Thursday, 12 May 2016

400-051 CCIE Collaboration Written Exam Topics v1.0 and Version 1.1

Exam Number 400-051 CCIE Collaboration
Associated Certifications CCIE Collaboration
Duration 120 minutes (90 - 110 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

 This exam validates that candidates have the skills to plan, design, implement, operate, and troubleshoot enterprise collaboration and communication networks.

Written Exam Topics v1.0 (Recommended for candidates scheduled to take the test BEFORE July 25, 2016)

Written Exam Topics v1.1 (Recommended for candidates scheduled to take the test ON July 25, 2016 and beyond)

Exam Description
The Cisco CCIE® Collaboration Written Exam (400-051) version 1.0 has 90-110 questions and is 2 hours in duration. This exam validates that candidates have the skills to plan, design, implement, operate, and troubleshoot enterprise collaboration and communication networks. The exam is closed book, and no outside reference materials are allowed.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

CCIE Collaboration Written Exam Topics v1.0 (Recommended for candidates who are scheduled to take the exam BEFORE July 25, 2016)

1.0 Cisco Collaboration Infrastructure 10%

1.1 Cisco UC Deployment Models

1.2 User management

1.3 IP routing in Cisco Collaboration Solutions

1.4 Virtualization in Cisco Collaboration Solutions

1.4.a UCS
1.4.b VMware
1.4.c Answer files

1.5 Wireless in Cisco Collaboration Solutions

1.6 Network services

1.6.a DNS
1.6.b DHCP
1.6.c TFTP
1.6.d NTP
1.6.e CDP/LLDP

1.7 PoE

1.8 Voice and data VLAN

1.9 IP multicast

1.10 IPv6

2.0 Telephony Standards and Protocols 15%


2.1 SCCP

2.1.a Call flows
2.1.b Call states
2.1.c Endpoint types

2.2 MGCP

2.2.a Call flows
2.2.b Call states
2.2.c Endpoint types

2.3 SIP

2.3.a Call flows
2.3.b Call states
2.3.c DP
2.3.d BFCP

2.4 H.323 and RAS

2.4.a Call flows
2.4.b Call states
2.4.c Gatekeeper
2.4.d H.239

2.5 Voice and video CODECs

2.5.a H.264
2.5.b ILBC
2.5.c ISAC
2.5.d LATM
2.5.e G.722
2.5.f Wide band

2.6 RTP, RTCP, and SRTP

3.0 Cisco Unified Communications Manager (CUCM) 25%

3.1 Device registration and redundancy

3.2 Device settings

3.3 Codec selection

3.4 Call features

3.4.a Call park
3.4.b Call pickup
3.4.c BLF speed dials
3.4.d Native call queuing
3.4.e Call hunting
3.4.f Meet-Me

3.5 Dial plan

3.5.a Globalized call routing
3.5.b Local route group
3.5.c Time-of-day routing
3.5.d Application dial rules
3.5.e Digit manipulations

3.6 Media resources

3.6.a TRP
3.6.b MOH
3.6.c CFB
3.6.d Transcoder and MTP
3.6.e Annunciator
3.6.f MRG and MRGL

3.7 CUCM mobility

3.7.a EM/EMCC
3.7.b Device Mobility
3.7.c Mobile Connect
3.7.d MVA

3.8 CUCM serviceability and OS administration

3.8.a Database replication
3.8.b CDR
3.8.c Service activation
3.8.d CMR

3.9 CUCM disaster recovery

3.10 ILS/URI dialing

3.10.a Directory URI
3.10.b ISL topology
3.10.c Blended addressing

3.11 Call Admission Control

3.11.a CAC/ELCAC
3.11.b RSVP
3.11.c SIP preconditions

3.12 SIP and H.323 trunks

3.12.a SIP trunks
3.12.b H.323 trunks
3.12.c Number presentation and manipulation

3.13 SAF and CCD

3.14 Call recording and silent monitoring

4.0 Cisco IOS UC Applications and Features 20%
4.1 CUCME

4.1.a SCCP phones registration
4.1.b SIP phones Registration
4.1.c SNR

4.2 SRST

4.2.a CME-as-SRST
4.2.b MGCP fallback
4.2.c MMOH in SRST

4.3 CUE

4.3.a AA
4.3.b Scripting
4.3.c Voiceview
4.3.d Web inbox
4.3.e MWI
4.3.f VPIM

4.4 Cisco IOS-based call queuing

4.4.a B-ACD
4.4.b Voice hunt groups
4.4.c Call blast

4.5 Cisco IOS media resources

4.5.a Conferencing
4.5.b Transcoding
4.5.c DSP management

4.6 CUBE

4.6.a Mid-call signaling
4.6.b SIP profiles
4.6.c Early and delayed offer
4.6.d DTMF interworking
4.6.e Box-to-box failover and redundancy

4.7 Fax and modem protocols

4.8 Analog telephony signalling

4.8.a Analog telephony signalling theories (FXS/FXO)
4.8.b Caller ID
4.8.c Line voltage detection
4.8.d THL sweep
4.8.e FXO disconnect
4.8.f Echo

4.9 Digital telephony signalling

4.9.a Digital telephony signalling theories (T1/E1, BRI/PRI/CAS)
4.9.b Q.921 and Q.931
4.9.c QSIG
4.9.d Caller ID
4.9.e R2
4.9.f NFAS

4.10 Cisco IOS dial plan

4.10.a Translation profile
4.10.b Dial-peer matching logics
4.10.c Test commands

4.11 SAF/CCD

4.12 IOS CAC

4.13 IOS accounting

5.0 Quality of Service and Security in Cisco Collaboration Solutions 12%

5.1 QoS: link efficiency

5.1.a LFI
5.1.b MMLPPP
5.1.c FRF.12
5.1.d cRTP
5.1.e VAD

5.2 QoS: classification and marking

5.2.a Voice versus video classification
5.2.b Soft clients versus hard clients
5.2.c Trust boundaries

5.3 QoS: congestion management

5.3.a Layer 2 priorities
5.3.b Low latency queue
5.3.c Traffic policing and shaping

5.4 QoS: medianet

5.5 QoS: wireless QoS

5.6 Security: mixed mode cluster

5.7 Security: secured phone connectivity

5.7.a VPN phones
5.7.b Phone proxy
5.7.c TLS proxy
5.7.d IEEE 802.1x

5.8 Security: default security features

5.9 Security: firewall traversal

5.10 Security: toll fraud

6.0 Cisco Unity Connection  8%

6.1 CUCM and CUCME integration

6.2 Single inbox

6.3 MWI

6.4 Call handlers

6.5 CUC dial plan

6.6 Directory handlers

6.7 CUC features


6.7.a High availability
6.7.b Visual voicemail
6.7.c Voicemail for Jabber

6.8 Voicemail networking

7.0 Cisco Unified Contact Center Express 4%

7.1 UCCX CTI Integration

7.2 ICD functions

7.3 UCCX scripting components

8.0 Cisco Unified IM and Presence 6%

8.1 Cisco Unified IM Presence Components

8.2 CUCM integration

8.3 Cisco Jabber

8.4 Federation

8.5 Presence Cloud Solutions

8.6 Group chat and compliance

CCIE Collaboration Written Exam (400-051) Version 1.1

Exam Description

The Cisco CCIE® Collaboration Written Exam [400-051] version 1.1 has 90-110 questions and is 2 hours in duration. This exam validates that candidates have the skills to plan, design, implement, operate, and troubleshoot enterprise collaboration and communication networks. The exam is closed book, and no outside reference materials are allowed.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

CCIE Collaboration Written Exam Topics v1.1 (Recommended for candidates who are scheduled to take the exam ON July 25, 2016 and beyond)

1.0 Cisco Collaboration Infrastructure 10%

1.1 Cisco UC Deployment Models

1.2 User management

1.3 IP routing in Cisco Collaboration Solutions

1.4 Virtualization in Cisco Collaboration Solutions

1.4.a UCS
1.4.b VMware
1.4.c Answer files

1.5 Wireless in Cisco Collaboration Solutions

1.6 Network services

1.6.a DNS
1.6.b DHCP
1.6.c TFTP
1.6.d NTP
1.6.e CDP/LLDP

1.7 PoE

1.8 Voice and data VLAN

1.9 IP multicast

1.10 IPv6

2.0 Telephony Standards and Protocols 12%

2.1 SCCP

2.1.a Call flows
2.1.b Call states
2.1.c Endpoint types

2.2 MGCP

2.2.a Call flows
2.2.b Call states
2.2.c Endpoint types

2.3 SIP

2.3.a Call flows
2.3.b Call states
2.3.c DP
2.3.d BFCP

2.4 H.323 and RAS

2.4.a Call flows
2.4.b Call states
2.4.c Gatekeeper
2.4.d H.239

2.5 Voice and video CODECs

2.5.a H.264
2.5.b ILBC
2.5.c ISAC
2.5.d LATM
2.5.e G.722
2.5.f Wide band

2.6 RTP, RTCP, and SRTP

3.0 Cisco Unified Communications Manager [CUCM] 22%


3.1 Device registration and redundancy

3.2 Device settings

3.3 Codec selection

3.4 Call features

3.4.a Call park
3.4.b Call pickup
3.4.c BLF speed dials
3.4.d Native call queuing
3.4.e Call hunting
3.4.f Meet-Me

