Learning Outcomes
- Map network assets, data flows, trust boundaries, components, and security-relevant dependencies in an authorized environment.
- Use OSI and TCP/IP models, encapsulation, headers, and protocol states to reason about network behavior and evidence.
- Explain Ethernet switching, MAC learning, broadcast domains, VLANs, trunks, loops, and Layer 2 segmentation risks.
- Plan IPv4 and IPv6 addressing, interpret prefixes, calculate subnets, and identify address-related exposure or misconfiguration.
- Interpret routing tables, path selection, gateways, NAT/PAT, asymmetry, and path-enforcement points during troubleshooting.
- Analyze ARP, ICMP, DHCP, DNS, and NTP dependencies and distinguish normal service flow from suspicious or failed behavior.
- Reconstruct TCP and UDP conversations using states, flags, ports, sockets, timing, and encrypted-session metadata.
- Evaluate wireless, VPN, remote-access, and cloud-network designs using authentication, encryption, segmentation, and least privilege.
- Review firewalls, proxies, IDS/IPS, segmentation, and zero-trust controls and translate policy intent into testable network rules.
- Collect and interpret authorized network evidence, use Wireshark safely, troubleshoot systematically, and triage a synthetic incident.
Certificate : DTF AI Academy
Course Features
- Lectures 60
- Quizzes 11
- Duration Lifetime access
- Skill level All levels
- Language English
- Students 4
- Certificate Yes
- Assessments Self
- 11 Sections
- 60 Lessons
- Lifetime
- Networks as Security Systems
Outcome: Map network assets, data flows, trust boundaries, components, and security-relevant dependencies in an authorized environment.
Case: A growing training company has an undocumented flat network. Staff, guest, lab, printer, camera, cloud, and administration traffic share paths, and no owner can explain which flows are essential.
Tools: Topology and trust-boundary map, Asset and data-flow inventory, Authorized-lab rules card
7 - Models, Protocols, and Encapsulation
Outcome: Use OSI and TCP/IP models, encapsulation, headers, and protocol states to reason about network behavior and evidence.
Case: A browser connection fails. Different teams blame DNS, routing, TLS, and the application, but no one can separate the layers or state the evidence that would confirm each hypothesis.
Tools: Layered evidence trace, Encapsulation worksheet, Protocol dependency map
7- 2.1Use models as reasoning tools
- 2.2Follow encapsulation and decapsulation
- 2.3Separate headers, payloads, and metadata
- 2.4Understand protocol state and dependency
- 2.5Distinguish plaintext, encryption, and tunnelling
- 2.6Trace a connection end to end
- 2.7Module 2 Assessment — Models, Protocols, and Encapsulation5 Minutes5 Questions
- Ethernet, Switching, and VLANs
Outcome: Explain Ethernet switching, MAC learning, broadcast domains, VLANs, trunks, loops, and Layer 2 segmentation risks.
Case: A new VLAN rollout creates intermittent access, excessive broadcasts, and unexpected reachability between laboratory and administration devices.
Tools: MAC-table analysis, VLAN and trunk plan, Layer 2 evidence worksheet
7 - IPv4, IPv6, and Subnetting
Outcome: Plan IPv4 and IPv6 addressing, interpret prefixes, calculate subnets, and identify address-related exposure or misconfiguration.
Case: A merger combines overlapping IPv4 space, an incomplete IPv6 rollout, inconsistent prefix documentation, and security rules that cover only part of the actual address plan.
Tools: Prefix and subnet worksheet, Dual-stack address plan, Address-exposure matrix
7 - Routing, NAT, and Network Paths
Outcome: Interpret routing tables, path selection, gateways, NAT/PAT, asymmetry, and path-enforcement points during troubleshooting.
Case: A cloud application works from one branch but not another. The failing path includes a default route, overlapping prefixes, PAT, an asymmetric return, and a firewall state table.
Tools: Routing-table analysis, End-to-end path map, NAT and state worksheet
7 - ARP, ICMP, DHCP, DNS, and NTP
Outcome: Analyze ARP, ICMP, DHCP, DNS, and NTP dependencies and distinguish normal service flow from suspicious or failed behavior.
Case: Users report intermittent access after a network change. Evidence includes duplicate address warnings, expired leases, delayed DNS answers, blocked ICMP errors, and time-skewed logs.
Tools: Service-sequence map, DNS and DHCP trace worksheet, Dependency-failure lab
7 - TCP, UDP, Ports, and Sessions
Outcome: Reconstruct TCP and UDP conversations using states, flags, ports, sockets, timing, and encrypted-session metadata.
Case: Monitoring reports thousands of short connections, UDP timeouts, retransmissions, and unexpected high ports. Analysts must distinguish normal application behavior from failure or suspicious activity.
Tools: TCP state worksheet, IANA registry lab, Session reconstruction exercise
7 - Wireless, VPNs, Remote Access, and Cloud Networks
Outcome: Evaluate wireless, VPN, remote-access, and cloud-network designs using authentication, encryption, segmentation, and least privilege.
Case: Remote staff use Wi-Fi, full and split-tunnel VPNs, cloud applications, and administrator access. Overlapping policies and unmanaged endpoints create inconsistent visibility and access.
Tools: Synthetic wireless review, VPN and remote-access decision matrix, Cloud network flow map
7 - Firewalls, Proxies, IDS/IPS, and Segmentation
Outcome: Review firewalls, proxies, IDS/IPS, segmentation, and zero-trust controls and translate policy intent into testable network rules.
Case: A rulebase has years of exceptions, broad address groups, disabled logging, shadowed rules, and unclear ownership. A new segmentation project must preserve critical services without recreating the flat network.
Tools: Firewall-rule review, Segmentation architecture, Control-placement matrix
7 - Monitoring, Packet Analysis, Troubleshooting, and Incident Triage
Outcome: Collect and interpret authorized network evidence, use Wireshark safely, troubleshoot systematically, and triage a synthetic incident.
Case: A synthetic incident combines DNS anomalies, a new outbound destination, repeated TCP resets, configuration drift, and time-skewed logs. The analyst must establish facts without capturing private production traffic.
Tools: Packet-analysis worksheet, Network triage runbook, Capstone evidence pack
7- 10.1Choose network evidence
- 10.2Establish baselines and anomalies
- 10.3Use Wireshark safely
- 10.4Troubleshoot systematically
- 10.5Triage suspicious network activity
- 10.6Capstone: map, segment, secure, monitor, investigate, improve
- 10.7Module 10 Assessment — Monitoring, Packet Analysis, Troubleshooting, and Incident Triage5 Minutes5 Questions
- Final ExaminationFinal assessment for Networking for Cyber Security. Passing score: 70%.1
Certificate



