Courses

Best Courses we offer

  • Home
  • CCNP Security

CCNP Enterprise CCNP Security CCNP-Data Center CCNP-Service Provider CCNP Collaboration

CCNP Security Training


The CCNP Security training will help you to gain the professional security skills required in the position of a Cisco Network Security Engineer who would be responsible for running security in a Cisco network.

80 Hours

Classroom Training

Monday
Tuesday
Wednesday
Thursday
Friday

Sunday


CCNP Security

The CCNP Security training will help you to gain the professional security skills required in the position This course is divided into four chapters. Implementation of Cisco Secure Access Solutions (SISAS), implementation of Cisco Edge Security Network Solutions (SENSS), implementation of Cisco Secure Mobility Solutions (SIMOS) and implementation of Cisco Threat Control Solutions (SITCS).




  1. Implementing and Operating Cisco Security Core Technologies v1.0 (350-701)
    • Security Concepts
      • Explain common threats against on-premises, hybrid, and cloud environments
        • On-premises: viruses, trojans, DoS/DDoS attacks, phishing, rootkits, man-in-the-middle attacks, SQL injection, cross-site scripting, malware
        • Cloud: data breaches, insecure APIs, DoS/DDoS, compromised credentials
      • Compare common security vulnerabilities such as software bugs, weak and/or hardcoded passwords, OWASP top ten, missing encryption ciphers, buffer overflow, path traversal, cross-site scripting/forgery
      • Describe functions of the cryptography components such as hashing, encryption, PKI, SSL, IPsec, NAT-T IPv4 for IPsec, preshared key, and certificate-based authorization
      • Compare site-to-site and remote access VPN deployment types and components such as virtual tunnel interfaces, standards-based IPsec, DMVPN, FlexVPN, and Cisco Secure Client including high availability considerations
      • Describe security intelligence authoring, sharing, and consumption
      • Describe the controls used to protect against phishing and social engineering attacks
      • Explain NorthBound and SouthBound APIs in the SDN architecture
      • Explain Cisco DNACenter APIs for network provisioning, optimization, monitoring, and troubleshooting
      • Interpret basic Python scripts used to call Cisco Security appliances APIs
    • Network Security
      • Compare network security solutions that provide intrusion prevention and firewall capabilities
      • Describe deployment models of network security solutions and architectures that provide intrusion prevention and firewall capabilities
      • Describe the components, capabilities, and benefits of NetFlow and Flexible NetFlow records
      • Configure and verify network infrastructure security methods
        • Layer 2 methods (network segmentation using VLANs; Layer 2 and port security; DHCP snooping; Dynamic ARP inspection; storm control; PVLANs to segregate network traffic; and defenses against MAC, ARP, VLAN hopping, STP, and DHCP rogue attacks)
        • Device hardening of network infrastructure security devices (control plane, data plane, and management plane)
      • Implement segmentation, access control policies, AVC, URL filtering, malware protection, and intrusion policies
      • Implement management options for network security solutions (single vs. multi-device manager, in-band vs. out-of-band, cloud vs. on-premises)
      • Configure AAA for device and network access such as TACACS+ and RADIUS
      • Configure secure network management of perimeter security and infrastructure devices such as SNMPv3, NetConf, RestConf, APIs, secure syslog, and NTP with authentication
      • Configure and verify site-to-site and remote access VPN
        • Site-to-site VPN using Cisco routers and IOS
        • Remote access VPN using Cisco AnyConnect Secure Mobility client
        • Debug commands to view IPsec tunnel establishment and troubleshooting
    • Securing the Cloud
      • Identify security solutions for cloud environments
        • Public, private, hybrid, and community clouds
        • Cloud service models: SaaS, PaaS, IaaS (NIST 800-145)
      • Compare security responsibility for the different cloud service models
        • Patch management in the cloud
        • Security assessment in the cloud
      • Describe the concept of DevSecOps (CI/CD pipeline, container orchestration, and secure software development)
      • Implement application and data security in cloud environments
      • Identify security capabilities, deployment models, and policy management to secure the cloud
      • Configure cloud logging and monitoring methodologies
      • Describe application and workload security concepts
    • Content Security
      • Implement traffic redirection and capture methods for web proxy
