Upload files to "/"
This commit is contained in:
184
cml.md
Normal file
184
cml.md
Normal file
@@ -0,0 +1,184 @@
|
|||||||
|
# CML Lab Setup Guide for SCOR Preparation
|
||||||
|
|
||||||
|
## 🚀 **Initial CML Environment Setup**
|
||||||
|
|
||||||
|
### **Required Images/Node Types in CML**
|
||||||
|
Make sure your CML environment has these images:
|
||||||
|
- **ASAv** (Cisco ASA Virtual) - Primary security appliance
|
||||||
|
- **IOSv** (Cisco IOS Virtual Router) - For routing infrastructure
|
||||||
|
- **IOSvL2** (Cisco IOS Virtual Switch) - For switching with 802.1X support
|
||||||
|
- **FTDv** (Firepower Threat Defense Virtual) - If available
|
||||||
|
- **Linux VMs** - Ubuntu/CentOS for endpoint simulation
|
||||||
|
- **Windows 10 VM** - For 802.1X supplicant testing
|
||||||
|
|
||||||
|
### **Basic Topology Template**
|
||||||
|
Create this as your **base topology** and clone it for each lab:
|
||||||
|
|
||||||
|
```
|
||||||
|
[Internet Cloud] --- [ASAv Outside] --- [ASAv Inside] --- [IOSvL2 Switch]
|
||||||
|
|
|
||||||
|
[Linux VMs x3]
|
||||||
|
[Windows VM x1]
|
||||||
|
```
|
||||||
|
|
||||||
|
## 📋 **Daily Lab Setup Instructions**
|
||||||
|
|
||||||
|
### **Day 1-5: VPN Week Setup**
|
||||||
|
|
||||||
|
#### **Base VPN Topology**
|
||||||
|
```
|
||||||
|
Network Addressing:
|
||||||
|
- Outside Network: 203.0.113.0/24 (simulated internet)
|
||||||
|
- DMZ Network: 192.168.100.0/24
|
||||||
|
- Inside Network: 192.168.1.0/24
|
||||||
|
- Branch Network: 192.168.2.0/24
|
||||||
|
|
||||||
|
Required Nodes:
|
||||||
|
- 2x ASAv (HQ and Branch)
|
||||||
|
- 2x IOSv (Internet routers)
|
||||||
|
- 4x Linux VMs (endpoints)
|
||||||
|
```
|
||||||
|
|
||||||
|
#### **Day 1 Specific Setup**
|
||||||
|
1. **Create New Lab**: "SCOR-Week1-Day1"
|
||||||
|
2. **Add Nodes**:
|
||||||
|
- 1x ASAv (name: HQ-ASA)
|
||||||
|
- 1x IOSv (name: Internet-RTR)
|
||||||
|
- 2x Linux VMs (name: Internal-PC, DMZ-Server)
|
||||||
|
3. **Configure Management IPs**:
|
||||||
|
- ASAv: 192.168.1.10/24
|
||||||
|
- Linux VMs: DHCP or static in respective subnets
|
||||||
|
4. **Start Lab** and wait for convergence (~5 minutes)
|
||||||
|
|
||||||
|
### **Week 2: Content Security Setup**
|
||||||
|
|
||||||
|
#### **Hybrid Approach** (CML + DevNet Sandboxes)
|
||||||
|
Since FMC/FTD requires significant resources:
|
||||||
|
1. **Use DevNet FMC Sandbox** for Firepower management
|
||||||
|
2. **Use CML for traffic generation** and network infrastructure
|
||||||
|
3. **Document configurations** from DevNet for later reference
|
||||||
|
|
||||||
|
#### **CML Components for Content Security**
|
||||||
|
```
|
||||||
|
Required Nodes:
|
||||||
|
- 1x ASAv (perimeter security)
|
||||||
|
- 2x IOSv (routing infrastructure)
|
||||||
|
- 3x Linux VMs (web server, mail server, DNS server)
|
||||||
|
- 1x Windows VM (client testing)
|
||||||
|
```
|
||||||
|
|
||||||
|
### **Week 3: Identity Services Setup**
|
||||||
|
|
||||||
|
#### **ISE Integration Approach**
|
||||||
|
1. **Primary**: Use DevNet ISE Sandbox for policy configuration
|
||||||
|
2. **Secondary**: Use CML for network infrastructure and endpoints
|
||||||
|
3. **Connection**: Configure CML devices to authenticate against DevNet ISE
|
||||||
|
|
||||||
|
#### **CML ISE Lab Components**
|
||||||
|
```
|
||||||
|
Required Nodes:
|
||||||
|
- 2x IOSvL2 (access switches with 802.1X)
|
||||||
|
- 1x IOSv (distribution router)
|
||||||
|
- 1x ASAv (perimeter security)
|
||||||
|
- 4x Linux VMs (different endpoint types)
|
||||||
|
- 1x Windows VM (domain-joined endpoint)
|
||||||
|
```
|
||||||
|
|
||||||
|
## 🔧 **CML Configuration Templates**
|
||||||
|
|
||||||
|
### **ASAv Basic Configuration Template**
|
||||||
|
```bash
|
||||||
|
! Save this as a text file for quick deployment
|
||||||
|
interface GigabitEthernet0/0
|
||||||
|
nameif outside
|
||||||
|
security-level 0
|
||||||
|
ip address 203.0.113.10 255.255.255.0
|
||||||
|
no shutdown
|
||||||
|
|
||||||
|
interface GigabitEthernet0/1
|
||||||
|
nameif inside
|
||||||
|
security-level 100
|
||||||
|
ip address 192.168.1.1 255.255.255.0
|
||||||
|
no shutdown
|
||||||
|
|
||||||
|
route outside 0.0.0.0 0.0.0.0 203.0.113.1
|
||||||
|
access-list OUTSIDE_IN extended deny ip any any
|
||||||
|
access-group OUTSIDE_IN in interface outside
|
||||||
|
|
||||||
|
! Enable SSH and HTTPS
|
||||||
|
aaa authentication ssh console LOCAL
|
||||||
|
username admin password cisco123
|
||||||
|
username admin privilege 15
|
||||||
|
ssh 192.168.1.0 255.255.255.0 inside
|
||||||
|
http server enable
|
||||||
|
http 192.168.1.0 255.255.255.0 inside
|
||||||
|
```
|
||||||
|
|
||||||
|
### **IOSvL2 802.1X Template**
|
||||||
|
```bash
|
||||||
|
! 802.1X Switch Configuration Template
|
||||||
|
aaa new-model
|
||||||
|
aaa authentication dot1x default group radius
|
||||||
|
aaa authorization network default group radius
|
||||||
|
|
||||||
|
radius server ISE
|
||||||
|
address ipv4 10.10.10.10 auth-port 1812 acct-port 1813
|
||||||
|
key cisco123
|
||||||
|
|
||||||
|
interface range GigabitEthernet0/1-3
|
||||||
|
switchport mode access
|
||||||
|
authentication host-mode multi-auth
|
||||||
|
authentication port-control auto
|
||||||
|
dot1x pae authenticator
|
||||||
|
spanning-tree portfast
|
||||||
|
```
|
||||||
|
|
||||||
|
### **Linux VM Endpoint Setup**
|
||||||
|
```bash
|
||||||
|
#!/bin/bash
|
||||||
|
# Quick endpoint setup script
|
||||||
|
# Save as setup-endpoint.sh
|
||||||
|
|
||||||
|
# Update system
|
||||||
|
sudo apt update && sudo apt upgrade -y
|
||||||
|
|
||||||
|
# Install network tools
|
||||||
|
sudo apt install -y net-tools tcpdump wireshark-common nmap
|
||||||
|
|
||||||
|
# Install web server (for testing)
|
||||||
|
sudo apt install -y apache2
|
||||||
|
|
||||||
|
# Configure basic firewall
|
||||||
|
sudo ufw enable
|
||||||
|
sudo ufw allow ssh
|
||||||
|
sudo ufw allow http
|
||||||
|
|
||||||
|
# Set up simple web page
|
||||||
|
echo "<h1>Test Endpoint - $(hostname)</h1>" | sudo tee /var/www/html/index.html
|
||||||
|
```
|
||||||
|
|
||||||
|
## 📊 **Lab Management Best Practices**
|
||||||
|
|
||||||
|
### **Naming Convention**
|
||||||
|
- **Lab Names**: SCOR-WeekX-DayY-Topic
|
||||||
|
- **Node Names**: Function-Location (HQ-ASA, Branch-RTR)
|
||||||
|
- **Saved Configs**: Day-XX-Description
|
||||||
|
|
||||||
|
### **Configuration Backup Strategy**
|
||||||
|
1. **Save after each successful configuration**
|
||||||
|
2. **Export configurations** to text files
|
||||||
|
3. **Use CML snapshots** for complex topologies
|
||||||
|
4. **Document IP addressing** in lab notes
|
||||||
