Latest News
  • Join CCNP Training Course & Get CCNA Absolutely FREE
  • Courses Available Both Online and Classroom
  • Best IT Networking Training Institute in Dubai

CCNP Security in Dubai

Training From CCIE Certified Instructors

Online & Classroom Trainings Available

Get Ready for CCNP Security Certification

IP Rulers - The Best IT Networking Training Institute in Dubai

Why Choose CCNP Security Certification?

Job Availability is High : CCNP certification qualifies you for many different jobs such as IT Managers, computers and information systems manager etc.

 

Salary Potential is High : Getting a CCNP certification will qualify you for an array of employment opportunities and the chance to earn a higher salary.

 

More Skill Recognition :  Being certified from a reputable organization like Cisco means that you will be recognized more in the industry.

 

Opportunity to Learn New Technology : The best way to keep your career growing is to keep up with the current technology, like getting CCNP certification.

 

Excellent Job Growth : Earning a CCNP certification puts you on the top of the list when it is time for promotions and career advancements. 

 

Makes You Eligible For Advanced Certifications : Many Cisco certifications work as stepping stones for more advanced certifications.

 

CCNP SECURITY Module Programs


Course Details

The CCNP Security Certification comprises of clearing two exams – one in a core subject, and another in a concentration subject. This gives a CCNP Security Badge.

350-701 SCOR Implementing and Operating Cisco Security Core Technologies (SCOR)

300-710 SNCF

Securing Networks with Cisco Firepower Next Generation Firewall (SSNGFW)
Securing Networks with Cisco Firepower Next-Generation IPS (SSFIPS)

300-715 SISEImplementing and Configuring Cisco Identity Services Engine (SISE)
300-720 SESASecuring Email with Cisco Email Security Appliance (SESA)
300-725 SWSASecuring the Web with Cisco Web Security Appliance (SWSA)
300-730 SVPNImplementing Secure Solutions with Virtual Private Networks (SVPN)
300-735 SAUTOImplementing Automation for Cisco Security Solutions (SAUI)

CCNP Security Training

Batch

Weekdays (Sun - Thu)

Weekend (Fri - Sat)

Mode

Classroom / Online

Classroom / Online

Hours

80 Hours

80 Hours

Duration

2 Month

3 Month


Our Next CCNP Security Batch Starting Soon......


Contact Us Today to Get a FREE Demo or to Get Training Details


Date

Course

Training Type

Batch

Register

29 Aug 2021

CCNP Security

Classroom / Online

Weekdays (Sun-Thu)

5 Sep 2021

CCNP Security

Classroom / Online

Weekdays (Sun-Thu)

27 Aug 2021

CCNP Security

Classroom / Online

Weekend (Fri-Sat)

3 Sep 2021

CCNP Security

Classroom / Online

Weekend (Fri-Sat)


Training Schedule


IP Rulers has a training schedule that can suit anyone, whether it be in groups or one-on-one, classroom-based, online or onsite corporate training, on weekdays or weekends. Each course, which is a combination of a core paper and a concentration paper, has a duration of 80 hours. For extra concentration papers, duration will change.


