8781  Reviews star_rate star_rate star_rate star_rate star_half
$3,395USD
Duration 3 days
Course Code ADMUMB-NTO
Available Formats Virtual, Classroom
Next Class: Aug 3, 2026

Overview

Course Description

Cisco Umbrella is a cloud-delivered security platform that provides the first line of defense against threats on the Internet. This course focuses on understanding, administering, and positioning Cisco Umbrella, along with its integration into modern security architectures. Students with a basic understanding of Cisco products and IT solutions will gain the ability to describe Cisco Umbrella, understand Secure Internet Gateway (SIG) capabilities, ransomware protection, and threat intelligence. In addition, the course introduces Cisco Secure Access (ZTA, VPN), providing insight into modern Zero Trust and cloud security solutions. Sign up with EnterOne to get access to this Cisco online training course today. The course qualifies for 18 Cisco Continuing Education Credits (CE).

Skills Gained

Upon completing this course, the learner will be able to meet these overall objectives:

  • Describe and position Cisco Umbrella
  • Discuss Secure Internet Gateway and Ransomware Protection
  • Learn about DNS & IP layer enforcement & Intelligent Proxy
  • Describe Command and control callback blocking
  • Discuss Threat Intelligence
  • Compare Umbrella Packages
  • Understand how to use Cisco Umbrella Virtual Appliance
  • Explain the ease of Integrating Cisco Umbrella into Active Directory
  • Discuss Umbrella Reporting
  • Understand Utilize Multi-Organization Tools
  • Understand Zero Trust Access (ZTA) concepts using Cisco Secure Access
  • Understand VPN-based access policies within Cisco Secure Access
  • Understand security validation and reporting in Cisco Secure Access

Who Can Benefit

The primary audience for this course is as follows:

  • Channel Partner
  • System Engineers
  • System Administrators
  • Architects
  • Security Professionals

Prerequisites

The knowledge and skills that the learner should have before attending this course are as follows:

  • Basic understanding of Cisco products and solutions
|
View Full Schedule

Course Details

Course Details

Course Outline: Module 1. Describe Cisco Umbrella

  • What Is Umbrella
  • Enforcement
  • Umbrella Investigate
  • DNS Overview
  • Why DNS?
  • Intelligence and Statistical Models
  • Co-occurrence Model
  • Spike Rank Model
  • Predictive IP Space Monitoring
  • Connecting to Umbrella

Module 2. Umbrella Deployment Options

  • On-Premises Deployment Options
  • DHCP Server
  • DNS Server Forwarders
  • Recursive DNS
  • Configuring DNS Forwarders

Module 3. Configure Policy Components: Part 1

  • Destination Lists
  • Content Categories
  • Application Settings
  • Tenant Controls
  • Security Settings

Module 4. Configure Policy Components: Part 2

  • Block Page Appearance
  • Integrations
  • Selective Decryption Lists
  • Bypass Users
  • Bypass Codes

Module 5. Umbrella Policies: DNS, Firewall, and Web

  • Umbrella Policy Types
  • DNS Policy
  • SSL Decryption
  • Identities
  • Security Categories
  • Content Access
  • Application Control
  • Destination Lists
  • File Analysis
  • Block Page
  • Bypass Users and Bypass Codes
  • Policy Summary
  • Web Policy
  • PAC File and SAML
  • HTTPS Inspection
  • File Type Control
  • Firewall Policy
  • Firewall Rule
  • IPsec Parameters
  • Network Tunnel Requirements
  • Network Tunnel Configuration
  • Policy Tester

Module 6. Integrating Umbrella with Active Directory

  • Integration Benefits
  • Umbrella Virtual Appliances (VAs)
  • Virtual Appliance Requirements
  • Firewall and ACL Requirements
  • Virtual Appliance with an HTTP/HTTPS Proxy
  • Virtual Appliance Deployment
  • Configure the Virtual Appliance
  • Active Directory Integration
  • Active Directory Prerequisites
  • Umbrella AD Components
  • Connect Active Directory to Umbrella

Module 7. Umbrella Roaming Security: Roaming Client

  • Why Roaming?
  • Cisco Secure Client
  • Migration from the Umbrella Roaming Client
  • Prerequisites and Supported Operating Systems
  • Deployment Methods
  • Manual and Standard Installation
  • Security Profile Installation (OrgInfo.json)
  • Configuring Secure Client Options
  • Behavior Behind a Virtual Appliance
  • Internal Domains

