CCNP (4 PAPERS) – SECURITY
Implementing Cisco Edge Network Security Solutions (300-206)
Exam Description: The Implementing Cisco Edge Network Security (SENSS) (300-206) exam tests the knowledge of a network security engineer to configure and implement security on Cisco network perimeter edge devices such as a Cisco switch, Cisco router, and Cisco ASA firewall. This 90 -minute exam consists of 65-75 questions and focuses on the technologies used to strengthen security of a network perimeter such as Network Address Translation (NAT), ASA policy and application inspect, and a zone-based firewall on Cisco routers. Candidates can prepare for this exam by taking the Cisco Edge Network Security (SENSS) course. The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
Threat Defense
- Implement firewall (ASA or IOS depending on which supports the implementation)
- Implement ACLs
- Implementstatic/dynamic NAT/PA
- Implement object groups
- Describe threat detection features
- Implement botnet traffic filtering
- Configure application filtering and protocol inspection
- Describe ASA security contexts
- Implement Layer 2 Security
- Configure DHCP snooping
- Describe dynamic ARP inspection
- Describe storm control 1
- Configure port security
- Describe common Layer 2 threats and attacks and mitigation
- Describe MACSec
- Configure IP source verification
- Configure device hardening per best practices
- Routers
- Switches
- Firewalls
Cisco Security Devices GUIs and Secured CLI Management
- Implement SSHv2, HTTPS, and SNMPv3 access on the network devices
- Implement RBAC on the ASA/IOS using CLI and ASDM
- Describe Cisco Prime Infrastructure
- Functions and use cases of Cisco Prime
- Device Management
- Describe Cisco Security Manager (CSM)
- Functions and use cases of CSM
- Device Management
- Implement Device Managers
- Implement ASA firewall features using ASDM
Management Services on Cisco Devices
- Configure NetFlow exporter on Cisco Routers, Switches, and ASA
- Implement SNMPv3
- Create views, groups, users, authentication, and encryption
- Implement logging on Cisco Routers, Switches, and ASA using Cisco best practices
- Implement NTP with authentication on Cisco Routers, Switches, and ASA
- Describe CDP, DNS, SCP, SFTP, and DHCP
- Describe security implications of using CDP on routers and switches
- Need for dnssec
Troubleshooting, Monitoring and Reporting Tools
- Monitor firewall using analysis of packet tracer, packet capture, and syslog
- Analyze packet tracer on the firewall using CLI/ASDM
- Configure and analyze packet capture using CLI/ASDM
- Analyze syslog events generated from ASA
Threat Defense Architectures
- Design a Firewall Solution
- High-availability
- Basic concepts of security zoning
- Transparent & Routed Modes
- Security Contexts
- Layer 2 Security Solutions
- Implement defenses against MAC, ARP, VLAN hopping, STP, and DHCP rogue attacks
- Describe best practices for implementation
- Describe how PVLANs can be used to segregate network traffic at Layer 2
Security Components and Considerations
- Describe security operations management architectures
- Single device manager vs. multi-device manager
- Describe Data Center security components and considerations
- Virtualization and Cloud security
- Describe Collaboration security components and considerations
- Basic ASA UC Inspection features
- Describe common IPv6 security considerations
- Unified IPv6/IPv4 ACL on the ASA
Implementing Cisco Threat Control Solutions (300-207)
The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
Content Security
- Cisco ASA 5500-X NGFW Security Services
- Describe features and functionality
- Implement web usage control (URL-filtering, reputation based, file filtering)
- Implement AVC
- Implement decryption policies
- Describe traffic redirection and capture methods
- Cisco Cloud Web Security
- Describe features and functionality
- Implement IOS and ASA connectors
- Implement AnyConnect web security module
- Describe web usage control
- Implement AVC
- Implement anti-malware
- Describe decryption policies
- Cisco WSA
- Describe features and functionality
- Implement data security
- Implement WSA Identity and Authentication, including Transparent User Identification
- Describe web usage control
- Implement AVC
- Implement anti-malware
- Describe decryption policies
- Describe traffic redirection and capture methods (Explicit Proxy vs. Transparent Proxy)
- Cisco ESA
- Describe features and functionality
- Implement email encryption
- Implement anti-spam policies
- Implement virus outbreak filter
- Implement DLP policies
- Implement anti-malware
- Implement inbound and outbound mail policies and authentication
- Describe traffic redirection and capture methods
Threat Defense
- Network IPS
- Implement traffic redirection and capture methods
- Implement network IPS deployment modes
- Describe signatures engines
- Implement event actions & overrides/filters
- Implement anomaly detection
- Implement risk ratings
- Describe IOS IPS
- Configure device hardening per best practices
- IPS
- Content Security appliances
Device GUIs and Secured CLI
- Content Security
- Implement HTTPS and SSH access
- Describe configuration elements
- Implement ESA GUI for message tracking
Troubleshooting, Monitoring, and Reporting Tools
- Configure IME and IP logging for IPS
- Content Security
- Describe reporting functionality
- Implement the WSA Policy Trace tool
- Implement the ESA Message Tracking tool
- Implement the ESA Trace tool
- Use web interface to verify traffic is being redirected to CWS
- Use CLI on IOS to verify CWS operations
- Use CLI on ASA to verify CWS operations
- Use the PRSM Event Viewer to verify ASA NGFW operations
- Describe the PRSM Dashboards and Reports
- Monitor Cisco Security IntelliShield