3.5 Dial plan

3.5.a Globalized call routing
3.5.b Local route group
3.5.c Time-of-day routing
3.5.d Application dial rules
3.5.e Digit manipulations

3.6 Media resources

3.6.a TRP
3.6.b MOH
3.6.c CFB
3.6.d Transcoder and MTP
3.6.e Annunciator
3.6.f MRG and MRGL

3.7 CUCM mobility

3.7.a EM/EMCC
3.7.b Device Mobility
3.7.c Mobile Connect
3.7.d MVA

3.8 CUCM serviceability and OS administration

3.8.a Database replication
3.8.b CDR
3.8.c Service activation
3.8.d CMR

3.9 CUCM disaster recovery

3.10 ILS/URI dialing

3.10.a Directory URI
3.10.b ISL topology
3.10.c Blended addressing

3.11 Call Admission Control

3.11.a CAC/ELCAC
3.11.b RSVP
3.11.c SIP preconditions

3.12 SIP and H.323 trunks

3.12.a SIP trunks
3.12.b H.323 trunks
3.12.c Number presentation and manipulation

3.13 SAF and CCD

3.14 Call recording and silent monitoring

4.0 Cisco IOS UC Applications and Features 16%

4.1 CUCME

4.1.a SCCP phones registration
4.1.b SIP phones Registration
4.1.c SNR

4.2 SRST

4.2.a CME-as-SRST
4.2.b MGCP fallback
4.2.c MMOH in SRST

4.3 CUE

4.3.a AA
4.3.b Scripting
4.3.c Voiceview
4.3.d Web inbox
4.3.e MWI
4.3.f VPIM

4.4 Cisco IOS-based call queuing

4.4.a B-ACD
4.4.b Voice hunt groups
4.4.c Call blast

4.5 Cisco IOS media resources

4.5.a Conferencing
4.5.b Transcoding
4.5.c DSP management

4.6 CUBE

4.6.a Mid-call signaling
4.6.b SIP profiles
4.6.c Early and delayed offer
4.6.d DTMF interworking
4.6.e Box-to-box failover and redundancy

4.7 Fax and modem protocols

4.8 Analog telephony signalling

4.8.a Analog telephony signalling theories [FXS/FXO]
4.8.b Caller ID
4.8.c Line voltage detection
4.8.d THL sweep
4.8.e FXO disconnect
4.8.f Echo

4.9 Digital telephony signalling

4.9.a Digital telephony signalling theories [T1/E1, BRI/PRI/CAS]
4.9.b Q.921 and Q.931
4.9.c QSIG
4.9.d Caller ID
4.9.e R2
4.9.f NFAS

4.10 Cisco IOS dial plan

4.10.a Translation profile
4.10.b Dial-peer matching logics
4.10.c Test commands

4.11 SAF/CCD

4.12 IOS CAC

4.13 IOS accounting

5.0 Quality of Service and Security in Cisco Collaboration Solutions 12%

5.1 QoS: link efficiency

5.1.a LFI
5.1.b MMLPPP
5.1.c FRF.12
5.1.d cRTP
5.1.e VAD

5.2 QoS: classification and marking

5.2.a Voice versus video classification
5.2.b Soft clients versus hard clients
5.2.c Trust boundaries

5.3 QoS: congestion management

5.3.a Layer 2 priorities
5.3.b Low latency queue
5.3.c Traffic policing and shaping

5.4 QoS: medianet

5.5 QoS: wireless QoS

5.6 Security: mixed mode cluster

5.7 Security: secured phone connectivity

5.7.a VPN phones
5.7.b Phone proxy
5.7.c TLS proxy
5.7.d IEEE 802.1x

5.8 Security: default security features

5.9 Security: firewall traversal

5.10 Security: toll fraud

6.0 Cisco Unity Connection 8%

6.1 CUCM and CUCME integration

6.2 Single inbox

6.3 MWI

6.4 Call handlers

6.5 CUC dial plan

6.6 Directory handlers

6.7 CUC features

6.7.a High availability
6.7.b Visual voicemail
6.7.c Voicemail for Jabber

6.8 Voicemail networking

7.0 Cisco Unified Contact Center Express 4%

7.1 UCCX CTI Integration

7.2 ICD functions

7.3 UCCX scripting components

8.0 Cisco Unified IM and Presence 6%

8.1 Cisco Unified IM Presence Components

8.2 CUCM integration

8.3 Cisco Jabber

8.4 Federation

8.5 Presence Cloud Solutions

8.6 Group chat and compliance

9.0 Evolving Technologies 10%

9.1 Cloud

9.1.a Compare and contrast Cloud deployment models
9.1.a [i] Infrastructure, platform, and software services [XaaS]
9.1.a [ii] Performance and reliability
9.1.a [iii] Security and privacy
9.1.a [iv] Scalability and interoperability
9.1.b Describe Cloud implementations and operations
9.1.b [i] Automation and orchestration
9.1.b [ii] Workload mobility
9.1.b [iii] Troubleshooting and management
9.1.b [iv] OpenStack components

9.2 Network programmability [SDN]

9.2.a Describe functional elements of network programmability [SDN] and how they interact
9.2.a [i] Controllers
9.2.a [ii] APIs
9.2.a [iii] Scripting
9.2.a [iv] Agents
9.2.a [v] Northbound vs. Southbound protocols
9.2.b Describe aspects of virtualization and automation in network environments
9.2.b [i] DevOps methodologies, tools and workflows
9.2.b [ii] Network/application function virtualization [NFV, AFV]
9.2.b [iii] Service function chaining
9.2.b [iv] Performance, availability, and scaling considerations

9.3 Internet of Things

9.3.a Describe architectural framework and deployment considerations for Internet of Things [IoT]
9.3.a [i] Performance, reliability and scalability
9.3.a [ii] Mobility
9.3.a [iii] Security and privacy
9.3.a [iv] Standards and compliance
9.3.a [v] Migration
9.3.a [vi] Environmental impacts on the network


QUESTION 1
A SIP carried delivers DIDs to a Cisco Unified Border Element in the form of +155567810XX,
where the last two digits could be anything from 00 to 99. To match the internal dial plan, that
number must be changed to 6785XXX, where the last two digits should be retained. Which two
translation profiles create the required outcome? (Choose two)

A. rule 1 /555\(.*\).*\(.*\)/ /\150\2/
B. rule 1 /+ 1555\(…\).\(…\)$/ /\15\2/
C. rule 1 /^\+ 1555\(678\)10\(..\)$/ /\150\2/
D. rule 1 /^15+678\(… .\)/678\1/
E. rule 1 /.15+678?10?\(..\)/ /67850\1/

Answer: C,E
Explanation:


QUESTION 2
Which Cisco Unified CM service is responsible for detecting new Call Detail Records files and
transferring them to the CDR Repository node?

A. Cisco CallManager
B. Cisco CDR Repository Manager
C. Cisco SOAP-CDRonDemand Service
D. Cisco Extended Functions
E. Cisco CDR Agent

Answer: E
Explanation:


QUESTION 3
Users report that they are unable to control their Cisco 6941 desk phone from their Jabber client,
but the Jabber client works as a soft phone. Which two configuration changes allow this? (Choose two)

A. Assign group “Standard CTI Allow Control of Phones supporting Connected Xfer and Conf” to the user.
B. Set the End User page to the Primary Extension on the desk phone.
C. Set the Owner User ID on the desk phone.
D. Assign group “Standard CTI Enabled User Group” to the user.
E. Assign group “Standard CTI Allow Control of Phones Supporting Rollover Mode” to the user.

Answer: A,E
Explanation:


QUESTION 4
Which two parameters, in the reply of an MGCP gateway to an Audit Endpoint message, indicate
to a Cisco Unified CM that it has an active call on an endpoint? (Choose two)

A. Bearer Information
B. Call ID
C. Capabilities
D. Connection ID
E. Connection Parameters
F. Connection Mode

Answer: A,D
Explanation:


QUESTION 5
Where the administrator can reset all database replication and initiate a broadcast of all tables on
a Cisco Unified CM cluster running version 9.1?

A. Real Time Monitoring Tool
B. Cisco Unified Serviceability
C. Cisco Unified OS Administration
D. Cisco Unified CM CLI
E. Disaster Recovery System

Answer: D
Explanation:


QUESTION 6
During a Cisco Connection extension greeting, callers can press a single key to be transferred to a
specific extension. However, callers report that the system does not process the call immediately
after pressing the key. Which action resolves this issue?

