Implementing and Configuring Cisco Identity Services Engine (300-715 SISE) Exam Guide
The 300-715 SISE validates practical knowledge of implementing Cisco Identity Services Engine for identity-based access control, authentication, authorization, guest access, profiling, BYOD, compliance, and network access administration. It is relevant to candidates pursuing the Cisco Certified Specialist – Security Identity Management Implementation certification or the concentration exam for CCNP Security. This guide helps you decide whether your current ISE experience is sufficient, which blueprint areas deserve the most study time, and how to build a focused lab and review plan.
What the 300-715 SISE exam is for
The exam tests whether you can connect identity, endpoint context, access policy, and network-device behavior in an ISE implementation. It is not best approached as a terminology quiz: your preparation should show how authentication, authorization, profiling, guest access, BYOD, compliance, and administration fit together in a working design.
Passing 300-715 SISE earns the Cisco Certified Specialist – Security Identity Management Implementation certification. Cisco also identifies the exam as satisfying the concentration-exam requirement for the Cisco Certified Network Professional (CCNP) Security certification, and states that passing it can be used toward recertification.
Cisco’s associated Implementing and Configuring Cisco Identity Services Engine training is designed to prepare candidates for this exam. The course description emphasizes hands-on experience with identity-based access control, authentication, authorization, guest access, BYOD onboarding, profiling, and compliance-based access controls.
Who should take it and who should wait
This exam is a stronger fit for a candidate who can reason through an ISE access decision and trace the interaction between an endpoint, a network access device, an identity store, and an authorization result. If your experience is limited to reading ISE concepts without configuring or troubleshooting them, build practical familiarity before scheduling.
Use your background in network access control as a readiness indicator, not as a substitute for ISE study. You should be able to explain what information ISE receives, which policy condition uses that information, what authorization profile is returned, and how the network access device enforces the result.
Candidates targeting CCNP Security should also decide whether this concentration exam matches their broader certification plan. Candidates seeking a specialist credential may have a narrower objective, but they still need coverage across the complete blueprint rather than only the policy features they use at work.
What skills the blueprint measures
The official exam coverage includes architecture and deployment, policy enforcement, Web Auth and guest services, profiler, BYOD, endpoint compliance, and network access device administration. Treat these as connected implementation tasks: an isolated review of menu names is less useful than tracing a complete access workflow.
The v1.2 blueprint weights architecture and deployment at 10% and policy enforcement at 25%. It assigns 15% each to Web Auth and guest services, Profiler, and BYOD. It assigns 10% each to endpoint compliance and network access device administration. Plan study time around these labeled domains, while still reviewing every objective.
The blueprint is the controlling study document for objective-level coverage. Use the exam-topics PDF to turn each domain into a checklist, then mark each item as explain, configure, troubleshoot, or not yet understood. This prevents the largest domain, policy enforcement, from crowding out smaller but separately tested areas.
Architecture and deployment: 10%
The architecture and deployment domain includes configuring Cisco ISE personas, deployment options, hardware and virtual-machine performance specifications, and zero-touch provisioning. Review the function of each persona and the consequences of selecting a deployment arrangement before moving into policy configuration.
A useful lab exercise is to sketch the traffic and management roles in an ISE deployment, identify where administration and policy services occur, and document what must be configured before a network access device can use ISE. Keep the exercise focused on decisions represented by the blueprint rather than on unsupported sizing assumptions.
Policy enforcement: 25%
The policy enforcement domain includes native Active Directory and LDAP integration, identity-store options, 802.1X access, IBNS 2.0 deployment modes, MAB, Cisco TrustSec, and authentication and authorization profiles. This is the broadest weighted domain, so it should anchor your lab sequence.
Build policies from inputs to outcomes. Start with the identity source and authentication method, add endpoint or group conditions, and finish with an authorization profile that produces a clear access result. Then change one condition at a time and observe how the selected rule changes.
Web Auth and guest services: 15%
The Web Auth and guest services domain covers Web Auth, guest and sponsor portals, and related access behavior. Study the distinction between the user journey, the portal configuration, and the network access device behavior that redirects or permits traffic.
Use separate diagrams for guest registration, sponsor approval, authentication, and authorization. For each diagram, identify who performs the action, which ISE component handles it, and what access state the endpoint receives. This approach is more reliable than memorizing portal labels without understanding sequence.
Profiler: 15%
The Profiler domain includes profiler probes and Change of Authorization (CoA). Preparation should connect the evidence collected from an endpoint to the profile selected by ISE and then to the policy result that may change after profiling.
Create a small troubleshooting table with the endpoint signal, the probe or source of information, the resulting profile, and the expected policy consequence. Include a CoA step so you can explain how a changed classification can lead to a new authorization decision without treating profiling as a one-time inventory task.
BYOD: 15%
The BYOD domain includes onboarding and certificates. Review the endpoint onboarding sequence, the role of certificates, and the relationship between registration, authentication, and authorization. Do not reduce BYOD to a portal exercise; certificate handling and the resulting access policy are central to the workflow.