CCNP Security Course Syllabus

Security Concept [25%]
  1. Explain common threats against on-premises and cloud environments
  •  On-premises:
    • viruses
    • trojans
    • DoS/DDoS attacks
    • phishing
    • rootkits
    • man-in-the-middle attacks
    • SQL injection
    • cross-site scripting
    • malware
  •  Cloud:
    • data breaches
    • insecure APIs
    • DoS/DDoS
    • compromised credentials
  1. Compare common security vulnerabilities
  • software bugs
  • weak and/or hardcoded passwords
  • SQL injection
  • missing encryption
  • buffer overflow
  • path traversal
  • cross-site scripting/forgery
  1. Describe functions of the cryptography components
  • Hashing
  • Encryption
  • PKI
  • SSL
  • IPsec
  • NAT-T IPv4 for IPsec
  • pre-shared key
  • certificatebased authorization
  1. Compare site-to-site VPN and remote access VPN deployment types
  • sVTI
  • IPsec
  • Cryptomap
  • DMVPN
  • FLEXVPN including high availability considerations
  • AnyConnect
  1. Describe security intelligence authoring, sharing, and consumption
  2. Explain the role of the endpoint in protecting humans from phishing and socialengineering attacks
  3. Explain North Bound and South Bound APIs in the SDN architecture
  4. Explain DNAC APIs for network provisioning, optimization, monitoring, and troubleshooting
  5. Interpret basic Python scripts used to call Cisco Security appliances APIs
Network Security [20%]
  1. Compare network security solutions that provide intrusion prevention and firewall capabilities
  2. Describe deployment models of network security solutions and architectures that provide intrusion prevention and firewall capabilities
  3. Describe the components, capabilities, and benefits of NetFlow and Flexible NetFlow records
  4. Configure and verify network infrastructure security methods (router, switch, wireless)
  • Layer 2 methods (Network segmentation using VLANs and VRF-lite)
  • Layer 2 and port security
  • DHCP snooping
  • Dynamic ARP inspection
  • storm control
  • PVLANs to segregate network traffic
  • defenses against MAC
  • ARP
  • VLAN hopping
  • STP
  • DHCP rogue attacks
  1. Device hardening of network infrastructure security devices
  • control plane
  • data plane
  • management plane
  • routing protocol security
  1. Implement segmentation, access control policies, AVC, URL filtering, and malware protection
  2. Implement management options for network security solutions
  • Intrusion prevention and perimeter security (Single vs. multidevice manager
  • In-band vs. out-of-band
  • CDP
  • DNS
  • SCP
  • SFTP
  • DHCP security
  • risks
  1. Configure AAA for device and network access
  • authentication and authorization
  • TACACS+
  • RADIUS and RADIUS flows
  • Accounting
  • dACL
  1. Configure secure network management of perimeter security and infrastructure devices (secure device management, SNMPv3, views, groups, users, authentication, and encryption, secure logging, and NTP with authentication)
  2. Configure and verify site-to-site VPN and remote access VPN
  • Site-to-site VPN utilizing Cisco routers and IOS
  • Remote access VPN using Cisco AnyConnect Secure Mobility client
  • Debug commands to view IPsec tunnel establishment and troubleshooting
Securing the cloud [15%]

1.Identify security solutions for cloud environments

  • Public, private, hybrid, and community clouds
  • Cloud service models: SaaS, PaaS, IaaS (NIST 800-145)
  1. Compare the customer vs. provider security responsibility for the different cloud service models
  •  Patch management in the cloud
  •  Security assessment in the cloud
  • Cloud-delivered security solutions such as firewall, management, proxy, security intelligence, and CASB
  1. Describe the concept of DevSecOps (CI/CD pipeline, container orchestration, and security
  2. Implement application and data security in cloud environments
  3. Identify security capabilities, deployment models, and policy management to secure the cloud
  4. Configure cloud logging and monitoring methodologies
  5. Describe application and workload security concepts
Content Security [15%]
  1. Implement traffic redirection and capture methods
  2. Describe web proxy identity and authentication including transparent user identification
  3. Compare the components, capabilities, and benefits of local and cloud-based email and web solutions (ESA, CES, WSA)
  4. Configure and verify web and email security deployment methods to protect on-premises and remote users (inbound and outbound controls and policy management)
  5. Configure and verify email security features
  • SPAM filtering
  • antimalware filtering
  • DLP
  • Blacklisting
  • email encryption
  1. Configure and verify secure internet gateway and web security features
  • Blacklisting
  • URL filtering
  • malware scanning
  • URL categorization
  • web application filtering
  • TLS decryption
  1. Describe the components, capabilities, and benefits of Cisco Umbrella
  2. Configure and verify web security controls on Cisco Umbrella
  • Identities
  • URL content settings
  • destination lists
  • reporting
End point protection and Detection [10%]
  1. Compare Endpoint Protection Platforms (EPP) and Endpoint Detection & Response (EDR) solutions
  2. Explain antimalware, retrospective security, Indication of Compromise (IOC), antivirus, dynamic file analysis, and endpoint-sourced telemetry
  3. Configure and verify outbreak control and quarantines to limit infection
  4. Describe justifications for endpoint-based security
  5. Describe the value of endpoint device management and asset inventory such as MDM
  6. Describe the uses and importance of a multifactor authentication (MFA) strategy
  7. Describe endpoint posture assessment solutions to ensure endpoint security
  8. Explain the importance of an endpoint patching strategy
Secure Network Access, Visibility and Enforcement [15%]
  1. Describe identity management and secure network access concepts
  • Guest services
  • Profiling
  • Posture assessment
  • BYOD
  1. Configure and verify network access device functionality
  • 1X
  • MAB
  • WebAuth
  1. Describe network access with CoA
  2. Describe the benefits of device compliance and application control
  3. Explain exfiltration techniques
  • DNS tunneling
  • HTTPS
  • Email
  • FTP/SSH/SCP/SFTP
  • ICMP
  • Messenger
  • IRC
  • NTP
  1. Describe the benefits of network telemetry
  2. Describe the components, capabilities, and benefits of these security products and solutions
  • Cisco Stealthwatch
  • Cisco Stealthwatch Cloud
  • Cisco pxGrid
  • Cisco Umbrella Investigate
  • Cisco Cognitive Threat Analytics
  • Cisco Encrypted Traffic Analytics
  • Cisco AnyConnect Network Visibility Module (NVM)