A. Reduce Caller Input timeout in Cisco Unity Connection Service Parameters.
B. Lower the timer Wait for Additional Digits on the Caller input page.
C. Enable Ignore Additional Input on the Edit Caller input page for the selected key.
D. Enable Prepend Digits to Dialed Extensions and configure complete extension number on the
Edit Caller input page for the selected key.
E. Reduce Caller input timeout in Cisco Unity Connection Enterprise Parameters.

Answer: C
Explanation:

Saturday, 7 May 2016

350-018 CCIE Security version 4.0 and version 4.1

CCIE Security
Exam Number 350-018 CCIE Security
Associated Certifications CCIE Security
Duration 120 minutes (90 - 110 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

This exam tests the skills and competencies of security professionals in terms of describing, implementing, deploying, configuring, maintaining, and troubleshooting Cisco network security solutions and products, as well as current industry best practices and internetworking fundamentals.

Topics include networking fundamentals and security-related concepts and best practices, as well as Cisco network security products and solutions in areas such as VPNs, intrusion prevention, firewalls, identity services, policy management, and device hardening. Content includes both IPv4 and IPv6 concepts and solutions.

CCIE Security Written Exam (350-018) version 4.0

Exam Description
The Cisco CCIE® Security Written Exam (350-018) version 4.0 is a 2-hour test with 90–110 questions. This exam tests the skills and competencies of security professionals in terms of describing, implementing, deploying, configuring, maintaining, and troubleshooting Cisco network security solutions and products, as well as current industry best practices and internetworking fundamentals.

Topics include networking fundamentals and security-related concepts and best practices, as well as Cisco network security products and solutions in areas such as VPNs, intrusion prevention, firewalls, identity services, policy management, and device hardening. Content includes both IPv4 and IPv6 concepts and solutions.

The exam is closed book, and no outside reference materials are allowed.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

CCIE Security Written Exam Topics v4.0 (Recommended for candidates who are scheduled to take the exam BEFORE July 25, 2016)


1.0 Infrastructure, Connectivity, Communications, and Network Security 20%

1.1 Network addressing basics

1.2 OSI layers

1.3 TCP/UDP/IP protocols

1.4 LAN switching (for example, VTP, VLANs, spanning tree, and trunking)

1.5 Routing protocols (for example, RIP, EIGRP, OSPF, and BGP)

1.5.a Basic functions and characteristics
1.5.b Security features

1.6 Tunneling protocols

1.6.a GRE
1.6.b NHRP
1.6.c IPv6 tunnel types

1.7 IP multicast

1.7.a PIM
1.7.b MSDP
1.7.c IGMP and CGMP
1.7.d Multicast Listener Discovery

1.8 Wireless

1.8.a SSID
1.8.b Authentication and authorization
1.8.c Rogue APs
1.8.d Session establishment

1.9 Authentication and authorization technologies

1.9.a Single sign-on
1.9.b OTPs
1.9.c LDAP and AD
1.9.d RBAC

1.10 VPNs

1.10.a L2 vs L3
1.10.b MPLS, VRFs, and tag switching

1.11 Mobile IP networks

2.0 Security Protocols 15%

2.1 RSA

2.2 RC4

2.3 MD5

2.4 SHA

2.5 DES

2.6 3DES

2.7 AES

2.8 IPsec

2.9 ISAKMP

2.10 IKE and IKEv2

2.11 GDOI

2.12 AH

2.13 ESP

2.14 CEP

2.15 TLS and DTLS

2.16 SSL

2.17 SSH

2.18 RADIUS

2.19 TACACS+

2.20 LDAP

2.21 EAP methods (for example, EAP-MD5, EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, and LEAP)

2.22 PKI, PKIX, and PKCS

2.23 IEEE 802.1X

2.24 WEP, WPA, and WPA2

2.25 WCCP

2.26 SXP

2.27 MACsec

2.28 DNSSEC
3.0 Application and Infrastructure Security 10%

3.1 HTTP

3.2 HTTPS

3.3 SMTP

3.4 DHCP

3.5 DNS

3.6 FTP and SFTP

3.7 TFTP

3.8 NTP

3.9 SNMP

3.10 syslog

3.11 Netlogon, NetBIOS, and SMB

3.12 RPCs

3.13 RDP and VNC

3.14 PCoIP

3.15 OWASP

3.16 Manage unnecessary services

4.0 Threats, Vulnerability Analysis, and Mitigation 10%

4.1 Recognize and mitigate common attacks

4.1.a ICMP attacks and PING floods
4.1.b MITM
4.1.c Replay
4.1.d Spoofing
4.1.e Backdoor
4.1.f Botnets
4.1.g Wireless attacks
4.1.h DoS and DDoS attacks
4.1.i Virus and worm outbreaks
4.1.j Header attacks
4.1.k Tunneling attacks

4.2 Software and OS exploits

4.3 Security and attack tools

4.4 Generic network intrusion prevention concepts

4.5 Packet filtering

4.6 Content filtering and packet inspection

4.7 Endpoint and posture assessment

4.8 QoS marking attacks

5.0 Cisco Security Products, Features, and Management 20%

5.1 Cisco Adaptive Security Appliance (ASA)

5.1.a Firewall functionality
5.1.b Routing and multicast capabilities
5.1.c Firewall modes
5.1.d NAT (before and after version 8.4)
5.1.e Object definition and ACLs
5.1.f MPF functionality (IPS, QoS, and application awareness)
5.1.g Context-aware firewall
5.1.h Identity-based services
5.1.i Failover options

5.2 Cisco IOS firewalls and NAT

5.2.a CBAC
5.2.b Zone-based firewall
5.2.c Port-to-application mapping
5.2.d Identity-based firewalling

5.3 Cisco Intrusion Prevention Systems (IPS)

5.4 Cisco IOS IPS

5.5 Cisco AAA protocols and application

5.5.a RADIUS
5.5.b TACACS+
5.5.c Device administration
5.5.d Network access
5.5.e IEEE 802.1X
5.5.f VSAs

5.6 Cisco Identity Services Engine (ISE)

5.7 Cisco Secure ACS Solution Engine

5.8 Cisco Network Admission Control (NAC) Appliance Server

5.9 Endpoint and client

5.9.a Cisco AnyConnect VPN Client
5.9.b Cisco VPN Client
5.9.c Cisco Secure Desktop
5.9.d Cisco NAC Agent

5.10 Secure access gateways (Cisco IOS router or ASA)

5.10.a IPsec
5.10.b SSL VPN
5.10.c PKI

5.11 Virtual security gateway

5.12 Cisco Catalyst 6500 Series ASA Services Modules

5.13 ScanSafe functionality and components

5.14 Cisco Web Security Appliance and Cisco Email Security Appliance

5.15 Security management

5.15.a Cisco Security Manager
5.15.b Cisco Adaptive Security Device Manager (ASDM)
5.15.c Cisco IPS Device Manager (IDM)
5.15.d Cisco IPS Manager Express (IME)
5.15.e Cisco Configuration Professional
5.15.f Cisco Prime

6.0 Cisco Security Technologies and Solutions 17%

6.1 Router hardening features (for example, CoPP, MPP, uRPF, and PBR)

6.2 Switch security features (for example, anti-spoofing, port, STP, MACSEC, NDAC, and NEAT)

6.3 NetFlow

6.4 Wireless security

6.5 Network segregation

6.5.a VRF-aware technologies
6.5.b VXLAN

6.6 VPN solutions

6.6.a FlexVPN
6.6.b DMVPN
6.6.c GET VPN
6.6.d Cisco EasyVPN

6.7 Content and packet filtering

6.8 QoS application for security

6.9 Load balancing and failover

7.0 Security Policies and Procedures, Best Practices, and Standards 8%

7.1 Security policy elements

7.2 Information security standards (for example, ISO/IEC 27001 and ISO/IEC 27002)

7.3 Standards bodies (for example, ISO, IEC, ITU, ISOC, IETF, IAB, IANA, and ICANN)

7.4 Industry best practices (for example, SOX and PCI DSS)

7.5 Common RFC and BCP (for example, RFC2827/BCP38, RFC3704/BCP84, and RFC5735)

7.6 Security audit and validation

7.7 Risk assessment

7.8 Change management process

7.9 Incident response framework

7.10 Computer security forensics

7.11 Desktop security risk assessment and desktop security risk management

CCIE Security Written Exam (350-018) Version 4.1

Exam Description
The Cisco CCIE® Security Written Exam [350-018] version 4.1 is a 2-hour test with 90–110 questions. This exam tests the skills and competencies of security professionals in terms of describing, implementing, deploying, configuring, maintaining, and troubleshooting Cisco network security solutions and products, as well as current industry best practices and internetworking fundamentals.

Topics include networking fundamentals and security-related concepts and best practices, as well as Cisco network security products and solutions in areas such as VPNs, intrusion prevention, firewalls, identity services, policy management, and device hardening. Content includes both IPv4 and IPv6 concepts and solutions.