      • Describe web proxy identity and authentication including transparent user identification
      • Compare the components, capabilities, and benefits of on-premises, hybrid, and cloud-based email and web solutions (Cisco Secure Email Gateway, Cisco Secure Email Cloud Gateway, and Cisco Secure Web Appliance)
      • Configure and verify web and email security deployment methods to protect on-premises, hybrid, and remote users
      • Configure and verify email security features such as SPAM filtering, anti-malware filtering, DLP, blocklisting, and email encryption
      • Configure and verify Cisco Umbrella Secure Internet Gateway and web security features such as blocklisting, URL filtering, malware scanning, URL categorization, web application filtering, and TLS decryption
      • Describe the components, capabilities, and benefits of Cisco Umbrella
      • Configure and verify web security controls on Cisco Umbrella (identities, URL content settings, destination lists, and reporting)
    • Endpoint Protection and Detection
      • Compare Endpoint Protection Platforms (EPP) and Endpoint Detection & Response (EDR) solutions
      • Configure endpoint anti-malware protection using Cisco Secure Endpoint
      • Configure and verify outbreak control and quarantine to limit infection
      • Describe justifications for endpoint-based security
      • Describe the value of endpoint device management and asset inventory systems such as MDM
      • Describe the uses and importance of a multifactor authentication (MFA) strategy
      • Describe endpoint posture assessments solutions to ensure endpoint security
      • Explain the importance of an endpoint patching strategy
    • Secure Network Access, Visibility, and Enforcement
      • Describe identity management and secure network access concepts such as guest services, profiling, posture assessment, and BYOD
      • Configure and verify network access control mechanisms such as 802.1X, MAB, WebAuth
      • Describe network access with CoA
      • Describe the benefits of device compliance and application control
      • Explain exfiltration techniques (DNS tunneling, HTTPS, email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP)
      • Describe the benefits of network telemetry
      • Describe the components, capabilities, and benefits of these security products and solutions
        • Cisco Secure Network Analytics
        • Cisco Secure Cloud Analytics
        • Cisco pxGrid
        • Cisco Umbrella Investigate
        • Cisco Cognitive Intelligence
        • Cisco Encrypted Traffic Analytics
        • Cisco Secure Client Network Visibility Module (NVM)
  2. Securing Networks with Cisco Firepower v1.0 (300-710)
    • 1.0 Deployment
      • 1.1 Implement NGFW modes
        • 1.1.a Routed mode
        • 1.1.b Transparent mode
      • 1.2 Implement NGIPS modes
        • 1.2.a Passive
        • 1.2.b Inline
      • 1.3 Implement high availability options
        • 1.3.a Link redundancy
        • 1.3.b Active/standby failover
        • 1.3.c Multi-instance
      • 1.4 Describe IRB configurations
    • 2.0 Configuration
      • 2.1 Configure system settings in Cisco Firepower Management Center
      • 2.2 Configure these policies in Cisco Firepower Management Center
        • 2.2.a Access control
        • 2.2.b Intrusion
        • 2.2.c Malware and file
        • 2.2.d DNS
        • 2.2.e Identity
        • 2.2.f SSL
        • 2.2.g Prefilter
      • 2.3 Configure these features using Cisco Firepower Management Center
        • 2.3.a Network discovery
        • 2.3.b Application detectors (Open AppID)
        • 2.3.c Correlation
        • 2.3.d Actions
      • 2.4 Configure objects using Firepower Management Center
        • 2.4.a Object Management
        • 2.4.b Intrusion Rules
      • 2.5 Configure devices using Firepower Management Center
        • 2.5.a Device Management
        • 2.5.b NAT
        • 2.5.c VPN
        • 2.5.d QoS
        • 2.5.e Platform Settings
        • 2.5.f Certificates
    • 3.0 Management and Troubleshooting
      • 3.1 Troubleshoot with FMC CLI and GUI
      • 3.2 Configure dashboards and reporting in FMC
      • 3.3 Troubleshoot using packet capture procedures
    • 4.0 Integration
      • 4.1 Configure Cisco AMP for Networks in Firepower Management Center
      • 4.2 Configure Cisco AMP for Endpoints in Firepower Management Center
      • 4.3 Implement Threat Intelligence Director for third-party security intelligence feeds
      • 4.4 Describe using Cisco Threat Response for security investigations
      • 4.5 Describe Cisco FMC PxGrid Integration with Cisco Identify Services Engine (ISE)
      • 4.6 Describe Rapid Threat Containment (RTC) functionality within Firepower Management Center
