Got official confirmation from TaskStream my Capstone passed. That makes the degree plan 125/125, graduation. YES!
Thoughts -- SBT1 -- Tech Writing
Tip 1: Ok, everyone...absolutely everyone says follow the rubric. DO IT. Don't be smart, don't assume the grader will find you satisfied the rubric buried in your paper. Simply follow the follow rubric using the template. It'll save you headaches. I had to resubmit my SBT1 due to failure to define objectives clearly. I had goals and deliverables, but my objectives (goals-->objectives-->deliverables) weren't clear. Resubmit and I passed.
Tip 2: if you have to make up a project (I did), do something you are good at and tie it back to your degree. I'm a network goober at heart, but my degree is IT Security. I did a pseudo-network redesign for pseudo company. Securing the edge was only part of the solution. Anyhow, you don't have to make the project explicitly about your degree program. I was going to do a wireless security project, but it was going to get out of control quickly. Not a good idea. You have to incorporate your emphasis somewhere, and that's it. Don't make it hard. Its a lot of writing as it is.
Tip 3: Yes, it is the department of redundancy department. You will feel like you are repeating yourself throughout. Just the nature of the beast. stick to the template. If you choose to review the capstones, don't over-analyze. Some are 3 years old, some don't have the same layout as the current templates. Use the current template.
Tip 4: have someone else read your paper. Doesn't matter if they are technical our not. Just need a grammar and structure check. You've read it too much. you know what you mean to say. they don't. let 'em read it and fix it. You aren't perfect. I'm not. No one is. Let your best friend, spouse, whoever help on the review. Plus it'll count on your 10 items list if you do it right.
RGT1 -- capstone
This is fairly straightforward. Don't overthink it. Do the conversion as given, and write the new sections. I did mine in 2 days (8 hours each). Most of the heavy lifting is in the SBT1. I created pseudo network diagrams, network schemes, etc. Dreaming that up took 4 hours. I got a 4 on the rubric for the add-ons. I dunno if the depth of information helped, but I'm going to guess it does. Make sure you had some depth to the project. SBT1 is just a dream. RGT1 is real. Make it tangible. Produce the paperwork you would for a job. Network diagrams, IP info, whatever your boss or you'd want your junior engineers to have after you were done. Make it come to life. And if you don't have the software, grab the timebombed versions and install them. (office/visio).
Anyhow that's it. i'm done. good luck on your adventures.
Ever wonder what a (former) IT director for a ~25,000 student district does, ponders, or decides to write down?
Monday, February 23, 2015
Wednesday, January 28, 2015
WGU Update -- MGC1 & TPV1 Done
I passed the TPV1 today, Project+. I thought it was relatively easy compared to some of the other courses. The prep material from uCertify was perfect for the course. I studied 6 days for this one. Only recommendation is use the uCertify material, and READ the questions and how they got the answers. Remember there are 5 phases, answers from the 4th phase will not be right for the planning phase questions. If you have a good vocabulary, that will help. Also, taking the MGC1 right before actually helped as Project+ had the stages of teams (yay!) plus the types of conflict resolution, and last, the types of organizations (matrix versus functional vs project). Nice carry-over.
I took the MGC1 course 12 days before and passed. Typical test. Study what they tell you. Do the practice test at least twice with at least a mid-80 grade. As noted above, this course carries over really well into the project+ course. In hindsight, I'd probably do the Org Behavior, followed by Principles of Mgmt, then project+ back to back to back. The concepts stack and less relearning. If you were feeling ambitious and wanted to go off track/do a victory lap, doing the ITIL Foundations would fit nicely at the end of these 3. It isn't quite the same as stacking of concepts, but a lot of the ideas/concepts are interrelated to these 3 courses.
That's 36 hrs this semester currently. Have the Tech Writing and Capstone to round out the degree making it 43 hrs total for this one with 25 the previous plus semester. Yay me.
