本站已运行

攻城狮论坛

作者: 华尔思_小号
查看: 899|回复: 3

主题标签Tag

more +今日重磅推荐Recommend No.1

所有IT类厂商认证考试题库下载所有IT类厂商认证考试题库下载

more +随机图赏Gallery

【新盟教育】2023最新华为HCIA全套视频合集【网工基础全覆盖】---国sir公开课合集【新盟教育】2023最新华为HCIA全套视频合集【网工基础全覆盖】---国sir公开课合集
【新盟教育】网工小白必看的!2023最新版华为认证HCIA Datacom零基础全套实战课【新盟教育】网工小白必看的!2023最新版华为认证HCIA Datacom零基础全套实战课
原创_超融合自动化运维工具cvTools原创_超融合自动化运维工具cvTools
重量级~~30多套JAVA就业班全套 视频教程(请尽快下载,链接失效后不补)重量级~~30多套JAVA就业班全套 视频教程(请尽快下载,链接失效后不补)
链接已失效【超过几百G】EVE 国内和国外镜像 全有了 百度群分享链接已失效【超过几百G】EVE 国内和国外镜像 全有了 百度群分享
某linux大佬,积累多年的电子书(约300本)某linux大佬,积累多年的电子书(约300本)
乾颐堂现任明教教主Python完整版乾颐堂现任明教教主Python完整版
乾颐堂 教主技术进化论 2018-2019年 最新31-50期合集视频(各种最新技术杂谈视频)乾颐堂 教主技术进化论 2018-2019年 最新31-50期合集视频(各种最新技术杂谈视频)
Python学习视频 0起点视频 入门到项目实战篇 Python3.5.2视频教程 共847集 能学102天Python学习视频 0起点视频 入门到项目实战篇 Python3.5.2视频教程 共847集 能学102天
约21套Python视频合集 核心基础视频教程(共310G,已压缩)约21套Python视频合集 核心基础视频教程(共310G,已压缩)
最新20180811录制 IT爱好者-清风羽毛 - 网络安全IPSec VPN实验指南视频教程最新20180811录制 IT爱好者-清风羽毛 - 网络安全IPSec VPN实验指南视频教程
最新20180807录制EVE开机自启动虚拟路由器并桥接物理网卡充当思科路由器最新20180807录制EVE开机自启动虚拟路由器并桥接物理网卡充当思科路由器

[新闻] CCIE安全 LAB考试升级说明 ccie安全认证5.0来了

[复制链接]
查看: 899|回复: 3
开通VIP 免金币+免回帖+批量下载+无广告
本帖最后由 宅男女神 于 2016-9-13 11:29 编辑
$ _( T0 R2 G  J! e4 Y$ @
3 o' T5 i- K( X  u思科官网消息, CCIE安全LAB考试将于2017年1月31日升级,新的考试版本号为 Lab Examv5.0 ; C. ^# `# @8 N3 M8 j! F0 L
思科CCIE安全实验考试v5.0,考试时间为8个小时,需要考生在给定的场景中计划,设计,执行,操作并故障排除复合网络安全完成动手实验考试。故障排除的知识是一项重要的技能,在实验考试中考生需要诊断并解决网络问题。
1 I2 [( W$ b- ]8 K9 O1 X( q8 h1 Z5 @% Q9 W+ G$ P
7 \% m, \( M7 k. {6 o, f  j+ o
CCIE安全v5.0 将笔试及实验考试考纲合二为一,并明确指出了每项考试主题的权重。" O& N5 N! M, l: R0 z3 Y# O. q: V
/ \3 Q& Q5 P; Z, Q0 F7 n! m
统一版的考纲
' G- x$ l% Z7 K  V$ N1 J; ]. x! u) y! R! D
% h' }  y3 O! A% J! G8 mCCIE安全实验考试v5.0统一版的考纲. v. S! f9 q( v: |( P# e