The exam is closed book, and no outside reference materials are allowed.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

CCIE Security Written Exam Topics v4.1 (Recommended for candidates who are scheduled to take the exam ON July 25, 2016 and beyond)


1.0 Infrastructure, Connectivity, Communications, and Network Security 14%

1.1 Network addressing basics

1.2 OSI layers

1.3 TCP/UDP/IP protocols

1.4 LAN switching [for example, VTP, VLANs, spanning tree, and trunking]

1.5 Routing protocols [for example, RIP, EIGRP, OSPF, and BGP]

1.5.a Basic functions and characteristics
1.5.b Security features

1.6 Tunneling protocols

1.6.a GRE
1.6.b NHRP
1.6.c IPv6 tunnel types

1.7 IP multicast

1.7.a PIM
1.7.b MSDP
1.7.c IGMP and CGMP
1.7.d Multicast Listener Discovery

1.8 Wireless

1.8.a SSID
1.8.b Authentication and authorization
1.8.c Rogue APs
1.8.d Session establishment

1.9 Authentication and authorization technologies

1.9.a Single sign-on
1.9.b OTPs
1.9.c LDAP and AD
1.9.d RBAC

1.10 VPNs

1.10.a L2 vs L3
1.10.b MPLS, VRFs, and tag switching

1.11 Mobile IP networks

2.0 Security Protocols 14%

2.1 RSA

2.2 RC4

2.3 MD5

2.4 SHA

2.5 DES

2.6 3DES

2.7 AES

2.8 IPsec

2.9 ISAKMP

2.10 IKE and IKEv2

2.11 GDOI

2.12 AH

2.13 ESP

2.14 CEP

2.15 TLS and DTLS

2.16 SSL

2.17 SSH

2.18 RADIUS

2.19 TACACS+

2.20 LDAP

2.21 EAP methods [for example, EAP-MD5, EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, and LEAP]

2.22 PKI, PKIX, and PKCS

2.23 IEEE 802.1X

2.24 WEP, WPA, and WPA2

2.25 WCCP

2.26 SXP

2.27 MACsec

2.28 DNSSEC

3.0 Application and Infrastructure Security 10%

3.1 HTTP

3.2 HTTPS

3.3 SMTP

3.4 DHCP

3.5 DNS

3.6 FTP and SFTP

3.7 TFTP

3.8 NTP

3.9 SNMP

3.10 syslog

3.11 Netlogon, NetBIOS, and SMB

3.12 RPCs

3.13 RDP and VNC

3.14 PCoIP

3.15 OWASP

3.16 Manage unnecessary services

4.0 Threats, Vulnerability Analysis, and Mitigation 10%

4.1 Recognize and mitigate common attacks

4.1.a ICMP attacks and PING floods
4.1.b MITM
4.1.c Replay
4.1.d Spoofing
4.1.e Backdoor
4.1.f Botnets
4.1.g Wireless attacks
4.1.h DoS and DDoS attacks
4.1.i Virus and worm outbreaks
4.1.j Header attacks
4.1.k Tunneling attacks

4.2 Software and OS exploits

4.3 Security and attack tools

4.4 Generic network intrusion prevention concepts

4.5 Packet filtering

4.6 Content filtering and packet inspection

4.7 Endpoint and posture assessment

4.8 QoS marking attacks

5.0 Cisco Security Products, Features, and Management 18%

5.1 Cisco Adaptive Security Appliance [ASA]

5.1.a Firewall functionality
5.1.b Routing and multicast capabilities
5.1.c Firewall modes
5.1.d NAT [before and after version 8.4]
5.1.e Object definition and ACLs
5.1.f MPF functionality [IPS, QoS, and application awareness]
5.1.g Context-aware firewall
5.1.h Identity-based services
5.1.i Failover options

5.2 Cisco IOS firewalls and NAT

5.2.a CBAC
5.2.b Zone-based firewall
5.2.c Port-to-application mapping
5.2.d Identity-based firewalling

5.3 Cisco Intrusion Prevention Systems [IPS]

5.4 Cisco IOS IPS

5.5 Cisco AAA protocols and application

5.5.a RADIUS
5.5.b TACACS+
5.5.c Device administration
5.5.d Network access
5.5.e IEEE 802.1X
5.5.f VSAs

5.6 Cisco Identity Services Engine [ISE]

5.7 Cisco Secure ACS Solution Engine

5.8 Cisco Network Admission Control [NAC] Appliance Server

5.9 Endpoint and client

5.9.a Cisco AnyConnect VPN Client
5.9.b Cisco VPN Client
5.9.c Cisco Secure Desktop
5.9.d Cisco NAC Agent

5.10 Secure access gateways [Cisco IOS router or ASA]

5.10.a IPsec
5.10.b SSL VPN
5.10.c PKI

5.11 Virtual security gateway

5.12 Cisco Catalyst 6500 Series ASA Services Modules

5.13 ScanSafe functionality and components

5.14 Cisco Web Security Appliance and Cisco Email Security Appliance

5.15 Security management

5.15.a Cisco Security Manager
5.15.b Cisco Adaptive Security Device Manager [ASDM]
5.15.c Cisco IPS Device Manager [IDM]
5.15.d Cisco IPS Manager Express [IME]
5.15.e Cisco Configuration Professional
5.15.f Cisco Prime

6.0 Cisco Security Technologies and Solutions 16%

6.1 Router hardening features [for example, CoPP, MPP, uRPF, and PBR]

6.2 Switch security features [for example, anti-spoofing, port, STP, MACSEC, NDAC, and NEAT]

6.3 NetFlow

6.4 Wireless security

6.5 Network segregation

6.5.a VRF-aware technologies
6.5.b VXLAN

6.6 VPN solutions

6.6.a FlexVPN
6.6.b DMVPN
6.6.c GET VPN
6.6.d Cisco EasyVPN

6.7 Content and packet filtering

6.8 QoS application for security

6.9 Load balancing and failover

7.0 Security Policies and Procedures, Best Practices, and Standards 8%

7.1 Security policy elements

7.2 Information security standards [for example, ISO/IEC 27001 and ISO/IEC 27002]

7.3 Standards bodies [for example, ISO, IEC, ITU, ISOC, IETF, IAB, IANA, and ICANN]

7.4 Industry best practices [for example, SOX and PCI DSS]

7.5 Common RFC and BCP [for example, RFC2827/BCP38, RFC3704/BCP84, and RFC5735]

7.6 Security audit and validation

7.7 Risk assessment

7.8 Change management process

7.9 Incident response framework

7.10 Computer security forensics

7.11 Desktop security risk assessment and desktop security risk management

8.0 Evolving Technologies 10%

8.1 Cloud

8.1.a Compare and contrast Cloud deployment models
8.1.a [i] Infrastructure, platform, and software services [XaaS]
8.1.a [ii] Performance and reliability
8.1.a [iii] Security and privacy
8.1.a [iv] Scalability and interoperability
8.1.b Describe Cloud implementations and operations
8.1.b [i] Automation and orchestration
8.1.b [ii] Workload mobility
8.1.b [iii] Troubleshooting and management
8.1.b [iv] OpenStack components

8.2 Network programmability [SDN]

8.2.a Describe functional elements of network programmability [SDN] and how they interact
8.2.a [i] Controllers
8.2.a [ii] APIs
8.2.a [iii] Scripting
8.2.a [iv] Agents
8.2.a [v] Northbound vs. Southbound protocols
8.2.b Describe aspects of virtualization and automation in network environments
8.2.b [i] DevOps methodologies, tools and workflows
8.2.b [ii] Network/application function virtualization [NFV, AFV]
8.2.b [iii] Service function chaining
8.2.b [iv] Performance, availability, and scaling considerations

8.3 Internet of Things

8.3.a Describe architectural framework and deployment considerations for Internet of Things [IoT]
8.3.a [i] Performance, reliability and scalability
8.3.a [ii] Mobility
8.3.a [iii] Security and privacy
8.3.a [iv] Standards and compliance
8.3.a [v] Migration
8.3.a [vi] Environmental impacts on the network


QUESTION 1
An RSA key pair consists of a public key and a private key and is used to set up PKI. Which statement applies to RSA and PKI?

A. The public key must be included in the certificate enrollment request.
B. The RSA key-pair is a symmetric cryptography.
C. It is possible to determine the RSA key-pair private key from its corresponding public key.
D. When a router that does not have an RSA key pair requests a certificate, the certificate request is sent, but a warning is shown to generate the RSA key pair before a CA signed certificate is received.

Answer: A

Explanation:
An RSA key pair consists of a public key and a private key. When setting up your PKI, you must include the public key in the certificate enrollment request. After the certificate has been granted, the public key will be included in the certificate so that peers can use it to encrypt data that is sent to the router. The private key is kept on the router and used both to decrypt the data sent by peers and to digitally sign transactions when negotiating with peers.
Reference: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuration/xe-3s/sec-pki-xe-3s-book/sec-pki-overview.html


QUESTION 2
Refer to the exhibit.


Which three descriptions of the configuration are true? (Choose three.)

