Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CCNP,CCIE Security SCOR (350-701) Training Part-1/2
Bestseller
Rating: 4.4 out of 5(1,556 ratings)
11,307 students

CCNP,CCIE Security SCOR (350-701) Training Part-1/2

Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) with Step by Step Lab Workbook
Created byAhmad Ali
Last updated 2/2025
English

What you'll learn

  • Compare common security vulnerabilities
  • Describe functions of the cryptography components
  • Compare site-to-site VPN and remote access VPN deployment types
  • Compare network security solutions that provide intrusion prevention
  • Configure and verify network infrastructure security methods
  • Device hardening of network infrastructure security devices
  • Implement segmentation, access control policies, AVC, URL filtering
  • Implement management options for network security solutions
  • Configure and verify site-to-site VPN and remote access VPN
  • Describe identity management and secure network access
  • common threats against on-premises and cloud environments
  • Configure secure network management of perimeter security

Course content

1 section95 lectures34h 22m total length
  • Lecture-01:Introduction to CCNP Security SCOR.7:15
  • Lecture-02:Confidentiality,Integrity & Availability.16:12

    Explain the CIA goals: confidentiality, integrity, and availability, in network security, detailing data in storage and in motion, encryption, hashing, and redundancy like backups and multiple links.

  • Lecture-03:Common Network Security Terms Asset etc.15:04

    discover common network security terms—assets, vulnerabilities, exploits, threats, attacks, risks, and countermeasures—and see how vulnerabilities enable exploits and how countermeasures protect assets.

  • Lecture-04:On-Premises, Cloud and Malware Theory.29:00
  • Lecture-05:SQL Database Injection Attack Theory and Lab.12:53
  • Lecture-06:Cross Site Scripting Attack Theory and Lab.7:45

    Explore cross-site scripting attack theory and lab, showing how scripts hijack cookies and session IDs to impersonate users, with a practical look at vulnerable web applications.

  • Lecture-07:Phishing Social Engineer Engineering Attack Lab.11:05
  • Lecture-08:Man-In-The-Middle Attack Theory and Lab.24:02
  • Lecture-09:Denial Of Service (DoS) Attack Theory and Lab.23:52
  • Lecture-10:Path Traversal Attack Theory and Lab.6:23
  • Lecture-11:Buffer Overflow Attack Theory and Lab.4:16
  • Lecture-12:Common Vulnerability Terms Theory.7:51

    Explore vulnerabilities as weaknesses in protocols, apps, or devices, including hardcoded default credentials, sql injection, cross-site scripting forgery, missing encryption, and weak https ssl version 1.1.

  • Lecture-13:VLAN (Virtual Local Area Network) Theory.23:52
  • Lecture-14:Layer 2 Attacks (DHCP Snooping) Theory & Lab.35:20

    Discover layer 2 attacks on access layer switches and how dhcp snooping mitigates dhcp starvation and rogue dhcp servers. Learn to configure trusted and untrusted ports for protection.

  • Lecture-15:ARP (Address Resolution Protocol) Theory.6:07
  • Lecture-16:ARP Poisoning or ARP Spoofing Attack Lab.27:23
  • Lecture-17:MAC (Media Access Control Address) Theory.6:20
  • Lecture-18:MAC (Media Access Control Address) Flooding Attack.4:19

    Explore mac flooding attacks on layer two switches that fill the mac address table, cause broadcasts, and enable packet capture, with port security using static, dynamic, and sticky options.

  • Lecture-19:Configure and Verify Port Security Theory & Lab.46:44
  • Lecture-20:STP (Spanning Tree Protocols) Theory.12:23
  • Lecture-21:STP Spanning Tree Protocols Attacks Labs.17:07

    Explore two STP attacks—becoming the root bridge and claiming the root port—and apply defenses using bpdu guard, portfast, and root guard to protect the topology.

  • Lecture-22:VLAN (Virtual Local Area Network) Hopping Attack Lab.20:33

    The VLAN hopping attack lab demonstrates switch spoofing and double tagging, and shows how changing the native VLAN and disabling negotiation with static access ports protects switches.