In a lab or diagram, separate the first connection from the post-onboarding connection. Record what credentials or certificate material exists at each stage, how ISE identifies the endpoint, and which policy outcome should apply. This exposes gaps that a feature-only review can miss.
Endpoint compliance: 10%
The endpoint compliance domain covers endpoint posture and compliance. Prepare to distinguish a device’s identity or profile from its compliance state and to connect that state to an authorization decision.
Practice writing two policy outcomes for the same user or endpoint: one for a compliant state and one for a noncompliant state. Then document how the endpoint could move between those outcomes. The point is to understand policy logic and remediation consequences, not to memorize an imagined product configuration.
Network access device administration: 10%
The network access device administration domain includes AAA protocols and TACACS+ command authorization. Study both the device registration and the authorization behavior that follows an administrator’s authentication.
Make a device-administration checklist covering the relationship between the network access device and ISE, the AAA function being used, and the command authorization result. Keep this separate from end-user 802.1X notes: the protocols and policy purpose may differ even though both involve AAA.
Delivery details to confirm before booking
Cisco identifies 300-715 SISE as a 90-minute certification exam offered in English. Cisco lists the exam price as US$300, or states that candidates may use Cisco Learning Credits. Verify the current booking information and any applicable delivery conditions through Cisco before paying or scheduling.
Cisco’s exam page provides the formal exam information, while the exam-topics page is useful for the current blueprint and version transition. Do not assume that a training course, practice environment, or third-party question bank provides the official delivery rules.
Cisco lists August 26, 2026, as the last date to test the 300-715 SISE v1.1 exam and August 27, 2026, as the first date to test v1.2. If your intended test date is near that transition, confirm the version attached to your appointment and study from the corresponding official topics.
How to turn the blueprint into a study plan
Start with an objective inventory rather than a calendar. Copy each blueprint objective into a working document, label your confidence, and attach one explanation, lab task, or troubleshooting question to every weak item. Then allocate the most repeated practice to policy enforcement and to the three 15% domains.
A practical sequence is architecture first, policy enforcement second, then guest services, profiling, BYOD, compliance, and network access device administration. This order gives you the deployment and policy foundation needed to understand the later workflows. Revisit architecture whenever a later exercise exposes a dependency.
Do not interpret the percentages as permission to skip the 10% domains. The exam covers all listed areas, and smaller domains can expose a specific weakness quickly. Use the official percentages to prioritize time, but use the complete blueprint to decide whether you are ready.
Phase one: map the implementation
Begin by drawing the ISE components, network access devices, identity stores, endpoints, and policy decisions in one reference diagram. Add the relevant personas, deployment options, and access methods from the blueprint. Your first goal is a coherent model, not configuration speed.
Next, write a plain-language explanation of an authentication request from arrival at the network access device through the ISE decision and returned authorization. Repeat the exercise for 802.1X, MAB, guest access, and administrator AAA where applicable. Note which assumptions differ between flows.
Phase two: build policy deliberately
Configure or simulate a small policy set with a limited number of clearly named rules. Use conditions that represent identity, endpoint context, or compliance and attach an explicit authorization profile to each result. Avoid creating a large policy matrix before you can explain every rule’s purpose.
After each change, test a positive case and a case that should fall through to another rule. Record the observed result, the expected result, and the reason for any difference. This habit develops troubleshooting judgment and helps you identify rule-order or identity-source misunderstandings.
Phase three: add the user and device journeys
Once core policy behavior is clear, work through guest portals, sponsor actions, profiling, BYOD onboarding, certificates, endpoint compliance, and TACACS+ command authorization. Treat each as a journey with an entry condition, ISE processing step, authorization result, and possible state change.
For each journey, create a one-page runbook. Include the evidence you would inspect when the result is wrong, such as the selected identity store, endpoint classification, certificate state, authorization profile, or network access device behavior. Keep the runbook tied to documented objectives rather than adding unrelated product features.
Phase four: close gaps under time pressure
In the final review period, stop expanding the lab and test retrieval. Choose an objective at random, explain it without notes, then connect it to a configuration or troubleshooting action. Follow with a mixed review that forces you to switch between policy, guest access, profiling, BYOD, compliance, and administration.
Because the exam is 90 minutes, practice reading a scenario for its decision points rather than trying to recall every sentence. Identify the identity source, authentication method, endpoint evidence, policy condition, authorization outcome, and network-device role. If a question concerns a narrow feature, return to the blueprint wording before guessing from general security knowledge.
A lab design that produces useful evidence
A compact lab is valuable when every component answers a blueprint question. Build around one ISE instance or documented environment, a network access device, an identity source, a test endpoint, and a second endpoint state when possible. Expand only when the next component demonstrates a defined objective.