I took the MGC1 course 12 days before and passed. Typical test. Study what they tell you. Do the practice test at least twice with at least a mid-80 grade. As noted above, this course carries over really well into the project+ course. In hindsight, I'd probably do the Org Behavior, followed by Principles of Mgmt, then project+ back to back to back. The concepts stack and less relearning. If you were feeling ambitious and wanted to go off track/do a victory lap, doing the ITIL Foundations would fit nicely at the end of these 3. It isn't quite the same as stacking of concepts, but a lot of the ideas/concepts are interrelated to these 3 courses.
That's 36 hrs this semester currently. Have the Tech Writing and Capstone to round out the degree making it 43 hrs total for this one with 25 the previous plus semester. Yay me.
Monday, January 12, 2015
CIW v MS v Cisco v WGU v CompTIA Exams
(Updated) -- I've seen people post what tests/providers are the hardest in the WGU lineup. I'll go ahead and post my thoughts. I'm doing IT w/Sec Emphasis so my experience may be different than yours. I have over 15 years of real world experience from Desktop goober to Network geek to Boss. I've also had the technical alphabet soup after my name in the early 2000s (MCSE, CCNP, A+, Others...). Translation, I've taken a few test in the past 20ish years. Mostly passed too. Shocking. My personal order of difficulty from easiest to hardest as for 2014/2015 from a WGU point of view:
- WGU assessments
- CIW
- MS
- CompTIA
- Cisco
On the WGU test, the amount material can be overwhelming as in the bio course. However, the bar tends to be set low. Most of the time, you can get it down to a 50/50 coinflip on the questions you don't know. The material always seems to match the test. No question will be a surprise topic. Plus some of the recorded lectures tell you how to take the test well. Last, you get to stay home and take it so the comfort of home helps (provided your house is quiet, the neighborhood is quiet, etc...)
CIW has seemed to be the easiest testing-center test makers. Part of it is due to the fact the questions are truly from the material. There haven't been any surprises taking this line of testing. In addition, it seems like some of the concepts are common sense and can reason your way into the right answers, especially if you know the definitions of the words/terms. These test also seem to be simply definition/term based. Unlike the Cisco, MS, and CompTIA, there wasn't a lot of application of knowledge to a situation.
It may shock you to see MS next, but the 2 tests were entry level tests for Win7 and something else. The material provided by WGU seemed to be sufficient with my experience to pass these fairly easy. I would not be shocked to hear the more advance server courses had some difficultly and were harder than the CompTIA.
CompTIA. I actually thinks these are some of the more interesting tests with the scenarios they offer. The study material offered past the A+ needs some updating within the curriculum & course of study. The material WGU offered for Project+ was spot on, especially the uCertify resource. Net+, Sec+, Linux+/LPI all took outside resources. I'd list the difficulty within these sub-tests from easiest to hardest:
- Net+ (Its what I do/did so only had to learn 1 section)
- Project+
- A+
- Sec+
- Linux+
The carry-over of my network life helps a lot on the first 3, but the Linux to a windows person required some hands on retraining. As for the people who will say CompTIA deals with outdated tech, I'd argue most environments will have some flavor of outdated equipment you'll have to support, or help upgrade. Knowing how the old stuff works will help make good choices when proposing and upgrade to your boss/customer/spouse. The last pro on the "old" information is that you can communicate with the people who got off their tech career tracks a while back and are coasting it home to retirement. These people exist (sometimes in high places). The reality of work and life.
Cisco. Disclaimer, I failed the CCNA Sec the first time (888 vs 898 - not happy). I thought the material was ok (Books + Video), but the other material on Cisco's site is a must. The site material was the difference between pass/fail. I didn't take the CCNA (ICND) within WGU as I came in with it. These tend to have a very high bar to reach for a passing grade(85% or higher), require some hands-on, and know some random ass stuff buried within the material. Plus, its difficult to get true hands-on practice for this one. WGU says use GNS3 (which I advocate too), however, getting an IOS to run is challenge.
I've also taken the CWNA and ITIL exams in the recent 18 months. Below is how I'd group all the tests I've taken in the past 2 years from my point of view.
