思科认证CCIE安全笔试考试大纲_第1页
思科认证CCIE安全笔试考试大纲_第2页
思科认证CCIE安全笔试考试大纲_第3页
思科认证CCIE安全笔试考试大纲_第4页
思科认证CCIE安全笔试考试大纲_第5页
已阅读5页,还剩6页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

思科认证CCIE平安笔试考试大纲思科CCIE平安笔试考试(400-251)v5.0,考试时间为2小时,考试题目90-110道,验证专业人士是否具备阐释,设计,施行,操作和故障排除的复合网络平安技能及解决方案。考生必须理解网络平安所需,以及网络平安部件之间如何互相操作,并将其翻译成设备配置语言。闭卷考试,考场中不允许带任何参考资料。1.1Describe,implement,andtroubleshootHAfeaturesonCiscoASAandCiscoFirePOWERThreatDefense(FTD)1.2Describe,implement,andtroubleshootclusteringonCiscoASAandCiscoFTD1.3Describe,implement,troubleshoot,andsecureroutingprotocolsonCiscoASAandCiscoFTD1.4Describe,implement,andtroubleshootdifferentdeploymentmodessuchasrouted,transparent,single,andmulticontextonCiscoASAandCiscoFTD1.5Describe,implement,andtroubleshootfirewallfeaturessuchasNAT(v4,v6),PAT,applicationinspection,trafficzones,policy-basedrouting,trafficredirectiontoservicemodules,andidentityfirewallonCiscoASAandCiscoFTD1.6Describe,implement,andtroubleshootIOSsecurityfeaturessuchasZone-BasedFirewall(ZBF),applicationlayerinspection,NAT(v4,v6),PATandTCPinterceptonCiscoIOS/IOS-XE1.7Describe,implement,optimize,andtroubleshootpoliciesandrulesfortrafficcontrolonCiscoASA,CiscoFirePOWERandCiscoFTD1.8Describe,implement,andtroubleshootCiscoFirepowerManagementCenter(FMC)featuressuchasalerting,logging,andreporting1.9Describe,implement,andtroubleshootcorrelationandremediationrulesonCiscoFMC1.10Describe,implement,andtroubleshootCiscoFirePOWERandCiscoFTDdeploymentsuchasin-line,passive,andTAPmodes1.11Describe,implement,andtroubleshootNextGenerationFirewall(NGFW)featuressuchasSSLinspection,useridentity,geolocation,andAVC(Firepowerappliance)1.12Describe,detect,andmitigatemontypesofattackssuchasDoS/DDoS,evasiontechniques,spoofing,man-in-the-middle,andbot2.1CompareandcontrastdifferentAMPsolutionsincludingpublicandprivateclouddeploymentmodels2.2Describe,implement,andtroubleshootAMPforworks,AMPforendpoints,andAMPforcontentsecurity(CWS,ESA,andWSA)2.3Detect,analyze,andmitigatemalwareincidents2.4DescribethebenefitofthreatintelligenceprovidedbyAMPThreatGRID2.5PerformpacketcaptureandanalysisusingWireshark,tcpdump,SPAN,andRSPAN2.6Describe,implement,andtroubleshootwebfiltering,useridentification,andApplicationVisibilityandControl(AVC)2.7Describe,implement,andtroubleshootmailpolicies,DLP,emailquarantines,andSenderBaseonESA2.8Describe,implement,andtroubleshootSMTPauthenticationsuchasSPFandDKIMonESA2.9Describe,implement,andtroubleshootSMTPencryptiononESA2.10CompareandcontrastdifferentLDAPquerytypesonESA2.11Describe,implement,andtroubleshootWCCPredirection2.12CompareandcontrastdifferentproxymethodssuchasSOCKS,Autoproxy/WPAD,andtransparent2.13Describe,implement,andtroubleshootSdecryptionandDLP2.14Describe,implement,andtroubleshootCWSconnectorsonCiscoIOSrouters,CiscoASA,CiscoAnyConnect,andWSA2.15DescribethesecuritybenefitsofleveragingtheOpenDNSsolution.2.16Describe,implement,andtroubleshootSMAforcentralizedcontentsecuritymanagement2.17DescribethesecuritybenefitsofleveragingLancope3.1CompareandcontrastcryptographicandhashalgorithmssuchasAES,DES,3DES,ECC,SHA,andMD53.2CompareandcontrastsecurityprotocolssuchasISAKMP/IKEv1,IKEv2,SSL,TLS/DTLS,ESP,AH,SAP,andMKA3.3Describe,implementcandtroubleshootremoteaessusingtechnologiessuchasFLEX,SSL-betweenCiscofirewalls,routers,andendhosts3.4Describe,implement,andtroubleshoottheCiscoIOSCAforauthentication3.5Describe,implement,andtroubleshootclientlessSSLtechnologieswithDAPandsmarttunnelsonCiscoASAandCiscoFTD3.6Describe,implement,andtroubleshootsite-to-sitessuchasGET,DMandIPsec3.7Describe,implement,andtroubleshootuplinkanddownlinkMACsec(802.1AE)3.8Describe,implement,andtroubleshoothighavailabilityusingCiscoASAclusteringanddual-hubDMdeployments3.9DescribethefunctionsandsecurityimplicationsofcryptographicprotocolssuchasAES,DES,3DES,ECC,SHA,MD5,ISAKMP/IKEv1,IKEv2,SSL,TLS/DTLS,ESP,AH,SAP,MKA,RSA,SCEP/EST,GDOI,X.509,WPA,WPA2,WEP,andTKIP3.10Describethesecuritybenefitsofworksegmentationandisolation3.11Describe,implement,andtroubleshootVRF-LiteandVRF-Aware3.12Describe,implement,andtroubleshootmicrosegmentationwithTrustSecusingSGTandSXP3.13Describe,implement,andtroubleshootinfrastructuresegmentationmethodssuchasVLAN,PVLAN,andGRE3.14DescribethefunctionalityofCiscoVSGusedtosecurevirtualenvironments3.15DescribethesecuritybenefitsofdatacentersegmentationusingACI,E,VXLAN,andNVGRE4.1Describe,implement,andtroubleshootvariouspersonasofISEinamultinodedeployment4.2Describe,implement,andtroubleshootworkaessdevice(NAD),ISE,andACSconfigurationforAAA4.3Describe,implement,andtroubleshootAAAforadministrativeaesstoCiscoworkdevicesusingISEandACS4.4Describe,implement,verify,andtroubleshootAAAforworkaesswith802.1XandMABusingISE.4.5Describe,implement,verify,andtroubleshootcut-throughproxy/auth-proxyusingISEastheAAAserver4.6Describe,implement,verify,andtroubleshootguestlifecyclemanagementusingISEandCiscoworkinfrastructure4.7Describe,implement,verify,andtroubleshootBYODon-boardingandworkaessflowswithaninternalorexternalCA4.8Describe,implement,verify,andtroubleshootISEandACSintegrationwithexternalidentitysourcessuchasLDAP,AD,andexternalRADIUS4.9DescribeISEandACSintegrationwithexternalidentitysourcessuchasRADIUSToken,RSASecurID,andSAML4.10Describe,implement,verify,andtroubleshootprovisioningofAnyConnectwithISEandASA4.11Describe,implement,verify,andtroubleshootpostureassessmentwithISE4.12Describe,implement,verify,andtroubleshootendpointprofilingusingISEandCiscoworkinfrastructureincludingdevicesensor4.13Describe,implement,verify,andtroubleshootintegrationofMDMwithISE4.14Describe,implement,verify,andtroubleshootcertificatebasedauthenticationusingISE4.15Describe,implement,verify,andtroubleshootauthenticationmethodssuchasEAPChainingandMachineAessRestriction(MAR)4.16DescribethefunctionsandsecurityimplicationsofAAAprotocolssuchasRADIUS,TACACS+,LDAP/LDAPS,EAP(EAP-PEAP,EAP-TLS,EAP-TTLS,EAP-FAST,EAP-TEAP,EAP-MD5,EAP-GTC),PAP,CHAP,andMS-CHAPv24.17Describe,implement,andtroubleshootidentitymappingonASA,ISE,WSAandFirePOWER4.18Describe,implement,andtroubleshootpxGridbetweensecuritydevicessuchasWSA,ISE,andCiscoFMC5.1IdentifymonattackssuchasSmurf,VLANhopping,andSYNfulknock,andtheirmitigationtechniques5.2Describe,implement,andtroubleshootdevicehardeningtechniquesandcontrolplaneprotectionmethods,suchasCoPPandIPSourcerouting.5.3Describe,implement,andtroubleshootmanagementplaneprotectiontechniquessuchasCPUandmemorythresholdingandsecuringdeviceaess5.4Describe,implement,andtroubleshootdataplaneprotectiontechniquessuchasiACLs,uRPF,QoS,andRTBH5.5Describe,implement,andtroubleshootIPv4/v6routingprotocolssecurity5.6Describe,implement,andtroubleshootLayer2securitytechniquessuchasDAI,IPDT,STPsecurity,portsecurity,DHCPsnooping,andVACL5.7Describe,implement,andtroubleshootwirelesssecuritytechnologiessuchasWPA,WPA2,TKIP,andAES5.8DescribewirelesssecurityconceptssuchasFLEXConnect,wIPS,ANCHOR,RogueAP,andManagementFrameProtection(MFP)5.9Describe,implement,andtroubleshootmonitoringprotocolssuchasNETFLOW/IPFIX,SNMP,SYSLOG,RMON,NSEL,andeSTREAMER5.10DescribethefunctionsandsecurityimplicationsofapplicationprotocolssuchasSSH,TELNET,TFTP,/S,SCP,SFTP/FTP,PGP,DNS/DNSSEC,NTP,andDHCP5.11DescribethefunctionsandsecurityimplicationsofworkprotocolssuchasVTP,802.1Q,TCP/UDP,CDP,LACP/PAgP,BGP,EIGRP,OSPF/OSPFv3,RIP/RIPng,IGMP/CGMP,PIM,IPv6,andWCCP5.12DescribethebenefitsofvirtualizingsecurityfunctionsinthedatacenterusingASAv,WSAv,ESAv,andNGIPSv5.13DescribethesecurityprinciplesofACIsuchasobjectmodels,endpointgroups,policyenforcement,applicationworkprofiles,andcontracts5.14DescribethenorthboundandsouthboundAPIsofSDNcontrollerssuchasAPIC-EM5.15Identifyandimplementsecurityfeaturestoplywithorganizationalsecuritypolicies,procedures,andstandardssuchasBCP38,ISO27001,RFC2827,andPCI-DSS5.16Describeandidentifykeythreatstodifferentplacesinthework(campus,datacenter,core,edge)asdescribedinCiscoSAFE5.17ValidateworksecuritydesignforadherencetoCiscoSAFEremendedpractices5.18InterpretbasicscriptsthatcanretrieveandsenddatausingRESTfulAPIcallsinscriptinglanguagessuchasPython5.19DescribeCiscoDigitalNetworkArchitecture(DNA)principlesandponents.6.1Cloud6.1.aCompareandcontrastClouddeploymentmodels6.1.a[i]Infrastructure,platform,andsoftwareservices(XaaS)6.1.a[ii]Performanceandreliability6.1.a[iii]Securityandprivacy6.1.a[iv]Scalabilityandinteroperability6.1.bDescribeCloudimplementat

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论