Security Concepts
Define threats, vulnerabilities, exploits and mitigations, then relate risk to likelihood and impact.
Security Programs
Describe how awareness, training, policy and physical access control reduce human and environmental risk.
Local Device Access
Configure and verify console and VTY access using local secrets, privileged mode protection and encrypted SSH.
Password Policy & Alternatives
Describe password management, complexity and safer alternatives including MFA, certificates and biometrics.
IPsec VPNs
Describe remote-access and site-to-site IPsec VPNs, tunnels, peers and the security services they provide.
Access Control Lists
Configure and verify numbered or named IPv4 ACLs using ordered ACEs, wildcard masks and correct placement.
Layer 2 Security
Configure and verify DHCP snooping, Dynamic ARP Inspection and port security as a coordinated access-layer defence.
AAA
Compare authentication, authorisation and accounting, and recognise how TACACS+ and RADIUS centralise control.
Wireless Security Protocols
Compare WPA, WPA2 and WPA3, personal and enterprise authentication, and the weaknesses of legacy wireless protection.
WLAN with WPA2-PSK
Interpret and verify wireless LAN controller GUI settings for a client WLAN protected by WPA2 pre-shared key.