  • Lecture-23:Configure and Verify Storm Control Theory & Lab.19:58

    Storm control on Cisco switches uses threshold-based limits for unicast, multicast, and broadcast traffic to protect against DDoS attacks by shutting down interfaces or sending logs.

  • Lecture-24:Configure and Verify Private VLAN Theory & Lab.30:12
  • Lecture-25:Configure and Verify VRF Lite Theory & Lab.33:09
  • Lecture-26:Configure and Verify Management Plane Theory & Lab Part-154:41
  • Lecture-27:Configure and Verify Management Plane Theory & Lab Part-245:51

    Configure management plane access with ssh version two, rsa keys, domain name, and vty security; restrict ssh via acl and enable http/https management.

  • Lecture-28:Configure and Verify Control Plane Theory & Lab28:45
  • Lecture-29:Introduction to Layer 2 and Layer 3 Data Plane.3:22
  • Lecture-30:Introduction and Compare In-Band and Out-of-Band.7:50
  • Lecture-31:Securing Routing Protocols (Authentication on RIP).23:40
  • Lecture-32:Securing Routing Protocols (Authentication on EIGRP & OSPF).31:14
  • Lecture-33:CDP, Risk, Reconnaissance and Flooding Attack.13:45
  • Lecture-34:Introduction DNS,DNS Spoofing,DNS Caching & DNSSEC.22:24

    Explore how the domain name system translates names to IPs, the role of root servers A to M and forwarders, DNS records and caching, and how DNSSEC defends against spoofing.

  • Lecture-35:Configure and Verify TFTP, FTP, SFTP and SCP.22:47
  • Lecture-36:Configure and Verify SNMP Version 2 and SNMP Version 3.31:54

    Configure and verify snmp version 2 and version 3 for network monitoring with a manager and agent. Explore get, get next, get bulk, trap messages, and v3 security options.

  • Lecture-37:Configure and Verify Syslog (Logging) in Cisco Router.31:16
  • Lecture-38:Introduction & Concept of Network Time Protocol (NTP).12:14
  • Lecture-39:Configure and Verify Network Time Protocol and Security.55:11
  • Lecture-40:Introduction and Concept of Cryptography & Terminologies.15:02

    Explore the fundamentals of cryptography, defining encryption, decryption, plaintext, and ciphertext, and illustrate with Caesar cipher and vinegar cipher examples.

  • Lecture-41:Introduction & Concept of Symmetric & Asymmetric Encryption.18:12
  • Lecture-42:Introduction and Concept of Cryptography Hash (SHA, MD5).15:42

    Explore cryptography basics, hash functions like MD5 and SHA, and how hashes ensure data integrity. Learn symmetric encryption with DES, 3DES, and AES, including HMAC concepts.

  • Lecture-43:Introduction and Concept of Virtual Private Network VPN.18:59
  • Lecture-44:Introduction and Concept of IPSec Protocols Features.18:02
  • Lecture-45:Introduction and Concept of Diffie-Hellman (DH).19:22
  • Lecture-46:Introduction and Concept of SSL/TLS and Handshake.21:24

    Explore how SSL and TLS provide authentication and confidentiality via certificates and public keys, with client hello, server hello, and key exchange establishing an encrypted session.

  • Lecture-47:Introduction and Concept of IKE, Versions & Modes.20:56
  • Lecture-48:Internet Key Exchange IKE Phase 1 two Modes Lab.12:23

    Explore ike phase 1 with main mode and aggressive mode in a lab, observing six packets in main mode, three in aggressive mode, with isakmp/ike version 1 and pre-shared key.

  • Lecture-49:Configure and Verify Site to Site IPSec VPN Routers.51:55

    Configure and verify site-to-site ipsec vpn between routers and firewalls using isakmp, pre-shared keys, transform sets, and crypto maps, then validate with show commands.

  • Lecture-50:Troubleshoot Site to Site IPSec VPN on Cisco Routers.48:05

    Troubleshoot site-to-site IPsec VPN on Cisco routers with hands-on configuration, verification of phase one and phase two, and diagnosis of ACL and transform-set mismatches using debug commands.

