The Security written exam (350-018) has 100 multiple-choice questions and is two hours in duration. The topic areas listed are general guidelines for the type of content that is likely to appear on the exam. Please note, however, that other relevant or related topic areas may also appear.
Security Protocols
Remote Authentication Dial In User Service (RADIUS)
Terminal Access Controller Access Control System Plus (TACACS+)
AES
EAP peap tkip tls
Data Encryption Standard (DES)
Triple DES (3DES)
IP Secure (IPSec)
Internet Key Exchange (IKE)
Certificate Enrollment Protocol (CEP)
Point to Point Tunneling Protocol (PPTP)
Layer 2 Tunneling Protocol (L2TP)
Application Protocols
Domain Name System (DNS)
Trivial File Transfer Protocol (TFTP)
File Transfer Protocol (FTP)
Hypertext Transfer Protocol (HTTP)
Secure Socket Layer (SSL)
Simple Mail Transfer Protocol (SMTP)
Network Time Protocol (NTP)
IOS SSH
Lightweight Directory Access Protocol (LDAP)
Active Directory
RDEP Remote Data Exchange Protocol
General Networking
Networking Basics
TCP/IP
Switching and Bridging (including: VLANs, Spanning Tree, etc.)
Access Devices (for example: Cisco AS 5300 series)
Telephony best practices
Wireless best practices
Security Technologies
Concepts - Security Policy Best Practices
Packet Filtering
PIX and IOS authentication proxies
Port Address Translation (PAT)
Network Address Translation (NAT)
Firewalls
Content Filters
Public Key Infrastructure (PKI)
Authentication Technologies
Authorization technologies
Virtual Private Networks (VPN)
Network IDS anomaly, signature, passive, inline
Host Intrusion Prevention
Cisco Threat Response
Cisco Security Applications
Cisco Secure NT
Cisco Secure PIX Firewall
VMS
Cisco Secure Intrusion Detection System (formerly NetRanger)
IOS® Firewall Feature Set
VPN 3000
Client side VPN
CAT Service Modules
IOS IDS (in line)
Cisco Secure ACS
Security Information Monitoring System (event correlation, basic forensics)
Security General
Policies - Security Policy Best Practices
Standards Bodies - IETF
Vulnerability discussions
Attacks and Common Exploits - recon, priv escalation, penetration, cleanup, backdoor
Cisco General
IOS Specifics
Routing and switching security features: IE mac address controls, port security, dhcp snoop
Security Policy best practices
Preparation Materials
The materials listed below can be helpful in preparing for exams. The list is only suggested,
however, and other books or resources may also cover the same topics.