  3. Implementing and Configuring Cisco Identity Services Engine v1.0 (300-715)
    • Architecture and Deployment
      • Configure personas
      • Describe deployment options
    • Policy Enforcement
      • Configure native AD and LDAP
      • Describe identity store options
        • LDAP
        • AD
        • PKI
        • OTP
        • Smart Card
        • Local
      • Configure wired/wireless 802.1X network access
      • Configure 802.1X phasing deployment
        • Monitor mode
        • Low impact
        • Closed mode
      • Configure network access devices
      • Implement MAB
      • Configure Cisco TrustSec
      • Configure policies including authentication and authorization profiles
    • Web Auth and Guest Services
      • Configure web authentication
      • Configure guest access services
      • Configure sponsor and guest portals
    • Profiler
      • Implement profiler services
      • Implement probes
      • Implement CoA
      • Configure endpoint identity management
    • BYOD
      • Describe Cisco BYOD functionality
        • Use cases and requirements
        • Solution components
        • BYOD flow
      • Configure BYOD device on-boarding using internal CA with Cisco switches and Cisco wireless LAN controllers
      • Configure certificates for BYOD
      • Configure blacklist/whitelist
    • Endpoint Compliance
      • Describe endpoint compliance, posture services, and client provisioning
      • Configure posture conditions and policy, and client provisioning
      • Configure the compliance module
      • Configure Cisco ISE posture agents and operational modes
      • Describe supplicant, supplicant options, authenticator, and server
    • Network Access Device Administration
      • Compare AAA protocols
      • Configure TACACS+ device administration and command authorization
  4. Securing the Web with Cisco Web Security Appliance v1.0 (300-725)
    • Cisco WSA Features
      • Describe Cisco WSA features and functionality
        • Proxy service
        • Cognitive Threat Analytics
        • Data loss prevention service
        • Integrated L4TM service
        • Management tools
      • Describe WSA solutions
        • Cisco Advanced Web Security Reporting
        • Cisco Content Security Management Appliance
      • Integrate Cisco WSA with Splunk
      • Integrate Cisco WSA with Cisco ISE
      • Troubleshoot data security and external data loss using log files
    • Configuration
      • Perform initial configuration tasks on Cisco WSA
      • Configure an Acceptable Use Policy
      • Configure and verify web proxy features
        • Explicit proxy functionality
        • Proxy access logs using CLI
        • Active directory proxy authentication
      • Configure a referrer header to filter web categories
    • Proxy Services
      • Compare proxy terms
        • Explicit proxy vs. transparent proxy
        • Upstream proxy vs. downstream proxy
      • Describe tune caching behavior for safety or performance
      • Describe the functions of a Proxy Auto-Configuration (PAC) file
      • Describe the SOCKS protocol and the SOCKS proxy services
    • Authentication
      • Describe authentication features
        • Supported authentication protocols
        • Authentication realms
        • Supported authentication surrogates supported
        • Bypassing authentication of problematic agents
        • Authentication logs for accounting records
        • Re-authentication
      • Configure traffic redirection to Cisco WSA using explicit forward proxy mode
      • Describe the FTP proxy authentication
      • Troubleshoot authentication issues
    • Decryption Policies to Control HTTPS Traffic
      • Describe SSL and TLS inspection
      • Configure HTTPS capabilities
        • HTTPS decryption policies
        • HTTPS proxy function
        • ACL tags for HTTPS inspection
        • HTTPS proxy and verify TLS/SSL decryption
        • Certificate types used for HTTPS decryption
      • Configure self-signed and intermediate certificates within SSL/TLS transactions
    • Differentiated Traffic Access Policies and Identification Profiles
      • Describe access policies
      • Describe identification profiles and authentication
      • Troubleshoot using access logs
    • Acceptable Use Control
      • Configure URL filtering
      • Configure the dynamic content analysis engine
      • Configure time-based & traffic volume acceptable use policies and end user notifications
      • Configure web application visibility and control (Office 365, third-party feeds)
      • Create a corporate global acceptable use policy
      • Implement policy trace tool to verify corporate global acceptable use policy
      • Configure WSA to inspect archive file types