  • Lecture-51:VPN ISAKMP Policy,Encryption Domain,Crypto Maps.10:49

    Configure site-to-site vpn by defining phase one policy and encryption domain with an acl, then bind them with a crypto map for the vpn tunnel.

  • Lecture-52:Configure and Verify NAT-T (Traversal) on Routers.25:59
  • Lecture-53:Concept of Dynamic Multi-point Virtual Private Network.29:01
  • Lecture-54:Configure and Verify Dynamic Multipoint VPN Phase-1 Lab.27:33
  • Lecture-55:Configure and Verify Client-Based Remote-Access VPN Lab.27:57
  • Lecture-56:Introduction & Concept of FlexVPN (Virtual Private Network).15:43
  • Lecture-57:FlexVPN Flexible Virutal Private Network SVTI Lab.18:02
  • Lecture-58:Site-to-Site & Remote VNP High Availability Considerations.7:28
  • Lecture-59:PKI (Public Key Infrastructure) Theory and Lab.20:43
  • Lecture-60:Introduction to Firewall Technologies and Types.20:39
  • Lecture-61:Introduction to Cisco ASA Firewall,Features & Services.7:51
  • Lecture-62:Install Cisco ASA Clustering Enable Firewall in GNS3.10:24
  • Lecture-63:Install Cisco ASA Clustering Enable Firewall in EVE NG.10:01

    Learn to deploy a fully licensed Cisco ASA firewall in Eve-ng with clustering enabled, using a simple drag-and-drop workflow: create a versioned folder, upload the image, and boot.

  • Lecture-64:Cisco ASA Firewall Basic Commands and Configuration.49:51
  • Lecture-65:Device Management In Cisco ASA Firewall Console.10:02

    Configure devices securely via out-of-band console management, using a console cable and serial/usb adapters with tools like Putty or SecureCRT, and protect access with AAA.

  • Lecture-66:Device Management In Cisco ASA Firewall SSH.20:46
  • Lecture-67:Device Management In Cisco ASA Firewall ASDM.31:29
  • Lecture-68:Device Management In Cisco ASA Firewall TFTP.20:46

    Discover how tftp stores and restores device configurations on Cisco ASA firewalls, using UDP port 69 to back up running and startup configurations and to upgrade or downgrade operating system.

  • Lecture-69:Device Management In Cisco ASA Firewall FTP.11:12
  • Lecture-70:Security Levels and Zoning in Cisco ASA Firewall.40:17
  • Lecture-71:Implement Access Control Lists in Cisco ASA Firewall.35:59

    Explore how access control lists on Cisco ASA firewalls filter traffic using top-to-bottom extended and standard ACLs, with permit and deny rules, interfaces inbound and outbound, and the implicit deny.

  • Lecture-72:Configure and Verify Extended ACLs in Cisco ASA Firewall.1:22:34

    Learn to configure and verify extended ACLs on Cisco ASA firewall, using permit and deny rules, inbound and global application, with IPv4/IPv6 and top-to-bottom evaluation.

  • Lecture-73:Configure and Verify Infrastructure ACLs in Cisco ASA.18:16
  • Lecture-74:Configure and Verify Time-Based ACLs in Cisco ASA Firewall.21:58

    Configure time-based ACLs on Cisco ASA by creating time ranges (periodic or absolute), then attach the time range to ACLs to permit or deny traffic during defined hours.

  • Lecture-75:Configure and Verify Standard ACLs in Cisco ASA Firewall.32:34
  • Lecture-76:Configure and Verify Object Groups ACLs in Cisco ASA Firewall.41:49
  • Lecture-77:Introduction and Theory of NAT and PAT in Cisco ASA Firewall.22:48

    Discover how NAT and PAT operate on Cisco ASA firewall, covering static and dynamic NAT, static and dynamic PAT, policy NAT, and identity NAT using network and service objects.

