Chapter 5 of 615% of exam

Security Fundamentals

Security fundamentals cover the threats networks face and the controls that stop them. This domain includes access control lists with wildcard masks, Layer 2 protections such as port security and DHCP snooping, centralized access control with AAA, wireless security standards, VPN basics, and device hardening. Expect ACL wildcard-mask math and questions on which Layer 2 feature stops which attack, both worked through here in plain terms.

Security Concepts and AAA

Network security defends three goals, the CIA triad: Confidentiality (only authorized parties read data, achieved with encryption), Integrity (data is not altered, verified with hashing), and Availability (systems stay reachable, protected against DoS). Threats exploit vulnerabilities; common attacks the exam expects you to recognize include denial-of-service and distributed DoS, man-in-the-middle, spoofing (MAC, IP, DHCP), reconnaissance, brute-force password attacks, phishing/social engineering, and malware. Defense in depth layers controls so no single failure is catastrophic. AAA centralizes access control into three functions. Authentication verifies identity (who you are) using passwords, certificates, or tokens. Authorization determines what an authenticated user may do (which commands, which resources). Accounting records what was done (commands entered, session times) for audit. Rather than storing credentials on every device, AAA points them at a central server, which is easier to manage and audit. Two AAA protocols appear on the exam. RADIUS is an open standard, uses UDP, combines authentication and authorization, and encrypts only the password — it is common for user/network access (802.1X, Wi-Fi). TACACS+ is Cisco-proprietary, uses TCP 49, separates authentication, authorization, and accounting, and encrypts the entire payload, which makes it the usual choice for granular device-administration control. Both let you keep a local username database as a fallback if the server is unreachable. Good password and access hygiene supports AAA: enforce strong, unique credentials, use "enable secret" (which is hashed) rather than the weak "enable password," encrypt configured passwords, apply role separation with privilege levels or role-based CLI, and use multi-factor authentication where possible. The physical, operational, and technical security programs surrounding devices — controlling who can reach the console, patching, and monitoring logs — are as important as the technical controls themselves. Understanding CIA plus the AAA split (authenticate, authorize, account) and the RADIUS-vs-TACACS+ contrast covers most conceptual security questions.

CIA triad: Confidentiality (encryption), Integrity (hashing), Availability (anti-DoS).
AAA = Authentication (who), Authorization (what you may do), Accounting (what you did).
RADIUS: open, UDP, encrypts only the password, combines authN/authZ (used for user/802.1X access).
TACACS+: Cisco, TCP 49, encrypts the whole payload, separates authN/authZ/accounting (device admin).
Use 'enable secret' (hashed), not 'enable password' (weak).

Access Control Lists and Wildcard Masks

ACLs (Access Control Lists) filter traffic by testing each packet against an ordered list of permit/deny statements, top to bottom, stopping at the first match. Every ACL ends with an invisible implicit deny any, so an ACL with only permit statements silently drops everything else — you must permit what you want or the traffic is lost. Order matters: put more specific statements before broader ones. Standard ACLs (numbered 1-99 and 1300-1999) match only the source IP address and should be placed close to the destination so they do not accidentally block traffic too early. Extended ACLs (numbered 100-199 and 2000-2699, or named) match source, destination, protocol (IP, TCP, UDP, ICMP), and port, so they can be precise and are placed close to the source to drop unwanted traffic before it crosses the network. Named ACLs are preferred for readability and editability. Wildcard masks tell the ACL which address bits to check: a 0 bit means "must match exactly" and a 1 bit means "ignore." A wildcard is effectively the inverse of a subnet mask. To match a whole /24, the subnet mask 255.255.255.0 becomes wildcard 0.0.0.255 (subtract each octet from 255). Worked examples: to match subnet 192.168.10.0/24 write "192.168.10.0 0.0.0.255"; to match a /26 (mask 255.255.255.192) use wildcard 0.0.0.63; to match a single host use "host 10.1.1.5" (wildcard 0.0.0.0); to match everything use "any" (equivalent to 0.0.0.0 255.255.255.255). A clever trick matches only odd or even addresses or every other subnet using non-contiguous wildcards, but the exam mostly tests contiguous cases. Apply an ACL to an interface with "ip access-group <name/number> in|out," choosing direction from the router's perspective. Verify with "show access-lists" (which shows match counts) and "show ip interface." A frequent mistake is a correct ACL applied in the wrong direction or on the wrong interface, so always confirm placement and direction.

