CCIE ® Security v3.0 Written Exam Topics: Eneral Etworking
CCIE ® Security v3.0 Written Exam Topics: Eneral Etworking
The topic areas listed are general guidelines for the type of content that is likely to appear on the exam.
Please note, however, that other relevant or related topic areas may also appear.
The CCIE Security written exam for the v3.0 curriculum is a two-hour, multiple choice test with 100
questions covering the areas of skills and competency needed by a Security Engineer to implement,
deploy, configure, maintain, and troubleshoot Cisco Network Security solutions and designs. Topics
include Cisco network security devices, appliances, protocols, firewalls, VPNs, intrusion prevention
devices, policy management, and best practices for implementing a secure network.
All exam materials are provided and no outside reference materials are allowed.
1.50 Routing Protocols (RIP, EIGRP, OSPF, and BGP) (IPv4 only)
1.70 IP Multicast
2.21 EAP Methods (e.g. EAP-MD5, EAP-TLS, EAP-TTLS, EAP-FAST, PEAP, LEAP)
3.10 Syslog
4.16 802.1x
5.17 Cisco Catalyst 6500 Series Security Services Modules (FWSM, IDSM-2, VPNSPA)
7.01 Router Security Features (e.g. ACL, NBAR, MQC, CAR, FPM, uRPF, CoPP, CPPr, MPP)
5|Page
7.02 Switch Security Features(e.g. IP & MAC Spoofing, MAC Address Controls, Port Security, DHCP
Snooping, DNS Spoofing, ARP Spoofing, BPDU/Root Guard, PVLAN)
7.03 NetFlow
9.03 Standards Bodies (e.g. ISO, IEC, ITU, ISOC, IETF, IAB, IANA, ICANN)
9.04 Industry/Regulatory Compliance (e.g. SOX, HIPAA, GLBA, PCI DSS, FISMA)