📖 About this Domain
This domain covers fundamental security concepts, threats, and vulnerabilities. It focuses on implementing security on network devices to maintain integrity, confidentiality, and availability. You will learn to configure basic security features on Cisco routers, switches, and wireless LAN controllers.
🎓 What You Will Learn
- You will learn to define key security concepts like threats, vulnerabilities, exploits, and mitigation techniques.
- You will learn to configure and verify access control lists (ACLs) to filter network traffic based on specific criteria.
- You will learn to implement Layer 2 security features such as port security, DHCP snooping, and dynamic ARP inspection.
- You will learn to configure a secure wireless LAN (WLAN) using WPA2 Pre-Shared Key (PSK) on a Wireless LAN Controller (WLC).
🛠️ Skills You Will Build
- You will build the skill to secure device access using local passwords and understand AAA concepts.
- You will build the skill to mitigate common Layer 2 attacks by configuring switch security features.
- You will build the skill to implement traffic filtering policies using standard and extended ACLs.
- You will build the skill to deploy a secure wireless network using current security protocols like WPA2 and WPA3.
💡 Top Tips to Prepare
- Master the configuration and verification of both standard and extended ACLs, including proper placement.
- Practice configuring port security, DHCP snooping, and DAI in a lab environment to understand their operational states.
- Differentiate clearly between the concepts of authentication, authorization, and accounting (AAA).
- Understand the purpose and configuration of site-to-site VPNs and remote access VPNs at a conceptual level.
📖 About this Domain
This domain focuses on Layer 2 technologies for wired and wireless network access. You will cover switch configuration, VLANs, trunking, Spanning Tree Protocol, and fundamental wireless LAN controller concepts.
🎓 What You Will Learn
- Configure VLANs and 802.1Q trunks to segment broadcast domains across multiple switches.
- Implement Layer 2 discovery protocols like CDP and LLDP for network device mapping.
- Describe Rapid PVST+ operations, including root bridge election and port states, to prevent switching loops.
- Configure a basic wireless LAN using a WLC GUI, including security settings like WPA2 PSK.
🛠️ Skills You Will Build
- Configure switch access ports for data/voice VLANs and trunk ports for interswitch connectivity.
- Bundle physical links into a logical EtherChannel using LACP for increased bandwidth and redundancy.
- Verify Layer 2 operations using show commands to troubleshoot VLANs, trunks, and STP.
- Deploy a secure WLAN for client access through a wireless LAN controller's graphical user interface.
💡 Top Tips to Prepare
- Master the configuration and verification of VLANs and 802.1Q trunks as they are fundamental to switched networks.
- Practice identifying STP port roles like Root Port and Designated Port in a given topology.
- Differentiate between the proprietary Cisco Discovery Protocol and the vendor-neutral LLDP.
- Familiarize yourself with the WLC GUI for creating a WLAN, as practical configuration is tested.
📖 About this Domain
This domain focuses on the IP services that support network functionality, management, and operations. It covers the configuration and verification of critical protocols like NAT, DHCP, and NTP. You will also learn the theory behind network monitoring and management services.
🎓 What You Will Learn
- You will learn to configure and verify inside source Network Address Translation (NAT) using static assignments and dynamic pools.
- You will learn the operational theory and configuration of DHCP, DNS, NTP, SNMP, and syslog for network support and management.
- You will learn to configure secure remote access using SSH and understand the role of TFTP/FTP for file management.
- You will learn to describe Quality of Service (QoS) concepts, including per-hop behavior (PHB) for traffic management.
🛠️ Skills You Will Build
- You will build the skill to configure a router as a DHCP client and a DHCP relay agent.
- You will gain the ability to implement both static NAT and Port Address Translation (PAT) on a Cisco router.
- You will develop the skill to configure SSH on a Cisco IOS device for secure remote administration.
- You will be able to explain the functions of key IP services like NTP, SNMP, and syslog in a production network.
💡 Top Tips to Prepare
- Use a network simulator to practice the command-line configuration for NAT, DHCP relay, and SSH repeatedly.
- Create flashcards to memorize the specific functions and differences between SNMP, syslog, DHCP, and DNS.
- Focus on understanding the conceptual steps of QoS PHB, such as classification, marking, and queuing, rather than deep configuration.
- Master the verification commands like 'show ip nat translations' and 'show ntp status' to troubleshoot IP service configurations.
