Book description
Official self-study test preparation guide for the Cisco IPS exam 642-532
The official study guide helps you master all the topics on the IPS exam, including:
IPS concepts
Command-line interface (CLI) and IPS Device Manager (IDM) configuration modes
Basic sensor and IPS signature configuration
IPS signature engines
Sensor tuning
IPS event monitoring
Sensor maintenance
Verifying system configuration
Using the Cisco IDS Module (IDSM) and Cisco IDS Network Module
Capturing network traffic
CCSP IPS Exam Certification Guide is a best of breed Cisco® exam study guide that focuses specifically on the objectives for the IPS exam. Cisco Security Test Engineer Earl Carter shares preparation hints and test-taking tips, helping you identify areas of weakness and improve your Intrusion Prevention System (IPS) knowledge. Material is presented in a concise manner, focusing on increasing your understanding and retention of exam topics.
CCSP IPS Exam Certification Guide presents you with an organized test preparation routine through the use of proven series elements and techniques. “Do I Know This Already” quizzes open each chapter and allow you to decide how much time you need to spend on each section. Exam topic lists and Foundation Summary materials make referencing easy and give you a quick refresher whenever you need it. Challenging chapter-ending review questions help you assess your knowledge and reinforce key concepts. The companion CD-ROM contains a powerful testing engine that allows you to focus on individual topic areas or take complete, timed exams. The assessment engine also tracks your performance and provides feedback on a module-by-module basis, presenting question-by-question remediation to the text. Well-regarded for its level of detail, assessment features, and challenging review questions and exercises, this book helps you master the concepts and techniques that will enable you to succeed on the exam the first time.
CCSP IPS Exam Certification Guide is part of a recommended learning path from Cisco Systems® that includes simulation and hands-on training from authorized Cisco Learning Partners and self-study products from Cisco Press. To find out more about instructor-led training, e-learning, and hands-on instruction offered by authorized Cisco Learning Partners worldwide, please visit www.cisco.com/go/authorizedtraining.
Companion CD-ROM
The CD-ROM contains an electronic copy of the book and more than 200 practice questions for the IPS exam, all available in study mode, test mode, and flash-card format.
This volume is part of the Exam Certification Guide Series from Cisco Press®. Books in this series provide officially developed exam preparation materials that offer assessment, review, and practice to help Cisco Career Certification candidates identify weaknesses, concentrate their study efforts, and enhance their confidence as exam day nears.
Table of contents
- Copyright
- About the Author
- About the Technical Reviewers
- Acknowledgments
- Command Syntax Conventions
- Foreword
-
I. Cisco IPS Overview
-
1. Cisco Intrusion Prevention System (IPS) Overview
-
Foundation and Supplemental Topics
- Cisco Intrusion Prevention Solution
- Intrusion Prevention Overview
- Cisco Intrusion Prevention System Hardware
- Inline Mode Versus Promiscuous Mode
- Software Bypass
- Cisco Sensor Deployment
- Cisco Sensor Communications Protocols
- Cisco Sensor Software Architecture
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
1. Cisco Intrusion Prevention System (IPS) Overview
-
II. Cisco IPS Configuration
-
2. IPS Command-Line Interface
-
Foundation and Supplemental Topics
- Sensor Installation
- Sensor Initialization
-
IPS CLI
- Using the Sensor CLI
- User Roles
-
CLI Command Modes
- Privileged Exec
- Global Configuration
- Service
- Service Analysis-Engine
- Service Authentication
- Service Event-Action-Rules
- Service Host
- Service Interface
- Service Logger
- Service Network-Access
- Service Notification
- Service Signature-Definition
- Service SSH-Known-Hosts
- Service Trusted-Certificates
- Service Web-Server
- Administrative Tasks
- Configuration Tasks
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
- 3. Cisco IPS Device Manager (IDM)
- 4. Basic Sensor Configuration
-
5. Basic Cisco IPS Signature Configuration
-
Foundation and Supplemental Topics