- Relatively Easy: WGU courses, CIW (ALL), Entry MS courses
- Moderate: ITIL Foundation, A+, Net+, Project+
- Somewhat Difficult: Sec+, LPI exams/Linux+, CCNA R&S
- Difficult: CWNA, CCNA Sec
Labels:
A+,
CCNA,
CCNA Security,
Certification Testing,
Cisco Certification,
CIW,
CompTIA,
CWNA,
ITIL,
MS,
Net+,
Security+,
Testing Difficulty,
WGU
CJV1 Passed -- CIW Database
Took the CJV1/CIW Database exam. 84 points achieved, 74 needed.
Test vs Material: the course and WGU material pretty much covered the test. Again, the practice questions aren't word for word the test, however they provided a good overview.
Test itself: Was actually fairly readable for an IT test. 50 questions, and only had one, maybe two questions where I had to decipher the phrase/word the test makers were dancing around. Again, nothing unexpected or new on the test.
Study Method: read the material end to end. Did chapter quizzes and exams. re-read 1-6 quickly. Did the 6 domain area quizzes. Did the domain area exams. Took test. Was making 90-94 on domain exams/quizzes. I didn't do any of the labs. I had enough practical experience in my few efforts query a DB to know the basic commands. SELECT, INSERT, UPDATE, CREATE, DROP, ALTER, ...etc.
Onto MGC1. Took the pre-assessment and made a 76. Guess I should schedule it...
Test vs Material: the course and WGU material pretty much covered the test. Again, the practice questions aren't word for word the test, however they provided a good overview.
Test itself: Was actually fairly readable for an IT test. 50 questions, and only had one, maybe two questions where I had to decipher the phrase/word the test makers were dancing around. Again, nothing unexpected or new on the test.
Study Method: read the material end to end. Did chapter quizzes and exams. re-read 1-6 quickly. Did the 6 domain area quizzes. Did the domain area exams. Took test. Was making 90-94 on domain exams/quizzes. I didn't do any of the labs. I had enough practical experience in my few efforts query a DB to know the basic commands. SELECT, INSERT, UPDATE, CREATE, DROP, ALTER, ...etc.
Onto MGC1. Took the pre-assessment and made a 76. Guess I should schedule it...
Monday, December 15, 2014
Network+ Done
Took and passed network+ with an 865. Woo, missed 4 questions. I think I whiffed a scenario, but I'm not sure. Funny.
Anyhow, regarding the material and test. Sorry, this wont be much help for a lot of folks.
Material: I quick glanced the material from WGU (Testout?). I took 4 notecards of notes. normally, I take a pile of them (50-150 cards depending). I had to beat into my head the 568A & 568B and 110 blocks. Ended up using WAG, BOW and BLOG for the scheme, A-GW (WAG), B-OW, Bl-O-G. The other cards had stuff on them. Don't even recall what. I took the practice tests, and did the scenarios in about 2/3rds of the sections. The ones testing ping, nslookup, dig, etc, I skipped. I've done these way too often in real life.
ping yourself
ping the gateway
ping your destination...
Took the full practice test, made a 96.
The test vs material: since I only quick-glanced it, I can't say how much it mapped up. I simply used my experience (CWNA, CCNA, CCNA-Sec) to ferret out most of the answers technical answers. I think the study material gave me 3-4 questions I would have missed or 50/50'd. I still love "choose the BEST" solution questions. Basic things to know
Anyhow, there is a lot on this one. experience helped a ton and made it relatively easy for me. knowing the OSI to services helps a lot for this test. Probably need to know it very well.
Anyhow, regarding the material and test. Sorry, this wont be much help for a lot of folks.
Material: I quick glanced the material from WGU (Testout?). I took 4 notecards of notes. normally, I take a pile of them (50-150 cards depending). I had to beat into my head the 568A & 568B and 110 blocks. Ended up using WAG, BOW and BLOG for the scheme, A-GW (WAG), B-OW, Bl-O-G. The other cards had stuff on them. Don't even recall what. I took the practice tests, and did the scenarios in about 2/3rds of the sections. The ones testing ping, nslookup, dig, etc, I skipped. I've done these way too often in real life.
ping yourself
ping the gateway
ping your destination...