Module 8. Umbrella Roaming Security: AnyConnect Roaming Security

  • AnyConnect Roaming Security Overview
  • Supported Operating Systems and Network Access
  • OrgInfo.json Profile
  • Deployment Through the Cisco ASA
  • Configure the Umbrella Profile
  • Configure and Apply the Group Policy
  • Roaming Computer Settings
  • IP-Layer Enforcement

Module 9. Cisco Umbrella DNS Mobile Security

  • Cisco Security Connector
  • Apple iOS Devices: Requirements and Installation
  • Android OS Devices: Prerequisites
  • Download the Umbrella Android Configuration
  • Push the Umbrella Certificate to Devices
  • Anonymizing Mobile Devices

Module 10. User Account Management

  • Manage Accounts
  • Manage User Roles
  • Custom User Roles

Module 11. Umbrella Reporting

  • Built-in Reports
  • Report Retention
  • Overview Page
  • Report Scheduling
  • Security Activity Report
  • Activity Search Report
  • Admin Audit Log

Module 12. Umbrella Investigate

  • Domain Summary View
  • Umbrella Risk Score
  • Timeline Section
  • DNS Resolution Table
  • WHOIS Record Data
  • GeoIP Section
  • Investigate Sample View
  • Security Features
  • IP Addresses Section
  • Subdomains Section
  • Co-occurrences

Module 13. Umbrella Multi-Organization

  • Multi-Org Console
  • Centralized Reports
  • Centralized Settings
  • Org Management
  • Admins and Delegated Admins

Module 14. Integrating Umbrella with Cisco XDR

  • Unified Detection and Response
  • Value of the Integration
  • Core Telemetry Sources
  • Integration Architecture
  • Operational Efficiency
  • Incident Response Workflow
  • Configuration Workflow

Module 15. Integrating Umbrella with Cisco Splunk

  • Why Integrate Umbrella with Splunk
  • Pre-Configuration Checklist
  • Integration Architecture
  • Cisco Cloud Security Umbrella Add-On for Splunk
  • Configure the Add-On Inputs

Lab Outline: Labs are designed to assure learners a whole practical experience, through the following practical activities: Lab 0. Accessing the Lab Devices Get familiar with the pod topology, IP addressing, and credentials, and verify connectivitybetween the Windows devices. Lab 1. Deploying Cisco Umbrella Log in to the Umbrella dashboard, forward DNS to the Umbrella resolvers, and confirm thatforwarding is active. Lab 2. Configuring Umbrella Policy Components Build destination lists, content categories, content security, application settings, and a blockpage. Lab 3. Configuring Umbrella DNS Policy (Instructor demo) Create and test a DNS policy, use the Policy Tester, and review the resulting activity. Lab 4. SIG Integration Configure a Web policy, deploy the root CA certificate and PAC file, and verify proxyenforcement and reporting. Lab 5. Cloud Firewall Integration Establish an SD-WAN tunnel to Umbrella, configure cloud-firewall rules, and validate thepolicy. Lab 6. Active Directory Integration Using Virtual Appliance (Instructor demo) Deploy virtual appliances, enable redirection, install the AD script and connector, andvalidate the integration. Lab 7. Umbrella User Account and Roles Management Configure user roles and accounts, then validate the resulting access. Lab 8. Umbrella Reporting Review the core and additional reports and configure scheduled reports. Lab 9. Leveraging Umbrella Investigate Investigate a domain and a SHA-256 file hash. Lab 10. Cisco XDR Integration Walk-Through Demo Log in to Cisco XDR and integrate Umbrella with the platform. Lab 11. Umbrella Integration with Catalyst Center (Instructor demo) Integrate Umbrella with Catalyst Center, modify the DNS default policy, provision anetwork device, and validate secure connectivity. Lab 12. Umbrella-Splunk Integration Install Splunk, install the add-on, and configure the data inputs. Appendix/Bonus Lab. Explore the Cisco Security Cloud Control Portal Explore the Cisco Security Cloud Control (SCC) dashboard. Bonus Labs Lab 13. Active Directory User Integration with Cisco Secure Access (Instructor demo) Remove the Umbrella integration, log in to Cisco Secure Access, install the AD script andconnector, and validate the integration. Lab 14. Configure AD FS for SAML (Instructor demo) Configure AD FS as a SAML identity provider and verify the integration. Lab 15. Cisco Secure Client with Zero Trust Access Create Zero Trust posture profiles and a private resource, then configure and test browser-based and client-based access. Lab 16. Cisco Secure Client with Virtual Private Networks (VPNs) Configure a VPN profile and posture, define resources and access rules, and test the VPNconnection. Lab 17. Configure and Test Security Create security profiles, enable IPS on an access policy, and validate enforcement. Lab 18. Cisco Secure Access Reporting