Deployment [30%]

1.1 Implement NGFW modes

  •  Routed mode
  •  Transparent mode

1.2 Implement NGIPS modes

  •  Passive
  •  Inline

1.3 Implement high availability options

  •  Link redundancy
  •  Active/standby failover
  •  Multi-instance

1.4 Describe IRB configurations

Configuration [30%]

2.1 Configure system settings in Cisco Firepower Management Center

2.2 Configure these policies in Cisco Firepower Management Center

  •  Access control
  •  Intrusion
  •  Malware and file
  •  DNS
  •  Identity
  • SSL
  •  Prefilter

2.3 Configure these features using Cisco Firepower Management Center

  •  Network discovery
  •  Application detectors (Open AppID)
  • Correlation
  • Actions

2.4 Configure objects using Firepower Management Center

  • Object Management
  • Intrusion Rules

2.5 Configure devices using Firepower Management Center

  • Device Management
  • NAT
  • VPN
  • QoS
  • Platform Settings
  • Certificates
Management and Troubleshooting [25%]

3.1 Troubleshoot with FMC CLI and GUI

3.2 Configure dashboards and reporting in FMC

3.3 Troubleshoot using packet capture procedures

3.4 Analyze risk and standard reports

Integration [15%]

4.1 Configure Cisco AMP for Networks in Firepower Management Center

4.2 Configure Cisco AMP for Endpoints in Firepower Management Center

4.3 Implement Threat Intelligence Director for third-party security intelligence feeds

4.4 Describe using Cisco Threat Response for security investigations

4.5 Describe Cisco FMC PxGrid Integration with Cisco Identify Services Engine (ISE)

4.6 Describe Rapid Threat Containment (RTC) functionality within Firepower Management Center

Architecture and Deployment [10%]

1.1 Configure personas

1.2 Describe deployment options

Policy Enforcement [25%]

2.1 Configure native AD and LDAP

2.2 Describe identity store options

  •  LDAP
  •  AD
  •  PKI
  •  OTP
  •  Smart Card
  •  Local

2.3 Configure wired/wireless 802.1X network access

2.4 Configure 802.1X phasing deployment

  • Monitor mode
  •  Low impact
  • Closed mode

2.5 Configure network access devices

2.6 Implement MAB

2.7 Configure Cisco TrustSec

2.8 Configure policies including authentication and authorization profiles

Web Auth & Guest Services [15%]

3.1 Configure web authentication

3.2 Configure guest access services

3.3 Configure sponsor and guest portals

Profiler [15%]

4.1 Implement profiler services

4.2 Implement probes

4.3 Implement CoA

4.4 Configure endpoint identity management

BYOD [15%]

