Search This Blog

Friday, October 18, 2013

CCNA Security: The Journey Begins... (Definitive Starting Guide)

Just yesterday I scheduled my CCNA Security exam. I felt this would be a good time to provide a starting tips for those who are not sure where to begin. In this post, I will address how to get to go about studying to get certified, talk about preparation materials, as well as lab setup choices.

Getting Started


Understanding what you will actually be tested on is an essential step for developing a study plan. First, I highly recommend familiarizing yourself with the official CCNA Security Syllabus, Exam Topics, and Exam FAQ. Take the time to figure out exactly what topics you may encounter on the exam. You should also take the time to familiarize yourself with Question Types and Exam Policies.

Now that you have a general understanding of what's covered, I will now cover different ways you can go about learning the material.

Option 1: Attend a Class or Bootcamp


Cisco offers top notch training through education partners. If you would like to learn using a structured curriculum this may be a viable option. Some of the advantages to this approach are:
  • Access to world class Cisco Certified instructors
  • Structured curriculum
  • Pre-built labs to further hone your skills
  • Exposure to concepts and ideas beyond just the certification
  • Examinations
  • Access to physical/virtual lab environments
  • Lab environments based off real world scenarios
If this option interests you, I would advice using the Global Learning Locator to find a class near you. Out of pocket, these classes are typically pretty expensive. If you are currently employed or work for a Cisco Certified Partner, they may be willing to cover these costs for you. The cost for one of these classes can range anywhere from $3000-4000 USD. So check with your boss or your personal finances to determine whether this is a viable option.

Option 2: Attend a Cisco Networking Academy Course


Another option is to check out the actual Cisco Networking Academy program for the CCNA Security. Like Option 1, the CNA offers a structured curriculum for learning the concepts covered in the 640-554 exam. The CNA is on of the largest IT training academies worldwide with over 1,000,000 students, and 10,000 academies in over 100 countries. The offered CNA courses are available to both college and non-college students.

Use the Academy Locator to find an academy near you. As a NetAcad, student you will have access to:
  • Structured curriculum developed through industry partnerships
  • Pre-built labs to further hone your skills
  • Packet Tracer simulation software (practice tool which simulates Cisco hardware)
  • Cisco Certified instructors
  • Online assessments and practice exams
  • Chance to receive a certificate of completion and letter signed by John Chambers for completion of the program (first attempt grade 80% or above on final exam)
  • Chance to receive a voucher (first attempt grade of 75% or above on final exam) which offers a substantial discount when you schedule your certification exam
  • As a netacad student at the (CCNA level only) you are eligible to compete in the Cisco NetRiders Skills Challenge
  • And many more benefits...
Some colleges and universities have also integrated the CNA as part of their degree programs. An additional benefit is that you could also receive college credit for attending the class. As a college undergrad, I attended both the CCNA Discovery, CCNA Exploration, and later the CCNP course as a grad student. My personal experience with the academy was very pleasant. The top notch curriculum through the CNA also made learning networking lots of fun. I cannot recommend the CNA enough.

If this option interests you, make sure to utilize the Academy Locator. The cost of this course is relative to the institution offering it. Make sure to ask this question when contacting an academy.

Option 3: Self Study


If you are highly self driven and motivated to learn, self studying is a great alternative (and cheaper) to a formal class. This is the route I opted for in my CCNA Sec studies. Ultimately, this path is more difficult to pursue. However, with a structured approach, you can master the 640-554 exam with relative ease.

Preparation Materials


Now I will talk about some free and also pay prep materials that will help you master the 640-554 exam. My personal recommendation is to combine both free materials as well as pay options for your studies.

    Free Options:


Cisco does offer some free prep materials for the IINS Exam. I would also recommend using youtube to your advantage. There are many video lessons freely available for your consumption. Also, consider joining a Study GroupCertCollection is also another great user community for studying a variety of IT exams. When having trouble understanding concepts, you would be surprised how a like minded community can help in explaining complex topics. Study groups and user forums are also a great source for GNS3 and Packet Tracer labs. Use these resources to your advantage.

    Pay Options:



Title: CCNA Security 640-554 Official Cert Guide and LiveLessons Bundle (Recommended)
Authors: Keith Barker, Scott Morris

The official cert guide is the definitive book I would recommend for those with prior exposure to information security. This book provides a concise and straight to the point discussion on all exam topics. It provides chapter quizzes as well as a companion disc with a practice test. Optionally, you can buy the premium upgrade (instructions provided in the book) which will give you access to additional practice exams. This book can be bought by itself or as a bundle with live lessons. I also highly recommend the live lessons which are from the author of the book as well.


