课程主题
Security
完全覆盖Access control lists, stateful filtering, port-based rules, segmentation, device access control and common attack types.
- lesson
- 7 lessons
- quiz
- 5 quizzes
- question
- 18 questions
- lab
- 21 labs
已教授、已评估,并已在实验中练习。
为什么这很重要
Writing a rule is easy; scoping it correctly and verifying it in both directions is the skill, and it is where ACLs go wrong.
学习
涵盖此主题的模块
7 lessons 门与此主题相关的课程,按顺序编排于这些模块中,并配有相应的测验与实验。
- Diagnosis in practiceNetwork operations and design
- Monitoring and file transferNetwork operations and design
- Direction and stateNetwork security and acls
- Filtering by addressNetwork security and acls
- Filtering by serviceNetwork security and acls
- Least privilege in practiceNetwork security and acls
- Protecting the devicesNetwork security and acls
- Security foundationsNetwork security and acls
- Translation and publishingNetwork services
- Layers and protocolsNetworking fundamentals
- Nat and aclsNetworking fundamentals
练习
实操实验
真实的虚拟网络,配有设备控制台,自动评分。每次尝试都会重新生成地址方案。
- ACL Fundamentals - Block a Single Host #1
- ACL: Block a Whole Subnet #1
- The Guest Host Can Reach the Management Segment
- Egress Filter on the Records Server
- Permit One Service, Not One Host
- Replies Leave the Server, But Never Reach the Client
- The Firewall That Never Saw the Request
- Slow, Not Broken
- DHCP Hands Out the Wrong Gateway
- The Config Backup Server Everyone Can Reach
- Keep Guest Traffic Outside the Office LAN
- Publish Server Port Forwarding
- Overly Broad Firewall Rule
- Contractor Limited Access
- Web Tier Bypasses App Tier
- Audit IoT VLAN Internet Scope
- Lock Down Management Access
- Finance Subnet Default Deny
- Divested Business Firewall Separation
- One Server, Wrong Exit Interface
- Allow Access to Wiki Replica
检验
评分测验
18 graded questions 道题目,分布在 5 quizzes 个测验中,在上方模块内进行。答错时会解释你所选选项背后的具体误区。
复习
间隔重复
Security 已纳入复习阶梯追踪。你回答过一道相关题目后,它会按照逐渐拉长的间隔重新出现,只要你持续答对;如果答错则会重置。查看你的复习队列。
认证
此主题覆盖的考试目标
Cisco CCNA 200-301 v1.1
- 1.5 比较 TCP 与 UDP
- 4.1 配置并验证使用静态方式与地址池的内部源 NAT
- 4.6 配置并验证 DHCP 客户端与中继
- 4.8 配置网络设备以使用 SSH 进行远程访问
- 4.9 描述 TFTP/FTP 在网络中的能力与作用
- 5.1 定义关键安全概念(威胁、漏洞、利用、缓解)
- 5.2 描述安全项目的构成要素
- 5.3 配置并验证使用本地密码的设备访问控制
- 5.4 描述安全密码策略要素
- 5.6 配置并验证访问控制列表
CompTIA Network+ N10-009
- 1.4 解释常见的网络端口、协议、服务与流量类型
- 3.5 比较网络访问与管理方法
- 4.1 解释基本网络安全概念的重要性
- 4.2 概述各类攻击及其对网络的影响
- 4.3 结合场景应用网络安全特性、防御技术与解决方案
- 5.3 结合场景排查网络服务的常见问题
- 5.4 结合场景排查常见的性能问题
- 5.5 结合场景排查并解决一般性网络问题