; V6 j, U# ]3 I实验考试格式
% g+ S! O6 r9 H5 n9 G! N1 j$ r: h0 f# {
实验考试时间为8个小时,由3个考试模块组成,在考试中需要完成以下:
" A6 h5 G6 c) Z/ [$ Z$ j6 D ) v% P' u7 h8 {  B7 q3 S
Module 1:故障排除单元(2小时)1 l" L; j5 a8 p* J
- q8 M+ K, ^( j5 v9 B, n4 L
故障排除单元中的题目之间相互独立。每道题目的解决方法也与其他题目的不尽相同。故障排除单元中的拓扑与配置单元中的拓扑不尽相同。
  r, q$ J/ G6 j: k% t( z3 s0 z+ @
) e, @6 Z: S' F故障排除单元的时间为两个小时;然而,考生可以从配置单元中借30分钟来答题。换而言之,考生可以额外使用30分钟来解决故障排除单元或配置单元中的问题。
1 x0 Y* o" Q! R2 Z9 Z
4 U  p7 U% g3 m4 g. u4 u6 [Module2:诊断单元(1小时)
. I% w' x) E  Z) Z0 g( T! q) F& d2 o9 I, T. ]9 Z: x
全新整段单元考生在没有设备访问的情况下,被提供一系列的文档,代表一种与真实工作场景相同的写照:一个网络工程师可能会在某个调查过程的某一点中遇到的场景。诊断单元的主要目标是验证考生是否具备正确诊断网络问题的技能。这些技能包括:
. O7 C. _* d/ M$ m
  • 分析4 ]' G+ k0 O/ P% A

- w2 g& Y" x- m4 M
  • 关联:查阅多种文档资源(例如电子邮件回复组,网络拓扑图,控制台输出,日志,甚至是流量捕捉)- a, n" w2 E" _
3 d' m1 q( J4 q' S* b
这些考核内容是整个故障排除技能中的自身的部分。由于题目的格式的显著不同,他们被分别设计在不同实验单元中。在故障排除单元,考试需要完成故障排除并再真实的设备上解决网络安全问题
3 a: Y& a- M4 z" V; |; k1 ? 1 d; h8 A  b, H3 a) w3 ?5 ?
在Diagnostic module(诊断单元)中,考生需要在预先定义的选项间做出决策:/ l: N! o5 S  @
  • 出现网络问题的根本原因是什么?
    & u/ |. g" I: ?; j+ J

5 Q/ d: S: ~& W8 |4 A* s( s3 g
  • 网络问题出现在图表中的哪个位置?
  • 哪些关键信息可以帮助确认根本原因?
  • 缺乏哪些能够帮助确认根本原因的信息?
    2 l# @! a: G% R" q+ u; f6 U

: n' a# c8 {7 G2 s) k0 ]* sModule 3:配置单元(5个小时)
; Y/ r/ P! K, k/ X0 _. i5 Z1 x& v4 I# j# N, g4 w" f* l
配置单元会提供一套设施,与实际的网络非常接近,能够提供在不同层面的网络中不同的节点上的各种的安全组成元件。虽然配置单元的主要部分是基于思科安全设备的虚拟实例,你可能也会被要求在物理设备上工作。在这个单元刚开始时,考生可以预览整个单元,并决定是否按照顺序答题。这完全取决于考生的舒适度以及整个场景和问题的关联度。
+ f& @) U# R+ f4 {
5 _0 w9 J8 |' \9 L( z注意
6 H: p  b" f. }0 o# l' Y: 考生必须按顺序完成每个单元,不允许在单元之间来回答题。0 l$ Y7 A( t* j; S/ Q& W) s

/ t& W: `* c, M. z当考生在答故障排除单元中的题目时,可以选择从配置单元的5个小时答题时间中借30分钟来答题。这样考生完成配置单元的总时间将缩短为4.5个小时。
' Y" j: s5 f: W2 N7 O  L$ g" V
: W- u' T! @+ A: u9 o为了保证整个考试时间为8个小时。可选的30分钟,考生可以决定使用在故障排除单元中,系统会自动从配置单元的时间中减去。
% A- o" z: r" P; M, F
0 I( A( B0 a) ]: _当考生在处理故障排除单元的问题时,若超过两小时时,基于网页的系统会跳出一个提示信息。系统会提问考生是否希望继续在故障排除单元中答题,在进入到下一个单元之前加上额外的30分钟,或者停止在故障排除单元的答题,跳转到下一个单元中。
, p  |1 H. H( {( V5 } : G% {4 _1 [1 j
考试通过标准
1 K2 a: _- x- w( M" F* a9 n! ]0 A5 G- \
为了通过实验考试,考生必须同时满足以下两个条件:
1 i: e) k* a% b7 A7 I
  • 高于每个单元的最低分数" `! ^8 @# ]8 n7 [
7 s2 o/ \! |" D2 S: }4 T
  • 总成绩高于整个考试的最低分数0 |+ s1 a- k$ d0 B2 |
( o+ R/ Z* u* }, H) T" o3 Z
设定这两项考试通过标准的原因是为了防止考生没有通过或绕过某个单元的考题,但总分却达到及格线的情况发生。例如,诊断单元。
* k3 X& }5 ~5 n! k3 s8 m4 r5 H
( a* V4 v+ a9 l- p+ S: N; X) D各个单元中的每个考题的得分情况都会告知考生。请注意只有当考生完成了考题的所有要求并满足了特定条件才能得分。任何考题都不会出现部分得分的情况。
2 A5 h2 d1 x8 t1 l! @ + ]9 f6 ^" n1 O8 A, o

