Security concepts
- Explain common threats against on-premises, hybrid and cloud environments.
- Compare common security vulnerabilities such as software bugs, weak and/or hardcoded passwords, OWASP top ten, missing encryption ciphers, buffer overflow, path traversal, cross-site scripting/forgery.
- Describe functions of the cryptography components such as hashing, encryption, PKI.SSL, IPsec, NAT-T IPv4 for IPsec, pre-shared key, and certificate-based authorization.
- Compare site-to-site and remote access VPN deployment types and components such as virtual tunnel interfaces, standards-based IPsec, DMVPN, Flex VPN, and Cisco Secure Client including high-availability considerations.
- Describe security intelligence authoring, sharing, and consumption.
- Describe the controls used to protect against phishing and social engineering attacks.
- Explain North Bound and South Bound APIs in the SDN architecture.
- Explain Cisco DNA Center APIs for network provisioning, optimization, monitoring, and troubleshooting.
- Interpret basic Python scripts used to call Cisco Security appliances APIs.