Syllabus
Learning Objectives
On Completion of this training the knowledge and skills that a learner will have are mentioned below
- . Threat Defense
- Implement firewall (ASA or IOS depending on which supports the implementation)
- Implement ACLs
- Implement static/dynamic NAT/PAT
- Implement object groups
- Describe threat detection features
- Implement botnet traffic filtering
- Configure application filtering and protocol inspection
- Describe ASA security contexts
- Implement Layer 2 Security
- Configure DHCP snooping
- Describe dynamic ARP inspection
- Describe storm control
- Configure port security
- Describe common Layer 2 threats and attacks and mitigation
- Describe MACSec
- Configure IP source verification
- Configure device hardening per best practices
- Routers
- Switches
- Firewalls
- . Cisco Security Devices GUIs and Secured CLI Management
- Implement SSHv2, HTTPS, and SNMPv3 access on the network devices
- Implement RBAC on the ASA/IOS using CLI and ASDM
- Describe Cisco Prime Infrastructure
- Functions and use cases of Cisco Prime
- Device Management
- Describe Cisco Security Manager (CSM)
- Functions and use cases of CSM
- Device Management
- Implement Device Managers
- Implement ASA firewall features using ASDM
- . Management Services on Cisco Devices
- Configure Net Flow exporter on Cisco Routers, Switches, and ASA
- Implement SNMPv3
- Create views, groups, users, authentication, and encryption
- Implement logging on Cisco Routers, Switches, and ASA using Cisco best Practices
- Implement NTP with authentication on Cisco Routers, Switches, and ASA
- Describe CDP, DNS, SCP, SFTP, and DHCP
- Describe security implications of using CDP on routers and switches
- Need for dnssec
- . Troubleshooting, Monitoring and Reporting Tools
- Monitor firewall using analysis of packet tracer, packet capture, and syslog
- Analyze packet tracer on the firewall using CLI/ASDM
- Configure and analyze packet capture using CLI/ASDM
- Analyze syslog events generated from ASA
- . Threat Defense Architectures
- Design a Firewall Solution
- High-availability
- Basic concepts of security zoning
- Transparent & Routed Modes
- Security Contexts
- Layer 2 Security Solutions
- Implement defenses against MAC, ARP, VLAN hopping, STP, and DHCP rogue attacks
- Describe best practices for implementation
- Describe how PVLANs can be used to segregate network traffic at Layer 2
- . Security Components and Considerations
- Describe security operations management architectures
- Single device manager vs. multi-device manager
- Describe Data Center security components and considerations
- Virtualization and Cloud security
- Describe Collaboration security components and considerations
- Basic ASA UC Inspection features
- Describe common IPv6 security considerations
- Unified IPv6/Pv4 ACL on the ASA
Implementing Cisco Edge Network Security Solutions (300-206)
Implementing Cisco Edge Network Security Solutions (300-206) at GATS primarily focuses on providing the skill set and knowledge necessary for a secured network infrastructure using Cisco products. On completing the course the candidate gets the knowledge of how a network security engineer has to configure and implement security on Cisco network perimeter edge devices such as a Cisco switch, Cisco router, and Cisco ASA firewall.
The course focuses on the technologies used to strengthen security of a network perimeter such as Network Address Translation (NAT), ASA policy and application inspect, and a zone-based firewall on Cisco routers.
Exam and Certification
- Exam Code : 300-206
- Exam Duration: 90 minutes
- No. of Questions: 60 to 70 questions
Candidates can prepare for this exam by taking Implementing Cisco Edge Network Security Solutions (300-206) course from GATS.
How to register for the exam ?
Visit a Pearson VUE Authorized exam center and get your exam registered.
You can also register online for the exam from
www.pearsonvue.com
What documents do you require for the exam ?
2 photo ID’s which have your name correctly registered along with your signature are required from any of the following:
Passport, Driver’s License, Pan Card, UID issued by Govt., Voter’s IDetc