZT is the cloud-access concentration in the CCNP Security track. Two PowerKram hubs back this exam.

Deep dive: zero trust & SASE, the CCNP Security path, and study strategy

Design and implement — zero trust for cloud access

SCAZT is about letting users and devices reach cloud and SaaS applications securely, using zero-trust principles: verify identity and device posture, enforce least-privilege access at a cloud-delivered edge (SASE/SSE), protect the applications and data behind it, and watch everything with strong telemetry. Unlike the design-only SDSI, SCAZT includes hands-on implementation objectives (MFA, SAML/OIDC, posture, policy). See SDSI (300-745) →

How SCAZT fits CCNP Security

CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SCAZT is the cloud-access concentration; the security-design concentration SDSI (300-745), identity via SISE (300-715), and secure access via SVPN (300-730) are related options. Passing SCAZT alone also earns Cisco Certified Specialist – Security Secure Cloud Access. See SISE (300-715) →

Realistic study path

Weight your time toward Application and Data Security (25%) and the two 20% domains (User/Device and Network/Cloud). Get familiar with the Cisco Security Reference Architecture and SAFE, and with the named products — Duo, Umbrella, Secure Firewall, ISE, Secure Workload, XDR — because questions reference them directly. Finish with objective-mapped practice and at least one timed 90-minute run. Confirm the current blueprint on Cisco’s exam topics. See SVPN (300-730) →

Frequently asked questions

What is the 300-740 SCAZT exam?
300-740 SCAZT is “Designing and Implementing Secure Cloud Access for Users and Endpoints,” a CCNP Security concentration exam. It covers designing and implementing secure, zero-trust-style access to cloud and SaaS applications across users, devices, and multicloud.
Is 300-740 a CCNP exam by itself?
SCAZT is a CCNP Security concentration exam. To earn CCNP Security you pass the SCOR 350-701 core plus one concentration such as SCAZT. Passing SCAZT on its own also earns the Cisco Certified Specialist – Security Secure Cloud Access credential.
What are the exam domains and weights?
Six weighted domains that sum to 100%: Cloud Security Architecture (10%), User and Device Security (20%), Network and Cloud Security (20%), Application and Data Security (25%, the heaviest), Visibility and Assurance (15%), and Threat Response (10%).
How long is the exam?
The exam runs 90 minutes. It uses a scaled score, and Cisco does not publish a fixed public cut score. Confirm current details on Cisco’s exam page before scheduling.
How is SCAZT different from SDSI?
SCAZT (300-740) focuses on designing and implementing secure cloud access for users and endpoints (SASE, ZTNA, identity, posture, cloud workload security). SDSI (300-745) is a broader security-architecture design exam. Both are CCNP Security concentrations and complement each other.

Start your free 24-hour 300-740 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all six SCAZT domains. No credit card required.

Start free trial →