' _+ F" C. \" o6 o8 z考试分数1 I- M6 e1 G0 u

* b/ ~  C! F1 B$ f/ l考生通常在48小时内就能够在网上查看实验考试分数(需要登录)。考试结果包含Pass/Fail以及failing scorereports,在report中会显示出对考生有用的,但需要额外学习并准备的内容。
+ v) U" Z/ T) k/ A) ~& r2 R: ] % g8 q& F9 O+ V$ `
实验考试结果申诉% E/ i3 O3 }1 X' ~
重阅卷将由另一位考官将考生的配置重新上传到机架上,重现考试并对整个测试重新评分。重阅卷适用于路由和交换,ServiceProvider考试。
, |. I! @& |: S' ^0 p/ C4 | # d+ ~) O" Y. r( w/ G
重评分将由另一位考官验证考生的答题以及从考生的考试中保持的任何可应用的system-generated debugdata。重评分适用于任何考试。
* L0 R: D0 y1 M ; E. P& M4 l; G: ]
考试费用
- T8 B4 H5 d- P% V. G. `7 @$ D3 c2 _# O; c$ G
实验考试费用/ [2 ~1 u& a- A1 O- V6 a
用不包括差旅以及住宿费。考试费用可能会由于汇率以及当地的税务(VAT,GST)产生不同。考生需要自行负责完成全部的支付交易费用。考试费用会产生浮动,以完成付款时的汇率为准。& z. D6 d7 j+ \# S( ]

# m7 Z( ~4 F' X8 [( V1 @, Q考试环境
8 B/ j* i. z. c2 }' s9 Q# v% O7 E8 }7 ^: ?& s
考试期间
/ r, ^  A/ c* a- z4 `. N+ mCisco documentation
1 C2 W% T% p$ P8 v: T- x可供考生参考,然而更多的共同协议和技术可以被假定。) P( m% B+ m  I" j% k8 g* P2 z( U8 B
Documentation
7 d9 i7 U. J2 ^- y/ ?& a% b8 a只能使用索引进行导航,搜索功能无法使用。
: P" e9 Z" g+ {# |外部的参考资料不允许带入实验考试考场。在考试期间你需要向考官汇报任何可疑的设备问题。考试结束时不允许做任何改动。- j# o; d, O# W
+ v( u. V  M" i3 O
) X, i  E' f  f2 W8 d) z, z" f& {8 {
CCIE安全考试(400-251)考试大纲2 b" S/ n; ?0 L+ K
* Y2 }5 Q+ n; _6 u+ z8 O
考试介绍:7 a# a+ Q0 L6 P1 X

, \& d+ Z2 U  i1 x" u
' Q/ e; B, o! N. G+ e+ U! i- ~CCIE安全v5.0 将笔试及实验考试考纲合二为一,并明确指出了每项考试主题的权重。' Y6 u$ y6 m9 _1 k
; A6 r' I0 ~# s2 V6 J
思科CCIE安全笔试考试(400-251)v5.0,考试时间为2小时,考试题目90-110道,验证专业人士是否具备阐释,设计,实施,操作和故障排除的复合网络安全技能及解决方案。考生必须理解网络安全所需,以及网络安全部件之间如何互相操作,并将其翻译成设备配置语言。闭卷考试,考场中不允许带任何参考资料。2 Q/ ?" k" n) ?% i0 U7 l8 Y, {
% o% c/ Z3 H# {/ a6 L: H* s* z8 A- I- s* n
思科CCIE安全实验考试v5.0,考试时间为8个小时,需要考生在给定的场景中计划,设计,执行,操作并故障排除复合网络安全完成动手实验考试。故障排除的知识是一项重要的技能,在实验考试中考生需要诊断并解决网络问题。
6 U! }9 k( `8 x
5 I; s% |  h. z6 W6 v4 D! d下列考纲列出了CCIE安全考试中可能出现的考试内容。但是,其他相关要点也可能会出现在考试中。下面的大纲可能会在未提前通知的情况下发生改变,这是为了更好地反映考试内容及更加透明化。
$ P3 x' t# V2 O" V% g# B6 ^ # H/ X$ }+ @3 k5 c- n
5 G+ _& g# M3 n

