Book description
A complete study guide for the new CCNA Security certification exam
In keeping with its status as the leading publisher of CCNA study guides, Sybex introduces the complete guide to the new CCNA security exam. The CCNA Security certification is the first step towards Cisco's new Cisco Certified Security Professional (CCSP) and Cisco Certified Internetworking Engineer-Security.
With a foreword by CCNA networking authority Todd Lammle, CCNA Security Study Guide fully covers every exam objective. The companion CD includes the Sybex Test Engine, flashcards, and a PDF of the book.
The CCNA Security certification is the first step toward Cisco's new CCSP and Cisco Certified Internetworking Engineer-Security
Describes security threats facing modern network infrastructures and how to mitigate threats to Cisco routers and networks using ACLs
Explores implementing AAA on Cisco routers and secure network management and reporting
Shows how to implement Cisco IOS firewall and IPS feature sets plus site-to-site VPNs using SDM
Foreword by Todd Lammle bestselling study guide author
CD includes the Sybex Test Engine, flashcards, and the book in PDF format
With hands-on labs and end-of-chapter reviews, CCNA Security Study Guide thoroughly prepares you for certification.
Table of contents
- Copyright
- Acknowledgments
- About The Author
- About the Contributor
- Introduction
- Assessment Test
- 1. Introduction to Network Security
-
2. Creating the Secure Network
- 2.1. Creating a Security Policy
- 2.2. Maintaining Operational Security
- 2.3. Evolution of Threats
- 2.4. The Cisco Self-Defending Network
- 2.5. Summary
- 2.6. Exam Essentials
- 2.7. Written Lab
- 2.8. Review Questions
- 2.9. Answers to Review Questions
- 2.10. Answers to Written Lab
-
3. Securing Administrative Access
- 3.1. Securing Administrative Access
- 3.2. Cisco ISR Routers
- 3.3. Cisco Security Device Manager (SDM)
- 3.4. Summary
- 3.5. Exam Essentials
- 3.6. Written Lab
- 3.7. Hands-on Lab
- 3.8. Review Questions
- 3.9. Answers to Review Questions
- 3.10. Answers to Written Lab
-
4. Configuring AAA Services
- 4.1. Defining AAA Services
- 4.2. Defining RADIUS and TACACS+
-
4.3. Configuring AAA Using Cisco Secure ACS
- 4.3.1. Introduction to Cisco Secure ACS for Windows
- 4.3.2. Preparation and Installation of Cisco Secure ACS for Windows
- 4.4. Configuring Authentication
- 4.5. Configuring Authorization
- 4.6. Configuring Accounting
- 4.7. Configuring TACACS+
- 4.8. Troubleshooting AAA on Cisco Routers
- 4.9. Summary
- 4.10. Exam Essentials
- 4.11. Written Lab
- 4.12. Hands-on Labs
- 4.13. Review Questions
- 4.14. Answers to Review Questions
- 4.15. Answers to Written Lab
-
5. Securing Your Router
- 5.1. Using the Command-Line Interface to Lock Down the Router
- 5.2. Understanding One-Step Lockdown
- 5.3. Securing Management and Logging
- 5.4. Summary
- 5.5. Exam Essentials
- 5.6. Written Lab
- 5.7. Hands-on Lab
- 5.8. Review Questions
- 5.9. Answers to Review Questions
- 5.10. Answers to Written Lab
-
6. Layer 2 Security
- 6.1. Basic Protection of Layer 2 Switches
- 6.2. How to Prevent VLAN Attacks
- 6.3. Mitigating STP Attacks
- 6.4. Mitigating DHCP Server Spoofing
- 6.5. Protecting against CAM Table Attacks
- 6.6. Preventing MAC Spoofing
- 6.7. Configuring Port Security
- 6.8. Configuring SPAN, RSPAN, and Storm Control
- 6.9. Summary
- 6.10. Exam Essentials
- 6.11. Written Lab
- 6.12. Hands-on Labs
- 6.13. Review Questions
- 6.14. Answers to Review Questions
- 6.15. Answers to Written Lab
-
7. Implementing Cisco IOS Firewall
- 7.1. Firewall Basics
- 7.2. Access Control Lists
- 7.3. The Cisco IOS Firewall
- 7.4. Configure Cisco IOS Firewall with SDM
-
7.5. Verify Cisco IOS Firewall Configurations
-
7.5.1. Basic Firewall
- 7.5.1.1. Inspection Commands for the Basic Firewall
- 7.5.1.2. HTTP Commands for the Basic Firewall