📖 About this Domain
This domain introduces the fundamental concepts of network automation and programmability. It explains the shift from traditional CLI-based management to modern, controller-based architectures and the use of APIs for network operations.
🎓 What You Will Learn
- You will learn to compare traditional networks with controller-based networking, including the separation of the control plane and data plane.
- You will learn to describe software-defined architectures such as overlay, underlay, and fabric, along with the function of northbound and southbound APIs.
- You will learn the characteristics of REST-based APIs, including CRUD operations, HTTP verbs, and data encoding.
- You will learn to recognize the capabilities of configuration management tools like Puppet, Chef, and Ansible.
🛠️ Skills You Will Build
- You will build the skill to differentiate between traditional device management and Cisco DNA Center enabled management.
- You will build the skill to interpret basic JSON encoded data structures used in network automation.
- You will build the skill to explain core SDN concepts and the role of APIs in a controller-based architecture.
- You will build the skill to identify the purpose of common configuration management mechanisms.
💡 Top Tips to Prepare
- Focus on the conceptual purpose of automation tools and APIs, not on writing code.
- Memorize the definitions and functions of REST API components like HTTP verbs and CRUD operations.
- Clearly understand the relationship between underlay, overlay, control plane, and data plane in an SDN model.
- Practice interpreting simple JSON data structures to identify key-value pairs.
📖 About this Domain
The IP Connectivity domain covers fundamental routing concepts and router operations. You will learn how routers build their routing tables and make packet forwarding decisions. This section emphasizes both static routing and the configuration of single-area OSPFv2.
🎓 What You Will Learn
- Interpret routing table components, including route source, administrative distance, and metric.
- Understand the router's forwarding decision process, including the longest prefix match rule.
- Configure and verify IPv4 and IPv6 static routes, including default, network, and floating static routes.
- Implement and verify single-area OSPFv2, including neighbor adjacencies and router ID election.
🛠️ Skills You Will Build
- Analyze an IP routing table to determine the best path for a given destination network.
- Implement static routing in a small network to provide point-to-point and default connectivity.
- Configure OSPFv2 routing on Cisco IOS routers to establish dynamic routing within a single area.
- Verify routing protocol operations and troubleshoot basic IP connectivity issues using show commands.
💡 Top Tips to Prepare
- Use Cisco Packet Tracer or GNS3 to lab static routing and OSPFv2 configurations extensively.
- Master the router's packet forwarding logic, focusing on administrative distance and the longest prefix match.
- Memorize key verification commands like 'show ip route', 'show ip ospf neighbor', and 'show ip protocols'.
- Understand the purpose and concepts behind First Hop Redundancy Protocols (FHRP) like HSRP.
📖 About this Domain
This domain covers foundational network components, architectures, and protocols. You will learn about the OSI and TCP/IP models, IP addressing, and the physical layer. It establishes the core knowledge required for all other networking topics.
🎓 What You Will Learn
- Explain the roles of network components like routers, L2/L3 switches, and access points in various network topologies.
- Configure and verify IPv4 subnetting and IPv6 addressing schemes, including GUA and LLA.
- Compare the TCP/IP and OSI models and describe the data encapsulation process through protocol data units (PDUs).
- Identify cabling types, such as UTP and fiber, and troubleshoot physical layer issues like collisions and duplex mismatches.
🛠️ Skills You Will Build
- Differentiating between network devices and architectures like spine-leaf, WAN, and SOHO.
- Calculating IPv4 subnets using CIDR notation and VLSM for efficient address allocation.
- Configuring IPv4 and IPv6 static addressing on client and router interfaces.
- Verifying Layer 1 connectivity and identifying issues with cabling and interface status.
💡 Top Tips to Prepare
- Master IPv4 subnetting and summarization through daily practice until it is second nature.
- Memorize the OSI and TCP/IP layers, their functions, and the corresponding PDUs like frames, packets, and segments.
- Utilize Cisco Packet Tracer to build simple topologies and visualize data flow with ARP, ICMP, and TCP/UDP.
- Learn Ethernet cabling standards, including pinouts for straight-through and crossover cables, and when to use each.
Premium Access Includes
- ✓ Quiz Simulator
- ✓ Exam Mode
- ✓ Progress Tracking
- ✓ Question Saving
- ✓ Flash Cards
- ✓ Drag & Drops
- ✓ 3 Months Access
- ✓ PDF Downloads