Took the full practice test, made a 96.
The test vs material: since I only quick-glanced it, I can't say how much it mapped up. I simply used my experience (CWNA, CCNA, CCNA-Sec) to ferret out most of the answers technical answers. I think the study material gave me 3-4 questions I would have missed or 50/50'd. I still love "choose the BEST" solution questions. Basic things to know
- IP networking (subnetting, broadcast, Classes, etc. One of the questions was on a CCNA level I thought. Good question, had to think and know your rules).
- OSI model and service at each level and device relationships to said model (Physical - cables,hubs; datalink - bridge/switch; etc;)
- devices to service provided (Firewall vs router vs switch vs packet filter vs content filter)
- Ports and protocols (FTP, SMTP, SNMP, etc)
- Cabling standards
- troubleshooting steps
- WiFi (a,b,g,n; security options/flavors; radio freqs; antenna basics; )
Anyhow, there is a lot on this one. experience helped a ton and made it relatively easy for me. knowing the OSI to services helps a lot for this test. Probably need to know it very well.
Tuesday, December 9, 2014
IINS 640-554 passed (CCNA Sec, WGU Course CNV1)
Passed. Only with a 918 out of a 1000.
Thoughts: This was a test with a high bar to reach. as stated in other notes, make sure you read the documents from the Cisco site beyond the book and the videos from CBTNuggets and Boson's tests. The books and videos will get you close, but the material from the others will get you the rest. I spent a lot of time in the CCP GUI and console the 2 days before the test. I re-reviewed my notes the night before.
GNS3 is almost required. I'm am using the most current version 1.2.1. Here is the practice I used (over and over and over).
Thoughts: This was a test with a high bar to reach. as stated in other notes, make sure you read the documents from the Cisco site beyond the book and the videos from CBTNuggets and Boson's tests. The books and videos will get you close, but the material from the others will get you the rest. I spent a lot of time in the CCP GUI and console the 2 days before the test. I re-reviewed my notes the night before.
GNS3 is almost required. I'm am using the most current version 1.2.1. Here is the practice I used (over and over and over).
- The Win7client was a VirtualBox Machine. It was used to manage all devices, ASDM and CCP. CCP IS dog-ass slow discovering.
- One Proc, 2Gigs of RAM, 40G HDD
- Installed Apps included
- ASDM -- for the ASA
- CCP -- for the routers
- Notepad++ -- cause i can't remember anything two seconds after i see it
- Chrome (w/adblock) -- my preferred
- Tftpd64
- to move asdm image back and forth to the ASA
- to provide file downloads for the IOS IPS
- default gateway was the IOS router (NOT THE ASA)
- Local/Host workstation
- Quad core Intel, 16gigs of RAM
- Connected to ISP router with physical connection. Physical connection is the Local Area Connection 2
- Served as VPN connection to the ASA.
- Routers
- 7200 series with IOS 15.0.x
- All routers had a 1GE Interface
- WANFU
- had qty 2 -- 2 port 100FE cards
- Was a DHCP client on g0/0 to get internet routable IP address. I hate looking at the damn yellow ! network icon on win7client box.
- did NAT (hey! a test objective) for other networks.
- Was known to blow up once IOS firewall was turned on (hey, another test objective!)
- Area4 & Area5 Routers
- Single 2 port 100fe cards
- Not shown interface was the interface used for vpn (f1/1 on both)
- Ran OSPF as the IGP. Redistributed on WANFU for default route.
- ASA used the known working image within GNS3. It spent most of its life OFF. It WILL eat a single core of your processor when it is on. Plus it is very fickle about keeping configs between reboots. As this is an entry-level course, redoing the interfaces didn't take long, and was good practice.
- The VMWare cloud hosted the ACS box. I'll figure out how to reconnect it.