Title: Implementing Cisco IOS Network Security (IINS 640-554) Foundation Learning Guide (2nd Edition) (Foundation Learning Guides) (Optional)
Authors: Catherine Paquet

The Foundation Learning Guide books contain the same material covered in the Cisco Networking Academy program mentioned above. This book is great for those that are newer to the Information Security industry. If you do not have a background in Information Assurance, Security Design, and/or Encryption algorithms, you should think about picking up a copy. Unlike the cert guide, the author spends more time covering these topics. I would even go so far as to say some chapters could even be used for a general security design class. If you have little or no background in IS I highly recommend this book.

Title: CBT Nuggets: CCNA Security (Optional)
Authors: Keith Barker

This video training series is authored by the same author of the cert guide book. Keith does a great job of breaking down the exam topics and combines real world experience with classroom instruction. Definitely consider this product if you prefer video lessons over text based publications.



Title: CCNA Portable Command Guide (Optional)
Authors: Bob Vachon

The portable command guide series of books are great for quickly covering a lot of material really quick. Aside from quick command lookups this book also contains all the concepts/material covered in the other books mentioned in a quick format. This is a great resource for the final days before your exam or as an aid for your lab work.


Title: CCNA Security Lab Manual Version 1.1 (2nd Edition) (Recommended)
Authors: Cisco Networking Academy

This is the same lab manual used by the Cisco Networking Academy. This book is highly recommended since it provides all the same labs offered to NetAcad students. Great for all your hands on practicing needs.

One final website I will recommend is Safari Books Online. If you can afford the yearly $400 subscription fee, you will have access to all Cisco press books as well as certification books for a variety of companies/products.

Practice Exams


As mentioned previously, the official cert guide comes with a practice exam. Optionally you can also upgrade to the premium and receive access to additional practice exams. It's no secret there are many exam dumps out there from companies like Pass4Sure, Lead2Pass. If you have a .vce reader there are also many websites out there which contain exam dumps as well. Exam Collection has a large databank of these .vce files. Just remember, if you use a dump, make sure you understand the concepts behind the question/answers and not just the answer itself. Securitytut is also a good resource for practice lab simulations (using packet tracer) and practice questions.

Also, as previously mentioned, join a study group and user forums. Users regularly post questions as well as practice lab simulations online.

Lab Equipment


Ideally real equipment is the way to go. According to the lab manual presented above you will need:
  • 3 1841 routers
  • 3 2950-T switches
  • 1 ASA 5505
  • 3 desktop machines
You may be asking why couldn't I just replace the 1841's with 2600 series routers? The short answer is you can but unfortunately the 2600 series doesn't support zone based firewall or IOS IPS which is covered in the 640-554 exam. The longer do's and dont's discussion about purchasing lab equipment can be found here. You should also make sure the equipment your buying comes with IOS version 12.4 with advanced IP services.

Another alternative is to virtualize your lab equipment using GNS3. GNS3 by itself is not enough to practice everything covered in the 640-554 exam (most notably Layer 2 security). For my personal lab setup, I took a hybrid approach which only cost $90. I bought two 2960-TT-L switches and borrowed a 2621XM. I then used USB Ethernet NIC's (make sure they support VLAN tagging) to connect my physical equipment to my GNS3 virtualized topology.

In another post, I wrote about how I accomplished this using individual NIC's. In a subsequent post, I plan on discussing in more detail how to set up a hybrid lab in more depth using both individual NIC's and a breakout switch design. GNS3 can also be used to emulate the ASA as well. However, in order to obtain image files required by GNS3, you will need to have access to a Cisco CCO account. I won't link to any sites here, but I will also say you can find GNS3 supported IOS and ASA image files elsewhere on the internet.

Just as an example, my physical and GNS3 lab topologies for the Chapter 9 lab from the lab manual are illustrated below:

 
 
 
For reference, here is the original topology:



This lab setup gives me the flexibility to complete all the labs in the lab manual (including Layer 2 security) all for $90 - $140. Additionally, another option is to completely virtualize your lab in GNS3 and use Cisco's Packet Tracer for practicing layer 2 hardening. As you can say there are a variety of ways to setup a practice lab. I recommend the hybrid approach for the budget conscious.

