Cisco Certified Network Professional Security Exam Questions

所在平台: Udemy

课程主页: https://www.udemy.com/course/cisco-certified-network-professional-security-exam-questions/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:思科认证网络专业安全考试问题总结 课程概述:为了获得 CCNP Security 或 CCIE Security 认证,考生需要通过 350-701 SCOR 考试。本课程旨在准备考生成功应对《实施和操作思科安全核心技术 v1.1(350-701)》的考试。该考试为120分钟,考查考生在实施和管理关键安全技术方面的专业知识,包括网络安全、云安全、内容安全、终端保护与检测、安全网络访问、可视化和强制执行等。 考试大纲: 1. **安全概念(25%)** - 解释针对本地、混合和云环境的常见威胁 - 比较常见安全漏洞 - 描述加密组件 - 比较VPN部署类型和组件 - 描述安全智能的创作、共享和消费 - 解释SDN架构中的API - 解读基础Python脚本 2. **网络安全(20%)** - 比较网络安全解决方案 - 描述网络安全解决方案的部署模型 - 配置和验证网络基础设施安全方法 - 实施分段、访问控制策略和恶意软件保护 - 配置设备和网络访问的AAA - 通过 VPN 配置网络的安全管理 3. **云安全(15%)** - 识别云环境的安全解决方案 - 比较云服务模型的安全责任 - 实施云环境中的应用和数据安全 4. **内容安全(15%)** - 实施流量重定向和捕获方法 - 配置和验证网络和电子邮件安全部署方法 - 配置和验证网络安全功能 5. **终端保护与检测(10%)** - 比较终端保护平台和终端检测与响应解决方案 - 配置终端的防恶意软件保护 - 描述多因素认证的重要性 6. **安全网络访问、可见性和强制执行(15%)** - 描述身份管理和安全网络访问概念 - 配置和验证网络访问控制机制 - 解释数据外泄技术 本课程为考生提供了全面的知识体系,以帮助其理解并掌握通过 350-701 SCOR 考试所需的各类安全技术和实施方案。

课程评论(0条)