A. The configuration is on the NHS.
B. The tunnel IP address represents the NBMA address.
C. This tunnel is a point-to-point GRE tunnel.
D. The tunnel is not providing peer authentication.
E. The configuration is on the NHC.
F. The tunnel encapsulates multicast traffic.
G. The tunnel provides data confidentiality.

Answer: A,F,G


QUESTION 3
Which two values you must configure on the Cisco ASA firewall to support FQDN ACL? (Choose two.)

A. a DNS server
B. an FQDN object
C. a policy map
D. a class map
E. a service object
F. a service policy

Answer: A,B
Reference: https://supportforums.cisco.com/document/66011/using-hostnames-dns-
access-lists-configuration-steps-caveats-and-troubleshooting


QUESTION 4
Which set of encryption algorithms is used by WPA and WPA2?

A. Blowfish and AES
B. CAST and RC6
C. TKIP and RC6
D. TKIP and AES

Answer: D


QUESTION 5
What are two enhancements in WCCP V2.0 over WCCP V1.0? (Choose two.)

A. support for HTTP redirection
B. multicast support
C. authentication support
D. IPv6 support
E. encryption support

Answer: B,C

Explanation: WCCP V2.0 supports the following enhancements to the WCCP V1.0
Protocol:
* Multi-Router Support.
WCCP V2.0 allows a farm of web-caches to be attached to more than one router.
* Multicast Support.
WCCP V2.0 supports multicasting of protocol messages between web-caches and routers.
* Improved Security.
WCCP V2.0 provides optional authentication of protocol packets received by web-caches and routers.
* Support for redirection of non-HTTP traffic.
WCCP V2.0 supports the redirection of traffic other than HTTP traffic through the concept of Service Groups.
* Packet return.
WCCP V2.0 allows a web-cache to decline to service a redirected packet and to return it to a router to be forwarded. The method by which packets are returned to a router is negotiable.
Reference: https://tools.ietf.org/id/draft-wilson-wrec-wccp-v2-01.txt


Tuesday, 3 May 2016

300-470 CLDAUT Designing the Cisco Cloud

Exam Number 300-470 CLDAUT
Associated Certifications CCNP Cloud
Duration 90 Minutes (55 - 65 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

Exam Description
The Automating the Cisco Enterprise Cloud (CLDAUT) exam (300-470) is a 90-minute, 55–65 question assessment that is associated with the CCNP Cloud Certification. This exam tests a candidate's knowledge and ability to provision private IaaS, provision private IaaS with catalog scaling, provision private IaaS with network automation, provision hybrid IaaS, and perform application provisioning a life-cycle management. Candidates can prepare for this assessment by taking the Automating the Cisco Enterprise Cloud (CLDAUT v1.0) course.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

1.0 Provision Private IaaS Infrastructure 27%

1.1 Create cloud tenant

1.1.a Provision infrastructure devices
1.1.a.1 Provision network
1.1.a.2 Provision compute
1.1.a.3 Provision storage

1.2 Develop policies

1.2.a Network
1.2.b Storage
1.2.c Compute
1.2.d Cost model
1.2.e Service catalog

1.3 Manage virtual data centers

1.3.a Create virtual data center
1.3.b Manage application categories in a VDC

1.4 Manage workflows

1.4.a Create input/output parameters
1.4.b Add tasks to workflow designer
1.4.c Create custom workflow tasks
1.4.d Describe the open automation took kit (SDK)

1.5 Manage catalogs

1.5.a Publish standard and advanced catalogs
1.5.b Cloning a catalog
1.5.c Create user VM action policy
1.5.d Cost (monetary) tracking

1.6 Configure self-service provisioning in Cisco UCS Director

1.6.a Customize portals
1.6.b Create service request workflow
1.6.c Monitor service requests

2.0 Provision Private IaaS Catalog 17%

2.1 Publish Cisco UCS Director services in PSC 11.0

2.1.a Discover Cisco UCS Director catalogs and templates
2.1.b Publish services with RBAC for end-user ordering

2.2 Order PSC IaaS services as end users

2.2.a Login as an end user
2.2.b Order a VM based on standard or advanced
2.2.c Catalogs
2.2.d Order a service container

2.3 Publish application stack services

2.3.a Design application stack services
2.3.b Publish application stack services with RBAC for end-user ordering
2.3.c Order application stack as an end user

3.0 Provision Private IaaS with Network Automation 18%

3.1 Define policies for container

3.1.a Computing policies
3.1.b Network policy
3.1.c Storage policies
3.1.d System policies

3.2 Defining global resource pools

3.2.a Configure VLAN/VXLAN pools
3.2.b Configure IP subnet pools
3.2.c Configure static IP pools

3.3 Creating a Cisco VACS three-tier internal template

3.3.a Specifying a template type
3.3.b Selecting the deployment options
3.3.c Configuring network resource pools
3.3.d Configuring VM networks
3.3.e Adding virtual machines to a template

3.4 Creating a Cisco VACS three-tier external template

3.4.a Define ACL for three-tier external template
3.4.b Configure security zones

3.5 Publish discovered VACS services in PSC 11.0

3.5.a Discover the VACS containers
3.5.b Register the VACS application container templates

4.0 Provision Hybrid IaaS 18%

4.1 Configure intercloud fabric connectivity

4.1.a Set up provider cloud account
4.1.b Set up infrastructure image
4.1.c Set up secure extension
4.1.d Add port profile
4.1.e Create IP pools for VMs
4.1.f Create user groups and users
4.1.g Configure vDCs
4.1.h Configure network and system policies

4.2 Create VM templates to deploy new workloads in the hybrid cloud

4.2.a Configure a virtual machine template
4.2.b Configure network policies
4.2.c Configure system policies
4.2.d Configure storage policies
4.2.e Configure VMware policies (network, system, computing, and storage)
4.2.f Create a catalog for templates

4.3 Create VM templates to migrate workloads between public cloud and private clouds

4.3.a Configure a virtual machine template
4.3.b Configure network policies
4.3.c Configure system policies
4.3.d Configure storage polices
4.3.e Configure VMware policies (network, system, computing, and storage)
4.3.f Create a catalog for templates

4.4 Deploy security appliances in the hybrid cloud

4.4.a Run infrastructure wizard through ICF to bring up ICS services controller and cloud components (such as: PNSC)
4.4.b Add the compute firewall
4.4.c Define compute security profile
4.4.d Define object groups, zones, rules, and policies
4.4.e Create service path
4.4.f Bind the service path to port profile

4.5 Configure routing policies to enable secure communication between hybrid cloud VMs

4.5.a Add edge routers
4.5.b Add system policies
4.5.c Add network policies
4.5.d Add routing policies
4.5.e Assign VMs

4.6 Configure end-user workflows to manage virtual machines in hybrid cloud environment

4.6.a Bursting
4.6.b Sandbox for development
4.6.c Disaster recovery
4.6.d Production deployment on public environment

5.0 Application Provisioning and Life-Cycle Management 20%

5.1 Order a virtual server on PSC 11.0

5.1.a Order a VM based on standard or advanced catalogs
5.1.b Order a service container

5.2 Order a physical server on PSC 11.0

5.2.a Order a bare-metal physical server
5.2.b Order a virtualized physical server

5.3 Order a multitier application container on PSC 11.0

5.3.a Order a three-tier application container

5.4 Managing application containers

5.4.a Access the application container reports
5.4.b Power on the application container
5.4.c Power off the application container
5.4.d Add VMs to application container
5.4.e Delete VMs from application container
5.4.f Delete an application container

5.5 Managing life cycles

5.5.a VM
5.5.b Compute
5.5.c Storage
5.5.d Network

5.6 Snapshots

5.6.a Types
5.6.b Requirements
5.6.c Limitations

QUESTION 1
Cisco Intelligent Automation Cloud is a solution that enables organizations to automate delivery of
physical and virtual servers through the use of a self-service portal. Which two key Cisco products
are used for the automation framework of this solution? (Choose two.)

A. Cisco Process Orchestrator
B. Cisco Prime Service Catalog
C. Cisco Cloud Orchestrator
D. Cisco Server Orchestrator
E. Cisco Process Portal

Answer: A,B

Explanation:


QUESTION 2
Which three statements are true regarding Cisco VACS and its benefit for cloud deployment?
(Choose three.)

A. Cisco VACS offers easy-to-use templates for rapid provisioning.
B. Cisco VACS lacks security although it offers intuitive user interface through Cisco UCS
Director.
C. Cisco VACS is a robust container for three-tier or custom application deployment.
D. CSR benefits up to 10-G/ps throughput with the advent of Cisco VACS support.
E. CSR benefits up to 40-G/ps throughput with the advent of Cisco VACS support.
F. Cisco VACS offers acustom application deployment for the Cisco Prime Service Catalog.

Answer: A,C,D

Explanation:


QUESTION 3
The Cisco UCS Director includes a set of wizards that guide through configuring features. Which
three wizards are available in the Cisco UCS Director? (Choose three.)

A. FlexPod Configuration
B. VDC Creation
C. Catalog Configuration
D. Device Discovery
E. Zoning Creation
F. Storage Discovery

Answer: A,B,D

Explanation:


QUESTION 4
A cost model in UCS Director is used to define the unit level costs of which two virtual resources?
(Choose two.)

A. socket
B. CPU
C. RAM
D. NIC
E. vNIC
F. datastore size

Answer: B,C

Explanation:


QUESTION 5
Which two statements are true regarding role-based access control in Prime Service Catalog?
(Choose two.)

A. IT admin usesthe Cisco Prime Service Catalog as the primary interface to manage tenant life
cycle and services.
B. Tenant admin in the private cloud is associated with tenant billing and cost model.
C. Development of stack designer for application deployment is not within the framework of RBAC.
D. IT admin manages infrastructure in the cloud and uses the Cisco Prime Service Catalog,
Horizon, and Openstack templates as the primary interface.

Answer: A,D

Explanation:

Thursday, 28 April 2016

300-465 CLDDES Designing the Cisco Cloud

Exam Number 300-465 CLDDES
Associated Certifications CCNP Cloud
Duration 90 Minutes (55 - 65 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

Exam Description
The 300-465 (CLDDES) Designing the Cisco Cloud is a 90-minute, 55-65 question assessment that is associated with the CCNP Cloud Certification. This exam tests a candidate's knowledge and ability to: translate requirements into cloud/automation process designs; design Private Cloud infrastructures; design Public Cloud infrastructures, design Cloud Security Policies; and design Virtualization and Virtual Network Services. Candidates can prepare for this assessment by taking the Designing the Cisco Cloud (CLDDES v1.0) course.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

1.0 Translate Requirements into Automation Designs 22%

1.1 Gather business requirements

1.1.a Identify key business requirements for cloud/automation
1.1.b Choose appropriate cloud implementation to meet business requirements

1.2 Describe automation as a foundation of cloud design

1.3 Design appropriate automation tasks to meet requirements

1.3.a Design infrastructure container automation within UCS Director
1.3.b Design catalog
1.3.c Define infrastructure container
1.3.d Design workflow and services

1.4 Design Prime Services Catalog store front for UCS Director

1.5 Design Application and Platform as a Service using Stack Designer

1.6 Select the appropriate solution to automate private or hybrid clouds

1.6.a Cisco Enablement Platform
1.6.b UCS Director
1.6.c Cisco Intelligent Automation for Cloud (CIAC)

2.0 Design a Private Cloud Infrastructure 22%

2.1 Compare and contrast the various private cloud integrated infrastructures

2.1.a Flexpod
2.1.b VBlock
2.1.c Virtual System Specifications (VSPEX)

2.2 Given a set of requirements, determine when to use file or block storage

2.3 Select the methods of accessing storage

2.3.a Determine connectivity types
2.3.b Determine access rights

2.4 Determine the thin/thick provisioning methods for a given environment

2.5 Determine the appropriate methods of interconnecting private clouds

2.6 Determine when to use the appropriate solution to automate network services

3.0 Design a Hybrid Cloud Infrastructure 16%

3.1 Compare and contrast the various public cloud architectures

3.2 Select the methodology to connect to public clouds

3.3 Select the appropriate solution to automate hybrid cloud provisioning

4.0 Design a Cloud Security Policy 20%

4.1 Describe best practices for securing cloud infrastructure

4.2 Describe best practices for securing cloud services

4.3 Design a secure multi tenant environment

4.4 Design a security policy to protect a private cloud

4.5 Design a security policy to protect a hybrid cloud

5.0 Virtualization and Virtual Network Services for Private and Hybrid Clouds 20%

5.1 Describe the advantages, disadvantages and features of different hypervisors

5.1.a Resource scheduling
5.1.b DR
5.1.c HA

5.2 Describe the use of cloud automation tools to facilitate physical to virtual or virtual to virtual migrations

5.2.a Workflows
5.2.a.1 Cisco Enablement Platform
5.2.a.2 UCS Director
5.2.a.3 Virtual Application Container Services (VACS)
5.2.b Compare benefits and limitation of Virtual Machines

5.3 Select the appropriate virtual network and security services to meet requirements

5.4 Describe context aware infrastructure and workflow identity

5.4.a Methodologies
5.4.b Components
5.4.c Use cases

5.5 Describe workload mobility

5.5.a Describe VM migration: move VMs from any hypervisor to any public cloud and back
5.5.b Describe VM conversion
5.5.c Describe use cases

5.6 Describe the ability to automate VM life cycle

5.6.a Describe workflow creation using Intercloud Fabric Director and Prime Services Catalog


Friday, 22 April 2016

300-320 ARCH Designing Cisco Network Service Architectures

Exam Number 300-320
Associated Certifications CCDP
Duration 75 minutes (60 - 70 questions)
Available Languages English

Exam Description
The Designing Cisco Network Service Architectures (ARCH) exam (300-320) is a 75-minute assessment with 60 – 70 questions associated with the Cisco Certified Design Professional certification. This exam tests a candidate's knowledge of the latest development in network design and technologies, including L2 and L3 infrastructures for the enterprise, WAN technologies, data center integration, network security and network services.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

1.0 Advanced Addressing and Routing Solutions for Enterprise Networks 22%

1.1 Create structured addressing designs to facilitate summarization

1.1.a Hierarchy
1.1.b Efficiency
1.1.c Scalability
1.1.d NAT

1.2 Create stable, secure, and scalable routing designs for IS-IS

1.3 Create stable, secure, and scalable routing designs for EIGRP

1.4 Create stable, secure, and scalable routing designs for OSPF

1.5 Create stable, secure, and scalable routing designs for BGP

1.5.a Transit prevention
1.5.b Basic route filtering
1.5.c Authentication
1.5.d Communities
1.5.e Basic traffic engineering (load distribution, creating path symmetry)
1.5.f Route reflectors

1.6 Determine IPv6 migration strategies

1.6.a Overlay (tunneling)
1.6.b Native (dual-stacking)
1.6.c Boundaries (IPv4/IPv6 translations)

2.0 Advanced Enterprise Campus Networks 20%

2.1 Design for high availability

2.1.a First Hop Redundancy Protocols
2.1.b Device virtualization

2.2 Design campus Layer 2 infrastructures

2.2.a STP scalability
2.2.b Fast convergence
2.2.c Loop-free technologies

2.3 Design multicampus Layer 3 infrastructures

2.3.a Convergence
2.3.b Load sharing
2.3.c Route summarization
2.3.d Route filtering
2.3.e VRFs
2.3.f Optimal topologies

2.4 Design a network to support network programmability

2.4.a Describe Application Centric Infrastructures (ACI)
2.4.b Select appropriate controller to meet requirements
2.4.c Identify and address key security issues with network programmability

3.0 WANs for Enterprise Networks 17%

3.1 Compare and contrast WAN connectivity options

3.1.a Dynamic Multipoint VPN (DMVPN)
3.1.b Layer 2 VPN
3.1.c MPLS Layer 3 VPN
3.1.d IPsec
3.1.e Generic Routing Encapsulation (GRE)
3.1.f Private lines

3.2 Design site-to-site VPNs

3.2.a DMVPN
3.2.b Layer 2 VPN
3.2.c MPLS Layer 3 VPN
3.2.d IPSec
3.2.e Group Encrypted Transport VPN (GETVPN)

3.3 Design for a resilient WAN strategy

3.3.a Single-homed
3.3.b Multi-homed
3.3.c Backup connectivity
3.3.d Failover

3.4 Design Extranet connectivity

3.4.a VPN
3.4.b Private lines
3.4.c Multitenant segmentation

3.5 Design Internet edge connectivity

3.5.a DMZ
3.5.b NAT
3.5.c Proxy functionality
3.5.d Resiliency
3.5.e Basic traffic engineering techniques (outbound/inbound load distribution, active/failover, symmetric outbound traffic flows)

4.0 Enterprise Data Center Integration 17%

4.1 Describe a modular and scalable data center network

4.1.a Top-of-rack
4.1.b End-of-row
4.1.c Multitenant environments
4.1.d Multitier topologies

4.2 Describe network virtualization technologies for the data center

4.2.a VPC
4.2.b VSS
4.2.c VDCs
4.2.d VRFs
4.2.e Multichassis EtherChannel
4.2.f VXLAN
4.2.g TRILL / Fabric Path

4.3 Describe high availability in a data center network

4.3.a VPC
4.3.b VSS
4.3.c Multichassis EtherChannel

4.4 Design data center interconnectivity

4.4.a OTV
4.4.b Private Line
4.4.c L2 vs. L3
4.4.d VPLS
4.4.e A-VPLS

4.5 Design data center and network integration

4.5.a Traffic flow
4.5.b Bandwidth
4.5.c Security
4.5.d Resiliency

5.0 Security Services 13%

5.1 Design firewall and IPS solutions

5.1.a Modes of operation
5.1.b Clustering
5.1.c High availability techniques
5.1.d IPS functionality and placement
5.1.e Multiple contexts

5.2 Design network access control solutions

5.2.a 802.1x
5.2.b TrustSec
5.2.c EAP
5.2.d Authentication services
5.2.e RBAC
5.2.f Basic denial of service mitigation techniques

5.3 Design infrastructure protection

5.3.a Infra structure ACLs
5.3.b CoPP
5.3.c Layer 2 / Layer 3 security considerations

6.0 Network Services 11%

6.1 Select appropriate QoS strategies to meet customer requirements

6.1.a DiffServ
6.1.b IntServ

6.2 Design end-to-end QoS policies

6.2.a Classification and marking
6.2.b Shaping
6.2.c Policing
6.2.d Queuing

6.3 Describe network management techniques

6.3.a In-band vs. out-of-band
6.3.b Segmented management networks
6.3.c Prioritizing network management traffic

6.4 Describe multicast routing concepts

6.4.a Source trees, shared trees
6.4.b RPF
6.4.c Rendezvous points

6.5 Design multicast services

6.5.a SSM
6.5.b PIM bidirectional
6.5.c MSDP

QUESTION 1
Which option maximizes EIGRP scalability?