Study Plan


This study plan assumes you 1.5 - 2 months worth of preparation time. If you have less, I recommend first taking a practice exam, then focus on the areas you are weakest. If your not sure if you fully understand a certain topic, write it down and keep going. Develop a algorithm (checklist) for different configuration tasks. Example:

For configuring a radius server:
  • Configure hostname
  • Configure enable secret and enable service password-encryption
  • Configure AAA
    • AAA new-model
    • Create AAA authentication list with group radius
  • Configure a radius server host (change auth port, accounting port, and configure a key)

Forming checklists like these will get you into good habits and will burn the configuration steps into your brain. Also make a list of all the different ways you can secure the Control, Data, and Management plane and study that list.

Assuming you bought the Cert guide, make sure to read the Introduction. They provide an already laid out study plan that I think you will find useful. In the first week, research common attacks on the network infrastructure and read the first 3 chapters of the cert guide. If you bought the foundation learning guide as well, make sure to read Chapters 1 and 2 as well. In week 1, also go through the Intro lab to make sure you can access your routers via CCP. You will have to know CCP and ASDM in and out come exam day.

Dedicate subsequent weeks to each Part of either book (ex. week 1 is dedicated to Part 1 so on and so forth). Ask questions in study groups if you are still unclear about something. Here is the general study plan I developed for myself. As a rough timeline I recommend doing the following:

  • Week 1: Read part 1 of CertGuide or Foundation book. Perform intro CCP lab from the lab manual as well as lab Chapter 1 Lab A. Research online common attacks on network infrastructure.
  • Week 2: Proceed by reading part 2 of either book. Perform labs Chapter 2 Lab A, Chapter 3 Lab A.
  • Week 3: Read part 3 of either book and do labs Chapter 4 Lab A, Chapter 5 Lab A, and Chapter 6 Lab A.
  • Week 4: Early in the week start reading Part 4 and work on Chapter 7 Lab A. Later in the week work on the Chapter 8 labs.
  • Week 5: Keep working on labs. If you marked down topics you didn't fully understand go back and read again. Finish the week off with Chapter 9 Lab A (Challenge lab). At this point you should have been exposed to most of the material in the book. If time permits during this week, take your first practice exam.
  • Remaining weeks until exam: Take the same approach as week 5. Work on the remaining labs. Review concepts you are not sure about. Keep taking practice exams.

Welp, that's all for this post! If you would like to contribute studying tips, please do so in the comments. Take care!

50 comments:

  1. Hi, It's the good think and you write such good thing.
    see @http://networkexpert.co

    ReplyDelete
  2. very good info. tomorrow i take the exam.

    visit my page for useful stuff www.jorgelargaespada.wordpress.com

    ReplyDelete

  3. Thanks Author,
    It's very useful about Cisco Training Promotions .I also want to recommend one another Expert in this field at New York who provide the great offers ..

    ReplyDelete
  4. Gaining Cisco CCNA certification justifies that you have high level of knowledge and needed skills in networking, Think It offer you guidance to achieve this certification.

    ReplyDelete
  5. Gaining Cisco CCNA certification justifies that you have high level of knowledge and needed skills in networking, Think It offer you guidance to achieve this certification.visit:www.thinkittraining.in/

    ReplyDelete
  6. The CCNA these information really worth saying, i think you are master of the content and thank you so much sharing that valuable information and get new skills after refer that post.
    sap basis training in chennai

    ReplyDelete
  7. "Good matter,
    It's very useful about IT Certification's .I also want to recommend one another Expert in this field at New York who provide the Cisco Training Course ..

    CCNA Security"

    ReplyDelete
  8. I wish I had your creative writing skills, progressive talent and self discipline to produce a blog like you did. Your blog really does deserve an honest compliment.
    ccna security training in noida


    ReplyDelete
  9. Usually I do not read post on blogs, but I would like to say that this write-up very forced me to try and do it! Your writing style has been surprised me. Thanks, very nice article.

    Corporate Training in Chennai

    ReplyDelete
  10. I do believe all of the concepts you’ve introduced in your post. They’re very convincing and will definitely work. Nonetheless, the posts are too short for novices. May you please extend them a bit from subsequent time? Thank you for the post.

    SMO Services Chennai

    ReplyDelete

  11. I am good follower of your site. Daily i will refer your site for enhance my knowledge in the area of website designing. Toady you really taught me how to write good content for your site.Great jobs done by you.