# Y8 W- t8 N( d7 v3 h# j附: CCIE安全5.0考试大纲
8 A! l4 n4 L$ Y8 N
( a, r  D/ U! P' Q8 H
& q" O9 X# _; j1 r8 R8 J

1 E4 u2 [1 V# x- M# W+ `+ B6 W) |
5 U# Q) R, u! w% T7 P1 x1.0 Perimeter Security and Intrusion Prevention8 P  M: y, c& y4 l1 B

# |& D8 s- s) T) w! q5 R/ f
0 N8 r7 z4 Z/ D' V2 ]

) m0 C6 c# {" w  R) y4 M& K4 s0 K/ N- b: }' M/ Y
1.1 Describe, implement, and troubleshoot HA features on CiscoASA and Cisco FirePOWER Threat Defense (FTD)
7 F; }9 g/ p- H; O2 p# C1.2 Describe, implement, and troubleshoot clustering on CiscoASA and Cisco FTD8 ?6 }  J. S5 W( Q- A
1.3 Describe, implement, troubleshoot, and secure routingprotocols on Cisco ASA and Cisco FTD
4 ~6 d2 V2 L, R1.4 Describe, implement, and troubleshoot different deploymentmodes such as routed, transparent, single, and multicontext onCisco ASA and Cisco FTD
9 O) Z3 N9 s/ c  y. G: H' Z9 Q1.5 Describe, implement, and troubleshoot firewall features suchas NAT (v4,v6), PAT, application inspection, traffic zones,policy-based routing,  traffic redirection toservice modules, and identity firewall on Cisco ASA and CiscoFTD
6 d8 b( Y  z& v4 e& {1.6 Describe, implement, and troubleshoot IOS security featuressuch as Zone-Based Firewall (ZBF), application layer inspection,NAT (v4,v6), PAT and  TCP intercept on CiscoIOS/IOS-XE8 x% v5 D% p; U: D0 Q
1.7 Describe, implement, optimize, and troubleshoot policies andrules for traffic control on Cisco ASA, Cisco FirePOWER and CiscoFTD
& z3 M' i1 f7 a2 D9 f* I1.8 Describe, implement, and troubleshoot Cisco FirepowerManagement Center (FMC) features such as alerting, logging, andreporting& }" g7 j+ x) p2 r  i
1.9 Describe, implement, and troubleshoot correlation andremediation rules on Cisco FMC
! q3 v$ U# C$ p( m1.10 Describe, implement, and troubleshoot Cisco FirePOWER andCisco FTD deployment such as in-line, passive, and TAP modes' l* v7 ]1 G& P% Y
1.11 Describe, implement, and troubleshoot Next GenerationFirewall (NGFW) features such as SSL inspection, user identity,geolocation, and AVC  (Firepower appliance): O5 B. @' l3 ~) s, @
1.12 Describe, detect, and mitigate common types of attacks suchas DoS/DDoS, evasion techniques, spoofing, man-in-the-middle, andbotnet& o) P2 z- u0 G# A2 W1 @7 e6 f
2.0 Advanced Threat Protection and Content Security
+ |1 l% `9 w# o' H0 h$ ~* o, u2 g* e$ g4 z. ?& u

