Security Concepts
- Typical threats in on-premises, hybrid and cloud environments
- Comparing vulnerabilities: software flaws, weak passwords, OWASP Top Ten, buffer overflow, path traversal, cross-site scripting
- Cryptography building blocks: hashing, encryption, PKI, TLS, IPsec and certificate-based authorisation
- Comparing VPN types: virtual tunnel interfaces, IPsec, DMVPN, FlexVPN, Cisco Secure Client
- Generating, sharing and using security intelligence
- Protection against phishing and social engineering
- Northbound and southbound APIs in the SDN architecture, Cisco DNA Center APIs
- Reading Python scripts for calls to Cisco security appliances
Network Security
- Comparing intrusion prevention and firewalling solutions
- Deployment models and architectures
- NetFlow and Flexible NetFlow as a security data source
- Segmentation, access policies, AVC, URL filtering, malware protection and intrusion policies
- Management options: single versus multi-device manager, in-band versus out-of-band, cloud versus on-premises
- Configuring AAA with TACACS+ and RADIUS
- Secure management with SNMPv3, NETCONF, RESTCONF, secure syslog and authenticated NTP
- Configuring and verifying site-to-site and remote-access VPN
Securing the Cloud
- Security solutions for cloud environments
- Shared responsibility across the different service models
- DevSecOps: CI/CD pipeline, container orchestration, secure software development
- Application and data security in the cloud
- Logging and monitoring in cloud environments
Content Security
- Redirecting and capturing traffic for the web proxy
- Identity and authentication at the web proxy
- Comparing Cisco Secure Email Gateway, Secure Email Cloud Gateway and Secure Web Appliance
- Email security: spam and malware filtering, DLP, block lists, encryption
- Cisco Umbrella: identities, URL filtering, destination lists, TLS decryption and reports
Endpoint Protection and Detection
- Comparing EPP and EDR
- Configuring Cisco Secure Endpoint
- Outbreak control and quarantine for containment
- Device management, asset inventory and MDM
- Multi-factor authentication and posture assessment
- Why a patch strategy for endpoints is critical
Secure Network Access and Visibility
- Identity management, guest access, profiling, posture and BYOD
- Configuring and verifying 802.1X, MAB and WebAuth
- Change of Authorization
- Device compliance and application control
- Detecting exfiltration techniques: DNS tunnelling, HTTPS, email, FTP, ICMP and more
- The value of network telemetry