ACLs are read top-down, first match wins, and end in an implicit deny any.
Standard ACL (1-99) matches source only → place near the destination.
Extended ACL (100-199) matches source, destination, protocol, and port → place near the source.
Wildcard mask = inverse of subnet mask: /24 = 0.0.0.255, /26 = 0.0.0.63; 'host' = 0.0.0.0, 'any' = 255.255.255.255.
Apply with ip access-group in|out; wrong direction/interface is the classic mistake.

Layer 2 Security

The access layer is a common attack surface, and several switch features harden it. Port security limits which and how many MAC addresses may use an access port. You set a maximum number of MACs and can learn them statically or "sticky" (dynamically learned then saved). On a violation the default action is shutdown (the port goes err-disabled and must be recovered); other modes are restrict (drop and log) and protect (drop silently). Port security stops MAC-flooding (CAM-table overflow) attacks and rogue devices. DHCP snooping defends against rogue DHCP servers and DHCP starvation. It classifies ports as trusted (toward the legitimate DHCP server or uplink) or untrusted (toward users). DHCP server messages (Offer, Ack) are only allowed from trusted ports, so an attacker plugging a rogue DHCP server into a user port is blocked. Snooping also builds a binding table of IP-to-MAC-to-port mappings that other features rely on. Dynamic ARP Inspection (DAI) uses that DHCP-snooping binding table to validate ARP messages, dropping forged ARP replies and stopping ARP-spoofing/man-in-the-middle attacks. IP Source Guard similarly uses the binding table to permit only traffic whose source IP/MAC matches the recorded binding, blocking IP spoofing. Other Layer 2 protections: BPDU Guard (from the STP topic) err-disables a PortFast edge port that receives a BPDU, stopping a rogue switch; storm control limits broadcast/multicast rates. Good hygiene also means shutting unused ports, putting them in an unused VLAN, changing the native VLAN off VLAN 1, and disabling DTP with "switchport nonegotiate" to prevent VLAN-hopping. For the exam, be able to match the attack to the mitigation: MAC flooding → port security; rogue DHCP / DHCP starvation → DHCP snooping; ARP spoofing → Dynamic ARP Inspection; IP spoofing → IP Source Guard; rogue switch on an edge port → BPDU Guard; VLAN hopping → disable DTP and secure the native VLAN.

Port security limits MACs per port; default violation action is shutdown (err-disabled); modes: shutdown, restrict, protect.
DHCP snooping marks trusted vs untrusted ports and blocks rogue DHCP replies on untrusted ports.
Dynamic ARP Inspection uses the DHCP-snooping binding table to stop ARP spoofing.
Match attack to fix: MAC flooding→port security, rogue DHCP→snooping, ARP spoof→DAI, IP spoof→IP Source Guard.
Prevent VLAN hopping: disable DTP (switchport nonegotiate) and move the native VLAN off VLAN 1.