    • Malware Defense
      • Describe anti-malware scanning
      • Configure file reputation filtering and file analysis
      • Describe Advanced Malware Protection (AMP)
      • Describe integration with Cognitive Threat Analytics
    • Reporting and Tracking Web Transactions
      • Configure and analyze web tracking reports
      • Configure Cisco Advanced Web Security Reporting ( AWSR)
        • Basic web usage
        • Custom filters
      • Troubleshoot connectivity issues
  5. Implementing Secure Solutions with Virtual Private Networks v1.0 (300-730)
    • Site-to-site Virtual Private Networks on Routers and Firewalls
      • Describe GETVPN
      • Implement DMVPN (hub-and-spoke and spoke-to-spoke on both IPv4 & IPv6)
      • Implement FlexVPN (hub-and-spoke on both IPv4 & IPv6) using local AAA
    • Remote access VPNs
      • Implement AnyConnect IKEv2 VPNs on ASA and routers
      • Implement AnyConnect SSLVPN on ASA and routers
      • Implement Clientless SSLVPN on ASA and routers
      • Implement Flex VPN on routers
    • Troubleshooting using ASDM and CLI
      • Troubleshoot IPsec
      • Troubleshoot DMVPN
      • Troubleshoot FlexVPN
      • Troubleshoot AnyConnect IKEv2 and SSL VPNs on ASA and routers
      • Troubleshoot Clientless SSLVPN on ASA and routers
    • Secure Communications Architectures
      • Identify functional components of GETVPN, FlexVPN, DMVPN, and IPsec for site-to-site VPN solutions
      • Identify functional components of FlexVPN, IPsec, and Clientless SSL for remote access VPN solutions
      • Identify VPN technology based on configuration output for site-to-site VPN solutions
      • Identify VPN technology based on configuration output for remote access VPN solutions
      • Identify split tunneling requirements for remote access VPN solutions
      • Design site-to-site VPN solutions
        • VPN technology considerations based on functional requirements
        • High availability considerations
      • Design remote access VPN solutions
        • VPN technology considerations based on functional requirements
        • High availability considerations
        • Clientless SSL browser and client considerations and requirements
      • Identify Elliptic Curve Cryptography (ECC) algorithms
  6. Automating and Programming Cisco Security Solutions v1.0 (300-735)
    • Network Programmability Foundation
      • Utilize common version control operations with git (add, clone, push, commit, diff, branching, and merging conflict)
      • Describe characteristics of API styles (REST and RPC)
      • Describe the challenges encountered and patterns used when consuming APIs synchronously and asynchronously
      • Interpret Python scripts containing data types, functions, classes, conditions, and looping
      • Describe the benefits of Python virtual environments
      • Explain the benefits of using network configuration tools such as Ansible and Puppet for automating security platforms
    • Network Security
      • Describe the event streaming capabilities of Firepower Management Center eStreamer API
      • Describe the capabilities and components of these APIs
        • Firepower (Firepower Management Center and Firepower Device Management)
        • ISE
        • pxGRID
        • Stealthwatch Enterprise
      • Implement firewall objects, rules, intrusion policies, and access policies using Firepower Management Center API
      • Implement firewall objects, rules, intrusion policies, and access policies using Firepower Threat Defense API (also known as Firepower Device Manager API)
      • Construct a Python script for pxGrid to retrieve information such as endpoint device type, network policy and security telemetry
      • Construct API requests using Stealthwatch API
        • perform configuration modifications
        • generate rich reports
    • Advanced Threat & Endpoint Security
      • Describe the capabilities and components of these APIs
        • Umbrella Investigate APIs
        • AMP for endpoints APIs
        • ThreatGRID API
      • Construct an Umbrella Investigate API request
      • Construct AMP for endpoints API requests for event, computer, and policies
      • Construct ThreatGRID APIs request for search, sample feeds, IoC feeds, and threat disposition
    • Cloud, Web, and Email Security
      • Describe the capabilities and components of these APIs
        • Umbrella reporting and enforcement APIs
        • Stealthwatch cloud APIs
        • Cisco Security Management Appliance APIs
      • Construct Stealthwatch cloud API request for reporting
      • Construct an Umbrella Reporting and Enforcement API request
      • Construct a report using Cisco Security Management Appliance API request (email and web)

Your message has been sent. Thank you!