Mental model
Cisco security is many products. The v1.1 blueprint names six (XDR, Firepower, Secure Connect, Secure Endpoint, ISE, Secure Malware Analytics). Each has a REST API; most authenticate with a bearer token after an initial login.
Cisco objective 3.5 asks you to describe their capabilities, not integrate them. Hit the one-paragraph summary for each.
XDR (eXtended Detection and Response)
- SaaS SOC platform. One pane for alerts from Cisco (Secure Endpoint, Secure Firewall, Umbrella / Secure Connect), SIEM feeds, and third-party sources.
- REST API: list incidents, add context, trigger playbooks, close.
- Auth: OAuth2 bearer token.
When used: central security operations.
Secure Firewall (ex-Firepower)
- The current branding for Cisco’s enterprise firewall family. Hardware (3100 / 4200 series) and virtual (FTDv).
- Managed by Firewall Management Center (FMC) on-prem, or Cloud-Delivered FMC (cdFMC).
- REST API on FMC: create network objects, access rules, deploy to firewalls.
- The individual firewall (FTD) also speaks RESTCONF.
When used: admin, deployment, rule orchestration.
Secure Connect
- Cisco’s SASE (Secure Access Service Edge) offering: VPN + SWG + CASB + ZTNA, cloud-delivered.
- Took the Umbrella + anti-malware stack and merged with Catalyst SD-WAN for on-ramp.
- REST API: policy, user groups, log retrieval.
When used: remote-worker secure access, branch-to-cloud security.
Secure Endpoint (ex-AMP for Endpoints)
- EDR agent on laptops/servers. Blocks malware, flags suspicious processes.
- REST API: event feed (what triggered on which host), inventory, policy.
When used: endpoint security operations, hunting.
ISE (Identity Services Engine)
- The policy engine for who/what gets onto the network. Does 802.1X, MAB, posture, TACACS+.
- REST API: ERS (External RESTful Services). CRUD on identity groups, endpoint lists, authorisation profiles.
When used: NAC provisioning, dynamic policy adjustments from automation scripts.
Secure Malware Analytics (ex-Threat Grid)
- Malware sandbox + threat intelligence platform. Submit a file; get back a detonation report.
- REST API: submit sample, poll for status, pull report JSON.
When used: incident response, enriching alerts with sandbox verdicts.
Comparison at a glance
| Platform | Deployment | Primary audience | Typical API call |
|---|---|---|---|
| XDR | SaaS | SOC analyst / automation | GET /incidents |
| Secure Firewall (FMC) | On-prem / cloud | Firewall admin | POST /api/fmc_config/v1/.../accesspolicies |
| Secure Connect | SaaS | Network / security admin | GET /policy/users |
| Secure Endpoint | SaaS (agents on hosts) | Endpoint / SOC | GET /v1/events |
| ISE | On-prem / cloud | Network access admin | GET /ers/config/identitygroup |
| SMA | SaaS | IR / threat intel | POST /api/v3/samples (submit a file) |
What dropped from the v1.1 blueprint
The old DEVASC blueprint listed Firepower, Umbrella, AMP, ISE, and ThreatGrid. Cisco rebranded or restructured:
- Umbrella + Secure Workload etc. → folded into Secure Connect (SASE).
- AMP for Endpoints → Secure Endpoint.
- ThreatGrid → Secure Malware Analytics.
- Added XDR as the “single pane” tying them together.
For the exam, learn the current names.
FAQ
Do I need to memorise every REST endpoint for every platform? No. Describe-level objective. Know what each platform does and the general shape of its API.
Which security product’s API is friendliest for a first script? Umbrella / Secure Connect’s reporting API, or SMA’s sample submission. Both are classic REST + JSON.
Is Catalyst SD-WAN security? Cisco markets it as part of its security SASE story because of Secure Connect integration. On the exam, treat Catalyst SD-WAN as a NETWORK platform (3.2) and Secure Connect as the security piece (3.5).