My practice labs I did a lot to get the commands down. Seeing enable secret level 6 0 level6pwd looks weird if you don't know what you are seeing. Test related info in bold. Maybe I'll write out a full step by step or some sort of solutions. Right now, please verify your work as you go. I just used this lab to reinforce what Keith Barker's Nuggets taught. I broke most of this out into sections. They can be done independently of each other AFTER the initialization section.
- Initialization: basic connectivity
- Give the routers IP addresses. I like loopbacks, so I added some. Mine were 10.0.255.25x/32. Also, make sure to set the g0/0 to DHCP client on WANFU
- Get IPv4 routing working. I used OSPF, everything in area0. Don't advertise the 192.168.xx.y nets. They are your site-to-site VPN networks. Notice you don't have to advertise them to get VPN working.
- Enable IPv6. Give the routers IPv6 addresses on all interfaces.
- Get some sort of IPV6 routing working.
- Check your IPV6 interfaces and routing
- show ipv6 int brief
- ping 2001:... source 2001:..
- Configure NTP . Make WANFU master (ha!). use encryption. Set Area4 to use WANFU. Area5 will be done later.
- Configure Users and CCP Login
- Create the users listed at the privilege listed
- enable secrets at the appropriate level with correct passwords
- TEST; login; give some rights.
- give all the boxes a domain-name (ip domain-name gns3.local is the syntax I used)
- turn on the web server on each router
- turn on both insecure and secure methods
- use local authentication
- generate your certs for SSH
- On all but Area5 Router, turn on AAA authentication, authorization. Area5 gets it in the GUI. that sounds wrong
- Authorized exec and commands. Again use the user accounts for levels. practice with both default and NAMED method lists. I always set my lists to use local, then 2 or 3 of the other options (group tacacs, enable, local-case, etc). Heck create 2 types, MYTAC and MYLOCAL for authentication.
- configure vty lines to use the aaa authentication and authorization, using the methods just created
- On Area5 Router
- configure login on the vty terminals WITHOUT AAA.
- Turn on CCP. CCP FUN time.
- Create a group of nodes, MYGNS3 is what i called them.
- I used loopback interfaces. Good practice in RL, but...up to you
- Discover your nodes! (good time to drink, use the facilities, talk to your family, order dinner). Yeah, it can be slow.
- Manage Area5 router's AAA in CCP
- Turn on AAA
- Configure the exact same method lists as WANFU and Area4
- Push the config out
- Manage NTP in CCP for Area5 Router. WANFU is the reference.
- Back to the consoles. Sad, so sad....
- enable views and login in with the root view. You did read what it told you when you turned it on?
- create more views! Assign some rights. commands exec all show ip; show ipv6; etc. test that bad boy.
- Test everything now. Login right and wrong.
- Debug AAA authentication/authorization
- test aaa group (yeah, no server, so what?). It fails, what a shock.
All right, i think we got most of the basics going and tested. CCP should work. AAA should work using local for SSH/Telnet. All routers are accessible. Life is good. NTP might work. I found NTP tended to cause WANFU to suffer an emotional breakdown and have to be deleted and re-added. Saving would be good if all works in a way you like. Let's move on!
- All right! more fun! Lets go out of order and do VPN! Why? Cause the longer before I make WANFU do a whole lot, the better off I was. Back to CCP! If you don't understand the jargon, read the study guide, watch Keith Barkers videos. These are just practice labs to reinforce.
- Rediscover Area4 and Area5 Routers
- Create an new site-to-site VPN on area4 router
- DO NOT USE Defaults. be wild, be crazy, just dont DES. friends don't let friends DES. For your HAGLE, lets pick...AES192, MD5, Pre-shared (ilikevpn), DH group 5. Leave the lifetime alone. Seriously, pick your own options. copy-cat.
- for the phase 2 portion, lets pick MD5-HMAC, and AES 256.
- Your interest traffic will be....????
- (192.168.40.x going to 192.168.50.x)
- Your interface will be??? (f1/0)
- Push that bad boy out.