|
|
||||||
|
### **Troubleshooting Setup**
|
||||||
|
Always include these in your labs:
|
||||||
|
- **Console access** to all devices
|
||||||
|
- **SSH/Telnet** for remote access
|
||||||
|
- **SNMP community** for monitoring
|
||||||
|
- **Syslog server** (Linux VM) for centralized logging
|
||||||
|
|
||||||
|
## ⚡ **Daily Lab Workflow**
|
||||||
|
|
||||||
|
### **Standard Process (60 minutes)**
|
||||||
|
1. **Minutes 0-5**: Start lab, wait for convergence
|
||||||
|
2. **Minutes 5-10**: Load base configurations 3
|
||||||
357
scor.md
Normal file
357
scor.md
Normal file
@@ -0,0 +1,357 @@
|
|||||||
|
# SCOR 350-701 & CCIE Security Master Study Plan
|
||||||
|
|
||||||
|
## 🎯 **4-Week SCOR Study Plan (350-701)**
|
||||||
|
|
||||||
|
### **Week 1: Network Security Foundation & VPN Technologies**
|
||||||
|
**Blueprint Coverage: 20% Network Security (Domains 1.0 & 2.0)**
|
||||||
|
|
||||||
|
#### **Daily Schedule (2-3 hours weekdays, 4-5 hours weekends)**
|
||||||
|
|
||||||
|
**Monday - Network Security Concepts**
|
||||||
|
- Review OSI/TCP-IP security implications
|
||||||
|
- Network segmentation strategies (VLANs, VRFs)
|
||||||
|
- Defense-in-depth principles
|
||||||
|
- **Lab**: Basic ASA interface configuration and zones
|
||||||
|
|
||||||
|
**Tuesday - Cisco ASA Fundamentals**
|
||||||
|
- ASA architecture and packet flow
|
||||||
|
- Security levels and interface types
|
||||||
|
- NAT configurations (object, twice, policy)
|
||||||
|
- **Lab**: ASA basic connectivity and NAT scenarios
|
||||||
|
|
||||||
|
**Wednesday - Site-to-Site VPN**
|
||||||
|
- IPSec fundamentals (IKE v1/v2, ESP, AH)
|
||||||
|
- ASA S2S VPN configuration
|
||||||
|
- Troubleshooting VPN connectivity
|
||||||
|
- **Lab**: ASA-to-ASA S2S VPN with PSK and certificates
|
||||||
|
|
||||||
|
**Thursday - Remote Access VPN**
|
||||||
|
- SSL/TLS VPN vs IPSec client VPN
|
||||||
|
- AnyConnect SSL VPN configuration
|
||||||
|
- Group policies and user attributes
|
||||||
|
- **Lab**: AnyConnect deployment with AD integration
|
||||||
|
|
||||||
|
**Friday - VPN Advanced Topics**
|
||||||
|
- FlexVPN introduction (CCIE prep foundation)
|
||||||
|
- DMVPN concepts
|
||||||
|
- VPN troubleshooting methodology
|
||||||
|
- **Lab**: Advanced AnyConnect features (host checker, posture)
|
||||||
|
|
||||||
|
**Weekend - VPN Deep Dive & Review**
|
||||||
|
- Complete comprehensive VPN lab scenarios
|
||||||
|
- Review all VPN technologies
|
||||||
|
- Practice VPN troubleshooting
|
||||||
|
- **First SCOR dumps review** (VPN sections only)
|
||||||
|
|
||||||
|
### **Week 2: Firepower & Content Security**
|
||||||
|
**Blueprint Coverage: 25% Content Security (Domain 3.0) + 15% Endpoint Security**
|
||||||
|
|
||||||
|
**Monday - Firepower Management Center (FMC)**
|
||||||
|
- FMC architecture and deployment modes
|
||||||
|
- Policy hierarchy (Access Control, Intrusion, Malware)
|
||||||
|
- Object management and reusability
|
||||||
|
- **Lab**: FMC initial setup and device registration
|
||||||
|
|
||||||
|
**Tuesday - Firepower Threat Defense (FTD)**
|
||||||
|
- FTD vs ASA with FirePOWER Services
|
||||||
|
- Access Control Policies
|
||||||
|
- Intrusion Prevention System (IPS) tuning
|
||||||
|
- **Lab**: Basic FTD deployment with access rules
|
||||||
|
|
||||||
|
**Wednesday - Content Security - Web (WSA)**
|
||||||
|
- WSA deployment modes (explicit/transparent proxy)
|
||||||
|
- Web reputation and URL filtering
|
||||||
|
- Data Loss Prevention (DLP) policies
|
||||||
|
- **Lab**: WSA basic configuration and policy testing
|
||||||
|
|
||||||
|
**Thursday - Content Security - Email (ESA)**
|
||||||
|
- Email security pipeline
|
||||||
|
- Anti-spam, anti-malware, and encryption
|
||||||
|
- Email authentication (SPF, DKIM, DMARC)
|
||||||
|
- **Lab**: ESA message flow and policy configuration
|
||||||
|
|
||||||
|
**Friday - Cloud Security (Umbrella)**
|
||||||
|
- DNS-layer security concepts
|
||||||
|
- Umbrella deployment methods
|
||||||
|
- Policy management and reporting
|
||||||
|
- **Lab**: Umbrella integration with on-premises infrastructure
|
||||||
|
|
||||||
|
**Weekend - Content Security Integration**
|
||||||
|
- End-to-end content security lab
|
||||||
|
- Integration scenarios (WSA + ESA + Umbrella)
|
||||||
|
- **Second SCOR dumps review** (Content Security sections)
|
||||||
|
|
||||||
|
### **Week 3: Identity Services & Network Visibility**
|
||||||
|
**Blueprint Coverage: 20% Identity Management (Domain 4.0) + Network Analytics**
|
||||||
|
|
||||||
|
**Monday - ISE Architecture & Deployment**
|
||||||
|
- ISE personas and distributed deployment
|
||||||
|
- Policy Service Nodes (PSN) and scalability
|
||||||
|
- Certificate management in ISE
|
||||||
|
- **Lab**: ISE basic installation and initial configuration
|
||||||
|
|
||||||
|
**Tuesday - 802.1X & Network Access Control**
|
||||||
|
- 802.1X authentication flow
|
||||||
|
- MAB (MAC Authentication Bypass)
|
||||||
|
- WebAuth and guest access
|
||||||
|
- **Lab**: Wired and wireless 802.1X with various endpoints
|
||||||
|
|
||||||
|
**Wednesday - ISE Policy Framework**
|
||||||
|
- Authorization policies and conditions
|
||||||
|
- Profiling services and probe configuration
|
||||||
|
- Posture assessment and compliance
|
||||||
|
- **Lab**: Dynamic VLAN assignment and posture assessment
|
||||||
|
|
||||||
|
**Thursday - Advanced ISE Features**
|
||||||
|
- TrustSec and Security Group Tags (SGT)
|
||||||
|
- pxGrid integration basics
|
||||||
|
- Device administration (TACACS+)
|
||||||
|
- **Lab**: TrustSec enforcement and pxGrid integration
|
||||||
|
|
||||||
|
**Friday - Network Analytics (Stealthwatch/SNA)**
|
||||||
|
- Flow-based network monitoring
|
||||||
|
- Behavioral analytics and anomaly detection
|
||||||
|
- Threat hunting methodologies
|
||||||
|
- **Lab**: Stealthwatch deployment and threat investigation
|
||||||
|
|
||||||
|
**Weekend - Identity & Analytics Integration**
|
||||||
|
- Complete ISE + TrustSec + Analytics lab
|
||||||
|
- **Third SCOR dumps review** (Identity & Analytics sections)
|
||||||
|
|
||||||
|
### **Week 4: Cloud Security, Automation & Final Review**
|
||||||
|
**Blueprint Coverage: 10% Cloud Security + 10% Automation + Comprehensive Review**
|
||||||
|
|
||||||
|
**Monday - Cloud Security Fundamentals**
|
||||||
|
- Shared responsibility model
|
||||||
|
- AWS/Azure security services overview
|
||||||
|
- Container security basics
|
||||||
|
- **Lab**: Cloud security assessment scenarios
|
||||||
|
|
||||||
|
**Tuesday - API Security & Automation**
|
||||||
|
- REST API security (authentication, authorization)
