← CCNP Security: SCOR core and operations
06 / 8 · 45 MIN

SSE, private access, and DLP

Relate identity, connectivity, and inspection to actual coverage.

Concept and mechanism

SSE brings together security functions for service and data access, while SASE also integrates WAN connectivity capabilities. Choosing an architecture label does not prove how each flow reaches a control. In Secure Access, Resource Connectors establish outbound connections to required regional destinations. DNS, egress, and deployment method should be checked against applicable documentation. A healthy connector does not guarantee a private resource is correctly defined or authorized for a particular user. Map identity, resource, path, and decision, including expected-denial tests. Support needs to identify which of those stages failed.

Guided application

Real-time DLP over HTTPS depends on inspection prerequisites and identity matching in access policy. Defining a data pattern does not automatically make encrypted content visible. In a fictional pilot, synthetic data are detected, but a critical application fails under inspection. Investigate compatibility, bound the pilot, and document exceptions, compensating controls, and review dates. Do not claim complete protection for excluded paths. For investigation, domain scores and indicators enrich context but do not alone prove endpoint compromise. Correlate process, time, destination, and behavior before assigning cause. The PM should request protection and continuity evidence, while APS should be able to locate the rule and path actually used by a concrete session.

IN PRACTICE

Healthy connector, misdefined resource, and unauthorized user are different states.

Common pitfalls

SSE as complete WAN; healthy component as accepted service; DLP without applicable inspection; score as proven compromise.

Related topics: Risk, identity, and AI security · Encryption, VPNs, and APIs · Firewall, inspection, and layer-two protection

Take this idea with you

State coverage by path and identity.

Create account

Reference: SASE and SSE architecture · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security