IPsolutions offers the highest quality CCNA Security training.
IPsolutions offers time tested and most updated training program for this certification. Our training program ensures that the student becomes well versed in various concepts and skills related to network security and all the basics and fundamentals are clear so that a strong foundation can be laid for further career enhancement . Our students have maintained the highest success rate since the time of our inception and have been able to develop and polish the skills necessary to manage and troubleshoot the most complex security network confidently.
CCNA – Security or Cisco Certified Network Associate Security is an associate level certification offered by Cisco Systems and is aimed at laying a strong foundation for the network engineers to move higher in their careers related to network security.
This certification is suitable for the job roles of Network Security Specialist or Support Engineer and Security Administrator with a professional work experience of 1 to 3 years.
A CCNA security certified professional is considered to be an expert in handling products and technologies like Cisco routers, Cisco IOS and security management.
The advance curriculum of this certification ensures that the certified engineer is not only able to develop security infrastructure but also able to determine the potential threats and mitigate them accordingly.
This certification is valid or active for a period of three years
Describe confidentiality, integrity, availability (CIA)
Identify common security terms
Describe the BYOD architecture framework
Describe IPsec protocols and delivery modes (IKE, ESP, AH, tunnel mode, transport mode)
Describe hairpinning, split tunneling, always-on, NAT traversal
Describe basic clientless SSL VPN
Describe basic AnyConnect SSL VPN
Implement an IPsec site-to-site VPN with pre-shared key authentication on Cisco routers and ASA firewalls
Verify an IPsec site-to-site VPN
Configure multiple privilege levels
Configure Cisco IOS role-based CLI access
Implement routing update authentication on OSPF
Implement routing update authentication on RIP
Implement routing update authentication on EIGRP
Compare in-band and out-of band
Configure secure network management
Configure and verify security for NTP
Describe RADIUS and TACACS+ technologies
Configure administrative access on a Cisco router using TACACS+
Verify connectivity on a Cisco router to a TACACS+ server
Explain the integration of Active Directory with AAA
Describe authentication and authorization using ACS and ISE
Identify the functions 802.1X components
Explain the function of control plane policing
Identify common network attacks
Describe social engineering
Identify malware
Describe key exchange
Describe hash algorithm
Compare and contrast symmetric and asymmetric encryption
Describe digital signatures, certificates, and PKI
Campus area network (CAN)
Cloud, wide area network (WAN)
Small office/home office (SOHO)
Describe STP attacks
Describe ARP spoofing
Describe MAC spoofing
Describe CAM table (MAC address table) overflows
Describe CDP/LLDP reconnaissance
Describe VLAN hopping
Describe DHCP spoofing
Implement DHCP snooping
Implement Dynamic ARP Inspection
Implement port security
Implement BPDU guard, root guard, loop guard
Verify mitigation procedures
VACL
Implementation of PVLAN
Static NAT
Dynamic NAT
PAT
Verify NAT operations
Zone to zone
Self zone
Configure ASA access management
Configure security access policies
Configure Cisco ASA interface security levels
Configure default Cisco Modular Policy Framework (MPF)
Describe modes of deployment (routed firewall, transparent firewall)
Describe methods of implementing high availability
Describe security contexts
Describe firewall services
Rules/signatures
Detection/signature engines
Trigger actions/responses (drop, reset, block, alert, monitor/log, shun)
Blacklist (static and dynamic)
Anti-virus/anti-malware
Personal firewall/HIPS