A. route redistribution
B. route redundancy
C. route filtering
D. route summarization

Answer: D


QUESTION 2
To which network layer should Cisco Express Forwarding be tuned to support load balancing and to make more informed forwarding decisions?

A. Layer 1
B. Layer 2
C. Layer 3
D. Layer 4
E. Layer 5
F. Layer 6
G. Layer 7

Answer: D


QUESTION 3
Which option is the Cisco preferred, most versatile, and highest-performance way to deploy IPv6 in existing IPv4 environments?

A. dual stack
B. hybrid
C. service block
D. dual service

Answer: A


QUESTION 4
An engineer is designing an address plan. Which IPv6 prefix removes any consideration regarding the number of hosts per subnet?

A. /32
B. /48
C. /64
D. /96

Answer: C


QUESTION 5
Which protocol is best when there are circuit connections with two different ISPs in a multihoming scenario?

A. VRRP
B. BGP
C. IPsec
D. SSL

Answer: B


QUESTION 6
What is the latest Cisco high-availability solution?

A. VRRP
B. HSRP
C. VSS
D. GLBP

Answer: C

Monday, 18 April 2016

300-208 SISAS Implementing Cisco Secure Access Solutions

Exam Number 300-208 SISAS
Associated Certifications CCNP Security
Duration 90 minutes (65 - 75 questions)
Available Languages English, Japanese

Exam Description
The Implementing Cisco Secure Access Solutions (SISAS) (300-208) exam tests whether a network security engineer knows the components and architecture of secure access, by utilizing 802.1X and Cisco TrustSec. This 90-minute exam consists of 65–75 questions and assesses knowledge of Cisco Identity Services Engine (ISE) architecture, solution, and components as an overall network threat mitigation and endpoint control solutions. It also includes the fundamental concepts of bring your own device (BYOD) using posture and profiling services of ISE. Candidates can prepare for this exam by taking the Implementing Cisco Secure Access Solutions (SISAS) course.

The following topics are general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines below may change at any time without notice.

1.0 Identity Management/Secure Access 33%
1.1 Implement device administration

1.1.a Compare and select AAA options
1.1.b TACACS+
1.1.c RADIUS
1.1.d Describe Native AD and LDAP

1.2 Describe identity management
1.2.a Describe features and functionality of authentication and authorization
1.2.b Describe identity store options (i.e., LDAP, AD, PKI, OTP, Smart Card, local)
1.2.c Implement accounting

1.3 Implement wired/wireless 802.1X
1.3.a Describe RADIUS flows
1.3.b AV pairs
1.3.c EAP types
1.3.d Describe supplicant, authenticator, and server
1.3.e Supplicant options
1.3.f 802.1X phasing (monitor mode, low impact, closed mode)
1.3.g AAA server
1.3.h Network access devices

1.4 Implement MAB
1.4.a Describe the MAB process within an 802.1X framework
1.4.b Flexible authentication configuration
1.4.c ISE authentication/authorization policies
1.4.d ISE endpoint identity configuration
1.4.e Verify MAB Operation

1.5 Implement network authorization enforcement
1.5.a dACL
1.5.b Dynamic VLAN assignment
1.5.c Describe SGA
1.5.d Named ACL
1.5.e CoA

1.6 Implement Central Web Authentication (CWA)
1.6.a Describe the function of CoA to support web authentication
1.6.b Configure authentication policy to facilitate CWA
1.6.c URL redirect policy
1.6.d Redirect ACL
1.6.e Customize web portal
1.6.f Verify central web authentication operation

1.7 Implement profiling
1.7.a Enable the profiling services
1.7.b Network probes
1.7.c IOS Device Sensor
1.7.d Feed service
1.7.e Profiling policy rules
1.7.f Utilize profile assignment in authorization policies
1.7.g Verify profiling operation

1.8 Implement guest services
1.8.a Managing sponsor accounts
1.8.b Sponsor portals
1.8.c Guest portals
1.8.d Guest Policies
1.8.e Self registration
1.8.f Guest activation
1.8.g Differentiated secure access
1.8.h Verify guest services operation

1.9 Implement posture services
1.9.a Describe the function of CoA to support posture services
1.9.b Agent options
1.9.c Client provisioning policy and redirect ACL
1.9.d Posture policy
1.9.e Quarantine/remediation
1.9.f Verify posture service operation

1.10 Implement BYOD access
1.10.a Describe elements of a BYOD policy
1.10.b Device registration
1.10.c My devices portal
1.10.d Describe supplicant provisioning

2.0 Threat Defense 10%
2.1 Describe TrustSec Architecture
2.1.a SGT Classification - dynamic/static
2.1.b SGT Transport - inline tagging and SXP
2.1.c SGT Enforcement - SGACL and SGFW
2.1.d MACsec

3.0 Troubleshooting, Monitoring and Reporting Tools 7%

3.1 Troubleshoot identity management solutions

3.1.a Identify issues using authentication event details in Cisco ISE
3.1.b Troubleshoot using Cisco ISE diagnostic tools
3.1.c Troubleshoot endpoint issues
3.1.d Use debug commands to troubleshoot RADIUS and 802.1X on IOS switches and wireless controllers
3.1.e Troubleshoot backup operations

4.0 Threat Defense Architectures 17%

4.1 Design highly secure wireless solution with ISE

4.1.a Identity Management
4.1.b 802.1X
4.1.c MAB
4.1.d Network authorization enforcement
4.1.e CWA
4.1.f Profiling
4.1.g Guest Services
4.1.h Posture Services
4.1.i BYOD Access

5.0 Identity Management Architectures 33%

5.1 Device administration
5.2 Identity Management
5.3 Profiling
5.4 Guest Services
5.5 Posturing Services
5.6 BYOD Access

QUESTION 1
With which two appliance-based products can Cisco Prime Infrastructure integrate to perform centralized management? (Choose two.)

A. Cisco Managed Services Engine
B. Cisco Email Security Appliance
C. Cisco Wireless Location Appliance
D. Cisco Content Security Appliance
E. Cisco ISE

Answer: A,E


QUESTION 2
Which two fields are characteristics of IEEE 802.1AE frame? (Choose two.)

A. destination MAC address
B. source MAC address
C. 802.1AE header in EtherType
D. security group tag in EtherType
E. integrity check value
F. CRC/FCS

Answer: C,E


QUESTION 3
Which three statements about the Cisco wireless IPS solution are true? (Choose three.)

A. It enables stations to remain in power-save mode, except at specified intervals to receive data from the access point.
B. It detects spoofed MAC addresses.
C. It identifies potential RF jamming attacks.
D. It protects against frame and device spoofing.
E. It allows the WLC to failover because of congestion.

Answer: B,C,D


QUESTION 4
In AAA, what function does authentication perform?

A. It identifies the actions that the user can perform on the device.
B. It identifies the user who is trying to access a device.
C. It identifies the actions that a user has previously taken.
D. It identifies what the user can access.

Answer: B


QUESTION 5
Which two EAP types require server side certificates? (Choose two.)

A. EAP-TLS
B. PEAP
C. EAP-MD5
D. LEAP
E. EAP-FAST
F. MSCHAPv2

Answer: A,B

Monday, 4 April 2016

300-135 TSHOOT

Troubleshooting and Maintaining Cisco IP Networks (TSHOOT)
Exam Number 300-135 TSHOOT
Associated Certifications CCNP Routing and Switching
Duration 120 minutes (15-25 questions)
Available Languages English, Japanese

Troubleshooting and Maintaining Cisco IP Networks (TSHOOT 300-135) is a qualifying exam for the Cisco CCNP Routing and Switching certification. The TSHOOT 300-135 exam certifies that the successful candidate has the knowledge and skills necessary to:

Plan and perform regular maintenance on complex enterprise routed and switched networks
Use technology-based practices and a systematic ITIL-compliant approach to perform network troubleshooting

Exam Description

Troubleshooting and Maintaining Cisco IP Networks (TSHOOT 300-135) is a 120-minute qualifying exam with 15‒25 questions for the Cisco CCNP Routing and Switching certification. The TSHOOT 300-135 exam certifies that the successful candidate has the knowledge and skills necessary to:

Plan and perform regular maintenance on complex enterprise routed and switched networks
Use technology-based practices and a systematic ITIL-compliant approach to perform network troubleshooting

The following topics are general guidelines for the content that is likely to be included on the exam. However, other related topics may also appear on any specific version of the exam. To better reflect the contents of the exam and for clarity, the following guidelines may change at any time without notice.

