640-553
CCNA Security Certification Resource Page
Tutorials And Articles To Help You Pass The 640-553 IINS Exam › Continue reading
CCNA Concentrations
CCNA Security Certification meets the needs of IT professionals who are responsible for network security. It confirms an individual’s skills for job roles such as Network Security Specialists, Security Administrators, and Network Security Support Engineers. This certification validates skills including installation, troubleshooting and monitoring of network devices to maintain integrity, confidentiality and availability of data and devices and develops competency in the technologies that Cisco uses in its security structure. Learn more at cisco.com. › Continue reading
CCNA Security 640-553 Quick Reference
CCNA Security Quick Reference (Digital Short Cut) › Continue reading
CCNA Security Prep from Networkers
CCNA Security: A New Associate Level Career Path Option › Continue reading
CCNA Security Quick Reference CHAPTER 5 Cisco IOS IPS
Understanding Intrusion Prevention and Detection
Cisco provides intrusion detection and prevention in a variety of ways in its current security portfolio. You might add this
powerful tool to your network via a dedicated hardware appliance known as a sensor, or you might add this functionality
using a network module inserted into a router or a switch. However you decide to implement the technology, the goal is
the same: to take some action based on an attack introduced to your network. This action might be to alert the network
administrator via an automated notification, or it might be to prevent the attack from dropping the packet at a device.
Intrusion Prevention Versus Intrusion Detection
Intrusion detection is powerful in that you can be notified when potential problems or attacks are introduced into your
network. Note, however, that detection cannot prevent these attacks from occurring. Detection cannot prevent the attacks
because it operates on copies of packets. Often, these copies of packets are received from another Cisco device (typically
a switch). Sensors operating using intrusion detection are said to be running in promiscuous mode.
Intrusion prevention is more powerful in that potential threats and attacks can be stopped from entering your network, or
a particular network segment. Prevention is possible by the sensor because it is operating inline with packet flows.
IPS/IDS Terminology
You should be aware of many security terms that are related to intrusion detection and prevention technologies.