5.1 Describe Cisco BYOD functionality

  • Use cases and requirements
  • Solution components
  • BYOD flow

5.2 Configure BYOD device on-boarding using internal CA with Cisco switches and Cisco wireless LAN controllers

5.3 Configure certificates for BYOD

5.4 Configure blacklist/whitelist

End point compliance [10%]

6.1 Describe endpoint compliance, posture services, and client provisioning

6.2 Configure posture conditions and policy, and client provisioning

6.3 Configure the compliance module

6.4 Configure Cisco ISE posture agents and operational modes

6.5 Describe supplicant, supplicant options, authenticator, and server

Network Access Device Administration [10%]

7.1 Compare AAA protocols

7.2 Configure TACACS+ device administration and command authorization

Cisco Email Security Appliance Administration [15%]

1.1. Configure Cisco Email Security Appliance features

  • Hardware performance specifications
  • Initial configuration process
  • Routing and delivery features
  • GUI

1.2. Describe centralized services on a Cisco Content SMA

1.3. Configure mail policies

  • Incoming and outgoing messages
  • User matching
  • Message splintering
SpamControl with Talos SenderBase and Antispam [15%]

2.1 Control spam with Talos SenderBase and Antispam

2.2 Describe graymail management solution

2.3 Configure file reputation filtering and file analysis features

2.4 Implement malicious or undesirable URLs protection

2.5 Describe the bounce verification feature

Content and Message filters [20%]

3.1 Describe the functions and capabilities of content filters

3.2 Create text resources such as content dictionaries, disclaimers, and templates

  • Dictionaries filter rules
  • Text resources management

3.3 Configure message filters components, rules, processing order and attachment scanning

3.4 Configure scan behavior

3.5 Configure the Cisco ESA to scan for viruses using Sophos and McAfee scanning engines

3.6 Configure outbreak filters

3.7 Configure Data Loss Prevention (DLP)

LDAP & SMTP sessions [15%]

4.1 Configure and verify LDAP servers and queries (Queries and Directory Harvest Attack)

4.2 Understand spam quarantine functions

  • Authentication for end-users of spam quarantine
  •  Utilize spam quarantine alias to consolidate queries

4.3 Understand SMTP functionality

  •  Email pipeline
  •  Sender and recipient domains
  •  SMTP session authentication using client certificates
  •  SMTP TLS authentication
  •  TLS email encryption
Email Authentication & Encryption [20%]

5.1 Configure Domain Keys and DKIM signing

5.2 Configure SPF and SIDF

5.3 Configure DMARC verification

5.4 Configure forged email detection

5.5 Configure email encryption

5.6 Describe S/MIME security services and communication encryption with other MTAs

5.7 Manage certificate authorities

System Quarantines and Delivery methods [15%]

6.1 Configure quarantine (spam, policy, virus, and outbreak)

6.2 Utilize safelists and blocklists to control email delivery

6.3 Manage messages in local or external spam quarantines

6.4 Configure virtual gateways

Cisco WSA Features [10%]

1.1 Describe Cisco WSA features and functionality

  •  Proxy service
  • Cognitive Threat Analytics
  • Data loss prevention service
  • Integrated L4TM service
  •  Management tools

1.2 Describe WSA solutions

  • Cisco Advanced Web Security Reporting
  • Cisco Content Security Management Appliance

1.3 Integrate Cisco WSA with Splunk

1.4 Integrate Cisco WSA with Cisco ISE

1.5 Troubleshoot data security and external data loss using log files

Configuration [20%]

2.1 Perform initial configuration tasks on Cisco WSA

2.2 Configure an Acceptable Use Policy

2.3 Configure and verify web proxy features

  •  Explicit proxy functionality
  • Proxy access logs using CLI
  • Active directory proxy authentication

2.4 Configure a referrer header to filter web categories

Proxy Service [10%]

