Concept and mechanism
CCNP Security combines a core exam and an eligible concentration. This course initially covers the six SCOR 2.0 domains; an internal assessment result awards no Cisco credential. In security practice, start by identifying the resource and decision needing protection. A CVSS base score describes intrinsic severity, but local priority also depends on exposure, threat, and impact. Zero trust requires evaluating resource access instead of granting automatic trust solely because a request came from the internal network. User identity, device state, and authorization serve complementary functions. One trust label does not demonstrate all those properties.
Guided application
In a fictional funds case, two fixes compete for one window. A higher-scoring vulnerability affects a disabled function; another affects an exposed service with observed exploitation. Present evidence and retain both in the register with justified priority and review. An APS assistant creates another boundary: external tickets can contain instructions attempting to change model behavior. Treat that text as data and restrict tools and secrets through external controls. The same care with distinct functions applies to post-quantum cryptography. ML-KEM establishes shared secrets; it is not a release-signing digital signature. Before proposing migration, inventory protocols, dependencies, and compatibility rather than treating an algorithm name as a complete identity or protection solution.
A higher score does not alone decide which fix reduces most risk within the window.
Common pitfalls
Score as complete risk; internal network as authorization; prompt as security boundary; KEM as signature.
Related topics: Encryption, VPNs, and APIs · Firewall, inspection, and layer-two protection · Secure management and VPN diagnosis
Explain the decision through context, limits, and evidence.
Reference: Zero Trust Architecture · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security