- 7.5.1.3. Inside Interface and Outbound ACL Commands for the Basic Firewall
- 7.5.1.4. Outside Interface and Inbound ACL Commands for the Basic Firewall
- 7.5.1.5. Access Lists Commands for the Basic Firewall
- 7.5.1.6. Putting It All Together
- 7.5.2. Advanced Firewall
-
7.5.1. Basic Firewall
- 7.6. Implementing Zone-Based Firewall
- 7.7. Summary
- 7.8. Exam Essentials
- 7.9. Written Lab
- 7.10. Hands-on Lab
- 7.11. Review Questions
- 7.12. Answers to Review Questions
- 7.13. Answers to Written Lab
-
8. Implementing Cisco IOS Intrusion Prevention
- 8.1. IDS and IPS
- 8.2. Configuring IOS IPS
- 8.3. Summary
- 8.4. Exam Essentials
- 8.5. Written Lab
- 8.6. Hands-on Lab
- 8.7. Review Questions
- 8.8. Answers to Review Questions
- 8.9. Answers to Written Lab
- 9. Understanding Cryptographic Solutions
-
10. Using Digital Signatures
- 10.1. Hashing Overview
- 10.2. Features of Hash Functions and Values
- 10.3. Hash Message Authentication Code
- 10.4. Hashing Algorithms
- 10.5. Digital Signatures
- 10.6. Summary
- 10.7. Exam Essentials
- 10.8. Written Lab
- 10.9. Hands-on Lab
- 10.10. Review Questions
- 10.11. Answers to Review Questions
- 10.12. Answers to Written Lab
-
11. Using Asymmetric Encryption and PKI
- 11.1. Asymmetric Encryption
- 11.2. Asymmetric Encryption Algorithms
- 11.3. Public Key Infrastructure
-
11.4. Digital Certificates
- 11.4.1. Certificate Enrollment
-
11.4.2. Digital Certificates Exposed
- 11.4.2.1. Certificate Information
- 11.4.2.2. Version Field
- 11.4.2.3. Serial Number Field
- 11.4.2.4. Signature Algorithm and Signature Hash Algorithm Fields
- 11.4.2.5. Issuer Field
- 11.4.2.6. Validity Fields
- 11.4.2.7. Subject Field
- 11.4.2.8. Public Key Field
- 11.4.2.9. Extension Fields
- 11.4.2.10. Certification Path
- 11.4.3. Certificate Usage
- 11.4.4. Certificate Limitations
- 11.5. PKI Standards
- 11.6. Summary
- 11.7. Exam Essentials
- 11.8. Written Lab
- 11.9. Hands-on Lab
- 11.10. Review Questions
- 11.11. Answers to Review Questions
- 11.12. Answers to Written Lab
-
12. Implementing Site-to-Site IPsec VPN Solutions
- 12.1. Introduction to Virtual Private Networks and IPsec
- 12.2. VPN Operation
- 12.3. Cisco Easy VPN
- 12.4. Summary
- 12.5. Exam Essentials
- 12.6. Written Lab
- 12.7. Hands-on Lab
- 12.8. Review Questions
- 12.9. Answers to Review Questions
- 12.10. Answers to Written Lab
- A. Securing Voice Solutions
-
B. Introduction to SAN Security
- B.1. Introduction to Storage Area Networks
- B.2. Benefits of a SAN
- B.3. SAN Transport Methods
-
B.4. Elements of a SAN
- B.4.1. Logical Unit Numbers (LUNs) and LUN Masking
- B.4.2. Fibre Channel Zoning
- B.4.3. World Wide Names
- B.4.4. VSANs
- B.4.5. Port Authentication Protocols
- B.4.6. SAN Security Essentials
- B.4.7. SAN Management Security Risks
- B.4.8. Fabric and Target Access Security Risks
- B.4.9. Secure SAN Protocols
- B.4.10. Secure IP Storage Access
- B.4.11. Secure Data
- B.5. Cisco MDS 9000 Features
- C. Exploring Endpoint Security
- D. Capstone Exercise
- E. About the Companion CD
- Glossary
Product information
- Title: CCNA® Security Study Guide
- Author(s):
- Release date: March 2010
- Publisher(s): Sybex
- ISBN: 9780470527672
You might also like
book
CCNA Security Official Exam Certification Guide (Exam 640-553)
CCNA Security Official Exam Certification Guide Master the IINS 640-553 exam with this official study guide …
book
CCNA Security Exam Cram (Exam IINS 640-553)
In this book you’ll learn how to: Build a secure network using security controls Secure network …
book
CCDA Official Exam Certification Guide, Third Edition
CCDA Official Exam Certification Guide Third Edition Master all 640-863 exam topics with the official study …
book
CompTIA Advanced Security Practitioner (CASP) CAS-002 Cert Guide
Trust the best selling Authorized Cert Guide series from Pearson IT Certification to help you learn, …