Module 8: CCNA Security Course Overview (13 min)

Module 8: CCNA Security Course Overview (13 min) Sew Hoon Yeo
Introduction (00:00)
Hello, I'm Sew Hoon, Product Manager for the Cisco Network Academy CCNA
Security course. I will be giving an overview of the CCNA Security course in this
presentation, covering the course overview and course design.
Need for security skills in networking (00:13)
The Cybersecurity series has provided a great opportunity to hear about the
challenges and opportunities in cyber security. Security isn't something that you
set up and forget about because the trends are constantly evolving. You need to
constantly evolve our knowledge and constantly update/upgrade the tools and
features to keep up with the trends.
From a career standpoint, we are seeing companies hiring dedicated security
people like the experts we heard from in this series. We'll focus on network
security like cyber security and becoming an expert in the field. But we're also
seeing that security knowledge has become just a baseline knowledge
requirements for people as they apply for jobs as network administrators,
technicians, and engineers.
What we have been hearing from employers is that when they're hiring a network
administrator or technician, they want these people to understand security and to
be able to set up and manage VPNs, administer and manage a firewall,
understand active directory and radius integration. Therefore basic security
knowledge above and beyond CCNA is becoming a requirement for a network
career.
In addition, as the Internet of Everything (IoE) brings new economic and social
opportunities to communities throughout the world, the global demand increases
for all information and communication technology skills. Security and risk
management skills are becoming the most highly sought after skills in
networking, and the demand continues to grow.
CCNA Security Course Goals (01:59)
For networking technology students and current IT networking professionals are
looking to enhance their core routing and switching skills to prepare for a career
in network security. The CCNA Security course is a hands on career oriented, elearning solution, that provides the specialized security technology skills needed
to achieve success in a market place with specialists skills. The CCNA Security
course was launched in 2009 and right now we have about 12,000 students a
year going through the program. At an associate level, we have CCNA Security
with one course aligned with the objectives of the Cisco CCNA Security
© 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public
Page 1 of 4
Module 8: CCNA Security Course Overview
certification. The curriculum prepares students for the certification exams leading
to the CCNA Security Certification.
CCNA Security Key Competencies (02:57)
The CCNA Security course provides an introduction to core security
technologies, and teaches students how to develop security policies and mitigate
risk. It teaches students how to install, configure, and troubleshoot monitor, and
troubleshoot network devices to maintain the integrity, confidentiality, and
availability of data and devices. It helps students acquire the competencies and
skills needed to develop a security infrastructure, able to recognize network
vulnerabilities, and mitigate potential security threats.
It focuses on the security configuration and management of industry leading
Cisco equipment by providing general network security knowledge that is
applicable across multiple and all solutions. When you complete the course,
these are the key competencies you will have, and these are pretty much the
same competencies you need to sit for the CCNA Security certification exam. It's
also a lot of the same competencies we see employers requesting from network
engineers and technicians, which is an understanding of these key security
features.
CCNA Security: Who should enroll? (04:21)
The CCNA Security course is designed for Networking Academy students
seeking entry level security specialist skills. Prospective students include
individuals enrolled in technology degree programs at institutions of higher
education, and IT professionals who want to enhance their core routing and
switching skills. CCNA Security provides a next step for Cisco CCENT or CCNA
students who want to expand their skill sets to prepare for a career in network
security. Students should have the following skills and knowledge: CCENT level
networking concepts and skills, and basic PC and Internet navigation skills.
CCNA Security Certification: Meets growing demand (05:14)
The CCNA Security course aligns to the industry recognized Cisco CCNA
Security certification. The CCNA Security certification lays the foundation for job
roles such as network security specialist, security administrator, and network
security support engineer. In addition, the U.S. National System Security and the
Committee on National Security Systems recognizes that the Cisco CCNA
Security courseware meets CNSS 4011 training standards. Next I will be diving
into what's actually in our CCNA Security course in this part of the presentation.
CCNA Security Course Design (06:05)
The CCNA Security curriculum provides an in depth theoretical and hands on
introduction to network security. The curriculum consists of the following
components: the course itself which is around 70 hours long consisting of 10
chapters which provides students the understanding of network security
principles as well as the tools and configurations available. There are 16 hands
on labs which help students develop critical thinking and problem solving skills.