|
||||||
|
- Python for security automation basics
|
||||||
|
- Infrastructure as Code security
|
||||||
|
- **Lab**: API security testing and basic Python security scripts
|
||||||
|
|
||||||
|
**Wednesday - Advanced Threats & Forensics**
|
||||||
|
- Threat intelligence integration
|
||||||
|
- Incident response procedures
|
||||||
|
- Digital forensics fundamentals
|
||||||
|
- **Lab**: Threat investigation and response scenarios
|
||||||
|
|
||||||
|
**Thursday - Comprehensive Lab Day**
|
||||||
|
- Multi-technology integration lab
|
||||||
|
- End-to-end security architecture deployment
|
||||||
|
- Troubleshooting complex scenarios
|
||||||
|
|
||||||
|
**Friday - Final Review & Mock Exam**
|
||||||
|
- Complete knowledge gaps review
|
||||||
|
- **Full SCOR dumps practice** (timed simulation)
|
||||||
|
- Weak areas identification and remediation
|
||||||
|
|
||||||
|
**Weekend - Exam Readiness**
|
||||||
|
- Final mock exams (2-3 full practice tests)
|
||||||
|
- Last-minute review of tricky concepts
|
||||||
|
- Exam day preparation and strategy
|
||||||
|
|
||||||
|
## 📚 **Essential Resources**
|
||||||
|
|
||||||
|
### **Primary Study Materials**
|
||||||
|
1. **OCG Book**: "CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide" - Omar Santos
|
||||||
|
2. **Video Training**:
|
||||||
|
- CBT Nuggets SCOR 350-701 (Jeremy Cioara)
|
||||||
|
- INE CCIE Security v6 (for deeper technical understanding)
|
||||||
|
3. **Cisco Documentation**:
|
||||||
|
- ASA Configuration Guides
|
||||||
|
- FMC/FTD Configuration Guides
|
||||||
|
- ISE Administration Guides
|
||||||
|
|
||||||
|
### **Hands-on Lab Resources**
|
||||||
|
1. **EVE-NG Community** (free) with GNS3 integration
|
||||||
|
2. **Cisco DevNet Sandboxes** (free):
|
||||||
|
- ASA Sandbox
|
||||||
|
- FMC Sandbox
|
||||||
|
- ISE Sandbox
|
||||||
|
3. **Cisco Learning Labs** (subscription)
|
||||||
|
4. **Personal Lab Equipment**:
|
||||||
|
- ASA 5506-X or 5508-X (used market)
|
||||||
|
- ISE VM deployment
|
||||||
|
- FMC/FTD virtual appliances
|
||||||
|
|
||||||
|
### **Additional Resources**
|
||||||
|
1. **Cisco Learning Network** - Study groups and expert discussions
|
||||||
|
2. **Cisco Live presentations** - Latest technology updates
|
||||||
|
3. **RFC documents** - For deep protocol understanding
|
||||||
|
4. **NIST Cybersecurity Framework** - For security methodology
|
||||||
|
|
||||||
|
## 🎯 **Strategic SCOR Dumps Usage**
|
||||||
|
|
||||||
|
### **Phase 1: Foundation Building (Weeks 1-2)**
|
||||||
|
- **DO NOT** use dumps yet
|
||||||
|
- Focus on understanding concepts through official materials
|
||||||
|
- Build hands-on experience first
|
||||||
|
|
||||||
|
### **Phase 2: Knowledge Validation (Week 3)**
|
||||||
|
- Use dumps **by domain** after completing each topic
|
||||||
|
- Identify knowledge gaps and weak areas
|
||||||
|
- **DO NOT** memorize answers - understand the "why"
|
||||||
|
|
||||||
|
### **Phase 3: Exam Simulation (Week 4)**
|
||||||
|
- Full practice exams using dumps as simulation
|
||||||
|
- Time management practice (90 minutes, ~100 questions)
|
||||||
|
- Focus on exam strategy and question interpretation
|
||||||
|
|
||||||
|
## ⚠️ **Common SCOR Exam Pitfalls**
|
||||||
|
|
||||||
|
1. **VPN Confusion**: IPSec vs SSL VPN scenarios - know when to use each
|
||||||
|
2. **ISE Policy Logic**: Understanding policy evaluation order and conditions
|
||||||
|
3. **ASA NAT**: Object NAT vs Twice NAT vs Policy NAT differences
|
||||||
|
4. **Firepower vs ASA**: When to use FTD vs ASA with FirePOWER Services
|
||||||
|
5. **Certificate Concepts**: PKI, certificate chains, and trust relationships
|
||||||
|
6. **Network Analytics**: Understanding flow-based vs packet-based analysis
|
||||||
|
7. **Cloud Security**: Shared responsibility model nuances
|
||||||
|
|
||||||
|
## 🚀 **Post-SCOR: CCIE Security Roadmap**
|
||||||
|
|
||||||
|
### **Immediate Post-SCOR (Month 2)**
|
||||||
|
**Transition Planning & Foundation Strengthening**
|
||||||
|
|
||||||
|
#### **SCOR Topics that Directly Transfer to CCIE Lab:**
|
||||||
|
- **ASA Advanced Features**: Clustering, failover, advanced NAT
|
||||||
|
- **VPN Technologies**: FlexVPN, DMVPN, GET VPN
|
||||||
|
- **ISE Advanced Policies**: TrustSec, pxGrid, device administration
|
||||||
|
- **Firepower Advanced**: Clustering, advanced threat policies
|
||||||
|
- **Network Analytics**: Advanced threat hunting and investigation
|
||||||
|
|
||||||
|
#### **New CCIE-Specific Topics to Learn:**
|
||||||
|
1. **SD-WAN Security**:
|
||||||
|
- Viptela (Cisco SD-WAN) security policies
|
||||||
|
- Application-aware security
|
||||||
|
- Cloud security integration
|
||||||
|
|
||||||
|
2. **Advanced TrustSec**:
|
||||||
|
- Manual SGT assignment
|
||||||
|
- Inline tagging
|
||||||
|
- SGACL enforcement points
|
||||||
|
|
||||||
|
3. **Advanced Automation**:
|
||||||
|
- Python for security automation
|
||||||
|
- Ansible security playbooks
|
||||||
|
- API integration for security tools
|
||||||
|
|
||||||
|
4. **Advanced Threat Defense**:
|
||||||
|
- Advanced Malware Protection (AMP)
|
||||||
|
- Threat Grid integration
|
||||||
|
- Custom detection rules
|
||||||
|
|
||||||
|
### **CCIE Security Lab Preparation Timeline (12-18 Months)**
|
||||||
|
|
||||||
|
#### **Months 2-4: Foundation Building**
|
||||||
|
- **Lab Infrastructure Setup**:
|
||||||
|
- EVE-NG professional or physical lab
|
||||||
|
- All necessary images and licenses
|
||||||
|
- Automation environment setup
|
||||||
|
|
||||||
|
- **Topic Deep Dive**:
|
||||||
|
- Master all SCOR topics at CCIE depth
|
||||||
|
- Add SD-WAN and advanced automation
|
||||||
|
- Focus on configuration speed and accuracy
|
||||||
|
|
||||||
|
#### **Months 5-8: Integration & Complex Scenarios**
|
||||||
|
- **Multi-technology Labs**:
|
||||||
|
- End-to-end security architecture deployment
|
||||||
|
- Troubleshooting complex multi-vendor scenarios
|
||||||
|
- Time-constrained configuration challenges
|
||||||
|
|
||||||
|
- **Bootcamp Consideration**:
|
||||||
|
- **INE CCIE Security Bootcamp** (highly recommended)
|
||||||
|
- **Cisco Learning Services** advanced courses
|
||||||
|
- **CBT Nuggets** hands-on labs
|
||||||
|
|
||||||
|
#### **Months 9-12: Mastery & Speed**
|
||||||
|
- **Configuration Speed Development**:
|
||||||
|
- Target: Complete common configs in <5 minutes
|
||||||
|
- Template development and reuse
|
||||||
|
- Keyboard shortcuts and CLI efficiency
|
||||||
|
|
||||||
|
- **Mock Lab Practice**:
|
||||||
|
- Full 8-hour lab simulations
|
||||||
|
- Various lab providers (INE, IPexpert, etc.)
