本帖最后由 goodluck 于 2012-10-10 10:50 编辑
" p0 p0 v5 }: z8 I$ L u1 z; }
1 s8 U q9 c5 J8 U640-554 IINS Exam TopicsExam DescriptionThe 640-554 Implementing Cisco IOS Network Security (IINS) exam is associated with the CCNA Security certification. This exam tests a candidate's knowledge of securing Cisco routers and switches and their associated networks. It leads to validated skills for installation, troubleshooting and monitoring of network devices to maintain integrity, confidentiality and availability of data and devices and develops competency in the technologies that Cisco uses in its security infrastructure. $ n) H% P& a/ N( N0 {
Candidates can prepare for this exam by taking the Implementing Cisco IOS Network Security (IINS) course. . c: _5 o% h- c) K
Exam TopicsThe following topics are general guidelines for the content likely to be included on the Implementing Cisco IOS Network Security (IINS) exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.
/ ]% A. R' V W$ E2 m) r3 CCommon Security Threats
$ { W+ D( h, [# {# |; FSecurity and Cisco Routers Implement security on Cisco routers Describe securing the control, data, and management plane Describe Cisco Security Manager Describe IPv4 to IPv6 transition . H" ~ p. k7 e1 w4 V
: }! M8 `# S4 d. u j& W
AAA on Cisco Devices
7 h/ h$ K$ J Y1 nIOS ACLsDescribe standard, extended, and named IP IOS access control lists (ACLs) to filter packets Describe considerations when building ACLs Implement IP ACLs to mitigate threats in a network
2 w6 E' E/ ?" G + I0 J# K' M* K. b. G
Secure Network Management and Reporting
4 @. {$ }" H, |( ]# b! Z' ]Common Layer 2 Attacks) t j2 o% i/ j- s$ j8 o4 e
Cisco Firewall TechnologiesDescribe operational strengths and weaknesses of the different firewall technologies Describe stateful firewalls Describe the types of NAT used in firewall technologies Implement zone-based policy firewall using CCP Implement the Cisco Adaptive Security Appliance (ASA) Implement Network Address Translation (NAT) and Port Address Translation (PAT)
, v" j a6 [5 ?' `: J2 ?) m% F
3 W. ^1 N% ?- u2 P9 M- K2 nCisco IPSDescribe Cisco Intrusion Prevention System (IPS) deployment considerations Describe IPS technologies Configure Cisco IOS IPS using CCP
, I1 U1 D" y" X
+ E# K, I# T: s4 uVPN TechnologiesDescribe the different methods used in cryptography Describe VPN technologies Describe the building blocks of IPSec Implement an IOS IPSec site-to-site VPN with pre-shared key authentication Verify VPN operations Implement Secure Sockets Layer (SSL) VPN using ASA device manager
5 s( @- w+ {: T s" z- H 1 U- Z7 [8 w# G/ q. ]( B
|