There are 10 Cisco Packet Tracer activities, and 1 Packet Tracer Practice Skills
© 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public
Page 2 of 4
Module 8: CCNA Security Course Overview
Based Assessment which gives you the ability to design, configure, and
troubleshoot various networks that you will experience in the lab.
Packet Tracer is not a replacement for hands on equipment. It is a nice
complement to real equipment especially when you cannot always get access to
real lab equipment. So, it is a great way to practice.
Lastly, 1 pre-test, quizzes, and chapter exams, 1 certification practice exam, 1
final practice exam, 1 final exam and skills based assessment which provides
immediate feedback to support the evaluation of knowledge and acquired skills.
The CCNA Security course uses the same graphical user interface as the CCNA
Routing and Switching curriculum. It is embedded with rich media, some static
and some interactive, to visually show what's happening and what's being
explained. The course is available in English only, and there is no plan for
translated versions.
CCNA Security Course Outline (07:53)
The CCNA Security course has 10 chapters. The first chapter is really an
overview looking at current network security trends such as viruses, worms,
Trojan horses, denial of service attacks, etc. and we will look at the various
mitigation technologies and tactics to overcome those various attacks.
Chapter 2 and 3 looks at securing network devices, namely the browsers. In
Chapter 2 we look at the basic functions on the routers to secure it. For example
the administrative access. We look at the network management streams coming
out of the router for SNMP and syslog, and how to secure those streams. We will
look at the services on the router where you get a router out of the box initially a
lot of the services are turned on by default, but if you really want to secure the
router, you really need to understand which of the services to turn off to make the
router more secure.
In Chapter 3 we look at router security further by looking at the AAA protocol:
authentication, authorization, and accounting, which really looks at who you are
letting in, what privilege levels are you giving them in terms of what commands
and functions you're giving them access to, and is also keeping a record of the
activities so that you can do an audit trail later on. Once the network devices are
secure, we look at securing the network itself, starting with the perimeter. You
probably have heard about firewalls. In this course, we talk about the various
firewalls technology: access control lists (ACL), the different flavors of it, and how
to implement them.
Then, we move into intrusion prevention in chapter 5. We look at the basics of
what it is, how to operate it. We look at the digital signatures that can be used to
detect and prevent attacks.
In Chapter 6, the only chapter that focuses on layer 2, we look at the threats for
Local Area Network and we also look at endpoint security. We look at the various
© 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public
Page 3 of 4
Module 8: CCNA Security Course Overview
features on the Cisco switch to implement security. We cover some of the
security features we have for email, and web type attacks. We specifically look at
the Cisco email security appliances...appliance solutions, which is a combination
of antivirus, antispam, and anti-malware solutions.
In Chapter 7, you learn all about cryptographic systems, including encryption,
hashes, digital signatures, public key infrastructure systems.
It is a good introduction to Chapter 8 which covers virtual private networks (VPN).
Though VPNs uses cryptograph and VPNs is widely used today for connecting
remote offices and telecommuters to their company networks via public
networks.
In Chapter 9 we look at attacks and capabilities of firewall and virtual private
network services, how to install, configure, and monitor firewalls and VPNs using
the multiservices Cisco Adaptive Security Appliance, ASA in short, a device
which combines firewalls, antivirus, intrusion prevention, and virtual private
network capabilities.
Chapter 10 is sort of a summary of the course. It looks at how to design a
network securely... the design principles. It also looks at operations. because you
can have a very secure network, and do all the right things from a configurations
standpoint, but if you don't have the right operational processes in place, such as
change control, configuration control, separation of duties, etc., then you're going
to run into problems. The last thing we look in Chapter 10 is a comprehensive
security policy, and what are the components and how to implement that in an
organization.
For More Information about CCNA Security (12:22)
For additional information on the CCNA Security course, we have some
documents that are posted in the CCNA Security resources area, accessible
through the offerings menu on the Cisco Netspace, including the Scope and
Sequence document, Frequently Asked Questions, At-a-Glance, and Overview
Presentations. Please check these documents for the latest information as we
may revise the course content and coverage from time to time to keep aligned
with the revisions in the CCNA Security certification examinations.
CCNA Security Certification page (13:03)
So please visit the CCNA Security certification page regularly for updates to the
certification exams as well. That is all I have to share. Thank you for your time.
© 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public
Page 4 of 4