|
||||||
|
- Peer study groups and lab partnerships
|
||||||
|
|
||||||
|
#### **Months 13-18: Exam Readiness**
|
||||||
|
- **Final Preparation**:
|
||||||
|
- Last-minute weak area remediation
|
||||||
|
- Stress testing under exam conditions
|
||||||
|
- Physical and mental preparation
|
||||||
|
|
||||||
|
### **Lab Equipment & Simulator Recommendations**
|
||||||
|
|
||||||
|
#### **Virtual Lab Setup (Recommended)**
|
||||||
|
1. **EVE-NG Professional** - Most comprehensive
|
||||||
|
2. **High-performance server**:
|
||||||
|
- 64GB+ RAM
|
||||||
|
- Modern CPU with virtualization support
|
||||||
|
- SSD storage for performance
|
||||||
|
|
||||||
|
#### **Physical Lab (Optional but Valuable)**
|
||||||
|
1. **Core Equipment**:
|
||||||
|
- 2x ASA 5508-X or 5516-X
|
||||||
|
- Cisco switches with TrustSec support
|
||||||
|
- Wireless infrastructure for ISE testing
|
||||||
|
|
||||||
|
2. **Cloud Integration**:
|
||||||
|
- AWS/Azure accounts for cloud security testing
|
||||||
|
- Hybrid deployment scenarios
|
||||||
|
|
||||||
|
### **CCIE Success Strategies**
|
||||||
|
|
||||||
|
#### **Study Discipline**
|
||||||
|
- **Consistent Schedule**: 15-20 hours/week minimum
|
||||||
|
- **Progressive Complexity**: Start simple, build to complex scenarios
|
||||||
|
- **Documentation**: Keep detailed notes and config templates
|
||||||
|
- **Regular Review**: Weekly review of previous topics
|
||||||
|
|
||||||
|
#### **Configuration Speed Development**
|
||||||
|
1. **Template Creation**: Develop reusable configuration templates
|
||||||
|
2. **Keyboard Efficiency**: Master CLI shortcuts and command abbreviations
|
||||||
|
3. **Logical Grouping**: Configure related features together
|
||||||
|
4. **Verification Scripts**: Create quick verification commands
|
||||||
|
|
||||||
|
#### **Mental Preparation**
|
||||||
|
- **Stress Management**: Practice under time pressure
|
||||||
|
- **Problem-Solving**: Develop systematic troubleshooting approaches
|
||||||
|
- **Confidence Building**: Regular successful lab completions
|
||||||
|
|
||||||
|
## 📊 **Success Metrics & Milestones**
|
||||||
|
|
||||||
|
### **SCOR Exam Readiness Indicators**
|
||||||
|
- ✅ Consistently scoring 85%+ on practice exams
|
||||||
|
- ✅ Can configure basic scenarios from memory
|
||||||
|
- ✅ Understand all technology interconnections
|
||||||
|
- ✅ Complete timed labs within allocated time
|
||||||
|
|
||||||
|
### **CCIE Lab Readiness Indicators**
|
||||||
|
- ✅ Complete full lab scenarios in 6-7 hours
|
||||||
|
- ✅ Achieve 80%+ on multiple practice labs
|
||||||
|
- ✅ Master all individual technology domains
|
||||||
|
- ✅ Demonstrate troubleshooting proficiency
|
||||||
|
|
||||||
|
### **Career Progression Timeline**
|
||||||
|
- **Month 1**: Pass SCOR exam
|
||||||
|
- **Months 2-18**: CCIE Security achievement
|
||||||
|
- **Month 19+**: Senior Security Architect roles
|
||||||
|
- **Long-term**: Security Consulting or CCIE Instructor roles
|
||||||
|
|
||||||
|
## 🔥 **Final Success Tips**
|
||||||
|
|
||||||
|
1. **Leverage Your TAC Experience**: Your troubleshooting skills are invaluable - apply them systematically
|
||||||
|
2. **Build on SESA Knowledge**: Your email security experience gives you an advantage in content security
|
||||||
|
3. **Network with CCIE Community**: Join study groups and find lab partners
|
||||||
|
4. **Stay Current**: Security evolves rapidly - subscribe to security blogs and threat intelligence
|
||||||
|
5. **Practice Under Pressure**: Simulate exam conditions regularly
|
||||||
|
6. **Document Everything**: Keep detailed notes for future reference and teaching others
|
||||||
|
|
||||||
|
Remember: The journey from CCNA to CCIE Security is challenging but absolutely achievable with your technical background. Your TAC experience provides excellent troubleshooting foundations - now we're building the comprehensive security expertise on top of that solid base.
|
||||||
|
|
||||||
|
**Success Mantra**: "Deep understanding over memorization, hands-on practice over theory, consistent progress over perfection."
