Cisco 350-401 ENCOR v1.2: What the Current Exam Covers

350-401 ENCOR is the core exam for Cisco’s enterprise professional and expert tracks, and the current version is v1.2. Cisco’s v1.2 blueprint went live on March 19, 2026. It remains a 120-minute exam and keeps the familiar six-domain structure: Architecture 15%, Virtualization 10%, Infrastructure 30%, Network Assurance 10%, Security 20%, and Automation and Artificial Intelligence 15%.

The biggest v1.2 change is subtraction rather than expansion. Cisco removed the former wireless design, wireless infrastructure, and wireless security objectives as the company moved wireless material into dedicated certification tracks. Cisco also updated product naming such as Cisco Catalyst SD-WAN and Cisco Catalyst Center. The domain percentages stayed the same, which means the remaining routing, switching, assurance, security, SD-WAN, SD-Access, virtualization, and automation content carries more practical importance inside the same weighting.

This makes the current exam easier to scope but not shallow. ENCOR still expects candidates to move between architecture, configuration, diagnosis, security, and programmability. It is best read as a systems exam for enterprise networks rather than six unrelated chapters.

Architecture now focuses more tightly on enterprise design and software-defined networking

The 15% Architecture domain covers high-level two-tier, three-tier, fabric, and cloud designs; high availability; Cisco Catalyst SD-WAN; Cisco SD-Access; and QoS interpretation. The removal of wireless design does not make architecture unimportant. It concentrates the domain on how enterprise networks are built, how they remain available, and how controller-based fabrics change control and data planes.

Candidates should be able to explain why a design uses redundancy, first-hop resiliency, or stateful switchover, and how SD-WAN or SD-Access introduces policy and centralized control. The point is not to memorize a marketing diagram. It is to understand what problem the architecture solves and what operational trade-offs it introduces.

Virtualization connects logical topology to the physical network

The 10% Virtualization domain covers type 1 and type 2 hypervisors, virtual machines, virtual switching, VRFs, GRE and IPsec tunnels, LISP, and VXLAN. Those topics can look disconnected until they are organized around one question: how can multiple logical networks or overlays share the same physical infrastructure without behaving as one flat network?

VRFs separate routing tables, GRE and IPsec provide tunnel mechanisms, and LISP/VXLAN support modern overlay designs. Candidates should understand the role of each technology and be able to differentiate endpoint or path virtualization from server hypervisor concepts.

Infrastructure remains the largest domain at 30%

Infrastructure is where ENCOR remains most recognizably hands-on. The current v1.2 blueprint includes 802.1Q trunk troubleshooting, EtherChannel troubleshooting, RSTP and MST, Spanning Tree protections, EIGRP versus OSPF comparison, multiarea OSPFv2/v3 configuration, directly connected eBGP, policy-based routing, NTP/PTP interpretation, NAT/PAT, HSRP/VRRP, and multicast concepts.

The weighting is a warning against over-focusing on new automation topics at the expense of core networking. A candidate should be able to read a topology, predict Layer 2 and Layer 3 behavior, recognize an adjacency or path-selection problem, and configure the common services that keep enterprise networks reachable.

Network Assurance is an evidence and observability domain

The 10% Network Assurance domain includes debugs, traceroute, ping, SNMP, syslog, Flexible NetFlow, SPAN/RSPAN/ERSPAN, IP SLA, Cisco Catalyst Center workflows, and NETCONF/RESTCONF configuration and verification. This domain turns the network from a configuration into an observable system.

A useful adjacent destination is 300-445 ENNA, Cisco’s enterprise network assurance concentration exam. ENCOR is not as deep, but it uses the same operational mindset: collect evidence, identify where behavior diverges from intent, and choose a tool that can prove the next hypothesis.

Security is still one fifth of the exam

The 20% Security domain includes device access control, local authentication, AAA, ACLs, Control Plane Policing, REST API security, and network security design concepts such as threat defense, endpoint security, next-generation firewalls, TrustSec, and MACsec. Wireless authentication objectives were removed with v1.2, but security remains a major portion of the exam.

The domain rewards candidates who can separate management-plane protection, control-plane protection, data-plane filtering, identity-based access, and API security. A general security principle such as least-privilege access becomes concrete here through AAA, ACLs, segmentation, TrustSec, and controlled automation interfaces.

