CCNA Security – Implementing Cisco IOS Network Security: Exam 640-553 IINS Course

Course Code: TO 150
Course Abstract:

Participants of this accelerated course are provided knowledge and skills to install and configure Cisco equipment for security purposes.

CCNA Security Certification meets the needs of IT professionals who are responsible for network security. It confirms an individual's skills for job roles such as Network Security Specialists, Security Administrators, and Network Security Support Engineers. This certification validates skills including installation, troubleshooting and monitoring of network devices to maintain integrity, confidentiality and availability of data and devices and develops competency in the technologies that Cisco uses in its security structure.

Participants completing the recommended Cisco training will gain an introduction to core security technologies as well as how to develop security policies and mitigate risks. IT organizations that employ CCNA Security-holders will have IT staff that can develop a security infrastructure, recognize threats and vulnerabilities to networks, and mitigate security threats.

The CCNA is considered to be the most universally rewarding certification produced in the IT industry. Individuals who possess a CCNA usually carry job titles such as Network Engineer or Network Architect.

Documentation
Course Materials consist of a CCNA Security Welcome kit and the following materials:
The CCNA Security textbook
The CCNA Virtual Lab e-trainer
Student manual containing all of the PowerPoint slides used in this class

Exam Preparation
Completion, review & discussion of examination question examples.

Examination
The 640-553 IINS Implementing Cisco IOS Network Security exam is associated with the CCNA Security certification. This exam tests a candidate's knowledge of securing Cisco routers and switches and their associated networks. It leads to validated skills for installation, troubleshooting and monitoring of network devices to maintain integrity, confidentiality and availability of data and devices and develops competency in the technologies that Cisco uses in its security infrastructure.

Candidates can prepare for this exam by taking the Implementing Cisco IOS Network Security (IINS) course.

Criteria for Certification
Cisco does not publish the pass score for this exam, but the community commonly accepts that the passing score is 825 out of 1000. The exam contains between 52 and 65 questions that include multiple choice, drag and drop, and simulation style questions in varying numbers.

Audience:

This course is designed for individuals that hold a valid CCNA certification.

Benefits
A solid credential that can be utilized in any industry
Validation of achievement in an industry-valued skill
Viable career path, leading to higher level positions

Domains of Exam 
Planning and Design
Implementing and Operation
Technology
Troubleshooting

Duration: 5 days
Learning Outcomes: Upon completion of this course, the participant will be able to:
> Describe the security threats facing modern network infrastructures
> Secure Cisco routers
> Implement AAA on Cisco routers using local router database and external ACS
> Mitigate threats to Cisco routers and networks using ACLs
> Implement secure network management and reporting
> Mitigate common Layer 2 attacks
> Implement the Cisco IOS firewall feature set using SDM
> Implement the Cisco IOS IPS feature set using SDM
> Implement site-to-site VPNs on Cisco Routers using SDM
Course Topics:

Describe the security threats facing modern network infrastructures
Describe and list mitigation methods for common network attacks
Describe and list mitigation methods for Worm, Virus, and Trojan Horse attacks
Describe the Cisco Self Defending Network architecture

Secure Cisco routers
Secure Cisco routers using the SDM Security Audit feature
Use the One-Step Lockdown feature in SDM to secure a Cisco router
Secure administrative access to Cisco routers by setting strong encrypted passwords, exec timeout, login failure rate and using IOS login enhancements
Secure administrative access to Cisco routers by configuring multiple privilege levels
Secure administrative access to Cisco routers by configuring role based CLI
Secure the Cisco IOS image and configuration file

Implement AAA on Cisco routers using local router database and external ACS
Explain the functions and importance of AAA
Describe the features of TACACS+ and RADIUS AAA protocols
Configure AAA authentication
Configure AAA authorization
Configure AAA accounting

Mitigate threats to Cisco routers and networks using ACLs
Explain the functionality of standard, extended, and named IP ACLs used by routers to filter packets
Configure and verify IP ACLs to mitigate given threats (filter IP traffic destined for Telnet, SNMP, and DDoS attacks) in a network using CLI
Configure IP ACLs to prevent IP address spoofing using CLI
Discuss the caveats to be considered when building ACLs

Implement secure network management and reporting
Use CLI and SDM to configure SSH on Cisco routers to enable secured management access
Use CLI and SDM to configure Cisco routers to send Syslog messages to a Syslog server

Mitigate common Layer 2 attacks
Describe how to prevent layer 2 attacks by configuring basic Catalyst switch security features

Implement the Cisco IOS firewall feature set using SDM
Describe the operational strengths and weaknesses of the different firewall technologies
Explain stateful firewall operations and the function of the state table
Implement Zone Based Firewall using SDM

Implement the Cisco IOS IPS feature set using SDM
Define network based vs. host based intrusion detection and prevention
Explain IPS technologies, attack responses, and monitoring options
Enable and verify Cisco IOS IPS operations using SDM

Implement site-to-site VPNs on Cisco Routers using SDM
Explain the different methods used in cryptography
Explain IKE protocol functionality and phases
Describe the building blocks of IPSec and the security functions it provides
Configure and verify an IPSec site-to-site VPN with pre-shared key authentication using SDM

Prerequisites: Due to the pace and duration of this course, ideal candidates for this course operate in medium to very large computing environment:
They have a minimum of one-year experience working in a LAN/WAN environment
They have a minimum of six months experience in a multi-LAN environment
They have passed the CCNA course and certification exam and/or possess this knowledge
Participants in this accelerated course should already know the basic Cisco commands for both Cisco routers and switches
Note: All fields are required
At the present time we do not offer training for individuals or groups less then 6 individuals. We apologize for any inconvenience.


We Value Your Privacy!

Ready to get started or in need of more information? Contact us today.

Go To Blog Virtual Learning