3.1 Compare proxy terms

  • Explicit proxy vs. transparent proxy
  • Upstream proxy vs. downstream proxy

3.2 Describe tune caching behavior for safety or performance

3.3 Describe the functions of a Proxy Auto-Configuration (PAC) file

3.4 Describe the SOCKS protocol and the SOCKS proxy services

 Authentication [10%]

4.1 Describe authentication features

  • Supported authentication protocols
  • Authentication realms
  • Supported authentication surrogates supported
  • Bypassing authentication of problematic agents
  • Authentication logs for accounting records
  • Re-authentication

4.2 Configure traffic redirection to Cisco WSA using explicit forward proxy mode

4.3 Describe the FTP proxy authentication

4.4 Troubleshoot authentication issues

 Decryption policies to control HTTPS Traffic [10%]

5.1 Describe SSL and TLS inspection

5.2 Configure HTTPS capabilities

  • HTTPS decryption policies
  • HTTPS proxy function
  • ACL tags for HTTPS inspection
  • HTTPS proxy and verify TLS/SSL decryption
  • Certificate types used for HTTPS decryption

5.3 Configure self-signed and intermediate certificates within SSL/TLS transactions

Differentiated Traffic Access Policies and Identification profiles [10%]

6.1 Describe access policies

6.2 Describe identification profiles and authentication

6.3 Troubleshoot using access logs

Acceptable Use Controls [10%]

7.1 Configure URL filtering

7.2 Configure the dynamic content analysis engine

7.3 Configure time-based & traffic volume acceptable use policies and end user notifications

7.4 Configure web application visibility and control (Office 365, third-party feeds)

7.5 Create a corporate global acceptable use policy

7.6 Implement policy trace tool to verify corporate global acceptable use policy

7.7 Configure WSA to inspect archive file types

Malware Defense [10%]

8.1 Describe anti-malware scanning

8.2 Configure file reputation filtering and file analysis

8.3 Describe Advanced Malware Protection (AMP)

8.4 Describe integration with Cognitive Threat Analytics

Reporting and Tracking Web Transaction  [10%]

9.1 Configure and analyze web tracking reports

9.2 Configure Cisco Advanced Web Security Reporting (AWSR)

  • Basic web usage
  • Custom filters

9.3 Troubleshoot connectivity issues

Site-to-site Virtual Private Networks on Routers and Firewalls [15%]

1.1 Describe GETVPN

1.2 Implement DMVPN (hub-and-spoke and spoke-to-spoke on both IPv4 & IPv6)

1.3 Implement FlexVPN (hub-and-spoke on both IPv4 & IPv6) using local AAA

Remote access VPNs[20%]

2.1 Implement AnyConnect IKEv2 VPNs on ASA and routers

2.2 Implement AnyConnect SSLVPN on ASA and routers

2.3 Implement Clientless SSLVPN on ASA and routers

2.4 Implement Flex VPN on routers

Troubleshooting using ASDM and CLI [35%]

3.1 Troubleshoot IPsec

3.2 Troubleshoot DMVPN

3.3 Troubleshoot FlexVPN

3.4 Troubleshoot AnyConnect IKEv2 and SSL VPNs on ASA and routers

3.5 Troubleshoot Clientless SSLVPN on ASA and routers

Secure Communications Architectures[30%]

4.1 Identify functional components of GETVPN, FlexVPN, DMVPN, and IPsec for site-to-site VPN solutions

4.2 Identify functional components of FlexVPN, IPsec, and Clientless SSL for remote access VPN solutions

4.3 Identify VPN technology based on configuration output for site-to-site VPN solutions

4.4 Identify VPN technology based on configuration output for remote access VPN solutions

4.5 Identify split tunneling requirements for remote access VPN solutions

4.6 Design site-to-site VPN solutions

  • VPN technology considerations based on functional requirements
  • High availability considerations

4.7 Design remote access VPN solutions

  • VPN technology considerations based on functional requirements
  • High availability considerations
  • Clientless SSL browser and client considerations and requirements

4.8 Identify Elliptic Curve Cryptography (ECC) algorithms

Network Programmability Foundation [10%]

