Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Cisco Security Platforms: XDR, Firepower, Secure Connect, Secure Endpoint, ISE, SMA

The six Cisco security platforms on CCNAAUTO 200-901 3.5 (v1.1): Cisco XDR, Firepower (now Secure Firewall), Secure Connect, Secure Endpoint, ISE, Secure Malware Analytics. What each does and how its API is shaped.

Quick summary
  • XDR = SOC analyst's one pane for alerts from Cisco + third-party sources. REST API for incidents and automation playbooks.
  • Firepower / Secure Firewall = network firewall family. FMC (manager) has a REST API; firewalls accept RESTCONF too.
  • ISE = policy engine for who/what connects to the network. REST + ERS API for admin tasks.

Mental model

Cisco security is many products. The v1.1 blueprint names six (XDR, Firepower, Secure Connect, Secure Endpoint, ISE, Secure Malware Analytics). Each has a REST API; most authenticate with a bearer token after an initial login.

Cisco objective 3.5 asks you to describe their capabilities, not integrate them. Hit the one-paragraph summary for each.

XDR (eXtended Detection and Response)

  • SaaS SOC platform. One pane for alerts from Cisco (Secure Endpoint, Secure Firewall, Umbrella / Secure Connect), SIEM feeds, and third-party sources.
  • REST API: list incidents, add context, trigger playbooks, close.
  • Auth: OAuth2 bearer token.

When used: central security operations.

Secure Firewall (ex-Firepower)

  • The current branding for Cisco’s enterprise firewall family. Hardware (3100 / 4200 series) and virtual (FTDv).
  • Managed by Firewall Management Center (FMC) on-prem, or Cloud-Delivered FMC (cdFMC).
  • REST API on FMC: create network objects, access rules, deploy to firewalls.
  • The individual firewall (FTD) also speaks RESTCONF.

When used: admin, deployment, rule orchestration.

Secure Connect

  • Cisco’s SASE (Secure Access Service Edge) offering: VPN + SWG + CASB + ZTNA, cloud-delivered.
  • Took the Umbrella + anti-malware stack and merged with Catalyst SD-WAN for on-ramp.
  • REST API: policy, user groups, log retrieval.

When used: remote-worker secure access, branch-to-cloud security.

Secure Endpoint (ex-AMP for Endpoints)

  • EDR agent on laptops/servers. Blocks malware, flags suspicious processes.
  • REST API: event feed (what triggered on which host), inventory, policy.

When used: endpoint security operations, hunting.

ISE (Identity Services Engine)

  • The policy engine for who/what gets onto the network. Does 802.1X, MAB, posture, TACACS+.
  • REST API: ERS (External RESTful Services). CRUD on identity groups, endpoint lists, authorisation profiles.

When used: NAC provisioning, dynamic policy adjustments from automation scripts.

Secure Malware Analytics (ex-Threat Grid)

  • Malware sandbox + threat intelligence platform. Submit a file; get back a detonation report.
  • REST API: submit sample, poll for status, pull report JSON.

When used: incident response, enriching alerts with sandbox verdicts.

Comparison at a glance

PlatformDeploymentPrimary audienceTypical API call
XDRSaaSSOC analyst / automationGET /incidents
Secure Firewall (FMC)On-prem / cloudFirewall adminPOST /api/fmc_config/v1/.../accesspolicies
Secure ConnectSaaSNetwork / security adminGET /policy/users
Secure EndpointSaaS (agents on hosts)Endpoint / SOCGET /v1/events
ISEOn-prem / cloudNetwork access adminGET /ers/config/identitygroup
SMASaaSIR / threat intelPOST /api/v3/samples (submit a file)

What dropped from the v1.1 blueprint

The old DEVASC blueprint listed Firepower, Umbrella, AMP, ISE, and ThreatGrid. Cisco rebranded or restructured:

  • Umbrella + Secure Workload etc. → folded into Secure Connect (SASE).
  • AMP for Endpoints → Secure Endpoint.
  • ThreatGrid → Secure Malware Analytics.
  • Added XDR as the “single pane” tying them together.

For the exam, learn the current names.

FAQ

Do I need to memorise every REST endpoint for every platform? No. Describe-level objective. Know what each platform does and the general shape of its API.

Which security product’s API is friendliest for a first script? Umbrella / Secure Connect’s reporting API, or SMA’s sample submission. Both are classic REST + JSON.

Is Catalyst SD-WAN security? Cisco markets it as part of its security SASE story because of Secure Connect integration. On the exam, treat Catalyst SD-WAN as a NETWORK platform (3.2) and Secure Connect as the security piece (3.5).

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Cisco Security Platforms: XDR, Firepower, Secure Connect, Secure Endpoint, ISE, SMA. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Cisco Security Platforms: XDR, Firepower, Secure Connect, Secure Endpoint, ISE, SMA fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.