|
||||||
664
scorupdate.md
Normal file
664
scorupdate.md
Normal file
@@ -0,0 +1,664 @@
|
|||||||
|
# SCOR 350-701 & CCIE Security Master Study Plan
|
||||||
|
|
||||||
|
## 🎯 **4-Week SCOR Study Plan (350-701)**
|
||||||
|
|
||||||
|
### **Week 1: Network Security Foundation & VPN Technologies**
|
||||||
|
**Blueprint Coverage: 20% Network Security (Domains 1.0 & 2.0)**
|
||||||
|
|
||||||
|
#### **Daily Schedule (2-3 hours weekdays, 4-5 hours weekends)**
|
||||||
|
|
||||||
|
**Monday - Network Security Concepts**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 1-2
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Review OSI/TCP-IP security implications
|
||||||
|
- Network segmentation strategies (VLANs, VRFs)
|
||||||
|
- Defense-in-depth principles
|
||||||
|
|
||||||
|
**CML Lab Day 1**: Basic Network Security Setup
|
||||||
|
```
|
||||||
|
Topology: 2x IOSv routers + 1x ASAv + 2x Linux VMs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure basic VLAN segmentation (DMZ, Internal, Guest)
|
||||||
|
2. Deploy ASAv with security levels (outside/inside/dmz)
|
||||||
|
3. Configure basic interface security and zones
|
||||||
|
4. Test connectivity between security zones
|
||||||
|
5. Implement basic access-lists for zone-to-zone traffic
|
||||||
|
Time: 60 minutes | Save topology as "Day1-Basic-Security"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tuesday - Cisco ASA Fundamentals**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 3
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- ASA architecture and packet flow
|
||||||
|
- Security levels and interface types
|
||||||
|
- NAT configurations (object, twice, policy)
|
||||||
|
|
||||||
|
**CML Lab Day 2**: ASA Core Configuration
|
||||||
|
```
|
||||||
|
Topology: Expand Day 1 topology
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure ASA network objects and object-groups
|
||||||
|
2. Implement Object NAT for DMZ server
|
||||||
|
3. Configure Twice NAT for internal-to-outside translation
|
||||||
|
4. Set up Policy NAT for specific traffic flows
|
||||||
|
5. Test and verify NAT translations with "show xlate"
|
||||||
|
Time: 60 minutes | Save as "Day2-ASA-NAT"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Wednesday - Site-to-Site VPN**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 4
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- IPSec fundamentals (IKE v1/v2, ESP, AH)
|
||||||
|
- ASA S2S VPN configuration
|
||||||
|
- Troubleshooting VPN connectivity
|
||||||
|
|
||||||
|
**CML Lab Day 3**: Site-to-Site VPN
|
||||||
|
```
|
||||||
|
Topology: 2x ASAv (Branch + HQ) + 2x IOSv + 4x Linux VMs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure IKEv1 PSK-based S2S VPN between ASAs
|
||||||
|
2. Set up crypto maps and transform sets
|
||||||
|
3. Configure IKEv2 with certificate authentication
|
||||||
|
4. Test VPN connectivity with encrypted traffic
|
||||||
|
5. Troubleshoot using "show crypto" commands
|
||||||
|
Time: 60 minutes | Save as "Day3-S2S-VPN"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Thursday - Remote Access VPN**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 5
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- SSL/TLS VPN vs IPSec client VPN
|
||||||
|
- AnyConnect SSL VPN configuration
|
||||||
|
- Group policies and user attributes
|
||||||
|
|
||||||
|
**CML Lab Day 4**: AnyConnect SSL VPN
|
||||||
|
```
|
||||||
|
Topology: ASAv + IOSv + Linux VMs (simulate remote clients)
|
||||||
|
Lab Tasks:
|
||||||
|
1. Install SSL VPN license on ASAv
|
||||||
|
2. Configure AnyConnect SSL VPN with local users
|
||||||
|
3. Set up group policies with VLAN assignments
|
||||||
|
4. Configure split tunneling policies
|
||||||
|
5. Test clientless SSL VPN access
|
||||||
|
Time: 60 minutes | Save as "Day4-AnyConnect"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Friday - VPN Advanced Topics**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 6
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- FlexVPN introduction (CCIE prep foundation)
|
||||||
|
- DMVPN concepts
|
||||||
|
- VPN troubleshooting methodology
|
||||||
|
|
||||||
|
**CML Lab Day 5**: Advanced VPN Features
|
||||||
|
```
|
||||||
|
Topology: Extend Day 4 topology
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure AnyConnect with host checker modules
|
||||||
|
2. Set up dynamic split tunneling
|
||||||
|
3. Implement AnyConnect posture assessment
|
||||||
|
4. Configure VPN load balancing (if multiple ASAs)
|
||||||
|
5. Practice VPN troubleshooting methodology
|
||||||
|
Time: 60 minutes | Save as "Day5-Advanced-VPN"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Weekend - VPN Deep Dive & Review**
|
||||||
|
*Study Time*: 2 hours - Review all VPN modules
|
||||||
|
*Lab Time*: 3 hours
|
||||||
|
- Complete comprehensive VPN lab scenarios
|
||||||
|
- Review all VPN technologies
|
||||||
|
- Practice VPN troubleshooting
|
||||||
|
|
||||||
|
**CML Weekend Lab**: Comprehensive VPN Scenario
|
||||||
|
```
|
||||||
|
Topology: Complex multi-site with HQ, 2 branches, remote users
|
||||||
|
Lab Tasks:
|
||||||
|
1. Deploy hub-and-spoke S2S VPN architecture
|
||||||
|
2. Configure AnyConnect for remote users
|
||||||
|
3. Implement redundant VPN gateways
|
||||||
|
4. Set up monitoring and logging
|
||||||
|
5. Perform end-to-end connectivity testing
|
||||||
|
6. Document troubleshooting steps for common issues
|
||||||
|
Time: 180 minutes | Save as "Weekend1-VPN-Complete"
|
||||||
|
```
|
||||||
|
- **First SCOR dumps review** (VPN sections only)
|
||||||
|
|
||||||
|
### **Week 2: Firepower & Content Security**
|
||||||
|
**Blueprint Coverage: 25% Content Security (Domain 3.0) + 15% Endpoint Security**
|
||||||
|
|
||||||
|
**Monday - Firepower Management Center (FMC)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 7
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- FMC architecture and deployment modes
|
||||||
|
- Policy hierarchy (Access Control, Intrusion, Malware)
|
||||||
|
- Object management and reusability
|
||||||
|
|
||||||
|
**CML Lab Day 6**: FMC Setup (DevNet Sandbox + CML Hybrid)
|
||||||
|
```
|
||||||
|
Lab Approach: Use DevNet FMC Sandbox + CML for traffic generation
|
||||||
|
Lab Tasks:
|
||||||
|
1. Access Cisco DevNet FMC Sandbox
|
||||||
|
2. Create network objects for CML topology networks
|
||||||
|
3. Configure device registration process
|
||||||
|
4. Set up basic Access Control Policy
|
||||||
|
5. Configure logging and monitoring settings
|
||||||
|
Time: 60 minutes | Document FMC configuration steps
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tuesday - Firepower Threat Defense (FTD)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 8
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- FTD vs ASA with FirePOWER Services
|
||||||
|
- Access Control Policies
|
||||||
|
- Intrusion Prevention System (IPS) tuning
|
||||||
|
|
||||||
|
**CML Lab Day 7**: FTD Policy Implementation
|
||||||
|
```
|
||||||
|
Lab Approach: Continue with DevNet FMC + document FTDv configs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Create Access Control rules for different traffic types
|
||||||
|
2. Configure Intrusion Policy with custom rules
|
||||||
|
3. Set up File & Malware Policy
|
||||||
|
4. Implement SSL/TLS inspection policies
|
||||||
|
5. Test policy enforcement with traffic simulation
|
||||||
|
Time: 60 minutes | Save policy configurations
|
||||||
|
```
|
||||||
|
|
||||||
|
**Wednesday - Content Security - Web (WSA)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 9
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- WSA deployment modes (explicit/transparent proxy)
|
||||||
|
- Web reputation and URL filtering
|
||||||
|
- Data Loss Prevention (DLP) policies
|
||||||
|
|
||||||
|
**CML Lab Day 8**: Web Security Simulation
|
||||||
|
```
|
||||||
|
Topology: IOSv router + Linux VM (proxy server simulation)
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure Linux VM as transparent proxy
|
||||||
|
2. Set up basic web filtering using iptables
|
||||||
|
3. Simulate web reputation scoring
|
||||||
|
4. Configure basic DLP pattern matching
|
||||||
|
5. Test web traffic redirection and filtering
|
||||||
|
Time: 60 minutes | Save as "Day8-Web-Security"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Thursday - Content Security - Email (ESA)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 10 (leverage your SESA knowledge!)