    Best Sharepoint Training institute in chennai

    ReplyDelete
  12. wow great,nowadays this type of blog id more important and informative technology,it was more impressive to read ,which helps to design more in effective ways

    Java J2ee training in chennai

    ReplyDelete
  13. Great post ,very useful for ccna networking students. As These topics on ccna security are great, and also the explanation is very effective. For training and placement visit : http://asiteducation.com/courses/ccnaroutingswitching/

    ReplyDelete
  14. Thanks to the author for great post. I really like your point of view.Please visit once at qosnetworking.com.

    ReplyDelete
  15. Thank you for describing there various options for CCNA for beginners. Yes of course there may choose upon with various but among that when choosing with desired institute or center i much difficult. Anyway thank you for providing this here.

    CCNA Training in Chennai

    ReplyDelete
  16. wow amazing post.The key points you mentioned here related to maintenance of car is really awesome.Checking all fluid levels,changing oil and of course the regular service of the car which is necessary to maintain our vehicle.Thank you for the information.

    House Cleaning Services in Mumbai
    Car Wash Services in Mumbai

    ReplyDelete
  17. Thank you for taking the time to provide us with your valuable information. We strive to provide our candidates with excellent care.As always, we appreciate you confidence and trust in us.
    Back to original

    ReplyDelete
  18. Superb. I really enjoyed very much with this article here. Really it is an amazing article I had ever read. I hope it will help a lot for all. Thank you so much for this amazing posts and please keep update like this excellent article.thank you for sharing such a great blog with us. expecting for your.
    seo company in india

    ReplyDelete
  19. This is a great post. I like this topic.This site has lots of advantage. It helps me in many ways.Thanks for posting this again.


    Best Dentists In Chennai

    ReplyDelete
  20. It’s amazing in support of me to have a site, which is useful in support of my know-how. thanks admin|, you surely come with remarkable articles. Cheers for sharing your website page.Excellent blog here...

    Car Spa at Doorstep in Mumbai

    ReplyDelete




  21. تعد عملية التنظيف من اهم الخدمات التي يجب ان تكون متوفره دوما ليساعدنا علي حياه افضل لنا جميعا ولكي تتم علي اكمل وجه يجب الاستعانه بمتخصصين في هذا المجال
    شركة تنظيف مساجد
    نظرا لما يمتلكون من ادوات وسبل للوصول لاعلي مستوي نظافه ممكن

    ReplyDelete
  22. A nice article here with some useful tips for those who are not used-to comment that frequently. Thanks for this helpful information I agree with all points you have given to us. I will follow all of them.
    Office Interiors in Chennai
    Interior Decorators in Chennai

    ReplyDelete
  23. CCNA training London

    We are leading cisco ccna trainin gprovider in London. We provide all the cisco courses including cisco ccna, ccna security.

    ReplyDelete
  24. My Genius Mind is a reputed educational facility providing portal that has been offering high-end Assignment Services Melbourne solutions.
    Live Chat @ https://www.mygeniusmind.com/new-south-wales-assignment-help

    Read More @ Brisbane Queensland Assignment Help
    Instant Assignment Help Tasmania
    Business Management Assignment Help

    ReplyDelete
  25. Nursing Assignment Writer Kansas – The Best Tutors is a reliable academic portal that is known to offer exceptional educational assistance to the nursing assignment services students at a small price. Live Chat @ https://www.besttutors.us/medical-assignment-help

    Read More @ Nursing Assignment Writer Kansas
    Software Engineering Homework Help Alaska

    ReplyDelete
  26. Australia Best Tutor is available providing Help with Assignment Services Melbourne that help the students in preparing a relevant and innovative assignment paper. These experts are highly efficient and well trained.

    Live Chat @ https://www.australiabesttutor.com

    Read More About

    Assignment Help Melbourne
    Help with Assignment Melbourne
    Mathematics Assignment Help Melbourne
    Engineering Assignment Help Melbourne

    ReplyDelete
  27. Australia Best Tutor is available providing Help with Assignment Services Melbourne that help the students in preparing a relevant and innovative assignment paper. These experts are highly efficient and well trained.

