The
following topics are general guidelines
for the content likely to be included
on the CCSP SECUR Exam 642-501. However,
other related topics may also appear on
any specific delivery of the exam (excerpts
from Cisco Certification web site).
1. Basic Cisco Router Security
1.1. Secure administrative access for
Cisco routers
1.2. Describe the components of a basic
AAA implementation
1.3. Test the perimeter router AAA implementation
using applicable debug commands
2. Advanced AAA Security for Cisco Router
Networks
2.1. Describe the features and architecture
of CSACS 3.0 for Windows
2.2. Configure the perimeter router to
enable AAA processes to use a TACACS
remote service
3. Cisco Router Threat Mitigation
3.1. Disable unused router services and
interfaces
3.2. Use access lists to mitigate common
router security threats
4. Cisco IOS Firewall CBAC Configuration
4.1. Define the Cisco IOS Firewall and
CBAC
4.2. Configure CBAC
5. Cisco IOS Firewall Authentication
Proxy Configuration
5.1. Describe how authentication proxy
technology works
5.2. Configure AAA on a Cisco IOS Firewall
6. Cisco IOS Firewall IDS Configuration
6.1. Name the two types of signature
implementations used by the Cisco IOS
Firewall IDS
6.2. Initialize a Cisco IOS Firewall
IDS router
7. Building Basic IPSec Using Cisco
Routers
7.1. Configure a Cisco router for IPSec
using pre-shared keys
7.2. Verify the IKE and IPSec configuration
7.3. Explain the issues regarding configuring
IPSec manually and using RSA encrypted
nonces
8. Building Advanced IPSec VPNs Using
Cisco Routers and Certificate Authorities
8.1. Advanced IPSec VPNs using Cisco
Routers and CAs
9. Configuring Cisco Remote Access IPSec
VPNs
9.1. Describe the Easy VPN Server
10. Managing Enterprise VPN Routers
10.1. Managing Enterprise VPN Routers
|