2 v) F0 t" U  T7 f" s

1 S' J9 j" c$ X6 f7 M
+ p" v. I; N" Z, A& I6 I: `2.1 Compare and contrast different AMP solutions includingpublic and private cloud deployment models
5 m+ L2 y- D2 g1 f" i2.2 Describe, implement, and troubleshoot AMP for networks, AMPfor endpoints, and AMP for content security (CWS, ESA, and WSA)
  J4 D& x) z( `( Z1 F- e2.3 Detect, analyze, and mitigate malware incidents1 }/ @' W, J  I7 \2 C! f& c1 |
2.4 Describe the benefit of threat intelligence provided by AMPThreat GRID
2 o2 V. y; @3 l  f, u+ ]2.5 Perform packet capture and analysis using Wireshark,tcpdump, SPAN, and RSPAN
3 t. u: x$ x; J5 ?( g  [% {5 x2.6 Describe, implement, and troubleshoot web filtering, useridentification, and Application Visibility and Control (AVC)
# I" z* S% v: I5 g$ Y7 ^0 n2.7 Describe, implement, and troubleshoot mail policies, DLP,email quarantines, and SenderBase on ESA
% @9 d9 |" L' a: c/ j0 a( t2.8 Describe, implement, and troubleshoot SMTP authenticationsuch as SPF and DKIM on ESA
" D+ z2 Q2 O/ {) ^3 L$ z0 c8 C2.9 Describe, implement, and troubleshoot SMTP encryption onESA: _2 d# Y7 O1 S( W4 p- V# ^
2.10 Compare and contrast different LDAP query types on ESA! O: B3 d* ], n$ B+ R
2.11 Describe, implement, and troubleshoot WCCP redirection5 ]$ ^0 f/ _1 G
2.12 Compare and contrast different proxy methods such as SOCKS,Auto proxy/WPAD, and transparent
; c8 [% j8 ?" z9 q- l2.13 Describe, implement, and troubleshoot HTTPS decryption andDLP. r# \* l3 o( j
2.14 Describe, implement, and troubleshoot CWS connectors onCisco IOS routers, Cisco ASA, Cisco AnyConnect, and WSA
+ {2 [# u) f" @" k9 O, `2.15 Describe the security benefits of leveraging the OpenDNSsolution.
  p( W# ~( ^/ Y/ e/ y7 V2.16 Describe, implement, and troubleshoot SMA for centralizedcontent security management
* I- x  \3 p3 f2.17 Describe the security benefits of leveraging Lancope4 s, E- v& O' ^4 P! x1 T
3.0 Secure Connectivity and Segmentation/ L+ q0 f2 y2 d+ [! s7 D

) P3 t; B, ?: v8 L" [2 [) T, U. d6 ]9 ^  @$ q

1 ]! \0 M% Y& h; w, w/ H) N, R& ]6 m4 g9 `( D0 W4 j) y4 s( D( j" P
3.1 Compare and contrast cryptographic and hash algorithms suchas AES, DES, 3DES, ECC, SHA, and MD53 k3 e3 t5 t' l+ H1 k# {7 j& a4 B
3.2 Compare and contrast security protocols such asISAKMP/IKEv1, IKEv2, SSL, TLS/DTLS, ESP, AH, SAP, and MKA- K) I/ E7 y% |
3.3 Describe, implementc and troubleshoot remote access VPNusing technologies such as FLEXVPN, SSL-VPN between Ciscofirewalls, routers, and end hosts
8 O- F& E5 {+ Z  W; N3.4 Describe, implement, and troubleshoot the Cisco IOS CA forVPN authentication: h( t/ y, b) M& U9 `1 V, e
3.5 Describe, implement, and troubleshoot clientless SSL VPNtechnologies with DAP and smart tunnels on Cisco ASA and CiscoFTD
. h, q* Q) p; e0 R' [3.6 Describe, implement, and troubleshoot site-to-site VPNs suchas GETVPN, DMVPN and IPsec
4 s; A! I* m" r3.7 Describe, implement, and troubleshoot uplink and downlinkMACsec (802.1AE)
! C, [/ F8 K# Y) A3.8 Describe, implement, and troubleshoot VPN high availabilityusing Cisco ASA VPN clustering and dual-hub DMVPN deployments
9 L& m; t" g; q3 d( `3.9 Describe the functions and security implications ofcryptographic protocols such as AES, DES, 3DES, ECC, SHA, MD5,ISAKMP/IKEv1, IKEv2, SSL,  TLS/DTLS, ESP, AH, SAP,MKA, RSA, SCEP/EST, GDOI, X.509, WPA, WPA2, WEP, and TKIP1 T: j6 D* D+ u6 s
3.10 Describe the security benefits of network segmentation andisolation# R. W/ j: b% m* `" j9 r
3.11 Describe, implement, and troubleshoot VRF-Lite andVRF-Aware VPN
( F0 q' Z1 S5 Z( j' |0 ^3.12 Describe, implement, and troubleshoot microsegmentationwith TrustSec using SGT and SXP
3 R$ d7 y5 U5 Q3 _; @( T3.13 Describe, implement, and troubleshoot infrastructuresegmentation methods such as VLAN, PVLAN, and GRE2 `5 U3 }3 T/ G3 G4 R4 w
3.14 Describe the functionality of Cisco VSG used to securevirtual environments
& Z0 u% u# ^- ?1 b3.15 Describe the security benefits of data center segmentationusing ACI, EVPN, VXLAN, and NVGRE/ T/ d5 Y+ L. d  q
4.0 Identity Management, Information Exchange, and AccessControl
$ g% c2 F$ H8 e8 S
) y% x1 d. d6 C" Q) L' Z/ H) L# j( h: V4 w: z
; v1 ~# ]$ e+ p1 t

