Domain 5 · 15% of the exam
Security Fundamentals
Threats, device hardening, VPNs, ACLs, Layer 2 security, AAA, wireless security.
Security is the part of networking that most beginners find both the most interesting and the most confusing, because it mixes big-picture ideas (what is a “threat”?) with very specific configuration (what exactly does switchport port-security violation restrict do?). This domain is worth 15% of the exam, which means roughly 15 to 20 questions. The good news is that the exam tests a well-defined set of facts, commands, and comparisons. If you learn the vocabulary in 5.1, the local password commands in 5.3, access control lists in 5.6, and the three Layer 2 features in 5.7 very well, you will pick up most of the available points.
Throughout this chapter, keep one mental model in mind: security is about controlling who can reach what. Every tool we discuss, from a login password to a firewall to an ACL, is a way of saying “this person or packet is allowed, and that one is not.”
Objectives
- 5.1Define key security concepts (threats, vulnerabilities, exploits, and mitigation techniques)
- 5.2Describe security program elements (user awareness, training, and physical access control)
- 5.3Configure and verify device access control using local passwords
- 5.4Describe security password policy elements, such as management, complexity, and password alternatives (multifactor authentication, certificates, and biometrics)
- 5.5Describe IPsec remote access and site-to-site VPNs
- 5.6Configure and verify access control lists
- 5.7Configure and verify Layer 2 security features (DHCP snooping, dynamic ARP inspection, and port security)
- 5.8Compare authentication, authorization, and accounting concepts
- 5.9Describe wireless security protocols (WPA, WPA2, and WPA3)
- 5.10Configure and verify WLAN within the GUI using WPA2 PSK