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Email security pipeline
|
||||||
|
- Anti-spam, anti-malware, and encryption
|
||||||
|
- Email authentication (SPF, DKIM, DMARC)
|
||||||
|
|
||||||
|
**CML Lab Day 9**: Email Security Concepts
|
||||||
|
```
|
||||||
|
Lab Approach: Linux VM mail server simulation
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure basic Postfix mail server on Linux VM
|
||||||
|
2. Set up mail routing and relay controls
|
||||||
|
3. Implement basic anti-spam rules
|
||||||
|
4. Configure SPF/DKIM record simulation
|
||||||
|
5. Test email flow and security policies
|
||||||
|
Time: 60 minutes | Document mail security workflow
|
||||||
|
```
|
||||||
|
|
||||||
|
**Friday - Cloud Security (Umbrella)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 11
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- DNS-layer security concepts
|
||||||
|
- Umbrella deployment methods
|
||||||
|
- Policy management and reporting
|
||||||
|
|
||||||
|
**CML Lab Day 10**: DNS Security Implementation
|
||||||
|
```
|
||||||
|
Topology: IOSv + Linux DNS server + Client VMs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure DNS server on Linux VM
|
||||||
|
2. Implement DNS filtering and blocking
|
||||||
|
3. Set up DNS-over-HTTPS (DoH) protection
|
||||||
|
4. Configure DNS logging and monitoring
|
||||||
|
5. Test malicious domain blocking
|
||||||
|
Time: 60 minutes | Save as "Day10-DNS-Security"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Weekend - Content Security Integration**
|
||||||
|
*Study Time*: 2 hours - Review all content security modules
|
||||||
|
*Lab Time*: 3 hours
|
||||||
|
- End-to-end content security lab
|
||||||
|
- Integration scenarios (WSA + ESA + Umbrella)
|
||||||
|
|
||||||
|
**CML Weekend Lab**: Integrated Content Security
|
||||||
|
```
|
||||||
|
Topology: Complete content security stack simulation
|
||||||
|
Lab Tasks:
|
||||||
|
1. Deploy integrated web, email, and DNS security
|
||||||
|
2. Configure policy coordination between systems
|
||||||
|
3. Set up centralized logging and reporting
|
||||||
|
4. Test multi-layer security enforcement
|
||||||
|
5. Practice incident response procedures
|
||||||
|
6. Document security architecture
|
||||||
|
Time: 180 minutes | Save as "Weekend2-Content-Security"
|
||||||
|
```
|
||||||
|
- **Second SCOR dumps review** (Content Security sections)
|
||||||
|
|
||||||
|
### **Week 3: Identity Services & Network Visibility**
|
||||||
|
**Blueprint Coverage: 20% Identity Management (Domain 4.0) + Network Analytics**
|
||||||
|
|
||||||
|
**Monday - ISE Architecture & Deployment**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 12
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- ISE personas and distributed deployment
|
||||||
|
- Policy Service Nodes (PSN) and scalability
|
||||||
|
- Certificate management in ISE
|
||||||
|
|
||||||
|
**CML Lab Day 11**: ISE Foundation (DevNet Sandbox Primary)
|
||||||
|
```
|
||||||
|
Lab Approach: Cisco DevNet ISE Sandbox + CML network infrastructure
|
||||||
|
Lab Tasks:
|
||||||
|
1. Access DevNet ISE Sandbox environment
|
||||||
|
2. Explore ISE Admin portal and navigation
|
||||||
|
3. Configure basic network device authentication
|
||||||
|
4. Set up certificate services and PKI integration
|
||||||
|
5. Document ISE architecture and data flows
|
||||||
|
Time: 60 minutes | Create ISE configuration notes
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tuesday - 802.1X & Network Access Control**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 13
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- 802.1X authentication flow
|
||||||
|
- MAB (MAC Authentication Bypass)
|
||||||
|
- WebAuth and guest access
|
||||||
|
|
||||||
|
**CML Lab Day 12**: 802.1X Implementation
|
||||||
|
```
|
||||||
|
Topology: IOSvL2 switch + Linux VMs (endpoints) + Windows VM
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure IOSvL2 switch for 802.1X authentication
|
||||||
|
2. Set up RADIUS authentication to DevNet ISE
|
||||||
|
3. Configure wired 802.1X with EAP-TLS
|
||||||
|
4. Implement MAB for non-802.1X devices
|
||||||
|
5. Test authentication with different endpoint types
|
||||||
|
Time: 60 minutes | Save as "Day12-802.1X"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Wednesday - ISE Policy Framework**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 14
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Authorization policies and conditions
|
||||||
|
- Profiling services and probe configuration
|
||||||
|
- Posture assessment and compliance
|
||||||
|
|
||||||
|
**CML Lab Day 13**: ISE Policy Implementation
|
||||||
|
```
|
||||||
|
Lab Approach: DevNet ISE + CML endpoint simulation
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure authorization policies in ISE
|
||||||
|
2. Set up dynamic VLAN assignment rules
|
||||||
|
3. Configure endpoint profiling probes
|
||||||
|
4. Implement posture assessment policies
|
||||||
|
5. Test policy enforcement with different scenarios
|
||||||
|
Time: 60 minutes | Document policy logic flows
|
||||||
|
```
|
||||||
|
|
||||||
|
**Thursday - Advanced ISE Features**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 15
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- TrustSec and Security Group Tags (SGT)
|
||||||
|
- pxGrid integration basics
|
||||||
|
- Device administration (TACACS+)
|
||||||
|
|
||||||
|
**CML Lab Day 14**: TrustSec and Advanced Features
|
||||||
|
```
|
||||||
|
Topology: IOSvL2 switches with TrustSec support + Linux VMs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure TrustSec on network devices
|
||||||
|
2. Set up SGT assignment and propagation
|
||||||
|
3. Implement SGACL enforcement
|
||||||
|
4. Configure device administration via TACACS+
|
||||||
|
5. Test SGT-based access control policies
|
||||||
|
Time: 60 minutes | Save as "Day14-TrustSec"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Friday - Network Analytics (Stealthwatch/SNA)**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 16
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Flow-based network monitoring
|
||||||
|
- Behavioral analytics and anomaly detection
|
||||||
|
- Threat hunting methodologies
|
||||||
|
|
||||||
|
**CML Lab Day 15**: Network Flow Analysis
|
||||||
|
```
|
||||||
|
Topology: IOSv routers + Linux VMs (traffic generators)
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure NetFlow/sFlow on network devices
|
||||||
|
2. Set up basic flow collection and analysis
|
||||||
|
3. Generate different traffic patterns for analysis
|
||||||
|
4. Implement basic anomaly detection rules
|
||||||
|
5. Practice threat hunting techniques with flow data
|
||||||
|
Time: 60 minutes | Save as "Day15-Flow-Analysis"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Weekend - Identity & Analytics Integration**
|
||||||
|
*Study Time*: 2 hours - Review identity and analytics modules
|
||||||
|
*Lab Time*: 3 hours
|
||||||
|
- Complete ISE + TrustSec + Analytics lab
|
||||||
|
- **Third SCOR dumps review** (Identity & Analytics sections)
|
||||||
|
|
||||||
|
**CML Weekend Lab**: Complete Identity Architecture
|
||||||
|
```
|
||||||
|
Topology: Full enterprise simulation with ISE integration
|
||||||
|
Lab Tasks:
|
||||||
|
1. Deploy comprehensive ISE policy framework
|
||||||
|
2. Integrate TrustSec with network infrastructure
