CCNA 200-301 v1.1 — Domain 5.0 — 15% of exam
Domain 05: Security Fundamentals
AAA, WPA2/WPA3, ACLs, DHCP snooping, DAI, port security, VPN basics.
10
Total Lessons
10
Live Now
15% of exam
Exam Weight
Domain Progress
10 of 10 live
Lessons in This Domain
Click any live lesson to start reading. New lessons added weekly.
Live
Coming Soon
1
✅ Live
Define key security concepts (threats, vulnerabilities, exploits, and mitigation techniques)
2
✅ Live
Describe security program elements (user awareness, training, and physical access control)
3
✅ Live
Configure and verify device access control using local passwords
4
✅ Live
Describe security password policies elements, such as management, complexity, and password alternatives (multifactor authentication, certificates, and biometrics)
5
✅ Live
Describe IPsec remote access and site-to-site VPNs
6
✅ Live
Configure and verify access control lists
7
✅ Live
Configure and verify Layer 2 security features (DHCP snooping, dynamic ARP inspection, and port security)
8
✅ Live
Compare authentication, authorization, and accounting concepts
9
✅ Live
Describe wireless security protocols (WPA, WPA2, and WPA3)
10
✅ Live
Configure and verify WLAN within the GUI using WPA2 PSK
Module 5 Summary and Common Pitfalls
→
Every ACL has an implicit deny at the end, even though it's never visible in the running configuration — this single fact explains a huge share of real-world "why isn't my traffic passing" troubleshooting scenarios.
→
Standard ACLs near the destination, extended ACLs near the source — remember this placement guidance as a design principle, not just a rule to memorize.
→
DHCP snooping, DAI, and port security work together but solve distinct problems: rogue DHCP servers, ARP spoofing, and unauthorized device connections, respectively.
→
TACACS+ (whole-packet encryption, separates AAA steps, device admin) vs. RADIUS (password-only encryption, combines steps, network access) is one of the most reliably tested direct comparisons in this domain.
→
WPA3's SAE handshake specifically closes the offline dictionary attack vulnerability in WPA2-PSK — know this as the headline improvement, not just "WPA3 is newer and better." Content How Routers Make Forwarding Decisions — CCNA 3.2 2 module-4-ip-services.md 179 lines MD module-5-security-fundamentals.md 154 lines MD
Ready to test yourself?
Practice 10 domain-specific questions with timer, scoring, and explanations.