
Cisco 642-502 SNRS Certification ExamSecuring Networks with Cisco Routers and Switches Exam 642-502... Continue Below To CCSP Exam Information and Cisco Articles. The real Cisco CCSP 642-502 SNRS Exam has a duration of 90 minutes and 60 -70 questions to complete.
The Securing Networks with Cisco Routers and Switches SNRS 642-502 exam is one of the exams associated with the Cisco Certified Security Professional CCSP certification. Candidates can prepare for the Cisco SNRS 642-502 exam by taking the SNRS v1.0 course. This Cisco SNRS 642-502 exam includes simulations and tests a candidate's knowledge and ability to secure networks using Cisco routers and switches. All these objectives are designated from the Cisco.com website. Please note that the 642-502 exam topics and objectives may change without notice, since technologies are always changing.
CCSP 642-502 Exam Objectives:
Implement Layer 2 security
- Utilize Cisco IOS and Cat OS commands to mitigate Layer 2 attacks
- Implement Cisco Identity-Based Networking Services
- Implement Cisco 802.1X Port-Based Authentication
- Identify and describe Layer 2 security best practices
Configure Cisco IOS Firewall features to meet security requirements
- Identify and describe the capabilities of the IOS firewall feature set
- Configure CBAC to dynamically mitigate identified threats to the network
- Verify and troubleshoot CBAC configuration and operation
- Configure authentication proxy to apply security policies on a per-user basis
- Verify and troubleshoot authentication proxy configuration and operation
Configure Cisco IOS-based IPS to identify and mitigate threats to network resources
- Identify and describe the capabilities of the IOS-IPS feature set
- Configure the IPS features to identify threats and dynamically block them from entering the network
- Verify and troubleshoot IDS operation
- Maintain and update the signatures
Configure basic IPSec VPNs to secure site-to-site and remote access to network resources
- Select the correct IPSec implementation based on specific stated requirements
- Configure IPSec Encryption for site-to-site VPN using pre-shared keys
- Configure IPSec Encryption for site-to-site VPN using certificate authority
- Verify and troubleshoot IPSec operation
- Configure EZ-VPN server
- Configure EZ-VPN remote using both hardware and software clients.
- Troubleshoot EZ-VPN
Configure authentication, authorization and accounting to provide basic secure access control for networks
- Configure administrative access to the Cisco Secure ACS server
- Configure AAA clients on the Cisco Secure ACS (for routers)
- Configure users, groups and access rights
- Configure router to enable AAA to use TACACS+
- Configure router to enable AAA to use a Radius server
- Verify and troubleshoot AAA operation
Use management applications to configure and monitor IOS security features
- Initialize SDM communications on Cisco routers
- Perform a LAN interface configuration of a Cisco router using SDM
- Use SDM to define and establish a site-to-site VPN
Certification Articles
|