收藏 分销(赏)

CCIESecurityLabExamTopicsv4.0.doc

上传人:xrp****65 文档编号:7664046 上传时间:2025-01-11 格式:DOC 页数:4 大小:92KB
下载 相关 举报
CCIESecurityLabExamTopicsv4.0.doc_第1页
第1页 / 共4页
CCIESecurityLabExamTopicsv4.0.doc_第2页
第2页 / 共4页
点击查看更多>>
资源描述
CCIE Security Lab Exam Topics v4.0 System Hardening and Availability Routing plane security features (e.g. protocol authentication, route filtering) Control Plane Policing Control Plane Protection and Management Plane Protection Broadcast control and switchport security Additional CPU protection mechanisms (e.g. options drop, logging interval) Disable unnecessary services Control device access (e.g. Telnet, HTTP, SSH, Privilege levels) Device services (e.g. SNMP, Syslog, NTP) Transit Traffic Control and Congestion Management Threat Identification and Mitigation Identify and protect against fragmentation attacks Identify and protect against malicious IP option usage Identify and protect against network reconnaissance attacks Identify and protect against IP spoofing attacks Identify and protect against MAC spoofing attacks Identify and protect against ARP spoofing attacks Identify and protect against Denial of Service (DoS) attacks Identify and protect against Distributed Denial of Service (DDoS) attacks Identify and protect against Man-in-the-Middle (MiM) attacks Identify and protect against port redirection attacks Identify and protect against DHCP attacks Identify and protect against DNS attacks Identify and protect against MAC Flooding attacks Identify and protect against VLAN hopping attacks Identify and protect against various Layer2 and Layer3 attacks NBAR NetFlow Capture and utilize packet captures Intrusion Prevention and Content Security IPS 4200 Series Sensor Appliance (a) Initialize the Sensor Appliance (b) Sensor Appliance management (c) Virtual Sensors on the Sensor Appliance (d) Implementing security policies (e) Promiscuous and inline monitoring on the Sensor Appliance (f) Tune signatures on the Sensor Appliance (g) Custom signatures on the Sensor Appliance (h) Actions on the Sensor Appliance (i) Signature engines on the Sensor Appliance (j) Use IDM/IME to  the Sensor Appliance (k) Event action overrides/filters on the Sensor Appliance (l) Event monitoring on the Sensor Appliance VACL/SPAN & RSPAN on Cisco switches WSA (a) Implementing WCCP (b) Active Dir Integration (c)Custom Categories (d) HTTPS Config (e) Services Configuration (Web Reputation) (f) Configuring Proxy By-pass Lists (g) Web proxy modes (h) App visibility and control Identity Management Identity Based Authentication/Authorization/Accounting (a) Cisco Router/Appliance AAA (b) RADIUS (c)TACACS+ Device Admin (Cisco IOS Routers, ASA, ACS5.x) Network Access (TrustSec Model) (a) Authorization Results for Network Access (ISE) (b) 802.1X (ISE) (c)VSAs (ASA / Cisco IOS / ISE) (d) Proxy-Authentication (ISE/ASA/Cisco IOS) Cisco Identity Services Engine (ISE) (a) Profiling Configuration (Probes) (b) Guest Services (c)Posture Assessment (d) Client Provisioning (CPP) (e) Configuring AD Integration/Identity Sources Perimeter Security and Services Cisco ASA Firewall (a) Basic firewall Initialization (b) Device management (c ) Address translation (nat, global, static) (d) Access Control Lists (e) IP routing/Route Tracking (f) Object groups (g) VLANs (h) Configuring Etherchannel (i) High Availability and Redundancy (j) Layer 2 Transparent Firewall (k) Security contexts (virtual firewall) (l) Modular Policy Framework (j) Identity Firewall Services (k) Configuring ASA with ASDM (l) Context-aware services (m) IPS capabilities (n) QoS capabilities Cisco IOS Zone Based Firewall (a) Network, Secure Group and User Based Policy (b) Performance Tuning (c) Network, Protocol and Application Inspection Perimeter Security Services (a) Cisco IOS QoS and Packet marking techniques (b) Traffic Filtering using Access-Lists (c)Cisco IOS NAT (d) uRPF (e) PAM - Port to Application Mapping (f) Policy Routing and Route Maps Confidentiality and Secure Access IKE (V1/V2) IPsec LAN-to-LAN (Cisco IOS/ASA) Dynamic Multipoint VPN (DMVPN) FlexVPN Group Encrypted Transport (GET) VPN Remote Access VPN (a) Easy VPN Server (Cisco IOS/ASA) (b) VPN Client 5.X (c)Clientless WebVPN (d)  AnyConnect VPN (e) EasyVPN Remote (f) SSL VPN Gateway VPN High Availability QoS for VPN VRF-aware VPN MacSec Digital Certificates (Enrollment and Policy Matching) Wireless Access (a) EAP methods (b) WPA/WPA-2 (c)WIPS - 4 -
展开阅读全文

开通  VIP会员、SVIP会员  优惠大
下载10份以上建议开通VIP会员
下载20份以上建议开通SVIP会员


开通VIP      成为共赢上传
相似文档                                   自信AI助手自信AI助手

当前位置:首页 > 教育专区 > 其他

移动网页_全站_页脚广告1

关于我们      便捷服务       自信AI       AI导航        抽奖活动

©2010-2025 宁波自信网络信息技术有限公司  版权所有

客服电话:4009-655-100  投诉/维权电话:18658249818

gongan.png浙公网安备33021202000488号   

icp.png浙ICP备2021020529号-1  |  浙B2-20240490  

关注我们 :微信公众号    抖音    微博    LOFTER 

客服