当前位置: 首页 > 学习 > 电脑学习 > 认证考试 > 思科认证 > CISCO概述 > 正文

Cisco Security Intrusion Detection Systems Exam (C

http://www.zk168.com.cn  招考学习网 2006-4-18 15:05:53
-----------------------------------------------------------[交流]-[打印]-[发送]-[收藏]--
Cisco Security Intrusion Detection Systems Exam (CSIDS 642-531)
Exam Number: 642-531
Associated Certifications: CCSP, Cisco IDS Specialist
Duration: 75 minutes (55-65 questions)
Available Languages: English
Click Here to Register: Pearson VUE or Prometric

Exam Description
Exam Topics
Recommended Training
Additional Resources

Exam Description

The Cisco Security Intrusion Detection Systems exam tests the knowledge and skills needed to design, install, and configure a Cisco Intrusion Protection solution for small, medium, and enterprise networks.


Exam Topics

The following information provides general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam.

Describe and explain the various intrusion detection technologies and evasive techniques
Define intrusion detection
Explain the difference between true and false, and positive and negative alarms
Describe the relationship between vulnerabilities and exploits
Explain the difference between HIP and NIDS
Describe the various techniques used to evade intrusion detection

Design a Cisco IDS protection solution for small, medium, and enterprise customers
List the network devices involved in capturing traffic for intrusion detection analysis
Describe the traffic flows for each of the network devices
Explain the features and benefits of IDM
Identify the requirements for IDM
Configure Cisco Catalyst switches to capture network traffic for intrusion detection analysis

Identify the Cisco IDS Sensor platforms and describe their features
Describe the features of the various IDS Sensor appliance models

Install and configure a Cisco IDS Sensor including a network appliance and IDS module Identify the interfaces and ports on the various Sensors
Distinguish between the functions of the various Catalyst IDS Module ports
Initialize a Catalyst IDS Module
Verify the Catalyst 6500 switch and Catalyst IDSM configurations
Install the Sensor software image
Install the Sensor appliance on the network
Obtain management access on the Sensor
Initialize the Sensor
Describe the various command line modes
Navigate the CLI
Apply configuration changes made via the CLI
Create user accounts via the CLI
Configure Sensor communication properties
Configure Sensor logging properties
Perform a configuration backup via the CLI
Setting up Sensors and Sensor Groups
Sensor Communications Sensor Logging

Tune and customize Cisco IDS signatures to work optimally in specific environments
Configure the Sensor's sensing parameters
Configure a signature's enable status, severity level, and action
Create signature filters to exclude or include a specific signature or list of signatures
Tune a signature to perform optimally based on a network's characteristics
Create a custom signature given an attack scenario

Configure a Cisco IDS Sensor to perform device management of supported blocking devices
Describe the device management capability of the Sensor and how it is used to perform blocking with a Cisco device
Design a Cisco IDS solution using the blocking feature, including the ACL placement considerations, when deciding where to apply Sensor-generated ACLs
Configure a Sensor to perform blocking with a Cisco IDS device
Configure a Sensor to perform blocking through a Master Blocking Sensor

Describe the Cisco IDS signatures and determine the immediate threat posed to the network
Explain the Cisco IDS signature features
Select the Cisco IDS signature engine to create a custom signature
Explain the global Cisco IDS signature parameters
Explain the engine-specific signature parameters

Perform maintenance operations such as signature updates, software upgrades, data archival and license updates
Identify the correct IDS software update files for a Sensor and an IDSM
Install IDS signature updates and service packs
Upgrade a Sensor and an IDSM to an IDS major release version

Describe the Cisco IDS architecture including supporting services and configuration files
Explain the Cisco IDS directory structure
Explain the communication infrastructure of the Cisco IDS
Locate and identify the Cisco IDS log and error files
List the Cisco IDS services and their associated configuration files
Describe the Cisco IDS configuration files and their function

Monitor a Cisco IDS protection solution for small and medium networks
Explain the features and benefits of IEV
Identify the requirements for IEV
Install the IEV software and configure it to monitor IDS devices
Create custom IEV views and filters
Navigate IEV to view alarm details
Perform IEV database administration functions
Configure IEV application settings and preferences

Manage a large scale deployment of Cisco IDS Sensors with Cisco IDS Management software
Define features and key concepts of the IDS MC
Install the IDS MC
Generate, approve, and deploy sensor configuration files
Administer the IDS MC Server
Use the IDS MC to set up Sensors
Use the IDS MC to configure Sensor communication properties
Use the IDS MC to configure Sensor logging properties

Monitor a large scale deployment of Cisco IDS Sensors with Cisco IDS Monitoring software
Define features and key concepts of the Security Monitor
Install and verify the Security Monitor functionality
Monitor IDS devices with the Security Monitor
Administer Security Monitor event rules
Create alarm exceptions to reduce alarms and possible false positives
Use the reporting features of the Security Monitor
Administer the Security Monitor server

Recommended Training

Cisco Secure Intrusion Detection System ( CSIDS v4.0 ) is the recommended training for this exam.

Courses listed are offered by Cisco Learning Partners—the only authorized source for Cisco IT training delivered exclusively by Certified Cisco Instructors. Check the List of Learning Partners for a Cisco Learning Partner nearest you.


Additional Resources

A variety of Cisco Press Self Study titles may be available for this exam and may be purchased through the Cisco Bookstore in the Cisco Marketplace , directly through Cisco Press, or wherever you purchase technical books.

-----------------------------------------------------------[交流]-[打印]-[发送]-[收藏]--
最新入库:
 
·实质、过程及意义——阿多尔诺“否定的辩证法”探微
·从Ontology的译名之争看哲学术语的翻译原则
·论马克思主义哲学经典的解释——解释学方法及其在马克
·中国哲学当前的核心与周边问题
·和合学与21世纪文化价值和科技
·中国文化的和合精神与21世纪
·宗教之间理当相互宽容
·上半个世纪的自由主义
·殷周至春秋时期神人关系之演进
·大学之道:构建以“三纲八目”为核心的道德修养体系
相关内容:
 
·环保企业人力资源开发与管理的实证研究————巨龙公
·21世纪以煤和天然气为原料的C1化学
·重油制气污水处理系统(A/O)技术改造
·OECD主要国家软件业发展概况
·IT环境下审计理论基础的重新认定
·英美CPA管理模式及其启示
·沙角C电厂事故顺序记录的通道组态分析及整改
·改造NERA微波公务信道为国产监控信道
·LFCB-102型微波分相差动保护的应用
·沙角C电厂厂用电结线分析
网友点评:
 
会员名称:
密码:匿名 ·注册·忘记密码?
评论内容:
(最多300个字符)
  查看评论
友情提醒:
 1.库中的资料大都来自互联网、网友上传、各类书籍,在录入的过程中难免会出现错误,恳请网
 友来信指正!
 2.如果网友在本库中未能找到所需要的材料,请登陆到我们的论坛《招考学习网》版块!
 3.考友想加入招考学习网的编辑部,请发信到XueXiWang#Gmail.com(#改为@)附带个人简历
 4.如需转载请注明出处及作者,谢谢合作!
 5.如果您有更好的建议或意见请EMAIL:XueXiWang#Gmail.com (#改为@)
 6.凡标题中有注有“[NO]”字样均不含答案且答案整理中.
 7.如本库中转载文章涉及版权等问题,请相关网站或作者在两周内发邮件通知(EMAIL:  XueXiWang#Gmail.com (#改为@))我们,我们接到通知后立即删除该文章及链接!
你问我答 更多>>