1.1 Utilize common version control operations with git (add, clone, push, commit, diff, branching, and merging conflict)

1.2 Describe characteristics of API styles (REST and RPC)

1.3 Describe the challenges encountered and patterns used when consuming APIs synchronously and asynchronously

1.4 Interpret Python scripts containing data types, functions, classes, conditions, and looping

1.5 Describe the benefits of Python virtual environments

1.6 Explain the benefits of using network configuration tools such as Ansible and Puppet for automating security platforms

Network Security [35%]

2.1 Describe the event streaming capabilities of Firepower Management Center eStreamer API

2.2 Describe the capabilities and components of these APIs

  • Firepower (Firepower Management Center and Firepower Device Management)
  • ISE
  • pxGRID
  • Stealthwatch Enterprise

2.3 Implement firewall objects, rules, intrusion policies, and access policies using Firepower Management Center API

2.4 Implement firewall objects, rules, intrusion policies, and access policies using Firepower Threat Defense API (also known as Firepower Device Manager API)

2.5 Construct a Python script for pxGrid to retrieve information such as endpoint device type, network policy and security telemetry

2.6 Construct API requests using Stealthwatch API

  • perform configuration modifications
  • generate rich reports
 Advanced Threat & Endpoint Security [30%]

3.1 Describe the capabilities and components of these APIs

  • Umbrella Investigate APIs
  • AMP for endpoints APIs
  • ThreatGRID API

3.2 Construct an Umbrella Investigate API request

3.3 Construct AMP for endpoints API requests for event, computer, and policies

3.4 Construct ThreatGRID APIs request for search, sample feeds, IoC feeds, and threat disposition

Cloud, Web, and Email Security [25%]

4.1 Describe the capabilities and components of these APIs

  • Umbrella reporting and enforcement APIs
  • Stealthwatch cloud APIs
  •  Cisco Security Management Appliance APIs

4.2 Construct Stealthwatch cloud API request for reporting

4.3 Construct an Umbrella Reporting and Enforcement API request

4.4 Construct a report using Cisco Security Management Appliance API request (email and web)


Key Features of Our CCNP Security

Learn Core Skills

Learn Deep Routed Technology from basics to advanced level

Dedicated Student Trainer

CCIE Certified trainers with industry experience.

Exam Materials

CCNP Security Written exam preparation materials provided

Study Resources

Get Class recordings , Class notes , Reference books and lab videos

Lab Facility

An enhanced lab topology that represents a real-world network

Training Duration

80 hours of technology labs


Lab Infrastructure

IP Rulers has a fully equipped lab, specially designed for the CCNP Security training, with an enhanced lab topology that represent real world network. Students will have the following equipment and software configured for their training; they may also get the chance to see newer hardware and software during this period.

  Cisco Identity Services Engine (ISE): 2.4

Cisco Web Security Appliance (WSA): 9.2

Cisco Email Security Appliance (ESA): 11.1

Cisco Firepower Management Center Virtual Appliance: 6.2

Cisco Firepower NGIPSv: 6.2

Cisco Firepower Threat Defense: 6.2

Cisco Adaptive Security Virtual Appliance (ASAv): 9.4(3)

Cisco CSR 1000V Series Cloud Services Router: 15.5.(3), 16.6.3

Cisco StealthWatch SMC-FC: 6.10

Cisco FireAMP Cloud: 5.3

Cisco Wireless Controller (WLC): 8.3

Cisco DNA Center Release 1.3.1

L2IOSv: 15.2

Cisco Adaptive Security Appliance: ASA5512: 9.2

Cisco Adaptive Security Appliance: ASA5516: 9.8

Cisco Catalyst Switch: C3650: 16.6

Cisco Catalyst Switch: C3850: 3.7

Cisco Wireless Access Point: AP1852: 8.3

Cisco iP phone 7965

 

 

 

 

 

 

 

 

 

 

 

 

 

Test PC: Windows 10 Enterprise

AD/DNS: Window Server 2016

Linux Kali: 4.17

Cisco Anyconnect: 4.2

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Interset To know more about us

Reach Us

If you Have Any Questions Call Us / Whats app On +971559454771

Testimonial

Open chat