Module 17: Zero Trust Access

  • Overview of Zero Trust Access (ZTA)
  • Cisco Secure Client (ZTNA)
  • Zero Trust Access Module

Module 18: Cisco Secure Client VPN Access

  • Overview of VPN in Cisco Secure Access
  • Manage Regions and IP Pools
  • Manage RADIUS Servers and Groups
  • Creating VPN profiles
  • Endpoint Posture for VPN

Module 19: Security features in Cisco Secure Access

  • Overview of security policies in Cisco Secure Access
  • Creating security profiles
  • Enabling Intrusion Prevention System (IPS)
  • Applying security profiles to access policies

Module 20: Cisco Secure Access Reporting

  • Cisco Secure Access Built-in ReportsSecurity activity dashboardsRemote Access LogsTotal Requests ReportActivity Volume ReportTop Destinations ReportTop Categories ReportReport Scheduling

Lab Outline: Labs are designed to assure learners a whole practical experience, through the following practical activities: Discovery Lab 0: Accessing the Lab Devices

  • Task 1: Understanding your Lab Environment
  • Task 2: Lab IP Addressing, Usernames and Passwords
  • Task 3: Testing Connectivity between Windows Devices

Discovery Lab 1: Deploying Cisco Umbrella

  • Task 1: Log in to the Umbrella Dashboard
  • Task 2: Configure your DNS Server Forwarder to Umbrella DNS Servers
  • Task 3: Confirm you are Forwarding to Umbrella DNS Servers

Discovery Lab 2: Configuring Umbrella Policy Components

  • Task 1: Configuring Destination Lists
  • Task 2: Configuring Content Categories
  • Task 3: Configuring Content Security
  • Task 4: Configuring Application Settings
  • Task 5: Configuring Block Page Appearance

Discovery Lab 3: Configuring Umbrella DNS Policy

  • Task 1: Configure Umbrella DNS Policy
  • Task 2: Test Your Umbrella DNS Policy
  • Task 3: Umbrella Policy Tester
  • Task 4: Review Umbrella Activities

Discovery Lab 4: SIG Integration

  • Task 1: Configure Umbrella Web Policy
  • Task 2: Deploy Umbrella Root CA Certificate and PAC file
  • Task 3: Verify Umbrella Web Policy
  • Task 4: Review Umbrella Proxy Reporting

Discovery Lab 5: Cloud Firewall Integration

  • Task 1: Pre-Cloud Firewall Configuration Test
  • Task 2: SD-WAN and Umbrella Tunnel Integration
  • Task 3: Configure Cloud-Firewall Rules
  • Task 4: Validate Cloud-Firewall Policy

Discovery Lab 6: Active Directory Integration using Virtual Appliance

  • Task 1: Deploy Umbrella Virtual Appliances
  • Task 2: Enable VA Redirect to Umbrella
  • Task 3: Installing the Active Directory Script and Connector
  • Task 4: Validate Umbrella Active Directory Integration

Discovery Lab 7: Umbrella User Account and Roles Management

  • Task 1: Configuring Umbrella User Roles
  • Task 2: Configuring Umbrella User Accounts
  • Task 3: Validating Umbrella User Roles and Accounts

Discovery Lab 8: Umbrella Reporting

  • Task 1: Reviewing Umbrella Core Reports
  • Task 2: Reviewing Umbrella Additional Reports
  • Task 3: Configuring Umbrella Scheduled Reports

