Bookmark  
   
 
cisco ccie security lab certification exam

Cisco CCIE Security Lab Certification Exam

Cisco CCIE Security LAB Exam... Continue Below To CCIE Exam Information, Cisco Articles, and CCIE Study Guides. The real Cisco CCIE Security LAB Exam has a duration of 8 hours to complete.

The CCIE security lab exam is an 8 hour, hands-on exam which requires you to configure a series of secure networks to given specifications. Knowledge of troubleshooting is an important skill and candidates are expected to diagnose and solve issues as part of the CCIE security lab exam. Point values and testing criteria are provided. The physical rack for Security is similar to the rack for Routing and Switching with the addition of the PIX, VPN concentrator, intrusion detection sensor and authentication server. All these objectives are designated from the Cisco.com website. Please note that the CCIE Security Lab exam topics and objectives may change without notice, since technologies are always changing.

CCIE Security Lab Exam Objectives:

Bridging and Switching

  • Basic frame relay configuration
  • Catalyst VLAN configuration
  • Catalyst VTP configuration
  • Port-VLAN assignments
  • Catalyst management and security
  • 802.1x
  • Traffic control and congestion management
  • Catalyst features and advanced catalyst configuration

IGP Routing

  • OSPF, EIGRP and RIP configurations
  • OSPF, EIGRP and RIP security
  • PIX routing
  • VPN3000 routing
  • Route filtering, redistribution, summarization and other advanced IGP features

PIX Firewall

  • Basic PIX configuration
  • Management
  • Address translation (NAT, global, static)
  • ACL, conduit
  • Routing
  • Object groups
  • VLANs
  • AAA
  • VPN
  • DHCP
  • PPPoE
  • Filtering
  • Fixup protocols
  • Other advanced PIX features

BGP

  • Basic IBGP, EBGP and BGP backbone configurations *
  • BGP security
  • Summarization, filtering and advanced BGP features

IP/IOS Features

  • IP services
  • QoS
  • NAT/PAT
  • NTP
  • DHCP
  • SNMP
  • IOS features and user interfaces
  • File management, system management and advanced IP/IOS features

AAA

  • Tacacs+
  • Radius
  • Switch and router management
  • PIX management
  • VPN3000 management
  • Proxy authentication
  • Service authentication FTP, telnet, HTTP, other
  • Advanced AAA features

VPN

  • IPSec LAN-to-LAN (IOS/ PIX/ VPN3000)
  • DMVPN
  • Pre-shared
  • CA (PKI)
  • Remote access VPN (IOS/ PIX/ VPN3000)
  • VPN3000 concentrator
  • Unity client
  • WebVPN
  • EzVPN Hardware client (IOS/ PIX)
  • Xauth, split-tunnel, RRI, NAT-T
  • High availability
  • IPSec redundancy
  • QoS for VPN
  • GRE, mGRE
  • L2TP
  • PPTP
  • Advanced VPN features

IOS Firewall

  • CBAC
  • Audit
  • Auth Proxy
  • PAM
  • Access control
  • Performance tuning
  • Advanced IOS firewall features

Advanced Security

  • DoS/DDoS attacks
  • Network/ Host attacks
  • Packet marking techniques
  • Mitigation techniques
  • Security RFCs
  • Service provider security
  • Black holes, sink holes
  • Access lists (standard, extended, named)
  • Lock-and-Key access-list
  • Reflexive access-list
  • TCP intercept
  • uRPF
  • CAR
  • NBAR
  • Netflow
  • 802.1x
  • PBR
  • Flooding
  • Spoofing
  • Policing
  • Fragmentation
  • Sniffer traces
  • Device security and management (telnet, SSH, pwd, priv lvls)
  • Other advanced features

Intrusion Detection System

  • IDS sensor appliance 42XX
  • Sensor configuration
  • Signature tuning
  • Shunning
  • TCP resets
  • Sensor features
  • IDM
  • IEV
  • IOS IDS
  • PIX IDS
  • SPAN, RSPAN
  • Advanced IDS features
CCIE Certification Exams
Cisco 350-001 CCIE Routing and Switching Written Certification Exam
Cisco CCIE Lab Certification Exam
Cisco 350-018 CCIE Security Written Certification Exam
Cisco CCIE Security Lab Certification Exam
Cisco 350-02X CCIE Service Provider Written Qualification Certification Exam
Cisco 350-040 CCIE Storage Networking Written Certification Exam
Cisco CCIE Storage Networking Lab Certification Exam
Cisco 350-030 CCIE Voice Written Certification Exam
Cisco CCIE VOICE Lab Certification Exam
Back to Cisco Certifications
Back to Certifications
 
Relevant Resources

Need Cisco Hardware for your Cert?
Call 813.852.6400 now for more information to find the best router or switch to best help you with your certification exam. Having "real" hands-on experience is extremely beneficial not just for testing, but also ensures you are actually familiar with the device you are working on.
Cisco Routers
Cisco 600/800/1000 Series Routers
Cisco 1600 Series Routers
Cisco 1700 Series Routers
Cisco 2500 Series Routers
Cisco 2600 Series Routers
Cisco 3600 Series Routers
Cisco 3700 Series Routers
Cisco 7000 Series Routers
Cisco 12000 Series Routers
Cisco Switches
Cisco 1900 Series Catalyst Switches
Cisco 2900 Series Catalyst Switches
Cisco 3500 Series Catalyst Switches
Cisco 3550 Series Catalyst Switches
Cisco 3750 Series Catalyst Switches
Cisco 4000 Series Catalyst Switches
Cisco 5000 Series Catalyst Switches
Cisco 6000 Series Catalyst Switches
Certification Articles
Cisco Certification Articles General Certification Articles  
Cisco CCNA Certification Articles   All General Certification Articles    
Cisco CCNP Certification Articles        
All Cisco Certification Articles        
           
Microsoft Certification Articles        
Microsoft MCSE Certification Articles        
All Microsoft Certification Articles      
CCIE Study Guides
  Download - Cisco CCIE Ebook
  Download - Cisco CCIE Certification Guide