- Configuring Cisco IPS Signatures
-
Signature Groups
- Displaying Signatures by Attack
- Displaying Signatures by L2/L3/L4 Protocol
- Displaying Signatures by Operating System
- Displaying Signatures by Signature Release
- Displaying Signatures by Service
- Displaying Signatures by Signature Identification
- Displaying Signatures by Signature Name
- Displaying Signatures by Response Action
- Displaying Signatures by Signature Engine
- Alarm Summary Modes
- Basic Signature Configuration
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
6. Cisco IPS Signature Engines
-
Foundation and Supplemental Topics
- Cisco IPS Signatures
- Cisco IPS Signature Engines
- Application Inspection and Control Signature Engines
- Atomic Signature Engines
- Flood Signature Engines
- Meta Signature Engine
- Normalizer Signature Engine
-
Service Signature Engines
- Service DNS Engine Parameters
- Service FTP Engine Parameters
- Service Generic Engine Parameters
- Service H225 Engine Parameters
- Service HTTP Engine Parameters
- Service Ident Engine Parameters
- Service MSSQL Engine Parameters
- Service NTP Engine Parameters
- Service RPC Engine Parameters
- Service SMB Engine Parameters
- Service SNMP Engine Parameters
- Service SSH Engine Parameters
- State Signature Engine
- String Signature Engines
- Sweep Signature Engines
- Trojan Horse Signature Engines
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
7. Advanced Signature Configuration
-
Foundation and Supplemental Topics
- Advanced Signature Configuration
- Meta-Event Generator
- Understanding HTTP and FTP Application Policy Enforcement
- Tuning an Existing Signature
- Creating a Custom Signature
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
- 8. Sensor Tuning
-
2. IPS Command-Line Interface
-
III. Cisco IPS Response Configuration
-
9. Cisco IPS Response Configuration
-
Foundation and Supplemental Topics
- Cisco IPS Response Overview
- Inline Actions
- Logging Actions
- IP Blocking
- Configuring IP Blocking
- Manual Blocking
- TCP Reset
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
9. Cisco IPS Response Configuration
-
IV. Cisco IPS Event Monitoring
-
10. Alarm Monitoring and Management
-
Foundation and Supplemental Topics
- CiscoWorks 2000
- Security Monitor
- Installing Security Monitor
- Security Monitor Configuration
- Security Monitor Event Viewer
- Security Monitor Administration
- Security Monitor Reports
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
10. Alarm Monitoring and Management
-
V. Cisco IPS Maintenance and Tuning
- 11. Sensor Maintenance
- 12. Verifying System Configuration
- 13. Cisco IDS Module (IDSM)
-
14. Cisco IDS Network Module for Access Routers
-
Foundation and Supplemental Topics
- NM-CIDS Overview
- NM-CIDS Hardware Architecture
- Traffic Capture for NM-CIDS
- NM-CIDS Installation and Configuration Tasks
- NM-CIDS Maintenance Tasks
- Recovering the NM-CIDS Software Image
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
-
15. Capturing Network Traffic
-
Foundation and Supplemental Topics
- Capturing Network Traffic
- Capturing Traffic for Inline Mode
- Capturing Traffic for Promiscuous Mode
- Configuring SPAN for Catalyst 4500 and 6500 Traffic Capture
- Configuring RSPAN for Catalyst 4500 and 6500 Traffic Capture
- Configuring VACLs for Catalyst 6500 Traffic Capture
- Configuring VACLs for Traffic Capture With Cisco Catalyst 6500 IOS Firewall
- Advanced Catalyst 6500 Traffic Capture
- Foundation Summary
- Q&A
-
Foundation and Supplemental Topics
- Answers to the “Do I Know This Already?” Quizzes and Q&A Questions
Product information
- Title: CCSP Self-Study: CCSP IPS Exam Certification Guide
- Author(s):
- Release date: September 2005
- Publisher(s): Cisco Press
- ISBN: None
You might also like
book
CCSP Self-Study: CCSP SNRS Exam Certification Guide
Official self-study test preparation guide for the Cisco SNRS exam 642-502 Attack threats Router management and …
book
Solaris 10 System Administration Exam Prep™
A new edition of this title is available, ISBN-10: 0789737906 ISBN-13: 9780789737908 The Solaris 10 System …
book
CCNA Security Exam Cram (Exam IINS 640-553)
In this book you’ll learn how to: Build a secure network using security controls Secure network …
book
CCSP IPS Quick Reference
As a final exam preparation tool, the CCSP IPS Quick Reference provides a concise review of …