  • Lecture-78:Creating Lab Topology for NAT and PAT for Cisco ASA Firewall.24:32
  • Lecture-79:Configure and Verify Static NAT in Cisco ASA Firewall.34:55
  • Lecture-80:Configure and Verify Static PAT in Cisco ASA Firewall.24:31
  • Lecture-81:Configure and Verify Dynamic NAT in Cisco ASA Firewall.26:21
  • Lecture-82:Configure and Verify Dynamic PAT in Cisco ASA Firewall.16:02
  • Lecture-83:Configure and Verify Identity NAT in Cisco ASA Firewall.22:59
  • Lecture-84:Configure and Verify Policy NAT in Cisco ASA Firewall.16:16
  • Lecture-85:Configure and Verify Transparent Firewall Cisco ASA Firewall.33:59
  • Lecture-86:Introduction and Concept of Cisco Firepower (FTD and FMC).13:33

    Trace the evolution from Snort to Sourcefire to Cisco Firepower, and discover how FTD and FMC enable a next generation firewall with IPS/IDS and centralized management.

  • Lecture-87:Install and Add Cisco FTD 6.2.3-83 on EVE-NG.8:33
  • Lecture-88:Install and Add Cisco FMC 6.2.3-83 on EVE-NG.6:00

    install and add Cisco FMC 6.2.3-83 on eve-ng by downloading from torrent, extracting with seven-zip, transferring with winSCP, and applying permissions to run FMC and ftd images.

  • Lecture-89:Firepower Thread Defense FTD First Time Configuration.16:13
  • Lecture-90:How to Configure and Add Manager in Cisco FTD.2:48

    Register each FTD with the FMC by configuring a manager, entering the FMC IP and a registration key. Verify with show manager to confirm FMC-based management instead of local configuration.

  • Lecture-91:Firepower Management Center FMC First Time Configuration.5:46
  • Lecture-92:Firepower Management Center FMC First Time Login Setup.4:16
  • Lecture-93:Enable Evaluation Smart Licenses in Cisco FMC.1:16
  • Lecture-94:How Integrate Cisco FTD Firewall with Cisco FMC.6:27

    Register FTDs with FMC, configure hostnames and IPs, apply a default policy, and activate smart licenses for malware, threat, and URL; then deploy unified policies from FMC to all FTDs.

  • EVE-NG Installation, Configuration & Images31:15

Requirements

  • Basic IP and security knowledge is nice to have.
  • Students need to understand basic networking.
  • CCNA routing and Switching Knowledge
  • Students needs to understand Networking Fundamentals.

Description

Security Concepts, Explain common threats against on-premises and cloud environments, Configure and verify network infrastructure security methods, Configure AAA for device and network access, Configure secure network management of perimeter security, Configure and verify site-to-site VPN and remote access VPN , Describe identity management and secure network access, Network security solutions that provide intrusion prevention and firewall, Network Security, Securing the Cloud, Content Security, Endpoint Protection and Detection , Secure Network Access, Visibility, and Enforcement, Secure network access, SDN and Network Automation Concepts, Describe the components, capabilities, and benefits of Cisco Umbrella, Endpoint Protection and Detection, Secure Network Access, Visibility, and Enforcement, Describe the benefits of network telemetry, Implement traffic redirection and capture methods, Describe the concept of DevSecOps, Identify security solutions for cloud environments, Compare the customer vs. provider security responsibility, Configure AAA for device and network access, Implement segmentation, access control policies, AVC, Explain North Bound and South Bound APIs in the SDN architecture, Describe security intelligence authoring, sharing, and consumption, Describe security intelligence authoring, sharing, and consumption, Interpret basic Python scripts used to call Cisco Security appliances APIs, Cloud service models: SaaS, PaaS, IaaS, Security assessment in the cloud, Patch management in the cloud, Describe the benefits of device compliance and application control

Who this course is for:

  • Course has been designed for anyone who wants to start learning Security
  • This course is for students trying to obtain the CCNP and CCIE SCOR
  • This course is for students trying to learn the CCNP Security
  • Any Network or Security Engineer want to learn or polish their Skills.