About Course
Course Objectives
-
Describe information security concepts, strategies, and common network attacks.
-
Implement access control using Cisco ASA and Firepower NGFW devices.
-
Deploy email and web content security using Cisco Email Security Appliance and Web Security Appliance.
-
Configure Cisco Umbrella, VPNs, and cryptography solutions.
-
Implement secure site-to-site and remote access VPNs using Cisco IOS and NGFW platforms.
-
Configure endpoint security using AMP for Endpoints.
-
Secure network infrastructure with control, management, and data plane protections.
-
Monitor and analyze network traffic using Stealthwatch Enterprise and Cloud.
-
Understand cloud security fundamentals and software-defined networking (SDN) concepts.
Course Outline
-
Information Security Concepts – Overview, assets, vulnerabilities, countermeasures, and risk management.
-
Common TCP/IP, Network Application, and Endpoint Attacks – Legacy vulnerabilities, DNS attacks, malware, and reconnaissance.
-
Network Security Technologies – Defense-in-depth, segmentation, and virtualization.
-
Deploying Cisco ASA and Firepower NGFW – Access control, NAT, policies, packet processing, and objects.
-
Email and Web Content Security – Email pipeline, SMTP, proxy services, authentication, malware protection.
-
Cisco Umbrella – Architecture, deployment, roaming client, and investigative console.
-
VPN and Cryptography – Site-to-site and remote access VPNs, IPsec, VTI, and SSL VPNs.
-
Cisco Secure Network Access & 802.1X – AAA, authentication methods, and role-based access.
-
Endpoint Security – AMP for Endpoints, host-based firewalls, anti-virus, and IPS.
-
Network Infrastructure Protection – Control plane, management plane, Layer 2/3 data plane security.
-
Traffic Telemetry and Monitoring – NTP, logging, NetFlow, and telemetry.
-
Cisco Stealthwatch Enterprise & Cloud – Network and cloud monitoring, CTA, alerting, watchlists.
-
Cloud Security & SDN Concepts – Cloud threats, security responsibilities, SDN fundamentals, and network programmability.
Lab Outline
-
Configure ASA and Firepower NGFW NAT and access control policies.
-
Configure IPS, malware, file policies, and discovery on Firepower NGFW.
-
Configure ESA mail policies and proxy services.
-
Explore Cisco Umbrella dashboards, investigate console, and ransomware protection.
-
Configure site-to-site and remote access VPNs (VTI/IPsec/SSL) on ASA and NGFW.
-
Explore AMP for Endpoints, perform endpoint analysis, and configure ransomware protection.
-
Explore Stealthwatch Enterprise, Cognitive Threat Analytics, and Cloudlock dashboards.
-
Explore Stealthwatch Cloud monitoring, alert settings, and sensors.