Wireless Security and VPNs

Wireless is broadcast into the air, so encryption and authentication are mandatory. The standards form a clear progression the exam tests. WEP is ancient and broken. The original WPA (TKIP) improved on WEP but is also deprecated. WPA2 uses AES with CCMP and is the long-standing secure baseline. WPA3 is the newest, replacing the pre-shared-key handshake with SAE (Simultaneous Authentication of Equals, also called Dragonfly), which resists offline dictionary attacks and provides forward secrecy so a captured session cannot be decrypted later. Use WPA3, or WPA2-AES at minimum; never WEP or TKIP. Two authentication modes exist. Personal (PSK) mode uses one shared passphrase for the whole network — simple for homes and small sites. Enterprise mode uses 802.1X with an authentication server (RADIUS), giving each user unique credentials and centralized control, which is standard for business networks. On a Cisco WLC you configure this per-WLAN under Layer 2 security. VPNs protect data crossing untrusted networks such as the Internet by creating an encrypted tunnel. A site-to-site VPN connects whole networks (typically two routers/firewalls) so users at each site communicate transparently; it commonly uses IPsec, which provides confidentiality (encryption), integrity (hashing), authentication, and anti-replay, negotiated by IKE. A remote-access VPN connects an individual user's device to the corporate network, often using SSL/TLS (for example Cisco AnyConnect) so it works easily through browsers and NAT. GRE is a tunneling protocol that can carry many protocols but has no encryption by itself, so it is frequently combined with IPsec. For the 200-301 exam, know the WEP → WPA → WPA2 → WPA3 order and which are secure, the difference between Personal (PSK) and Enterprise (802.1X/RADIUS) modes, and the distinction between site-to-site and remote-access VPNs, plus that IPsec supplies confidentiality, integrity, authentication, and anti-replay.

Wi-Fi security order: WEP (broken) → WPA/TKIP (deprecated) → WPA2/AES (secure baseline) → WPA3/SAE (newest).
WPA3 uses SAE, resisting offline dictionary attacks and providing forward secrecy.
Personal mode = shared PSK; Enterprise mode = 802.1X with a RADIUS server (per-user credentials).
Site-to-site VPN connects whole networks (IPsec); remote-access VPN connects one user (often SSL/TLS).
IPsec provides confidentiality, integrity, authentication, and anti-replay; GRE tunnels but does not encrypt.

Device Hardening and Secure Access

Hardening reduces a device's attack surface. Manage devices only over SSH, never Telnet, so credentials and commands are encrypted in transit. Protect privileged mode with "enable secret" (hashed with a strong algorithm) rather than the reversible "enable password," and run "service password-encryption" so passwords are not stored in clear text in the configuration. Configure minimum password length and, where supported, use "username ... secret" for local accounts so they are hashed too. Restrict administrative access. Apply an ACL to the VTY lines with "access-class" so only management subnets can even attempt to connect, and set "exec-timeout" so idle sessions disconnect. Configure "login local" (or AAA) so logins require a real username and password, and use "login block-for" to slow brute-force attempts. Present a legal login banner ("banner login") warning that access is restricted — important for prosecution and required by many policies; avoid "Welcome" banners that invite intruders. Turn off what you do not use. Disable unneeded services and interfaces, shut unused switch ports and place them in an unused VLAN, disable auto-trunking with "switchport nonegotiate," and turn off risky legacy features. Keep IOS patched to close known vulnerabilities, and back up configurations regularly (for example to a secure server) so a compromised or failed device can be restored quickly. Control-plane and management hygiene rounds this out: use SNMPv3 rather than v1/v2c, send logs to a Syslog server with accurate NTP time, and separate management traffic where possible. On the exam, the recurring themes are: SSH over Telnet, enable secret over enable password, service password-encryption, VTY ACLs plus exec-timeout, login banners, disabling unused ports/services, and using the secure versions of management protocols (SSHv2, SNMPv3, WPA2/WPA3). Together these turn a default, wide-open device into a hardened one without adding any new hardware.

Manage over SSH, not Telnet; use 'enable secret' (hashed) not 'enable password'.
Run service password-encryption and use 'username ... secret' for hashed local accounts.
Restrict VTY lines with an access-class ACL, set exec-timeout, and use login local / AAA.
Add a legal login banner (not 'Welcome'); disable unused ports, services, and auto-trunking.
Prefer secure management protocols: SSHv2, SNMPv3, WPA2/WPA3; patch IOS and back up configs.

Keep going: the full Cisco CCNA 200-301 guide covers every section of the exam. Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Studying in order?

Practice stays free. The full Cisco CCNA 200-301 study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $14.99
Report