- Describe at a high level the features of the Cisco Security IntelliShield Alert Manager Service
Threat Defense Architectures
- Design IPS solution
- Deploy Inline or Promiscuous
- Deploy as IPS appliance, IPS software or hardware module or IOS IPS
- Describe methods of IPS appliance load-balancing
- Describe the need for Traffic Symmetry
- Inline modes comparison – inline interface pair, inline VLAN pair, and inline VLAN group
- Management options
Content Security Architectures
- Design Web Security solution
- Compare ASA NGFW vs. WSA vs. CWS
- Compare Physical WSA vs. Virtual WSA
- List available CWS connectors
- Design Email Security solution
- Compare Physical ESA vs. Virtual ESA
- Describe Hybrid mode
- Design Application Security solution
- Describe the need for application visibility and control
Implementing Cisco Secure Access Solutions (300-208)
The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
Identity Management and Secure Access
- Implement device administration
- Compare and select AAA options
- TACACS+
- RADIUS
- Describe Native AD and LDAP
- Describe identity management
- Describe features and functionality of authentication and authorization
- Describe identity store options (i.e., LDAP, AD, PKI, OTP, Smart Card, local)
- Implement accounting
- Implement wired/wireless 802.1X
- Describe RADIUS flows
- AV pairs
- EAP types
- Describe supplicant, authenticator, and server
- Supplicant options
- 802.1X phasing (monitor mode, low impact, closed mode)
- AAA server
- Network access devices
- Implement MAB
- Describe the MAB process within an 802.1X framework
- Flexible authentication configuration
- ISE authentication/authorization policies
- ISE endpoint identity configuration
- Verify MAB Operation
- Implement network authorization enforcement
- dACL
- Dynamic VLAN assignment
- Describe SGA
- Named ACL
- CoA
- Implement Central Web Authentication (CWA)
- Describe the function of CoA to support web authentication
- Configure authentication policy to facilitate CWA
- URL redirect policy
- Redirect ACL
- Customize web portal
- Verify central web authentication operation
- Implement profiling
- Enable the profiling services
- Network probes
- IOS Device Sensor
- Feed service
- Profiling policy rules
- Utilize profile assignment in authorization policies
- Verify profiling operation
- Implement guest services
- Managing sponsor accounts
- Sponsor portals
- Guest portals
- Guest Policies
- Self registration
- Guest activation
- Differentiated secure access
- Verify guest services operation
- Implement posture services
- Describe the function of CoA to support posture services
- Agent options
- Client provisioning policy and redirect ACL
- Posture policy
- Quarantine/remediation
- Verify posture service operation
- Implement BYOD access
- Describe elements of a BYOD policy
- Device registration
- My devices portal
- Describe supplicant provisioning
Threat Defense
- Describe TrustSec Architecture
- SGT Classification – dynamic/static
- SGT Transport – inline tagging and SXP
- SGT Enforcement – SGACL and SGFW
- MACsec
Troubleshooting, Monitoring, and Reporting Tools
- Troubleshoot identity management solutions
- Identify issues using authentication event details in Cisco ISE
- Troubleshoot using Cisco ISE diagnostic tools
- Troubleshoot endpoint issues Use debug commands to troubleshoot RADIUS and 802.1X on IOS switches and wireless controllers
- Troubleshoot backup operations
Threat Defense Architectures
- Design highly secure wireless solution with ISE
- Identity Management
- 802.1X
- MAB
- Network authorization enforcement
- CWA
- Profiling
- Guest Services
- Posture Services
- BYOD Access
Design Identity Management Architectures
- Device administration
- Identity Management
- Profiling
- Guest Services
- Posturing Services
- BYOD Access
Implementing Cisco Secure Mobility Solutions (300-209)
The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
Secure Communications
- Site-to-site VPNs on routers and firewalls
- Describe GETVPN
- Implement IPsec (with IKEv1 and IKEv2 for both IPV4 & IPV6)
- Implement DMVPN (hub-Spoke and spoke-spoke on both IPV4 & IPV6)
- Implement FlexVPN (hub-Spoke on both IPV4 & IPV6) using local AAA
- AppSecure
- Implement AnyConnect IKEv2 VPNs on ASA and routers
- Implement AnyConnect SSLVPN on ASA and routers
- Implement clientless SSLVPN on ASA and routers
- Implement FLEX VPN on routers
Troubleshooting, Monitoring, and Reporting Tools (as implemented above)
- Troubleshoot VPN using ASDM & CLI 2.1.a Troubleshoot IPsec
- Troubleshoot DMVPN
- Troubleshoot FlexVPN
- Troubleshoot AnyConnect IKEv2 and SSL VPNs on ASA and routers
- Troubleshoot clientless SSLVPN on ASA and routers
Secure Communications Architectures
- Design site-to-site VPN solutions
- Identify functional components of GETVPN, FlexVPN, DMVPN, and IPsec
- VPN technology considerations based on functional requirements
- High availability considerations
- Identify VPN technology based on configuration output
- Design remote access VPN solutions
- Identify functional components of FlexVPN, IPsec, and Clientless SSL
- VPN technology considerations based on functional requirements
- High availability considerations
- Identify VPN technology based on configuration output
- Identify AnyConnect client requirements
- Clientless SSL browser and client considerations/requirements
- Identify split tunneling requirements
- Describe encryption, hashing, and Next Generation Encryption (NGE)
- Compare and contrast Symmetric and asymmetric key algorithms
- Identify and describe the cryptographic process in VPNs – Diffie-Hellman, IPsec – ESP, AH, IKEv1, IKEv2, hashing algorithms MD5 and SHA, and authentication methods
- Describe PKI components and protection methods
- Describe Elliptic Curve Cryptography (ECC)
- Compare and contrast SSL, DTLS, and TLS