500-750: Cisco Network Security Specialist (CNSS)
Cisco 500-750 Exam Overview:
Exam Name | Cisco Network Security Specialist |
Exam Number | 500-750 CNSS |
Exam Number | $300 USD |
Duration | 90 minutes |
Number of Questions | 55-65 |
Passing Score | Variable (750-850 / 1000 Approx.) |
Recommended Training | Implementing Cisco Network Security v3.0 |
Sample Questions | Cisco 500-750 Sample Questions |
Practice Exam | Implementing Cisco Network Security Practice Test |
Cisco 500-750 Exam Topics:
Section | Weight | Objectives |
Security Concepts | 12% |
- Common security principles ◉ Describe Confidentiality, Integrity, Availability (CIA) - Common security threats ◉ Identify common network attacks - Cryptography concepts ◉ Describe key exchange - Describe network topologies ◉ Campus Area Network (CAN) |
SecureAccess | 14% |
- Secure management ◉ Compare In-band and out of band - AAA concepts ◉ Describe RADIUS & TACACS+ technologies - 802.1X authentication ◉ Identify the functions 802.1X components - BYOD ◉ Describe the BYOD architecture framework |
VPN | 17% |
- VPN concepts ◉ Describe IPSec protocols and delivery modes (IKE, ESP, AH, tunnel mode, transport mode) - Remote Access VPN ◉ Implement basic clientless SSL VPN using ASDM - Site-to-Site VPN ◉ Implement an IPSec site-to-site VPN with pre-shared key authentication on Cisco routers and ASA firewalls |
Secure Routing & Switching | 18% |
- Security on Cisco Routers ◉ Configure multiple privilege levels - Securing routing protocols ◉ Implement routing update authentication on OSPF - Securing the control plane ◉ Explain the function of control plane policing - Common Layer 2 attacks ◉ Describe STP attacks - Mitigation procedures ◉ Implement DHCP snooping - VLAN security ◉ Describe the security implications of a PVLAN |
Cisco Firewall Technologies | 18% |
- Describe operational strengths and weaknesses of the different firewall technologies ◉ Proxy firewalls - Compare stateful vs. stateless firewalls ◉ Operations - Implement NAT on Cisco ASA 9.x ◉ Static - Implement zone-based firewall ◉ Zone to zone - Firewall features on the Cisco Adaptive Security Appliance (ASA) 9.x ◉ Configure ASA Access Management |
IPS | 9% |
- Describe IPS deployment considerations ◉ Network based IPS vs. host based IPS - Describe IPS technologies ◉ Rules/Signatures |
Content and Endpoint Security | 12% |
- Describe mitigation technology for email-based threats ◉ SPAM filtering, anti-malware filtering, DLP, block listing, email encryption - Describe mitigation technology for Web-based threats ◉ Local & cloud-based Web proxies - Describe mitigation technology for endpoint threats ◉ Anti-Virus/Anti-Malware |
0 comments:
Post a Comment