IT Certification and Career Paths

300-206 SENSS

Implementing Cisco Edge Network Security Solutions

Exam Number 300-206 SENSS
Associated Certifications CCNP Security
Duration 90 minutes (65 - 75 questions)
Available Languages English
Register Pearson VUE
Exam Policies Read current policies and requirements
Exam Tutorial Review type of exam questions

The 300-206 Implementing Cisco Edge Network Security (SENSS) exam tests the knowledge of a network security engineer to configure and implement security on Cisco network perimeter edge devices such as a Cisco Switch, Cisco Router, and Cisco ASA Firewall. This exam focuses on the technologies used to secure the perimeter of a network such as Network Address Translation (NAT), ASA policy and application inspect, and Zone-Based Firewall on Cisco routers. Candidates can prepare for this exam by taking the Cisco Edge Network Security (SENSS) course.

Exam Topics

The exam is closed book, and no outside reference materials are allowed. The following topics are general guidelines for the content that is likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes, the guidelines that follow may change at any time without notice.

  • 25%     1.0   Threat Defense

      • 1.1   Implement Firewall
        • 1.1.a   Implement ACLs
        • 1.1.b   Implement static/dynamic NAT/PAT
        • 1.1.c   Implement object groups
        • 1.1.d   Describe threat detection features
        • 1.1.e   Implement Botnet traffic filtering
           
      • 1.2   Implement Layer 2 security
        • 1.2.a   Configure DHCP snooping
        • 1.2.b   Describe dynamic ARP inspection
        • 1.2.c   Describe storm control
        • 1.2.d   Configure port security
        • 1.2.e   Describe common layer 2 threats and attacks and mitigation
        • 1.2.f   Describe private VLAN
        • 1.2.g   Describe MACSec
           
      • 1.3   Configure device hardening per best practices
        • 1.3.a   Routers
        • 1.3.b   Switches
        • 1.3.c   Firewalls
           
      • 1.4   Implement Firewalls
        • 1.4.a   Configure application filtering and protcol inspection
        • 1.4.b   Describe virtualized firewalls
           
  • 25%     2.0   Cisco Security Devices GUIs and
                Secured CLI Management

      • 2.1   Implement SSHv2, SSL, SNMPv3 access on the network devices
         
      • 2.2   Implement RBAC on the ASA/IOS CLI and on ASDM
         
      • 2.3   Describe Cisco Prime Infrastructure
         
      • 2.4   Describe CSM
         
      • 2.5   Implement device managers
         
  • 12%     3.0   Management Services on Cisco
                Devices

      • 3.1   Implement NetFlow exporter
         
      • 3.2   Implement SNMPv3
         
      • 3.3   Implement logging
         
      • 3.4   Implement NTP with authentication
         
      • 3.5   Describe CDP, DNS, SCP, SFTP, and DHCP
         
  • 10%     4.0   Troubleshooting, Monitoring and Reporting
                Tools

      • 4.1   Monitor firewall using analysis of packet tracer, packet capture,
                and syslog
         
  • 16%     5.0   Threat Defense Architectures

      • 5.1   Design a firewall solution
         
      • 5.2   Design Layer 2 security solution
         
  • 12%     6.0   Security Components and Considerations
     

      • 6.1   Describe security operations management architecture
         
      • 6.2   Describe Data Center Security components and considerations
         
      • 6.3   Describe Collaboration security components and considerations
         
      • 6.4   Describe common IPv6 security considerations
         
  • The following course is the recommended training for this exam:

    Courses listed are offered by Cisco Learning Partners-the only authorized source for Cisco IT training delivered exclusively by Certified Cisco Instructors. Check the List of Learning Partners for a Cisco Learning Partner nearest you

    A variety of Cisco Press titles may be available for this exam. These titles can be purchased through the Cisco Marketplace Bookstore, directly from Cisco Press.

          Register at Pearson VUE      

    Cisco Learning Network

    Get valuable IT training resources for all Cisco certifications. Access study tools, CCNA practice tests, IT salaries, and find IT jobs.

    Go Now

    Cisco Training Tools

    Use the following tools to assist in your certification journey.

    Cisco Learning Locator Self Assessment Tool Certification Tracking System Certifications & Communities Online Support

    Cisco Learning Labs

    Get hands-on routing / switching lab experience using Cisco IOS on UNIX.

    Learn More