|
||||||
|
3. Configure advanced analytics and monitoring
|
||||||
|
4. Test end-to-end identity-based access control
|
||||||
|
5. Implement guest access and BYOD scenarios
|
||||||
|
6. Practice troubleshooting identity issues
|
||||||
|
Time: 180 minutes | Save as "Weekend3-Identity-Complete"
|
||||||
|
```
|
||||||
|
|
||||||
|
### **Week 4: Cloud Security, Automation & Final Review**
|
||||||
|
**Blueprint Coverage: 10% Cloud Security + 10% Automation + Comprehensive Review**
|
||||||
|
|
||||||
|
**Monday - Cloud Security Fundamentals**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 17
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Shared responsibility model
|
||||||
|
- AWS/Azure security services overview
|
||||||
|
- Container security basics
|
||||||
|
|
||||||
|
**CML Lab Day 16**: Cloud Security Concepts
|
||||||
|
```
|
||||||
|
Lab Approach: Simulation using Linux VMs and Docker
|
||||||
|
Lab Tasks:
|
||||||
|
1. Set up Docker containers on Linux VMs
|
||||||
|
2. Configure basic container networking security
|
||||||
|
3. Implement container access controls
|
||||||
|
4. Set up basic API security testing
|
||||||
|
5. Simulate cloud security assessment scenarios
|
||||||
|
Time: 60 minutes | Save as "Day16-Cloud-Security"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tuesday - API Security & Automation**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 18
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- REST API security (authentication, authorization)
|
||||||
|
- Python for security automation basics
|
||||||
|
- Infrastructure as Code security
|
||||||
|
|
||||||
|
**CML Lab Day 17**: API Security and Automation
|
||||||
|
```
|
||||||
|
Topology: Linux VMs with Python environment
|
||||||
|
Lab Tasks:
|
||||||
|
1. Set up Python environment for security automation
|
||||||
|
2. Create basic REST API security testing scripts
|
||||||
|
3. Implement API authentication and authorization
|
||||||
|
4. Configure automated security policy deployment
|
||||||
|
5. Test API security validation scripts
|
||||||
|
Time: 60 minutes | Save Python scripts for future use
|
||||||
|
```
|
||||||
|
|
||||||
|
**Wednesday - Advanced Threats & Forensics**
|
||||||
|
*Study Time*: 2 hours - Cisco U Module 19
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Threat intelligence integration
|
||||||
|
- Incident response procedures
|
||||||
|
- Digital forensics fundamentals
|
||||||
|
|
||||||
|
**CML Lab Day 18**: Threat Investigation
|
||||||
|
```
|
||||||
|
Topology: Complete network with logging infrastructure
|
||||||
|
Lab Tasks:
|
||||||
|
1. Configure comprehensive logging across all devices
|
||||||
|
2. Generate simulated attack scenarios
|
||||||
|
3. Practice log analysis and correlation
|
||||||
|
4. Implement threat hunting procedures
|
||||||
|
5. Document incident response workflows
|
||||||
|
Time: 60 minutes | Create threat hunting playbook
|
||||||
|
```
|
||||||
|
|
||||||
|
**Thursday - Comprehensive Lab Day**
|
||||||
|
*Study Time*: 1 hour - Review weak areas
|
||||||
|
*Lab Time*: 2 hours
|
||||||
|
- Multi-technology integration lab
|
||||||
|
- End-to-end security architecture deployment
|
||||||
|
- Troubleshooting complex scenarios
|
||||||
|
|
||||||
|
**CML Lab Day 19**: Integration Challenge
|
||||||
|
```
|
||||||
|
Topology: Complete enterprise security architecture
|
||||||
|
Lab Tasks:
|
||||||
|
1. Deploy end-to-end security from previous weeks
|
||||||
|
2. Integrate all security technologies (ASA, ISE, etc.)
|
||||||
|
3. Configure centralized management and monitoring
|
||||||
|
4. Test complex security scenarios
|
||||||
|
5. Practice rapid troubleshooting techniques
|
||||||
|
Time: 120 minutes | Save as "Day19-Full-Integration"
|
||||||
|
```
|
||||||
|
|
||||||
|
**Friday - Final Review & Mock Exam**
|
||||||
|
*Study Time*: 2 hours - Cisco U final review modules
|
||||||
|
*Lab Time*: 1 hour
|
||||||
|
- Complete knowledge gaps review
|
||||||
|
- **Full SCOR dumps practice** (timed simulation)
|
||||||
|
- Weak areas identification and remediation
|
||||||
|
|
||||||
|
**CML Lab Day 20**: Troubleshooting Mastery
|
||||||
|
```
|
||||||
|
Topology: Broken configurations from previous labs
|
||||||
|
Lab Tasks:
|
||||||
|
1. Load pre-broken configurations
|
||||||
|
2. Practice systematic troubleshooting approach
|
||||||
|
3. Time yourself on common problem resolution
|
||||||
|
4. Document troubleshooting methodologies
|
||||||
|
5. Create quick reference troubleshooting guide
|
||||||
|
Time: 60 minutes | Finalize troubleshooting notes
|
||||||
|
```
|
||||||
|
|
||||||
|
**Weekend - Exam Readiness**
|
||||||
|
- Final mock exams (2-3 full practice tests)
|
||||||
|
- Last-minute review of tricky concepts
|
||||||
|
- Exam day preparation and strategy
|
||||||
|
|
||||||
|
## 📚 **Essential Resources (Optimized for Your Access)**
|
||||||
|
|
||||||
|
### **Primary Study Materials**
|
||||||
|
1. **Cisco U SCOR Course** (your main resource - excellent choice!)
|
||||||
|
- Complete video content with hands-on demonstrations
|
||||||
|
- Integrated lab exercises and simulations
|
||||||
|
- Official Cisco exam preparation materials
|
||||||
|
2. **Supplementary Resources**:
|
||||||
|
- OCG Book: "CCNP and CCIE Security Core SCOR 350-701" - Omar Santos (for reference)
|
||||||
|
- Cisco Documentation (Configuration Guides)
|
||||||
|
- Cisco Learning Network community discussions
|
||||||
|
|
||||||
|
### **Hands-on Lab Resources (Your Advantage!)**
|
||||||
|
1. **Cisco CML (Primary Lab Platform)** ⭐
|
||||||
|
- ASAv virtual appliances
|
||||||
|
- IOSv/IOSvL2 for switching infrastructure
|
||||||
|
- FTDv (if available in your CML version)
|
||||||
|
- Linux VMs for endpoint simulation
|
||||||
|
2. **Cisco DevNet Sandboxes** (supplementary):
|
||||||
|
- FMC Sandbox (for Firepower management)
|
||||||
|
- ISE Sandbox (for policy testing)
|
||||||
|
- Umbrella Dashboard access
|
||||||
|
3. **Cisco U Lab Simulations** (integrated with course content)
|
||||||
|
|
||||||
|
### **Additional Resources**
|
||||||
|
1. **Cisco Learning Network** - Study groups and expert discussions
|
||||||
|
2. **Cisco Live presentations** - Latest technology updates
|
||||||
|
3. **RFC documents** - For deep protocol understanding
|
||||||
|
4. **NIST Cybersecurity Framework** - For security methodology
|
||||||
|
|
||||||
|
## 🎯 **Strategic SCOR Dumps Usage**
|
||||||
|
|
||||||
|
### **Phase 1: Foundation Building (Weeks 1-2)**
|
||||||
|
- **DO NOT** use dumps yet
|
||||||
|
- Focus on understanding concepts through official materials
|
||||||
|
- Build hands-on experience first
|
||||||
|
|
||||||
|
### **Phase 2: Knowledge Validation (Week 3)**
|
||||||
|
- Use dumps **by domain** after completing each topic
|
||||||
|
- Identify knowledge gaps and weak areas
|
||||||
|
- **DO NOT** memorize answers - understand the "why"
|
||||||
|
|
||||||
|
### **Phase 3: Exam Simulation (Week 4)**
|
||||||
|
- Full practice exams using dumps as simulation
|
||||||
|
- Time management practice (90 minutes, ~100 questions)
|
||||||
|
- Focus on exam strategy and question interpretation
|
||||||
|
|
||||||
|
## ⚠️ **Common SCOR Exam Pitfalls**
|
||||||
|
|
||||||
|
1. **VPN Confusion**: IPSec vs SSL VPN scenarios - know when to use each
|
||||||
|
2. **ISE Policy Logic**: Understanding policy evaluation order and conditions
