カリキュラムのトピック
Security
完全Access control lists, stateful filtering, port-based rules, segmentation, device access control and common attack types.
- lesson
- 7 lessons
- quiz
- 5 quizzes
- question
- 18 questions
- lab
- 21 labs
教えて、評価して、ラボで練習します。
重要な理由
Writing a rule is easy; scoping it correctly and verifying it in both directions is the skill, and it is where ACLs go wrong.
学ぶ
このトピックを扱うモジュール
このトピックに関する7 lessonsが、クイズやラボとともにこれらのモジュール内に順序立てて配置されています。
- Diagnosis in practiceNetwork operations and design
- Monitoring and file transferNetwork operations and design
- Direction and stateNetwork security and acls
- Filtering by addressNetwork security and acls
- Filtering by serviceNetwork security and acls
- Least privilege in practiceNetwork security and acls
- Protecting the devicesNetwork security and acls
- Security foundationsNetwork security and acls
- Translation and publishingNetwork services
- Layers and protocolsNetworking fundamentals
- Nat and aclsNetworking fundamentals
練習する
実践ラボ
デバイスコンソールを備えたリアルな仮想ネットワークで、自動採点されます。アドレッシングは試行のたびに再生成されます。
- ACL Fundamentals - Block a Single Host #1
- ACL: Block a Whole Subnet #1
- The Guest Host Can Reach the Management Segment
- Egress Filter on the Records Server
- Permit One Service, Not One Host
- Replies Leave the Server, But Never Reach the Client
- The Firewall That Never Saw the Request
- Slow, Not Broken
- DHCP Hands Out the Wrong Gateway
- The Config Backup Server Everyone Can Reach
- Keep Guest Traffic Outside the Office LAN
- Publish Server Port Forwarding
- Overly Broad Firewall Rule
- Contractor Limited Access
- Web Tier Bypasses App Tier
- Audit IoT VLAN Internet Scope
- Lock Down Management Access
- Finance Subnet Default Deny
- Divested Business Firewall Separation
- One Server, Wrong Exit Interface
- Allow Access to Wiki Replica
確認する
採点付きクイズ
5 quizzesにわたる18 graded questionsを、上記のモジュール内で受験します。誤答には、選んだ選択肢の背後にある具体的な誤解が説明されます。
復習
間隔反復
Securityは復習ラダーで追跡されます。一度その問題に回答すると、正解し続ける限りスケジュールが伸びながら再登場し、間違えるとリセットされます。復習キューを見る。
資格試験
このトピックがカバーする出題範囲
Cisco CCNA 200-301 v1.1
- 1.5 TCPとUDPを比較する
- 4.1 スタティックとプールを使用した内部ソースNATを設定し検証する
- 4.6 DHCPクライアントとリレーを設定し検証する
- 4.8 SSHを使用したリモートアクセス用にネットワーク機器を設定する
- 4.9 ネットワークにおけるTFTP/FTPの機能と役割を説明する
- 5.1 主要なセキュリティの概念(脅威、脆弱性、エクスプロイト、緩和策)を定義する
- 5.2 セキュリティプログラムの構成要素を説明する
- 5.3 ローカルパスワードを使用した機器アクセス制御を設定し検証する
- 5.4 セキュリティパスワードポリシーの要素を説明する
- 5.6 アクセス制御リストを設定し検証する
CompTIA Network+ N10-009
- 1.4 一般的なネットワークポート、プロトコル、サービス、トラフィックの種類を説明する
- 3.5 ネットワークアクセスと管理方法を比較対照する
- 4.1 基本的なネットワークセキュリティの概念の重要性を説明する
- 4.2 さまざまな種類の攻撃とネットワークへの影響を要約する
- 4.3 シナリオに基づき、ネットワークセキュリティ機能、防御技術、ソリューションを適用する
- 5.3 シナリオに基づき、ネットワークサービスのよくある問題をトラブルシューティングする
- 5.4 シナリオに基づき、よくあるパフォーマンスの問題をトラブルシューティングする
- 5.5 シナリオに基づき、一般的なネットワークの問題をトラブルシューティングして解決する
