
Explore CCNA security fundamentals by identifying threats to Cisco switches and networks, and apply firewall features, zone-based security, and secure management practices to prevent attacks such as spoofing and DoS.
Explore CCNA Security (210-260 IINS v3.0) exam information, guiding engineers to identify threats, secure networks, and implement Cisco security features, with formats ranging from multiple choice to simulations.
Explore fundamentals of network security, common threats, and best practices while learning secure remote access, VPNs, firewalls, cryptography, and email security.
Explore network security basics, including assets, threats, risks, and mitigations, and how proper design and updated systems protect against attacks like fishing, Trojan malware, and unauthorized access.
Examine the goals of network security, emphasizing confidentiality, integrity, and availability, and how encryption, hashing, and access controls prevent unauthorized viewing, modification, and disruption of information.
Identify physical, internal, and external threat types to networks, and apply mitigations such as physical security, ID access controls, surveillance, backups, and firewall protections that alert and respond.
Identify and classify assets by type, value, confidentiality, and useful life, assign ownership, custodians, and end users to apply security measures for confidential, private, public, and top secret assets.
Classify countermeasures into administrative, physical, and technical controls to reduce attack risk, illustrating with security policies and trainings, audits, physical safeguards, firewall and VPN protections.
Classify vulnerabilities by identifying weaknesses in networks, systems, and protocols, from misconfigurations and policy flaws to software, hardware, human factors, and physical access risks, to prevent attacks.
Explore design principles for network security, including policy-based access, defense in depth, network segmentation, least-privilege access, and auditing to deter social engineering and enforce accountable user behavior.
Identify financial motives, such as stealing banking and credit card details for transfer, and discuss disruption and geopolitical aims behind network attacks.
Learn how social engineering attacks deceive users to reveal confidential credentials through phishing emails, fake phone calls, shoulder surfing, and spoofing, and how malicious code can spread to compromise networks.
Explore phishing attacks, including e-mail phishing and farming, that manipulate DNS to redirect users to fake bank sites. Learn how attackers harvest credentials through targeted calls and nontechnical end users.
Educate end users on security policies and phishing awareness; verify identities, avoid sharing personal or financial details, and beware look-alike websites, while deploying email filters and monitoring.
Explains how denial of service attacks overwhelm servers by flooding them with thousands of requests, with spoofed IP addresses, delaying legitimate users.
Explore distributed denial of service attacks, how botnets from multiple infected devices flood a victim with traffic, and how firewalls and hardening mitigate these threats.
Explore spoofing attacks that place an attacker in the middle of a connection to capture traffic, spoof IPs or DNS responses, and trigger denial of service.
Mitigate spoofing by filtering private ip traffic, dropping spoofed packets at the firewall, enabling uRPF checks, and applying switch-based dynamic inspection and snooping to prevent mac and ip spoofing.
See how a man-in-the-middle attack intercepts communications by spoofing servers and IP or DNS, and how dynamic up inspection with unicast helps prevent it.
Explore password attacks, including brute force and keylogging, and learn how attackers guess or capture passwords using manual or automated tools, and why strong passwords matter.
Enforce strong password policies with minimum length and at least one special character and one number, prohibit reuse, and promote one-time or time-limited codes to mitigate password attacks.
Explain reflector attacks in which spoofed requests cause third-party reflectors to flood a victim with responses, triggering denial-of-service and disrupting access.
amplification attacks use multiple devices to send spoofed requests to dns servers, causing large dns replies to flood the victim and exhaust bandwidth and resources.
Reconnaissance attacks gather network information, identifying operating systems, services, and IP addresses to plan future exploits. Attackers use scanners, packet sniffers, and internet information queries to map devices and ports.
Mitigate reconnaissance attacks by deploying firewall protections, strong encryption with digital certificates and credentials, and anti-sniffing measures to detect and defeat packet sniffers on the network.
Explore how malicious codes like viruses infect data files and programs, require a host to run, and spread across networks, risking system failure, high resource use, and data loss.
Examine how worms function as self-contained malicious codes that propagate across networks without a host, identify victims on the network, and inject themselves to affect devices.
Identify how trojan horses disguise malicious code inside games or software downloads and explain how they run in the background to infect computers.
Hackers act as actors seeking network access, staying undetected to steal high value information for financial gain, targeting defense, manufacturing, and financial sectors, then exiting quickly to avoid detection.
Explore how script kiddies—beginners who use free hacking tools on linux—attempt network access, and contrast with advanced hackers who set up bait holes to break into systems.
Explore malware services on the darknet, define your target and goals, and see how tools and support shape possible outcomes.
Master AAA concepts: authentication, authorization, and accounting, and learn how verification, access control, and auditing govern who can access resources on devices and networks.
Use Cisco traffic telemetry methods to monitor network activity, detect anomalies, synchronize time across devices, and trigger alerts and reports when devices fail.
Explore how a firewall controls traffic between networks, enforces security policies, inspects traffic between LAN, DMZ, and Internet, and preserves trusted boundaries with defined rules.
Explore virtual private networks within a transport network to connect customer sites over private or public infrastructure. Examine point-to-point and point-to-multipoint VPNs, endpoints, and cost-efficient connectivity using public IPs.
Explore next generation firewalls and their enhanced features, including traffic filtering from local area network to Internet, cloud and content controls, and reputation-based blocking of malicious sites via identity-based policies.
This Course is designed to prepare CCNA Security candidates for the exam topics covered by the 210-260 IINS exam.
This course allows learners to understand common security concepts, and deploy basic security techniques utilizing a variety of popular security appliances within a "real-life" network infrastructure. It focuses on security principles and technologies, using Cisco security products to provide hands-on examples.
This Cisco self-paced course is designed to be as effective as classroom training.
Course content is presented in easily-consumable segments via both Instructor Video and text. Makes the learning experience hands-on, increasing course effectiveness
The revised CCNA Security (IINS v3.0) curriculum is designed to bring data, device, and administration together to have better network security, which is more relevant and valuable than ever. It is destined to meet the current business demand so that the network security professionals are able to acquire new knowledge, training and vital skills to be successful in evolving job roles.
1. Security Concepts – This section includes security principles, threats, cryptography, and network topologies. It constitutes 12% of the questions asked in the exam.
2. Secure Access – This section deals with secure management, AAA concepts, 802.1X authentication, and BYOD. It makes 14% of the exam.
3. VPN (Virtual Private Networks) – This focuses on VPN concepts, remote access VPNs, and site-to-site VPNs. It is 17% of the exam.
4. Secure Routing & Switching – This section concentrates on VLAN security, mitigation techniques, layer 2 attacks, routing protocols, and overall security of Cisco routers. That is 18% of the exam.
5. Cisco Firewall Technologies – This section is 18% of the exam and focuses on stateful and stateless firewalls, proxy firewalls, application, and personal firewalls. Additionally, it concentrates on Network Address Translation (NAT) and other features of Cisco ASA 9.x.
6. IPS – It is 9% of the exam and this portion focuses on network-based and host-based IPS, deployment, and IPS technologies.
7. Content and Endpoint Security –Constituting 12% of the exam, this section checks your understanding on the endpoint, web-based, and email-based threats. Later it leads to apt and effective mitigation technology and techniques to counter those threats.