课程详情

To obtain your CCNP Security or CCIE Security certification, you need to pass the 350-701 SCOR exam. Implementing and Operating Cisco Security Core Technologies v1.1 (350-701)Exam Description:The 350-701 SCOR exam, associated with CCNP and CCIE Security Certifications, is a 120-minute test that evaluates a candidate's expertise in implementing and managing key security technologies. These include network security, cloud security, content security, endpoint protection and detection, secure network access, visibility, and enforcement. The course, Implementing and Operating Cisco Security Core Technologies, is designed to prepare candidates for success in this exam.Exam Outline:25% - 1.0 Security Concepts1.1 Explain common threats against on-premises, hybrid, and cloud environments1.1.a On-premises threats: viruses, trojans, DoS/DDoS, phishing, rootkits, man-in-the-middle attacks, SQL injection, cross-site scripting, malware1.1.b Cloud threats: data breaches, insecure APIs, DoS/DDoS, compromised credentials1.2 Compare common security vulnerabilitiesSoftware bugs, weak/hardcoded passwords, OWASP top ten, missing encryption ciphers, buffer overflow, path traversal, cross-site scripting/forgery1.3 Describe cryptography componentsHashing, encryption, PKI, SSL, IPsec, NAT-T IPv4 for IPsec, preshared key, certificate-based authorization1.4 Compare VPN deployment types and componentsSite-to-site and remote access VPNs, virtual tunnel interfaces, IPsec, DMVPN, FlexVPN, Cisco Secure Client, high availability1.5 Describe security intelligence authoring, sharing, and consumption1.6 Describe controls against phishing and social engineering attacks1.7 Explain North Bound and South Bound APIs in SDN architecture1.8 Explain Cisco DNA Center APIsFor network provisioning, optimization, monitoring, and troubleshooting1.9 Interpret basic Python scriptsUsed to call Cisco Security appliance APIs20% - 2.0 Network Security2.1 Compare network security solutionsIntrusion prevention and firewall capabilities2.2 Describe deployment models of network security solutionsIncluding architectures for intrusion prevention and firewall capabilities2.3 Describe components, capabilities, and benefits of NetFlow and Flexible NetFlow records2.4 Configure and verify network infrastructure security methods2.4.a Layer 2 methods: VLAN segmentation, Layer 2 and port security, DHCP snooping, ARP inspection, storm control, PVLANs, defense against MAC, ARP, VLAN hopping, STP, DHCP rogue attacks2.4.b Device hardening: control plane, data plane, management plane2.5 Implement segmentation, access control policies, URL filtering, malware protection, and intrusion policies2.6 Implement management options for network security solutionsSingle vs. multi-device manager, in-band vs. out-of-band, cloud vs. on-premises2.7 Configure AAA for device and network accessTACACS+ and RADIUS2.8 Configure secure network management of perimeter security and infrastructure devicesSNMPv3, NetConf, RestConf, APIs, secure syslog, NTP with authentication2.9 Configure and verify site-to-site and remote access VPN2.9.a Site-to-site VPN: Cisco routers and IOS2.9.b Remote access VPN: Cisco AnyConnect Secure Mobility client2.9.c Debug commands: IPsec tunnel establishment and troubleshooting15% - 3.0 Securing the Cloud3.1 Identify security solutions for cloud environmentsPublic, private, hybrid, and community clouds3.2 Compare security responsibility for cloud service modelsPatch management, security assessment3.3 Describe the concept of DevSecOpsCI/CD pipeline, container orchestration, secure software development3.4 Implement application and data security in cloud environments3.5 Identify security capabilities, deployment models, and policy management for securing the cloud3.6 Configure cloud logging and monitoring methodologies3.7 Describe application and workload security concepts15% - 4.0 Content Security4.1 Implement traffic redirection and capture methods for web proxy4.2 Describe web proxy identity and authenticationTransparent user identification4.3 Compare components, capabilities, and benefits of email and web security solutionsOn-premises, hybrid, cloud-based (Cisco Secure Email Gateway, Cisco Secure Web Appliance)4.4 Configure and verify web and email security deployment methodsFor on-premises, hybrid, and remote users4.5 Configure and verify email security featuresSPAM filtering, antimalware filtering, DLP, blocklisting, email encryption4.6 Configure and verify Cisco Umbrella Secure Internet Gateway and web security featuresBlocklisting, URL filtering, malware scanning, TLS decryption4.7 Describe components, capabilities, and benefits of Cisco Umbrella4.8 Configure and verify web security controls on Cisco UmbrellaIdentities, URL content settings, destination lists, reporting10% - 5.0 Endpoint Protection and Detection5.1 Compare Endpoint Protection Platforms (EPP) and Endpoint Detection & Response (EDR) solutions5.2 Configure endpoint antimalware protection using Cisco Secure Endpoint5.3 Configure and verify outbreak control and quarantines5.4 Describe justifications for endpoint-based security5.5 Describe the value of endpoint device management and asset inventory systemsMobile Device Management (MDM)5.6 Describe the uses and importance of multifactor authentication (MFA) strategy5.7 Describe endpoint posture assessment solutions to ensure endpoint security5.8 Explain the importance of an endpoint patching strategy15% - 6.0 Secure Network Access, Visibility, and Enforcement6.1 Describe identity management and secure network access conceptsGuest services, profiling, posture assessment, BYOD6.2 Configure and verify network access control mechanisms802.1X, MAB, WebAuth6.3 Describe network access with CoA (Change of Authorization)6.4 Describe the benefits of device compliance and application control6.5 Explain exfiltration techniquesDNS tunneling, HTTPS, email, FTP/SSH/SCP/SFTP, ICMP, Messenger, IRC, NTP6.6 Describe the benefits of network telemetry6.7 Describe components, capabilities, and benefits of security products and solutions6.7.a Cisco Secure Network Analytics6.7.b Cisco Secure Cloud Analytics6.7.c Cisco pxGrid6.7.d Cisco Umbrella Investigate6.7.e Cisco Cognitive Intelligence6.7.f Cisco Encrypted Traffic Analytics6.7.g Cisco Secure Client Network Visibility Module (NVM)

课程标签

0人关注该课程

主题相关的课程