Subscribe to Cisco Learning Network Premium and access the most comprehensive e-learning training, resources and tools you’ll need to prepare for your CCENT, CCNA and CCNP Routing and Switching certifications.


1.0 Network Principles 5%

1.1 Use Cisco IOS troubleshooting tools

1.1.a Debug, conditional debug
1.1.b Ping and trace route with extended options

1.2 Apply troubleshooting methodologies

1.2.a Diagnose the root cause of networking issues (analyze symptoms, identify and describe root cause)
1.2.b Design and implement valid solutions
1.2.c Verify and monitor resolution

2.0 Layer 2 Technologies 40%

2.1 Troubleshoot switch administration

2.1.a SDM templates
2.1.b Managing MAC address table
2.1.c Troubleshoot Err-disable recovery

2.2 Troubleshoot Layer 2 protocols

2.2.a CDP, LLDP
2.2.b UDLD

2.3 Troubleshoot VLANs

2.3.a Access ports
2.3.b VLAN database
2.3.c Normal, extended VLAN, voice VLAN

2.4 Troubleshoot trunking

2.4.a VTPv1, VTPv2, VTPv3, VTP pruning
2.4.b dot1Q
2.4.c Native VLAN
2.4.d Manual pruning

2.5 Troubleshoot EtherChannels

2.5.a LACP, PAgP, manual
2.5.b Layer 2, Layer 3
2.5.c Load balancing
2.5.d EtherChannel misconfiguration guard

2.6 Troubleshoot spanning tree

2.6.a PVST+, RPVST +, MST
2.6.b Switch priority, port priority, path cost, STP timers
2.6.c PortFast, BPDUguard, BPDUfilter
2.6.d Loopguard, Rootguard

2.7 Troubleshoot other LAN switching technologies

2.7.a SPAN, RSPAN

2.8 Troubleshoot chassis virtualization and aggregation technologies

2.8.a Stackwise

3.0 Layer 3 Technologies 40%

3.1 Troubleshoot IPv4 addressing and subnetting

3.1.a Address types (Unicast, broadcast, multicast, and VLSM)
3.1.b ARP
3.1.c DHCP relay and server
3.1.d DHCP protocol operations

3.2 Troubleshoot IPv6 addressing and subnetting

3.2.a Unicast
3.2.b EUI-64
3.2.c ND, RS/RA
3.2.d Autoconfig (SLAAC)
3.2.e DHCP relay and server
3.2.f DHCP protocol operations

3.3 Troubleshoot static routing

3.4 Troubleshoot default routing

3.5 Troubleshoot administrative distance

3.6 Troubleshoot passive interfaces

3.7 Troubleshoot VRF lite

3.8 Troubleshoot filtering with any protocol

3.9 Troubleshoot between any routing protocols or routing sources

3.10 Troubleshoot manual and autosummarization with any routing protocol

3.11 Troubleshoot policy-based routing

3.12 Troubleshoot suboptimal routing

3.13 Troubleshoot loop prevention mechanisms

3.13.a Route tagging, filtering
3.13.b Split-horizon
3.13.c Route poisoning

3.14 Troubleshoot RIPv2

3.15 Troubleshoot EIGRP neighbor relationship and authentication

3.16 Troubleshoot loop free path selection

3.16.a RD, FD, FC, successor, feasible successor

3.17 Troubleshoot EIGPR operations

3.17.a Stuck in active

3.18 Troubleshoot EIGRP stubs

3.19 Troubleshoot EIGRP load balancing

3.19.a Equal cost
3.19.b Unequal cost

3.20 Troubleshoot EIGRP metrics

3.21 Troubleshoot EIGRP for IPv6

3.22 Troubleshoot OSPF neighbor relationship and authentication

3.23 Troubleshoot network types, area types, and router types

3.23.a Point-to-point, multipoint, broadcast, nonbroadcast
3.23.b LSA types, area type: backbone, normal, transit, stub, NSSA, totally stub
3.23.c Internal router, backbone router, ABR, ASBR
3.23.d Virtual link

3.24 Troubleshoot OSPF path preference

3.25 Troubleshoot OSPF operations

3.26 Troubleshoot OSPF for IPv6

3.27 Troubleshoot BGP peer relationships and authentication

3.27.a Peer group
3.27.b Active, passive
3.27.c States and timers

3.28 Troubleshoot eBGP

3.28.a eBGP
3.28.b 4-byte AS number
3.28.c Private AS

4.0 VPN Technologies 5%
4.1 Troubleshoot GRE

5.0 Infrastructure Security 5%


5.1 Troubleshoot IOS AAA using local database

5.2 Troubleshoot device access control

5.2.a Lines (VTY, AUX, console)
5.2.b Management plane protection
5.2.c Password encryption

5.3 Troubleshoot router security features

5.3.a IPv4 access control lists (standard, extended, time-based)
5.3.b IPv6 traffic filter
5.3.c Unicast reverse path forwarding

6.0 Infrastructure Services 5%

6.1 Troubleshoot device management

6.1.a Console and VTY
6.1.b Telnet, HTTP, HTTPS, SSH, SCP
6.1.c (T) FTP

6.2 Troubleshoot SNMP

6.2.a v2
6.2.b v3

6.3 Troubleshoot logging

6.3.a Local logging, syslog, debugs, conditional debugs
6.3.b Timestamps

6.4 Troubleshoot Network Time Protocol(NTP)

6.4.a NTP master, client, version 3, version 4
6.4.b NTP authentication

6.5 Troubleshoot IPv4 and IPv6 DHCP

6.5.a DHCP client, IOS DHCP server, DHCP relay
6.5.b DHCP options (describe)

6.6 Troubleshoot IPv4 Network Address Translation (NAT)

6.6.a Static NAT, Dynamic NAT, PAT

6.7 Troubleshoot SLA architecture

6.8 Troubleshoot tracking objects

6.8.a Tracking objects
6.8.b Tracking different entities (for example, interfaces, IPSLA results)

QUESTION 1
Exhibit:



A network administrator is troubleshooting an EIGRP connection between RouterA, IP address
10.1.2.1, and RouterB, IP address 10.1.2.2. Given the debug output on RouterA, which two
statements are true? (Choose two.)

A. RouterA received a hello packet with mismatched autonomous system numbers.
B. RouterA received a hello packet with mismatched hello timers.
C. RouterA received a hello packet with mismatched authentication parameters.
D. RouterA received a hello packet with mismatched metric-calculation mechanisms.
E. RouterA will form an adjacency with RouterB.
F. RouterA will not form an adjacency with RouterB.

Answer: D,F

Explanation:


QUESTION 2
When troubleshooting an EIGRP connectivity problem, you notice that two connected EIGRP
routers are not becoming EIGRP neighbors. A ping between the two routers was successful. What
is the next thing that should be checked?

A. Verify that the EIGRP hello and hold timers match exactly.
B. Verify that EIGRP broadcast packets are not being dropped between the two routers with the
show ip EIGRP peer command.
C. Verify that EIGRP broadcast packets are not being dropped between the two routers with the
show ip EIGRP traffic command.
D. Verify that EIGRP is enabled for the appropriate networks on the local and neighboring router.

Answer: D

Explanation:


QUESTION 3
Refer to the exhibit.



How would you confirm on R1 that load balancing is actually occurring on the default-network
(0.0.0.0)?

A. Use ping and the show ip route command to confirm the timers for each default network resets
to 0.
B. Load balancing does not occur over default networks; the second route will only be used for
failover.
C. Use an extended ping along with repeated show ip route commands to confirm the gateway of
last resort address toggles back and forth.
D. Use the traceroute command to an address that is not explicitly in the routing table.

Answer: D

Explanation:


QUESTION 4
Which IPsec mode will encrypt a GRE tunnel to provide multiprotocol support and reduced
overhead?

A. 3DES
B. multipoint GRE
C. tunnel
D. transport

Answer: D

Explanation:


QUESTION 5
Which three features are benefits of using GRE tunnels in conjunction with IPsec for building siteto-
site VPNs? (Choose three.)

A. allows dynamic routing over the tunnel
B. supports multi-protocol (non-IP) traffic over the tunnel
C. reduces IPsec headers overhead since tunnel mode is used
D. simplifies the ACL used in the crypto map
E. uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration

Answer: A,B,D

Explanation: