Introduction |
|
xxii | |
Digital Study Guide |
|
xxvi | |
Day 31: Common Security Principles |
|
1 | (4) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
1 | (1) |
|
|
1 | (1) |
|
Confidentiality, Integrity, and Availability (CIA) |
|
|
1 | (1) |
|
|
1 | (1) |
|
Common Network Security Terms |
|
|
2 | (1) |
|
|
2 | (2) |
|
|
4 | (1) |
Day 30: Common Security Threats |
|
5 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
5 | (1) |
|
|
5 | (1) |
|
|
5 | (2) |
|
|
5 | (1) |
|
|
5 | (1) |
|
|
6 | (1) |
|
|
7 | (1) |
|
|
7 | (1) |
|
|
8 | (1) |
|
|
8 | (1) |
|
|
9 | (1) |
|
|
10 | (1) |
Day 29: Cryptographic Technologies |
|
11 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
11 | (1) |
|
|
11 | (1) |
|
|
11 | (1) |
|
Key Exchange and Management |
|
|
11 | (1) |
|
|
12 | (3) |
|
Well-known Hash Functions |
|
|
12 | (1) |
|
Authentication Using Hashing |
|
|
13 | (1) |
|
Hashing in Cisco Products |
|
|
14 | (1) |
|
Symmetric and Asymmetric Encryption |
|
|
15 | (3) |
|
|
15 | (1) |
|
Symmetric Encryption Algorithms |
|
|
15 | (1) |
|
Asymmetric Encryption Algorithms |
|
|
16 | (2) |
|
Digital Signatures and RSA Certificates |
|
|
18 | (1) |
|
|
19 | (2) |
Day 28: PKI and Network Security Architectures |
|
21 | (14) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
21 | (1) |
|
|
21 | (1) |
|
Public Key Infrastructure |
|
|
21 | (7) |
|
PKI Terminology, Components, and Classes of Certificates |
|
|
22 | (1) |
|
|
23 | (1) |
|
|
24 | (1) |
|
|
25 | (2) |
|
Enrollment and Revocation |
|
|
27 | (1) |
|
Network Architectures and Topologies |
|
|
28 | (5) |
|
Campus-Area Network (CAN) |
|
|
28 | (1) |
|
|
29 | (2) |
|
|
31 | (1) |
|
Cloud and Virtual Networks |
|
|
31 | (2) |
|
|
33 | (2) |
Day 27: Secure Management Systems |
|
35 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
35 | (1) |
|
|
35 | (1) |
|
In-band and Out-of-band Management |
|
|
35 | (1) |
|
Management Plane Security |
|
|
36 | (3) |
|
|
36 | (2) |
|
|
38 | (1) |
|
|
38 | (1) |
|
Simple Network Management Protocol (SNMP) |
|
|
39 | (3) |
|
Network Time Protocol (NTP) |
|
|
42 | (1) |
|
Secure Copy Protocol (SCP) |
|
|
43 | (1) |
|
|
44 | (1) |
Day 26: AAA Concepts |
|
45 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
45 | (1) |
|
|
45 | (1) |
|
|
45 | (1) |
|
|
46 | (2) |
|
|
46 | (1) |
|
|
47 | (1) |
|
|
48 | (2) |
|
|
49 | (1) |
|
|
49 | (1) |
|
|
50 | (1) |
Day 25: TACACS+ and RADIUS Implementation |
|
51 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
51 | (1) |
|
|
51 | (1) |
|
Server-based AAA Authentication |
|
|
51 | (2) |
|
Server-based AAA Authorization |
|
|
53 | (1) |
|
Server-based AAA Accounting |
|
|
54 | (1) |
|
Server-based AAA Verification and Troubleshooting |
|
|
55 | (3) |
|
|
58 | (3) |
Day 24: 802.1X |
|
61 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
61 | (1) |
|
|
61 | (1) |
|
|
61 | (4) |
|
|
61 | (2) |
|
Configuration and Verification |
|
|
63 | (2) |
|
|
65 | (2) |
Day 23: BYOD |
|
67 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
67 | (1) |
|
|
67 | (1) |
|
|
67 | (2) |
|
|
69 | (3) |
|
|
72 | (1) |
Day 22: IPsec Technologies |
|
73 | (12) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
73 | (3) |
|
|
76 | (5) |
|
|
77 | (2) |
|
|
77 | (1) |
|
|
78 | (1) |
|
IPsec Modes of Operations |
|
|
78 | (1) |
|
|
79 | (1) |
|
|
79 | (1) |
|
|
80 | (1) |
|
|
80 | (1) |
|
Suite B Cryptographic Standard |
|
|
81 | (1) |
|
|
81 | (3) |
|
|
82 | (1) |
|
|
83 | (1) |
|
|
83 | (1) |
|
|
84 | (1) |
Day 21: Clientless Remote-Access VPN |
|
85 | (14) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
85 | (1) |
|
|
85 | (1) |
|
Clientless SSL VPN Concepts |
|
|
85 | (2) |
|
Clientless SSL VPN Configuration |
|
|
87 | (8) |
|
Task 1: Launch Clientless SSL VPN Wizard from ASDM |
|
|
88 | (1) |
|
Task 2: Configure the SSL VPN URL and Interface |
|
|
88 | (1) |
|
Task 3: Configure User Authentication |
|
|
89 | (1) |
|
Task 4: Configure User Group Policy |
|
|
90 | (1) |
|
Task 5: Configure Bookmarks |
|
|
90 | (5) |
|
Clientless SSL VPN Verification |
|
|
95 | (2) |
|
|
97 | (2) |
Day 20: AnyConnect Remote Access VPN |
|
99 | (14) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
99 | (1) |
|
|
99 | (1) |
|
AnyConnect SSL VPN Concepts |
|
|
99 | (2) |
|
SSL VPN Server Authentication |
|
|
100 | (1) |
|
SSL VPN Client Authentication |
|
|
100 | (1) |
|
SSL VPN Client IP Address Assignment |
|
|
100 | (1) |
|
AnyConnect SSL VPN Configuration and Verification |
|
|
101 | (10) |
|
Phase 1: Configure Cisco ASA for Cisco AnyConnect |
|
|
101 | (5) |
|
Task 1: Connection Profile Identification |
|
|
101 | (1) |
|
Task 2: VPN Protocols and Device Certificate |
|
|
102 | (1) |
|
|
102 | (1) |
|
Task 4: Authentication Methods |
|
|
103 | (1) |
|
Task 5: Client Address Assignment |
|
|
103 | (1) |
|
Task 6: Network Name Resolution Servers |
|
|
104 | (1) |
|
Task 7: Network Address Translation Exemption |
|
|
104 | (1) |
|
Task 8: AnyConnect Client Deployment and Summary |
|
|
105 | (1) |
|
Phase 2: Configure the Cisco AnyConnect VPN Client |
|
|
106 | (2) |
|
Phase 3: Verify AnyConnect Configuration and Connection |
|
|
108 | (3) |
|
|
111 | (2) |
Day 19: Site-to-Site VPN |
|
113 | (18) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
113 | (1) |
|
|
113 | (1) |
|
|
113 | (1) |
|
Cisco IOS CLI-based Site-to-Site IPsec VPN |
|
|
114 | (8) |
|
|
115 | (4) |
|
Step 1: ACL Compatibility |
|
|
115 | (1) |
|
Step 2: IKE Phase 1—ISAKMP Policy |
|
|
115 | (2) |
|
Step 3: IKE Phase 2—IPsec Transform Set |
|
|
117 | (1) |
|
|
117 | (1) |
|
|
118 | (1) |
|
|
119 | (3) |
|
Cisco ASA Site-to-Site IPsec VPN |
|
|
122 | (6) |
|
|
123 | (2) |
|
Step 1: Launch the ASDM Site-to-Site VPN Wizard |
|
|
123 | (1) |
|
Step 2: Peer Device Identification |
|
|
123 | (1) |
|
Step 3: Traffic to Protect |
|
|
124 | (1) |
|
|
124 | (1) |
|
|
125 | (1) |
|
|
125 | (3) |
|
|
128 | (3) |
Day 18: VPN Advanced Topics |
|
131 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
131 | (1) |
|
|
131 | (1) |
|
Hairpinning and Client U-Turn |
|
|
131 | (1) |
|
|
132 | (2) |
|
|
134 | (1) |
|
|
134 | (1) |
|
Endpoint Posture Assessment |
|
|
135 | (1) |
|
|
136 | (1) |
Day 17: Secure Device Access |
|
137 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
137 | (1) |
|
|
137 | (1) |
|
Cisco IOS Authorization with Privilege Levels |
|
|
137 | (1) |
|
Authorization with Role-Based CLI |
|
|
138 | (1) |
|
Cisco IOS Resilient Configuration |
|
|
139 | (1) |
|
Cisco IOS File Authenticity |
|
|
140 | (2) |
|
|
142 | (1) |
Day 16: Secure Routing Protocols |
|
143 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
143 | (1) |
|
|
143 | (1) |
|
Routing Protocol Authentication |
|
|
143 | (1) |
|
|
144 | (2) |
|
MD5 Authentication with Key Chain |
|
|
144 | (1) |
|
MD5 Authentication Without Key Chain |
|
|
145 | (1) |
|
|
146 | (2) |
|
|
148 | (1) |
Day 15: Control Plane Security |
|
149 | (4) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
149 | (1) |
|
|
149 | (1) |
|
Functional Planes of the Network |
|
|
149 | (1) |
|
|
150 | (1) |
|
If Control Plane Protection |
|
|
151 | (1) |
|
|
152 | (1) |
Day 14: Layer 2 Infrastructure Security |
|
153 | (8) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
153 | (1) |
|
|
153 | (1) |
|
|
153 | (6) |
|
|
153 | (2) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
157 | (1) |
|
|
157 | (1) |
|
|
157 | (1) |
|
|
158 | (1) |
|
|
159 | (2) |
Day 13: Layer 2 Protocols Security |
|
161 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
161 | (1) |
|
|
161 | (1) |
|
|
161 | (2) |
|
|
163 | (1) |
|
|
164 | (1) |
|
|
165 | (2) |
|
|
167 | (2) |
|
|
167 | (1) |
|
|
168 | (1) |
|
|
168 | (1) |
|
|
168 | (1) |
|
|
169 | (2) |
Day 12: VLAN Security |
|
171 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
171 | (1) |
|
|
171 | (1) |
|
|
171 | (3) |
|
|
174 | (1) |
|
|
175 | (3) |
|
|
176 | (1) |
|
|
177 | (1) |
|
|
178 | (2) |
|
|
180 | (1) |
Day 11: Firewall Technologies |
|
181 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
181 | (1) |
|
|
181 | (1) |
|
|
181 | (2) |
|
|
183 | (2) |
|
Proxy and Application Firewalls |
|
|
185 | (2) |
|
|
187 | (1) |
|
Next-Generation Firewalls |
|
|
188 | (1) |
|
|
189 | (1) |
|
|
189 | (2) |
Day 10: Cisco ASA NAT Implementation |
|
191 | (18) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
191 | (1) |
|
|
191 | (1) |
|
|
191 | (2) |
|
|
193 | (2) |
|
|
195 | (3) |
|
|
198 | (3) |
|
|
201 | (2) |
|
|
203 | (5) |
|
|
208 | (1) |
Day 9: Cisco IOS Zone-Based Policy Firewall |
|
209 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
210 | (1) |
|
|
211 | (2) |
|
|
212 | (1) |
|
|
212 | (1) |
|
|
213 | (1) |
|
Default Policies and Traffic Flows |
|
|
213 | (1) |
|
ZPF Configuration and Verification |
|
|
214 | (4) |
|
|
214 | (1) |
|
|
215 | (1) |
|
Configuration and Verification |
|
|
216 | (2) |
|
|
218 | (1) |
Day 8: Cisco ASA Firewall Concepts |
|
219 | (8) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
219 | (1) |
|
|
219 | (1) |
|
|
219 | (2) |
|
ASA Features and Services |
|
|
221 | (1) |
|
|
222 | (1) |
|
|
223 | (2) |
|
|
225 | (1) |
|
|
226 | (1) |
Day 7: ASA Firewall Configuration |
|
227 | (18) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
227 | (1) |
|
|
227 | (1) |
|
ASA Default Configuration |
|
|
227 | (2) |
|
|
229 | (1) |
|
|
230 | (2) |
|
|
232 | (2) |
|
ASA Objects and Object Groups |
|
|
234 | (6) |
|
ASA Modular Policy Framework |
|
|
240 | (4) |
|
|
244 | (1) |
Day 6: IDS/IPS Concepts |
|
245 | (8) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
245 | (1) |
|
|
245 | (1) |
|
|
245 | (2) |
|
Host-based vs. Network-based IPS |
|
|
247 | (1) |
|
|
248 | (1) |
|
|
249 | (1) |
|
|
250 | (1) |
|
|
251 | (2) |
Day 5: IDS/IPS Technologies |
|
253 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
253 | (1) |
|
|
253 | (1) |
|
|
253 | (1) |
|
|
254 | (1) |
|
|
255 | (1) |
|
|
256 | (1) |
|
Next-Generation IPS with FirePOWER |
|
|
256 | (1) |
|
|
257 | (2) |
Day 4: Email-based Threat Mitigation |
|
259 | (10) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
259 | (1) |
|
|
259 | (1) |
|
|
259 | (1) |
|
|
260 | (3) |
|
|
263 | (2) |
|
|
263 | (1) |
|
Fighting Viruses and Malware |
|
|
264 | (1) |
|
Email Data Loss Prevention |
|
|
264 | (1) |
|
Advanced Malware Protection |
|
|
264 | (1) |
|
|
265 | (2) |
|
|
265 | (1) |
|
|
266 | (1) |
|
|
267 | (2) |
Day 3: Web-based Threat Mitigation |
|
269 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
269 | (1) |
|
|
269 | (1) |
|
|
269 | (3) |
|
|
272 | (2) |
|
|
274 | (1) |
Day 2: Endpoint Protection |
|
275 | (6) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
275 | (1) |
|
|
275 | (1) |
|
Endpoint Security Overview |
|
|
275 | (1) |
|
|
276 | (1) |
|
|
276 | (1) |
|
|
277 | (1) |
|
|
278 | (1) |
|
|
279 | (1) |
|
|
280 | (1) |
Day 1: CCNA Security Skills Review and Practice |
|
281 | (18) |
|
CCNA Security 210-260 IINS Exam Topics |
|
|
281 | (1) |
|
|
281 | (1) |
|
CCNA Security Skills Practice |
|
|
281 | (8) |
|
|
281 | (1) |
|
|
281 | (1) |
|
|
282 | (1) |
|
|
283 | (1) |
|
|
283 | (6) |
|
Step 1: Cable the Network As Shown in the Topology |
|
|
283 | (1) |
|
Step 2: Configure Initial Settings for R1_BRANCH |
|
|
283 | (1) |
|
Step 3: Configure Initial Settings for HQ_SW |
|
|
284 | (1) |
|
Step 4: Configure Initial Settings for HQ-ASA |
|
|
285 | (1) |
|
Step 5: Configure Clientless SSL VPN |
|
|
286 | (1) |
|
Step 6: Configure Site-to-Site IPsec VPN |
|
|
286 | (2) |
|
Step 7: Configure a Zone-Based Policy Firewall |
|
|
288 | (1) |
|
Answers to CCNA Security Skills Practice |
|
|
289 | (10) |
|
Step 1: Cable the Network As Shown in the Topology |
|
|
289 | (1) |
|
Step 2: Configure Initial Settings for R1_BRANCH |
|
|
289 | (1) |
|
Step 3: Configure Initial Settings for HQ_SW |
|
|
290 | (1) |
|
Step 4: Configure Initial Settings for HQ-ASA |
|
|
291 | (2) |
|
Step 5: Configure Clientless SSL VPN |
|
|
293 | (1) |
|
Step 6: Configure Site-to-Site IPsec VPN |
|
|
294 | (1) |
|
Step 7: Configure a Zone-Based Policy Firewall |
|
|
295 | (4) |
Exam Day |
|
299 | (2) |
|
What You Need for the Exam |
|
|
299 | (1) |
|
What You Should Receive After Completion |
|
|
299 | (1) |
|
|
300 | (1) |
Post-Exam Information |
|
301 | (2) |
|
Receiving Your Certificate |
|
|
301 | (1) |
|
U.S. Government Recognition |
|
|
301 | (1) |
|
Examining Certification Options |
|
|
302 | (1) |
|
|
302 | (1) |
|
|
302 | (1) |
Index |
|
303 | |