Discovery Lab 9: Leveraging Umbrella Investigate

  • Task 1: Investigating a Domain
  • Task 2: Investigating a SHA-256 File Hash

Discovery Lab 10: Cisco XDR Integration Walk Through Demo

  • Task 1: Login Your Cisco XDR
  • Task 2: Integrating Umbrella Within Cisco XDR

Discovery Lab 11: Umbrella Integration with CATC

  • Task 1: CATC Umbrella Integration
  • Task 2: Modify Umbrella DNS Default Policy
  • Task 3: Provision Network device with Cisco Umbrella Policies
  • Task 4: Validate Your Switch Securely Connects to Umbrella

Discovery Lab 12: Umbrella-Splunk Integration

  • Task 1: Install Splunk
  • Task 2: Install Cisco Secure Access App
  • Task 3: Perform the Necessary Configuration for the Cisco Secure Access App

Discovery Lab 13: Active Directory User Integration with Cisco Secure Access

  • Task 1: Unintegration of Umbrella
  • Task 2: Login your Cisco Secure Access
  • Task 3: Installing the Active Directory Script and Connector
  • Task 4: Validate Cisco Secure Access Active Directory Integration

Discovery Lab 14: Configure AD FS for SAML Discovery Lab 15: Cisco Secure Client with Zero Trust Access

  • Task 1: Create Zero Trust (ZT) Posture Profiles
  • Task 2: Create Private Resource
  • Task 3: Configure and Test Browser-Based ZTA
  • Task 4: Configure and Test Client-Based ZTA

Discovery Lab 16: Cisco Secure Client with Virtual Private Networks (VPNs)

  • Task 1: Configure a VPN Profile
  • Task 2: Create VPN Posture Profile
  • Task 3: Create Internet Resources
  • Task 4: Create Access Policy Rules
  • Task 5: Test VPN Connection

Discovery Lab 17: Configure and Test Security

  • Task 1: Create Security Profiles
  • Task 2: Assign Security Profile to Access Policy and Enable IPS
  • Task 3: Validate Access Policy with Security Settings

Discovery Lab 18: Cisco Secure Access Reporting

  • Task 1: Reviewing Security Activity
  • Task 2: Reviewing Additional Reports
  • Task 3: Configuring Scheduled Reports

Schedule

10 options available

FAQ

Does the course schedule include a Lunchbreak?

Classes typically include a 1-hour lunch break around midday. However, the exact break times and duration can vary depending on the specific class. Your instructor will provide detailed information at the start of the course.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does Ascendient Learning deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

What does vendor-authorized training mean?

As a vendor-authorized training partner, we offer a curriculum that our partners have vetted. We use the same course materials and facilitate the same labs as our vendor-delivered training. These courses are considered the gold standard and, as such, are priced accordingly.

Is the training too basic, or will you go deep into technology?

It depends on your requirements, your role in your company, and your depth of knowledge. The good news about many of our learning paths, you can start from the fundamentals to highly specialized training.

How up-to-date are your courses and support materials?

We continuously work with our vendors to evaluate and refresh course material to reflect the latest training courses and best practices.

Are your instructors seasoned trainers who have deep knowledge of the training topic?

Ascendient Learning instructors have an average of 27 years of practical IT experience and have also served as consultants for an average of 15 years. To stay current, instructors spend at least 25 percent of their time learning new, emerging technologies and courses.

Do you provide hands-on training and exercises in an actual lab environment?

Lab access is dependent on the vendor and the type of training you sign up for. However, many of our top vendors will provide lab access to students to test and practice. The course description will specify lab access.

Will you customize the training for our company’s specific needs and goals?

We will work with you to identify training needs and areas of growth.  We offer a variety of training methods, such as private group training, on-site of your choice, and virtually. We provide courses and certifications that are aligned with your business goals.

How do I get started with certification?

Getting started on a certification pathway depends on your goals and the vendor you choose to get certified in. Many vendors offer entry-level IT certification to advanced IT certification that can boost your career. To get access to certification vouchers and discounts, please contact info@ascendientlearning.com.

Will I get access to content after I complete a course?

You will get access to the PDF of course books and guides, but access to the recording and slides will depend on the vendor and type of training you receive.

How do I request a W9 for Ascendient Learning?

View our filing status and how to request a W9.

Reviews

Both course material and instructor demonstrated a sound foundation on Maximo material

Courseware was effective but would like to have some PDF material on BPML and XPATH

Overall ExitCertified is a great training provider and the remote learning is as effective as in person.

I think the platform is very good and look forward to taking my next course in early October.

Great oppportunity for me to get training on the software during my work day.