0 x8 h+ G4 C2 l8 }4.1 Describe, implement, and troubleshoot various personas ofISE in a multinode deployment
; l  ~/ s! d) a; c& `* j, k5 h6 o4.2 Describe, implement, and troubleshoot network access device(NAD), ISE, and ACS configuration for AAA  [" O, ?% c7 d; N6 x" v) Y( B
4.3 Describe, implement, and troubleshoot AAA for administrativeaccess to Cisco network devices using ISE and ACS4 |7 M. b  H" P  ?
4.4 Describe, implement, verify, and troubleshoot AAA fornetwork access with 802.1X and MAB using ISE.
6 r. t2 v/ X# X& R( \4.5 Describe, implement, verify, and troubleshoot cut-throughproxy/auth-proxy using ISE as the AAA server
) \. [2 T; y% F4 X- A4.6 Describe, implement, verify, and troubleshoot guest lifecycle management using ISE and Cisco network infrastructure  z. c8 k$ h! n2 Y1 J
4.7 Describe, implement, verify, and troubleshoot BYODon-boarding and network access flows with an internal or externalCA
5 h+ N) E  O/ q4 ~# C" H0 |7 H7 L4.8 Describe, implement, verify, and troubleshoot ISE and ACSintegration with external identity sources such as LDAP, AD, andexternal RADIUS0 k+ }6 s  d% V
4.9 Describe ISE and ACS integration with external identitysources such as RADIUS Token, RSA SecurID, and SAML& f8 J* u+ k" u# U3 M
4.10 Describe, implement, verify, and troubleshoot provisioningof AnyConnect with ISE and ASA
8 g  D1 }4 L4 y8 D4.11 Describe, implement, verify, and troubleshoot postureassessment with ISE
2 a- v2 n4 @% e+ M$ r3 o9 x4.12 Describe, implement, verify, and troubleshoot endpointprofiling using ISE and Cisco network infrastructure includingdevice sensor
! Y, J; D4 D( s. B% c2 z9 j& x4.13 Describe, implement, verify, and troubleshoot integrationof MDM with ISE, @% X% K+ B; |4 Z8 F+ t
4.14 Describe, implement, verify, and troubleshoot certificatebased authentication using ISE* w8 O- w3 k: c2 S: h, \
4.15 Describe, implement, verify, and troubleshootauthentication methods such as EAP Chaining and Machine AccessRestriction (MAR)
" ^( Q6 a4 [$ c/ f4 v0 C8 e4.16 Describe the functions and security implications of AAAprotocols such as RADIUS, TACACS+, LDAP/LDAPS, EAP (EAP-PEAP,EAP-TLS, EAP-TTLS, EAP-FAST,  EAP-TEAP, EAP- MD5,EAP-GTC), PAP, CHAP, and MS-CHAPv2
$ O( o# p; l; ~1 E2 E% g4.17 Describe, implement, and troubleshoot identity mapping onASA, ISE, WSA and FirePOWER* @3 c9 C3 ^. {5 I& Y
4.18 Describe, implement, and troubleshoot pxGrid betweensecurity devices such as WSA, ISE, and Cisco FMC; Z  M; x; q- z, C
5.0 Infrastructure Security, Virtualization, andAutomation! Y8 y- w: F- C
# r; ~6 U0 R2 [
( W$ k$ g; w1 l! n+ f( ~8 V/ V$ t

! M, }  C  N" w. x) ]. Q" v7 b% ~9 B  q* _4 a8 \0 X0 x* F
5.1 Identify common attacks such as Smurf, VLAN hopping, andSYNful knock, and their mitigation techniques; L  g; C2 r$ E1 p; n
5.2 Describe, implement, and troubleshoot device hardeningtechniques and control plane protection methods, such as CoPP andIP Source routing.
* B0 h: [9 O+ x7 D5.3 Describe, implement, and troubleshoot management planeprotection techniques such as CPU and memory thresholding andsecuring device access3 w/ q" n9 s3 a* A& n
5.4 Describe, implement, and troubleshoot data plane protectiontechniques such as iACLs, uRPF, QoS, and RTBH
$ e9 @# N% B* j( J+ J  v# |5.5 Describe, implement, and troubleshoot IPv4/v6 routingprotocols security) A6 h5 J$ i5 m, V$ e9 [
5.6 Describe, implement, and troubleshoot Layer 2 securitytechniques such as DAI, IPDT, STP security, port security, DHCPsnooping, and VACL8 D6 R) X+ ?; ?' _! R
5.7 Describe, implement, and troubleshoot wireless securitytechnologies such as WPA, WPA2, TKIP, and AES
# z7 r6 L* R; g) [% f# T5.8 Describe wireless security concepts such as FLEX Connect,wIPS, ANCHOR, Rogue AP, and Management Frame Protection (MFP)6 t' `0 I  a( ]
5.9 Describe, implement, and troubleshoot monitoring protocolssuch as NETFLOW/IPFIX, SNMP, SYSLOG, RMON, NSEL, and eSTREAMER
8 R0 A4 z1 Z) C) Q9 ]" V5.10 Describe the functions and security implications ofapplication protocols such as SSH, TELNET, TFTP, HTTP/HTTPS, SCP,SFTP/FTP, PGP, DNS/DNSSEC,  NTP, and DHCP6 D3 V% I4 \% d5 ~; A2 X. E
5.11 Describe the functions and security implications of networkprotocols such as VTP, 802.1Q, TCP/UDP, CDP, LACP/PAgP, BGP, EIGRP,OSPF/OSPFv3,  RIP/RIPng, IGMP/CGMP, PIM, IPv6, andWCCP: s% ]4 Y: F2 {7 e9 K) \
5.12 Describe the benefits of virtualizing security functions inthe data center using ASAv, WSAv, ESAv, and NGIPSv$ @, R! O5 L3 |% @4 S5 o
5.13 Describe the security principles of ACI such as objectmodels, endpoint groups, policy enforcement, application networkprofiles, and contracts4 z( @- r9 c* l& s$ Z' ^5 _5 Y: f
5.14 Describe the northbound and southbound APIs of SDNcontrollers such as APIC-EM2 W, L$ X0 J! ]3 \
5.15 Identify and implement security features to comply withorganizational security policies, procedures, and standards such asBCP 38, ISO 27001, RFC  2827, and PCI-DSS
" N$ A& M. Q. r4 F; s5.16 Describe and identify key threats to different places inthe network (campus, data center, core, edge) as described in CiscoSAFE
" y3 {  R& b2 n0 n1 d2 m5.17 Validate network security design for adherence to CiscoSAFE recommended practices
( l& |5 v1 F. S0 C6 Q2 |5.18 Interpret basic scripts that can retrieve and send datausing RESTful API calls in scripting languages such as Python
- S8 Q2 o# R! ~2 ?! j. g9 Y: n  [5.19 Describe Cisco Digital Network Architecture (DNA)principles and components.
! r& [* g. M6 \6.0 Evolving Technologies
; m7 x  F. x( v$ o! ]% I  s
0 L/ k+ I4 ]# `5 J1 Z6.1 Cloud
) D- G0 O& ?9 |' K# H7 a# V' K2 }

% w/ G/ F# o/ N( V( T
3 I) \' @9 B  W3 c# m" _
  • 6.1.a Compare and contrast Cloud deployment models* H+ D9 B. L& }- M( l3 z" }
    • 6.1.a Infrastructure, platform, and software services(XaaS)
      6 T0 B2 K. Q! }* Y( P/ \" ?
      ; C, I  P7 Q: r9 u: O( z/ W
  • 6.1.a [ii] Performance and reliability
    - C+ p, e3 E  X, f: W

