Friday, November 21, 2014

CNV1 -- IINS 640-554 Test -- Failed

I recently took the Cisco CCNA Security 640-554 test and failed with a 888 with an 898 needed Yeah, big suckage. 5 days for Cisco before retake and I do know now how long for the WGU retake.

Thoughts on the test without hopefully violating the terms.

  • Know the CCP GUI for all the sections and material you are responsible for. The test expects some level of knowledge here
    • This includes how to do a configuration of the selected tasks.
    • What the path/where to click to access the task or information. (IE, where do you go to configure NTP Servers in CCP).
    • The tasks to know
      • How to view and configure everything related to an access-list
      • How to view and configure everything related to IOS VPN
      • How to view and configure everything related to IOS Firewall
      • How to view and configure everything related to AAA
      • How to view and configure everything related to time
      • The tasks and steps under the security audit tab
  • Know the same topics from the command line too. :)
  • Know your ASA for SSL VPN options and setup
  • The books provide most of the test information you will need. However, some areas that I think the books, practice tests, video (CBT) were short on.
    • IPv6
    • IPv6 access-lists
    • PVlan
    • Layer 2 (books and video especially)
  • Have a better understanding than the books give for the other Cisco products basically outside the scope of the test. Inside the scope would be CCP, ASA, IOS, IOS IPS, & ASDM. The books do cover these other items (SecureScan, IronPort, SCM). You don't need a detailed knowledge of how to configure or use these devices, but know the feature sets they offer.
  • Have a good understanding of layer 2 protocols and protections. Understand Layer 2 from what the Boson practice test quizzes you over. The books and videos aren't enough.
  • Know the Cisco answer to the question. I got a question that there were 3 rights and I had to pick 2. It wasn't one of the, "which of the following is the best..." either. Experience in the real world can be good AND bad.
  • The study material probably covers only 85-90% of what I was tested on.
  • Review the official Cisco Exam topics. Like everything else in life, what you don't prepare for  always seems to show up.
Personal thoughts:
  • I think I might have got a pretty crappy role from the RNG on what I was tested over in certain areas. I'm sure life evens itself out eventually.
  • Never forget Cisco certs are highly sought after so the questions and material will reflect it. Lots of opportunity for "bad" people to dump answers and raise the bar for the rest of us. Cisco has to make it harder somehow so they will do the following:
    • Expect poorly worded questions to distract, confuse or frustrate you.
    • Expect to see some minutiae questions. They will test you over a single sentence from the book.
    • Test outside of the book & video but still within exam objectives (NOT NICE!)
  • Studying for this one isn't fun. You will spend quite a bit of time messing with the environment to get enough hands on practice. You will be reloading OS, configs, scenarios, waiting for CCP, etc...
From the WGU Perspective:
  • There's NO help in the forums for the current version of the test. You are on your own.
  • Again there is a large gap between the test and the material. As a college course you kinda hope to have materials that provide you an environment to simulate the material on the test especially if it is hands on. Access to IOS, ASA, ASDM, IOS IPS, CCP are either memorize the lecture steps (hahahaha), buy equipment to practice, or find emulators to practice.

No comments:

Post a Comment