- Ok, go clear the phase 1 that is pushed out by default by CCP. Defaults suck (well, not really, but what fun is letting someone else pick?)
- And lets go Area5 router and do the same thing! Fun. Switch nodes in CCP to Area5.
- Create a new site-to-site VPN. match it up with your others.
- your interest traffic might need an adjustment? (the answer is yes)
- Push out the config. Destroy the default Phase 1 it sends. You are remembering what screen on CCP all this stuff is buried as you do this?
- To the console. About time. keep the CCP up tho. You'll want to view both
- Generate some interesting traffic. On Area4 Router; ping 192.168.50.1 source 192.168.40.1. If you did it right, the establishment of the tunnel might eat one or two packets, but otherwise work. nomnomnom. If not, well, crud. You get to troubleshoot! Haha! (or reboot the boxes and retry. i wont judge you. much. You have to suffer through a rediscovery in CCP. Another 5 minutes of your life lost waiting.).
- Practice your show commands
- show crypto ipsec ?; show crypto isakmp ?; show crypto map; show run. what does the map do and have in it? what does the sa option show you? Where is everything applied
- go to the GUI. check the tunnel status. Answer all the questions you had in the console via the GUI.
- If you are feeling really spicy, turn on your debugs. debug crypto...bring the tunnels up/down etc.
- Do a show run. see what is in the crypto map. what is in the isakmp part. what is in the ipsec part. what does the ACL do and which one is it?
- We'll put off the ASA VPNs for a bit. Your host workstation will thank you.
Did your VPN work? if so, save it! we are moving on! Let do some more security, a security audit.
- Is CCP up and everything discovered. Yep. do it. Pull up your favorite 3-5 minute youtube video while you wait.
- Lets manage WANFU. Lets do a security audit!
- OMG! what should you trust and not trust
- No one trusts their internet.
- Although i don't trust the guy configuring the rest of this lab, lets say the rest of we do for now (f/x interfaces and loopback0)
- DNS, use google 8.8.8.8, 8.8.4.4
- Run the security audit! go ahead and let it do service password-encryption, and some others if you feel it.
- Push it out if you are feeling lucky
- ALright! lets do a one step lock-down. save your config before you start (and gns environment)
- You'll need to see the screens.
- let it push out one time. I've always had craptacular luck and had to reload the OS at this point.
- read the screen. see what options you can turn up/down.
That was fun? easy? simple? Onward. IOS based firewall next on WANFU
- get CCP going. manage WANFU.
- go ahead and turn up the down dmz interface, f1/1. 172.31.255.1/24 is good. I like using the boundary addresses to reinforce. everyone puts the lower bounds, practice on the upper.
- you'll have to do this one a couple of times
- do a basic firewall
- do an advance firewall
- This is all virtual, so make up a virtual server for the dmz. if you are really feeling it, go ahead and connect it to the switch in a different vlan and attach some magic box running whatever service you let through
To be continued...
Labels:
CCNA Security,
GNS3,
IINS 640-554,
Labs,
Study Info,
WGU
Monday, December 1, 2014
Additional Resources for IINS 640-554 (WGU CNV1)
I am in the process of adding additional resources I used beyond the CBTNuggets and official Cisco book for the test.
This is based off of my actual test experience and Cisco's CCNA Security Exam Topics.
This is based off of my actual test experience and Cisco's CCNA Security Exam Topics.
- Overall information to review and study directly from Cisco itself is here. They have several resources that are beyond the scope of the material from CBT and the books.
- Chapter 6, For Layer 2 Security/Common Layer 2 attacks, the link doesn't appear to work. I used this resource from Pearson. This beyond what is in the the book. Since it is 25 pages and the reference link is 25 pages, I'm guessing it is the resource link we are to use. Based upon experience, I am confident this is the material. Seriously, read it, take notes.
I'll add more as I get back into this test.
Labels:
Additional Study Material,
CNV1,
IINS 640-554,
WGU
Subscribe to:
Posts (Atom)