    2 F! [# E8 J8 D

7 E( n$ |, w; D7 a% m5 j
  • 6.1.a [iii] Security and privacy
  • 6.1.a [iv] Scalability and interoperability
  • 6.1.b Describe Cloud implementations and operations
    ' p! N) X& L" F- {9 v2 v4 O
    • 6.1.b Automation and orchestration
      : m  A7 u3 P6 Z9 Z2 _' H
      5 Q; E. D  z* G4 e' b
  • 6.1.b [ii] Workload mobility
  • 6.1.b [iii] Troubleshooting and management
  • 6.1.b [iv] OpenStack components
    ! ^+ Q7 B, k8 L# c+ e& \
    1 g! @! o! q) r! z( ?$ J* z
6.2 Network Programmability (SDN)0 k2 U" w( D$ I6 n# Q9 W$ o3 b0 B' F
  • 6.2.a Describe functional elements of network programmability(SDN) and how they interact
    : ~( z0 m+ Q9 Y3 b2 s
    • 6.2.a Controllers
      3 h* R- O. O; V( L

      , t2 R+ D/ N2 c2 i. {

9 F0 l* _" o/ |' Z  E
  • 6.2.a [ii] APIs
  • 6.2.a [iii] Scripting
  • 6.2.a [iv] Agents
  • 6.2.a [v] Northbound vs. Southbound protocols
  • 6.2.b Describe aspects of virtualization and automation innetwork environments
    , N9 n6 y' y) s% M% |# {% E
    • 6.2.b DevOps methodologies, tools and workflows
      2 x/ S2 x4 u- x1 J0 {$ Y# i6 t# V
      7 t' y3 N7 N! E5 X+ |* F/ U
  • 6.2.b [ii] Network/application function virtualization (NFV,AFV)
  • 6.2.b [iii] Service function chaining
  • 6.2.b [iv] Performance, availability, and scalingconsiderations
    # {8 o3 N8 ?! b5 I$ N% w5 d/ o, m

    7 p& u4 F! s# J4 q
6.3 Internet of Things (IoT)  n3 m7 c$ i. K( `' ~
  • 6.3.a Describe architectural framework and deploymentconsiderations for Internet of Things
    7 f; @; r7 ?$ L% a( i
    • 6.3.a Performance, reliability and scalability
        H6 q( _; X, J8 W! `! G% R
      + K9 G+ [0 l+ e; X" ?9 b
1 g& k" O; E( F+ a' V
  • 6.3.a [ii] Mobility
  • 6.3.a [iii] Security and privacy
  • 6.3.a [iv] Standards and compliance
  • 6.3.a [v] Migration
  • 6.3.a [vi] Environmental impacts on the network
    " {- H. n* Y; l, i) Y0 r$ B

' U3 c* D% p( @( p: H # o  }& U# j# j9 ~+ x
! P% {1 S5 X  C
# H2 W7 H( j5 S$ Q, H* O9 t! ^/ O
参加免费公开课,请您说是由【攻城狮论坛】推荐的。报名收费培训的论坛会员,可享受优惠价格+赠送攻城狮论坛VIP会员。本文转自 华尔思 www.wallslab.net,版权归原作者所有。
CCNA考试 官方正规报名 仅需1500元
回复 论坛版权

使用道具 举报

Rockyw [Lv10 举世无双] 发表于 2016-9-13 12:06:39 | 显示全部楼层
路过了解一下
回复 支持 反对

使用道具 举报

muhu325 [Lv6 略有所成] 发表于 2019-2-23 08:01:38 | 显示全部楼层
攻城狮论坛 每天更新 免费下载 谁来谁知道
回复 支持 反对

使用道具 举报

gentlebrother [Lv8 技术精悍] 发表于 2022-9-15 07:58:18 | 显示全部楼层
知道么? 加2000人思科华为网络技术讨论群2258097 然后私聊群主 可以免费回答学习 工作中遇到的问题
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|无图浏览|手机版|网站地图|攻城狮论坛

GMT+8, 2026-7-20 11:04 , Processed in 0.116623 second(s), 16 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4 © 2001-2013 Comsenz Inc.

Designed by ARTERY.cn