Securing the Web with Cisco Secure Web Appliance v1.1

CCNP Security - Concentration: SWSA 300-725

The CCNP Security 300-725 (SWSA) certification exam is focused on Securing the Web with Cisco Web Security Appliance (WSA).

Securing the Web with Cisco Web Security Appliance (300-725 SWSA)

The Cisco 300-725 SWSA (Securing the Web with Cisco Web Security Appliance) is a certification exam that tests a candidate's knowledge and skills in securing web traffic using Cisco Web Security Appliance (WSA). This certification is part of the Cisco Certified Specialist - Web Content Security certification and also contributes towards the Cisco Certified CyberOps Professional and Cisco Certified Security Professional certifications.

What you’ll learn 

  • Features
  • Configuration
  • Proxy Services
  • Authentication
  • Decryption Policies to Control HTTPS Traffic
  • Differentiated Traffic Access Policies and Identification Profiles
  • Acceptable Use Control
  • Malware Defense
  • Reporting and Tracking Web Transactions

Syllabus Summary

Cisco WSA Features

• Describe Cisco Secure Web Appliance features and functionality

  • Proxy service
  • Cognitive Intelligence (formerly Cognitive Threat Analytics)
  • Data loss prevention service
  • Integrated L4TM service
  • Management tools

• Describe Secure Web Appliance solutions

  • Cisco Advanced Web Security Reporting
  • Cisco Secure Email and Web Manager

• Integrate Cisco Secure Web Appliance with Advanced Web Security Reporting

• Integrate Cisco Secure Web Appliance with Cisco ISE

• Troubleshoot data security and external data loss using log files

Configuration
  • Perform initial configuration tasks on Cisco Secure Web Appliance
  • Configure an access policy
  • Configure and verify web proxy features

o Explicit proxy functionality

o Proxy access logs using CLI

o Active directory proxy authentication

  • Configure a referrer header to filter web categories
Proxy Services

• Describe deployment options

  • Explicit proxy
  • Transparent proxy
  • Upstream proxy
  • High availability

• Describe these features:

  • Tune caching
  • IP spoofing
  • Web proxy ports
  • Range requests

• Describe the functions of a Proxy Auto-Configuration (PAC) file

• Describe the SOCKS protocol and the SOCKS proxy services

Authentication

• Describe authentication features

  • Supported authentication methods
  • Authentication realms
  • Supported authentication surrogates supported
  • Bypassing authentication of problematic agents
  • Authentication logs for accounting records
  • Re-authentication

• Configure traffic redirection to Cisco Secure Web Appliance using transparent proxy with WCCP, PBR, or an L4 switch

• Describe the FTP proxy authentication

• Troubleshoot authentication issues

Decryption Policies to Control HTTPS Traffic

• Describe SSL and TLS inspection

• Configure HTTPS capabilities

  • HTTPS decryption policies
  • HTTPS proxy function
  • ACL tags for HTTPS inspection
  • HTTPS proxy and verify TLS/SSL decryption
  • Certificate types used for HTTPS decryption

• Configure self-signed and intermediate certificates within SSL/TLS transactions

Differentiated Traffic Access Policies and Identification Profiles
  • Describe access policies
  • Describe identification profiles and authentication
  • Troubleshoot using access logs
Acceptable Use Control
  • Configure URL filtering
  • Configure time-based and traffic volume acceptable use policies and end user notifications
  • Configure web application visibility and control (Office 365, third-party feeds)
  • Create a corporate global acceptable use policy
  • Implement policy trace tool to verify corporate global acceptable use policy
  • Configure Secure Web Appliance to inspect archive file types
Malware Defense
  • Describe scanning engines
  • Configure file reputation filtering and file analysis
  • Describe Cisco Secure Endpoint
  • Describe integration with Cognitive Intelligence
Reporting and Tracking Web Transactions
  • Configure and analyze web tracking reports
  • Configure Cisco Advanced Web Security Reporting (AWSR)

o Basic web usage

o Custom filters

  • Troubleshoot connectivity issues
  • Interpret system health using the System Health Dashboard
  • Describe REST API support

Required Exam

  • Exam Code: SWSA 300-725
  • Duration: 90 minutes
  • Exam Cost: 300 USD

Related Courses

experts-banner-background

EMIGO Expert Training Team

new-batch-mage

New Batches Commence On

Testimonials

enquiry-section1-bg
enquiry-form-model1

Learn like a Leader
Not a follower

Scan or Click on the QR Code to submit your enquiry

Enquiry
enquiry-section1-qrcode
footer-enquiry footer-enquiry