|
||||||
|
3. **ASA NAT**: Object NAT vs Twice NAT vs Policy NAT differences
|
||||||
|
4. **Firepower vs ASA**: When to use FTD vs ASA with FirePOWER Services
|
||||||
|
5. **Certificate Concepts**: PKI, certificate chains, and trust relationships
|
||||||
|
6. **Network Analytics**: Understanding flow-based vs packet-based analysis
|
||||||
|
7. **Cloud Security**: Shared responsibility model nuances
|
||||||
|
|
||||||
|
## 🚀 **Post-SCOR: CCIE Security Roadmap**
|
||||||
|
|
||||||
|
### **Immediate Post-SCOR (Month 2)**
|
||||||
|
**Transition Planning & Foundation Strengthening**
|
||||||
|
|
||||||
|
#### **SCOR Topics that Directly Transfer to CCIE Lab:**
|
||||||
|
- **ASA Advanced Features**: Clustering, failover, advanced NAT
|
||||||
|
- **VPN Technologies**: FlexVPN, DMVPN, GET VPN
|
||||||
|
- **ISE Advanced Policies**: TrustSec, pxGrid, device administration
|
||||||
|
- **Firepower Advanced**: Clustering, advanced threat policies
|
||||||
|
- **Network Analytics**: Advanced threat hunting and investigation
|
||||||
|
|
||||||
|
#### **New CCIE-Specific Topics to Learn:**
|
||||||
|
1. **SD-WAN Security**:
|
||||||
|
- Viptela (Cisco SD-WAN) security policies
|
||||||
|
- Application-aware security
|
||||||
|
- Cloud security integration
|
||||||
|
|
||||||
|
2. **Advanced TrustSec**:
|
||||||
|
- Manual SGT assignment
|
||||||
|
- Inline tagging
|
||||||
|
- SGACL enforcement points
|
||||||
|
|
||||||
|
3. **Advanced Automation**:
|
||||||
|
- Python for security automation
|
||||||
|
- Ansible security playbooks
|
||||||
|
- API integration for security tools
|
||||||
|
|
||||||
|
4. **Advanced Threat Defense**:
|
||||||
|
- Advanced Malware Protection (AMP)
|
||||||
|
- Threat Grid integration
|
||||||
|
- Custom detection rules
|
||||||
|
|
||||||
|
### **CCIE Security Lab Preparation Timeline (12-18 Months)**
|
||||||
|
|
||||||
|
#### **Months 2-4: Foundation Building**
|
||||||
|
- **Lab Infrastructure Setup**:
|
||||||
|
- EVE-NG professional or physical lab
|
||||||
|
- All necessary images and licenses
|
||||||
|
- Automation environment setup
|
||||||
|
|
||||||
|
- **Topic Deep Dive**:
|
||||||
|
- Master all SCOR topics at CCIE depth
|
||||||
|
- Add SD-WAN and advanced automation
|
||||||
|
- Focus on configuration speed and accuracy
|
||||||
|
|
||||||
|
#### **Months 5-8: Integration & Complex Scenarios**
|
||||||
|
- **Multi-technology Labs**:
|
||||||
|
- End-to-end security architecture deployment
|
||||||
|
- Troubleshooting complex multi-vendor scenarios
|
||||||
|
- Time-constrained configuration challenges
|
||||||
|
|
||||||
|
- **Bootcamp Consideration**:
|
||||||
|
- **INE CCIE Security Bootcamp** (highly recommended)
|
||||||
|
- **Cisco Learning Services** advanced courses
|
||||||
|
- **CBT Nuggets** hands-on labs
|
||||||
|
|
||||||
|
#### **Months 9-12: Mastery & Speed**
|
||||||
|
- **Configuration Speed Development**:
|
||||||
|
- Target: Complete common configs in <5 minutes
|
||||||
|
- Template development and reuse
|
||||||
|
- Keyboard shortcuts and CLI efficiency
|
||||||
|
|
||||||
|
- **Mock Lab Practice**:
|
||||||
|
- Full 8-hour lab simulations
|
||||||
|
- Various lab providers (INE, IPexpert, etc.)
|
||||||
|
- Peer study groups and lab partnerships
|
||||||
|
|
||||||
|
#### **Months 13-18: Exam Readiness**
|
||||||
|
- **Final Preparation**:
|
||||||
|
- Last-minute weak area remediation
|
||||||
|
- Stress testing under exam conditions
|
||||||
|
- Physical and mental preparation
|
||||||
|
|
||||||
|
### **Lab Equipment & Simulator Recommendations**
|
||||||
|
|
||||||
|
#### **Virtual Lab Setup (Recommended)**
|
||||||
|
1. **EVE-NG Professional** - Most comprehensive
|
||||||
|
2. **High-performance server**:
|
||||||
|
- 64GB+ RAM
|
||||||
|
- Modern CPU with virtualization support
|
||||||
|
- SSD storage for performance
|
||||||
|
|
||||||
|
#### **Physical Lab (Optional but Valuable)**
|
||||||
|
1. **Core Equipment**:
|
||||||
|
- 2x ASA 5508-X or 5516-X
|
||||||
|
- Cisco switches with TrustSec support
|
||||||
|
- Wireless infrastructure for ISE testing
|
||||||
|
|
||||||
|
2. **Cloud Integration**:
|
||||||
|
- AWS/Azure accounts for cloud security testing
|
||||||
|
- Hybrid deployment scenarios
|
||||||
|
|
||||||
|
### **CCIE Success Strategies**
|
||||||
|
|
||||||
|
#### **Study Discipline**
|
||||||
|
- **Consistent Schedule**: 15-20 hours/week minimum
|
||||||
|
- **Progressive Complexity**: Start simple, build to complex scenarios
|
||||||
|
- **Documentation**: Keep detailed notes and config templates
|
||||||
|
- **Regular Review**: Weekly review of previous topics
|
||||||
|
|
||||||
|
#### **Configuration Speed Development**
|
||||||
|
1. **Template Creation**: Develop reusable configuration templates
|
||||||
|
2. **Keyboard Efficiency**: Master CLI shortcuts and command abbreviations
|
||||||
|
3. **Logical Grouping**: Configure related features together
|
||||||
|
4. **Verification Scripts**: Create quick verification commands
|
||||||
|
|
||||||
|
#### **Mental Preparation**
|
||||||
|
- **Stress Management**: Practice under time pressure
|
||||||
|
- **Problem-Solving**: Develop systematic troubleshooting approaches
|
||||||
|
- **Confidence Building**: Regular successful lab completions
|
||||||
|
|
||||||
|
## 📊 **Success Metrics & Milestones**
|
||||||
|
|
||||||
|
### **SCOR Exam Readiness Indicators**
|
||||||
|
- ✅ Consistently scoring 85%+ on practice exams
|
||||||
|
- ✅ Can configure basic scenarios from memory
|
||||||
|
- ✅ Understand all technology interconnections
|
||||||
|
- ✅ Complete timed labs within allocated time
|
||||||
|
|
||||||
|
### **CCIE Lab Readiness Indicators**
|
||||||
|
- ✅ Complete full lab scenarios in 6-7 hours
|
||||||
|
- ✅ Achieve 80%+ on multiple practice labs
|
||||||
|
- ✅ Master all individual technology domains
|
||||||
|
- ✅ Demonstrate troubleshooting proficiency
|
||||||
|
|
||||||
|
### **Career Progression Timeline**
|
||||||
|
- **Month 1**: Pass SCOR exam
|
||||||
|
- **Months 2-18**: CCIE Security achievement
|
||||||
|
- **Month 19+**: Senior Security Architect roles
|
||||||
|
- **Long-term**: Security Consulting or CCIE Instructor roles
|
||||||
|
|
||||||
|
## 🔥 **Final Success Tips**
|
||||||
|
|
||||||
|
1. **Leverage Your TAC Experience**: Your troubleshooting skills are invaluable - apply them systematically
|
||||||
|
2. **Build on SESA Knowledge**: Your email security experience gives you an advantage in content security
|
||||||
|
3. **Network with CCIE Community**: Join study groups and find lab partners
|
||||||
|
4. **Stay Current**: Security evolves rapidly - subscribe to security blogs and threat intelligence
|
||||||
|
5. **Practice Under Pressure**: Simulate exam conditions regularly
|
||||||
|
6. **Document Everything**: Keep detailed notes for future reference and teaching others
|
||||||
|
|
||||||
|
Remember: The journey from CCNA to CCIE Security is challenging but absolutely achievable with your technical background. Your TAC experience provides excellent troubleshooting foundations - now we're building the comprehensive security expertise on top of that solid base.
|
||||||
|
|
||||||
|
**Success Mantra**: "Deep understanding over memorization, hands-on practice over theory, consistent progress over perfection."
|
||||||
Reference in New Issue
Block a user