    Live Chat @ https://www.australiabesttutor.com

    Read More About

    Assignment Help Melbourne
    Help with Assignment Melbourne
    Mathematics Assignment Help Melbourne
    Engineering Assignment Help Melbourne

    ReplyDelete
  28. My Homework Help Services Australian Territory – Help with Assignments is a reliable academic company offering high-end direction and help to the students pursuing homework help at a very reasonable price.
    Live Chat @ https://www.helpwithassignments.com/homework-help-services

    Read More @ Economics Help Online Victoria

    Management Assignment Help Victoria

    ReplyDelete
  29. Nursing Assignment Writer Arkansas – The Best Tutors is a best academic portal that is known for success help in completing assignment services to the students. Live Chat @ https://www.besttutors.us/medical-assignment-help

    Read More @ Forensic Accounting Homework Help Alaska
    Pre- Calculus Homework Help Alabama

    ReplyDelete
  30. My Genius Mind is a reputed academic concern that extends best professional Assignment Help to the students. This service can be availed at any time anywhere.
    Live Chat @ https://www.mygeniusmind.com/my-assignment-help
    Read More Information @ Accounting Assignment Help Brisbane
    Boston South Australia Assignment Help
    Mandurah Western Australia Assignment Help
    NewCastle NSW Assignment Help

    ReplyDelete
  31. Management Tutors, known for offering fantastic coursework help to the students. It is beneficial to the students in the achievement of their goals and getting good grades by the teachers.
    Live Chat @ https://www.managementtutors.com/professional-help-with-assignment-uk
    Read More @ Dissertation Help Services Adelaide
    Business Management Help Melbourne
    Project Management Help Queensland
    Operational Management Assignment Brisbane

    ReplyDelete
  32. Management Tutors, known for offering fantastic coursework help to the students. It is beneficial to the students in the achievement of their goals and getting good grades by the teachers.
    Live Chat @ https://www.managementtutors.com/professional-help-with-assignment-uk
    Read More @ Dissertation Help Services Adelaide
    Business Management Help Melbourne
    Project Management Help Queensland
    Operational Management Assignment Brisbane

    ReplyDelete
  33. Australia Best Tutor is offering online assignment help services Australia at affordable price. Here students are joining for best academics grades and good quality content.Services are under below

    Engineering Assignment Help Brisbane
    Management Assignment Help Brisbane
    Assignment Writing Services Brisbane
    Nursing Assignment Help Perth
    Finance Assignment Help Perth

    Live Chat @ https://www.australiabesttutor.com

    ReplyDelete
  34. The Live Web Experts is a popular academic portal that has made a name for itself with its Geometry assignment Help to the students at the very effective rate.
    Live Chat @ https://www.livewebexperts.com/homework-help/maths-assignment-help

    Read More @ Geometry Assignment Help Michigan
    Accounting Homework Topics Chicago
    Online Probability Homework Illinois

    ReplyDelete
  35. The Best Tutors is one of the well-acclaimed and celebrated academic portals that offer the Math Homework Help. These services are the rapid and affordable price.
    Live Chat @ https://www.besttutors.us/mathematics-homework-help
    Read More @ Civil Engineering Homework Help Arkansas
    Internal Auditing Homework Help

    ReplyDelete
  36. The Best Tutors is a reliable and accessible academic portal that is known for offering exclusively detailed Accounting Homework help to the students.Live Chat @ https://www.besttutors.us/accounting-homework-help
    Read More @ Electrical Engineering Homework Help Colorado
    Thesis Writing Services Connecticut
    Thesis Writing Services Arkansas

    ReplyDelete
  37. Live Web Experts is a favourite educational website that has gained a lot of reputation for submission eccentric Homework Help Online to the students.
    Live Chat @ https://www.livewebexperts.com/homework-help

    Read More @ Finance Textbook Assignment Illinois
    Assignment Help Experts Alaska
    Help Me Write A Paper Taxes

    ReplyDelete
  38. This comment has been removed by the author.

    ReplyDelete
  39. The Salesforce B2C-Solution-Architect exam is a certification that evaluates a candidate's ability to design and implement B2C commerce solutions on the Salesforce platform. It covers topics like online storefronts, order management, and customer service. Passing this exam demonstrates expertise in creating effective B2C solutions, making certified professionals valuable assets in the world of Salesforce commerce.

    ReplyDelete
  40. The 300-410 dumps, commonly known as the Implementing Cisco Enterprise Advanced Routing and Services (ENARSI exam), is a certification exam that evaluates your expertise in advanced routing technology and services. You may become a certified Cisco Certified Specialist in Enterprise Advanced Infrastructure Implementation by passing this exam.

    ReplyDelete