Automation and Artificial Intelligence is practical even without a large AI task list

The 15% final domain is named Automation and Artificial Intelligence, but the published v1.2 tasks remain focused on Python, JSON, YANG, Catalyst Center and SD-WAN Manager APIs, REST response interpretation, EEM applets, and agent versus agentless orchestration tools. Candidates should therefore avoid studying generic AI theory at the expense of the actual published tasks.

The automation skill is operational literacy. You should be able to read a basic Python script, construct valid JSON, understand why YANG provides a data model, interpret REST results, and recognize when an EEM applet or orchestration tool can automate configuration, troubleshooting, or data collection. The ENAUTO concentration goes much deeper, but ENCOR expects a solid foundation.

v1.2 changes what candidates should stop studying

The most important transition discipline is knowing what left the blueprint. Cisco explicitly removed wireless deployment models, WLAN location services and client density, the former wireless infrastructure task group, wireless security configuration, and several other v1.1 tasks. The current training materials may still contain some wireless lessons for continuity, but Cisco notes that those sections can be skipped for v1.2 exam preparation.

This distinction matters because stale study plans can waste many hours. An older article about ENCOR v1.1 is useful historical context, but the candidate should treat the official v1.2 blueprint as the authority for what is tested now.

ENCOR sits at the center of the CCNP Enterprise path

Passing ENCOR earns the Cisco Certified Specialist – Enterprise Core credential and satisfies the core-exam requirement for CCNP Enterprise. Candidates then add a concentration such as ENARSI, Catalyst SD-WAN, enterprise design, automation, cloud connectivity, or network assurance depending on their role.

The exam also serves as the core requirement for CCIE Enterprise Infrastructure. That explains its breadth: ENCOR needs enough routing, switching, architecture, security, assurance, and automation to support several different advanced directions without becoming a specialist exam itself.

A strong preparation plan follows the current blueprint, not the memory of older ENCOR

The safest workflow is to build a v1.2 checklist from the official topic document, map each objective to a lab or explanation, and mark the removed v1.1 topics so they do not keep consuming study time. Use the Cisco certification inventory to understand adjacent destinations, but keep the current 350-401 objectives as the center of preparation.

If you can explain the architecture, configure and troubleshoot the core infrastructure, collect assurance evidence, secure device and network access, and interpret basic automation workflows, you are preparing for the ENCOR that exists now—not the broader wireless-inclusive version many older resources still describe.

The official v1.2 topic document is especially valuable because it resolves a common source conflict. Some Cisco overview pages and older books still say v1.1, while the v1.2 release notes and current ENCOR training state that the update went live on March 19, 2026. Candidates should prioritize the current topic PDF and release notes when those labels disagree.

The removals are not trivial. Wireless deployment models, location services, client density, the dedicated wireless infrastructure group, and wireless security configuration no longer belong in the v1.2 blueprint. Cisco also removed the standalone switching-mechanisms task that named CEF, CAM, TCAM, FIB, RIB, and adjacency tables. Those concepts can still be useful operational knowledge, but they should not receive the same exam-preparation weight as objectives that remain explicitly listed.

At the same time, the six percentages are unchanged. That means the 30% Infrastructure domain still dominates, Security still carries 20%, and Automation and Artificial Intelligence remains 15%. The update narrows the content inside those domains rather than changing the overall balance of the exam.

Candidates should also notice what did not change. OSPF, eBGP, spanning tree, EtherChannel, first-hop redundancy, NAT, multicast concepts, assurance tooling, AAA, ACLs, CoPP, APIs, Python, JSON, YANG, and EEM remain central. v1.2 is therefore not a new exam that can be prepared for from scratch with a short delta sheet; it is the same enterprise core with a cleaner boundary around wireless and a refreshed naming model.

For study planning, that means old v1.1 books are not automatically useless. Their wired enterprise, virtualization, security, assurance, and automation chapters may still map well to v1.2. The candidate simply needs to reconcile every chapter against the current topic list and stop treating removed objectives as required coverage.

The safest final check is to compare every study resource with the three-page v1.2 topic document. If a chapter teaches a current objective, keep it. If it is useful background but no longer listed, mark it optional. If it describes an old product name, translate it to the current Catalyst terminology. This small reconciliation step prevents otherwise strong preparation from drifting toward a version of ENCOR that is no longer delivered.

Version alignment is part of exam readiness.