What this objective tests
350-401 Security — Key Topics
Configure device hardening and access control using AAA (TACACS+/ISE), ACLs, CoPP, 802.1X/MAB, port security, DHCP snooping, and Dynamic ARP Inspection. The most important thing: verify ACL and CoPP order/interface direction, since mistakes silently drop or permit traffic.
- Configuring AAA with TACACS+ or RADIUS, including authentication, authorization, and accounting method lists
- Implementing Layer 2 protections: port security, DHCP snooping, Dynamic ARP Inspection, and 802.1X with MAB
- Building and ordering standard, extended, and named ACLs, plus Control Plane Policing for management traffic
- Configuring IPsec site-to-site VPNs and MACsec link encryption, including verifying SA and key status