Keep a configuration journal with four columns: change made, expected behavior, observed behavior, and lesson learned. Include the policy rule and authorization profile involved. Over time, this becomes a troubleshooting reference and exposes topics you have only read about.
Use diagrams for flows that are easy to confuse. A guest portal journey, a BYOD certificate journey, and a profiled endpoint receiving a changed authorization each deserve separate diagrams. Mark where the network access device, ISE, endpoint, and administrator act; the separation makes dependencies visible.
How to study each policy question
For any access-control scenario, answer five questions in order: who or what is requesting access, how is it authenticated, what evidence does ISE use, which policy rule matches, and what authorization result is returned. This sequence gives you a repeatable method for both learning and exam reasoning.
Then ask whether the endpoint’s state can change after the initial decision. Profiling, compliance, guest registration, BYOD onboarding, and CoA can alter the context or trigger a new result. A candidate who understands state changes is less likely to treat the first authorization as permanent.
Finally, separate authentication from authorization. A successful identity check does not by itself describe the access permitted. Write the authentication result and the authorization result as separate lines in your notes, then identify the profile or condition responsible for each.
Common preparation mistakes
The most damaging mistake is studying feature names without tracing the access decision. Correct this by requiring every note to answer what the feature receives, what it changes, and how the network access device or endpoint behaves afterward.
Another mistake is spending all available time on 802.1X while neglecting guest services, Profiler, BYOD, compliance, and TACACS+ administration. The blueprint deliberately covers these separate domains. Use a checklist and schedule a review block for every domain, even when your job uses only one access method.
A third mistake is treating a practice question as proof of readiness. A memorized answer may hide a missing concept, and unauthorized exam content is not a safe preparation method. Instead, explain why an answer follows from the stated identity source, condition, workflow, and authorization result.
Do not let a lab become an unstructured installation project. If you cannot state which blueprint objective a task supports, defer it. The goal is not to collect screenshots; it is to develop an accurate mental model and evidence-based troubleshooting process.
Avoid relying on old version material without checking the official version information. Cisco identifies a v1.1-to-v1.2 testing transition, so candidates scheduling around the listed dates should verify the applicable blueprint before final review.
How to decide whether you are ready
You are closer to readiness when you can explain every blueprint domain in your own words, perform or accurately diagram the major workflows, and diagnose a wrong authorization result from evidence rather than intuition. Confidence should come from repeatable reasoning, not from recognizing familiar terminology.
Use a readiness review with three passes. First, mark each objective as understood or unclear. Second, perform a mixed set of lab tasks without following a step-by-step guide. Third, explain the expected result and the likely evidence for a failure. Any objective that fails one of these passes returns to the study queue.
Schedule only after checking the current official exam page, the applicable blueprint version, the English-language requirement, the listed price or Learning Credits option, and the appointment details. These are booking decisions, not assumptions to carry over from an older exam guide.
What to do in the final week
The final week should consolidate the blueprint, not introduce an unrelated technology. Review your domain checklist, rebuild the most error-prone policy or workflow, and revisit notes about identity stores, authorization profiles, certificates, CoA, posture, and TACACS+ command authorization.
Create short scenario prompts for yourself. For example, describe an endpoint that authenticates but receives the wrong access, a newly profiled device that retains an old result, or a BYOD endpoint whose certificate state does not produce the expected policy. Solve each by naming the evidence you would inspect first.
Check your administrative details before the appointment: the exam version, English delivery, scheduled time, and payment or Learning Credits arrangement. Keep the official Cisco links available for any detail that may change. Use the final study session for recall and decision-making, not for unverified question collections.
Where the official information fits
Use Cisco’s exam page for the exam purpose, certification outcomes, language, duration, pricing information, and broad domain list. Use the official v1.2 exam-topics PDF for the detailed objectives and weights. Use Cisco’s training page to understand the hands-on areas associated with the course, and use the Cisco Learning Network topics page to check version timing.
Third-party material can help you organize practice, but it should not replace the official blueprint. For a factual dispute about an objective, exam version, or booking condition, return to the relevant Cisco source rather than relying on an undated summary.
Conclusion
Prepare for 300-715 SISE as an implementation and troubleshooting exam centered on identity-based access decisions. Anchor your plan in the official v1.2 domains, give policy enforcement its largest labeled allocation, and build connected exercises for guest services, profiling, BYOD, compliance, and network-device administration. Before scheduling, verify the applicable version and current booking details with Cisco. Your next step is to turn the blueprint into an objective checklist, identify the first three gaps, and assign each a lab task or written decision path.
Related exams
- Securing Networks with Cisco Firepower (300-710 SNCF)
- Securing Email with Cisco Email Security Appliance (300-720 SESA)
- Securing the Web with Cisco Web Security Appliance (300-725 SWSA)
- 300-730 exam — Implementing Secure Solutions with Virtual Private Networks (SVPN)
- Automating and Programming Cisco Security Solutions (300-735 SAUTO)
- 300-740 exam — Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT)