FREE COURSE // 11 PARTS

Networking for Cyber Security

A structured networking course for cybersecurity beginners: ten professional study-note parts followed by a 50-question final MCQ exam. Pass mark: 75%.

01

Part 1 — Networking Fundamentals & Devices

Part 1 covers the foundation of networking that a cybersecurity analyst needs before working with logs, packets, firewalls, SIEM alerts or incident-response data.

STUDY NOTES

NETWORKING FUNDAMENTALS

Network is a collection of connected devices that communicate to exchange data and services using agreed communication protocols. A network can connect computers, servers, phones, printers, security appliances, cloud workloads and Internet services. In cybersecurity, networking is foundational because an alert is rarely meaningful without understanding the path taken by the traffic, the source and destination addresses, the protocol, the ports and the device that should have handled the communication.

NETWORK TYPES AND SCOPE

PAN (Personal Area Network) covers a very small personal range, such as a phone communicating with a wearable. LAN (Local Area Network) normally covers a home, office, laboratory or building. WLAN is a LAN implemented through wireless networking. MAN (Metropolitan Area Network) can connect sites across a city or metropolitan area. WAN (Wide Area Network) connects geographically separated networks; the Internet is the most familiar example of a very large interconnected network.

CLIENT-SERVER AND PEER-TO-PEER

In a client-server design, clients request services from centralized servers. Examples include DNS servers, DHCP servers, file servers, web servers and authentication servers. Centralization makes management and security controls easier to apply, but a compromised server can have a large impact. In a peer-to-peer (P2P) design, endpoints can provide services directly to one another. P2P can be useful for specific applications, but unmanaged P2P communication can make monitoring and access control more difficult.

NETWORK TOPOLOGIES

Star topology connects endpoints to a central switch or similar device. It is common in Ethernet LANs and makes individual-link troubleshooting relatively straightforward. Bus topology places devices on a shared communication path and is largely historical in modern enterprise Ethernet. Ring topology connects devices in a logical or physical ring. Mesh topology provides multiple paths between devices; a full mesh of n devices requires n(n-1)/2 links, which becomes expensive as n grows. Tree topology organizes networks into hierarchical layers and is common in enterprise designs.

NETWORK DEVICES

Router: forwards IP packets between networks and normally separates broadcast domains. A router uses a routing table and chooses the most specific matching route. Switch: forwards Ethernet frames using learned source MAC addresses and a CAM/MAC table. A normal switch port is a separate collision domain, while VLAN design determines Layer 2 broadcast boundaries. Hub: repeats incoming signals to every port and creates a shared collision domain; it has no MAC learning. Bridge: connects Layer 2 segments and makes forwarding decisions based on MAC addresses; modern switches perform the same basic function at much greater scale. Repeater: regenerates or repeats a signal to extend a physical link. Modem: converts or modulates signals for a particular access technology so a local network can communicate across an ISP service. Gateway: acts as an entry/exit point and can translate or mediate between different networks or protocols. Access Point: provides wireless connectivity and bridges wireless clients into a wired or virtual LAN. Firewall: enforces traffic policy according to addresses, ports, protocols, connection state and, in advanced products, application or identity context.

SECURITY VIEW OF NETWORK DESIGN

A cybersecurity analyst should know where security controls sit in the path. A firewall may block an unwanted connection before it reaches a server. A switch can enforce VLANs and port security. An access point can enforce wireless authentication. A router can apply ACLs and route filtering. Network segmentation can limit the blast radius of a compromised endpoint. When investigating an event, ask: Who communicated? From which IP and MAC? Through which switch, router, firewall or gateway? Which protocol and port were used? Was the traffic expected for that network segment?

02

Part 2 — OSI & TCP/IP Models

Part 2 explains the layered models used to reason about communication, troubleshooting and security events.

STUDY NOTES

OSI MODEL The OSI model has seven layers: Layer 1 Physical, Layer 2 Data Link, Layer 3 Network, Layer 4 Transport, Layer 5 Session, Layer 6 Presentation and Layer 7 Application. The model is a conceptual framework rather than a requirement that every modern protocol stack implement seven separate software layers. LAYER 1 — PHYSICAL The Physical layer carries raw signals over copper, fiber, radio or another medium. It includes connectors, cabling, signaling and physical transmission characteristics. Common security concerns include cable tapping, device theft, hardware tampering, unauthorized port access and radio interference. Troubleshooting starts with power, link status, cabling, transceivers and signal quality. LAYER 2 — DATA LINK The Data Link layer provides local network delivery. Ethernet frames contain source and destination MAC addresses. Switching, VLAN tagging and protocols such as ARP-related local behavior are closely associated with Layer 2 operations. Security issues include ARP spoofing, MAC flooding, VLAN hopping, rogue DHCP and wireless attacks. Switch CAM tables, VLAN configuration and port-security state are useful evidence during investigations. LAYER 3 — NETWORK The Network layer provides logical addressing and routing. IPv4 and IPv6 are the major Internet Protocol versions. Routers use routing tables to determine the next hop. ICMP supports diagnostics and error reporting. Layer 3 attacks include IP spoofing, routing manipulation, ICMP flooding and fragmentation abuse. LAYER 4 — TRANSPORT TCP is connection-oriented and provides sequencing, acknowledgements, retransmission and flow/congestion controls. UDP is connectionless and has less protocol overhead. Transport-layer indicators include source/destination ports, TCP flags, connection state, retransmissions and unusual connection rates. SYN floods, UDP floods and connection exhaustion are examples of Layer 4 availability attacks. LAYERS 5–7 The Session layer concerns logical conversations and session management. The Presentation layer concerns representation, encoding, compression and encryption functions. The Application layer contains user-facing protocols such as HTTP, DNS, SMTP, SSH and many others. Security attacks at these layers include session hijacking, replay, TLS downgrade, phishing, SQL injection, XSS and command injection. TCP/IP MODEL The TCP/IP model commonly groups the stack into Link, Internet, Transport and Application layers. The TCP/IP Internet layer corresponds most closely to OSI Layer 3. The TCP/IP Transport layer corresponds to OSI Layer 4. TCP/IP's Application layer combines much of the functionality represented by OSI Layers 5, 6 and 7. The Link layer covers much of OSI Layers 1 and 2. PDU NAMES AND ANALYST USE At the Physical layer the unit is commonly discussed as bits. At the Data Link layer it is a frame. At the Network layer it is a packet. TCP uses a segment at the Transport layer, while UDP uses a datagram. Using the correct layer helps an analyst narrow down an incident: an Ethernet broadcast problem suggests Layer 2; an unreachable subnet suggests Layer 3; a SYN flood suggests Layer 4; and suspicious HTTP parameters suggest Layer 7.

03

Part 3 — IP Addressing, Subnetting & VLSM

Part 3 develops IPv4/IPv6 addressing skills used in routing, firewall rules, asset identification and SOC investigations.

STUDY NOTES

IP ADDRESSING IPv4 addresses are 32 bits and are normally written as four decimal octets. An address is interpreted together with a prefix length or subnet mask. The prefix identifies the network portion and the remaining bits identify hosts within that network. PRIVATE IPv4 RANGES RFC 1918 private ranges are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. These addresses are intended for private networks and are normally translated before reaching the public Internet. A 172.32.0.1 address is not inside the private 172.16.0.0/12 range. SPECIAL IPv4 ADDRESSES 169.254.0.0/16 is APIPA/link-local addressing used by many Windows hosts when automatic addressing fails. 127.0.0.0/8 is the IPv4 loopback range. The network address identifies the subnet itself and the broadcast address identifies all hosts on a traditional IPv4 subnet. IPv6 IPv6 uses 128-bit addresses. fe80::/10 is the link-local prefix. 2000::/3 is the global unicast range commonly used on the Internet. ff00::/8 is multicast. fc00::/7 is unique local addressing. IPv6 changes many operational details, but the security analyst still needs to understand source/destination addressing, routing, neighbor discovery and filtering. SUBNETTING Subnetting divides an address block into smaller networks. A /27 leaves five host bits, giving 2^5 = 32 total addresses and 30 usable host addresses in the traditional IPv4 model. To find a network ID, identify the block size in the changing octet and determine which block contains the address. For example, 192.168.10.77/26 has blocks of 64 addresses, so 77 belongs to the 192.168.10.64–192.168.10.127 subnet and the network ID is 192.168.10.64. BROADCAST CALCULATION For 172.16.45.200/20, the third octet has a block size of 16. The block containing 45 begins at 32 and ends at 47, so the broadcast is 172.16.47.255. HOST CAPACITY A /23 has nine host bits and therefore 512 total addresses, traditionally 510 usable hosts. A /24 has 254 usable hosts. Therefore a requirement for 500 hosts needs a /23 rather than a /24. VLSM Variable Length Subnet Masking allows different subnet sizes inside a larger address plan. Allocate the largest requirement first, then progressively smaller requirements. This makes it easier to keep ranges contiguous and prevents a large requirement from becoming impossible to place after smaller allocations consume the available space. ROUTE SUMMARIZATION Four contiguous /24 networks can be summarized into a /22 when their address boundaries align. For example, 192.168.0.0/24 through 192.168.3.0/24 summarize as 192.168.0.0/22. Summarization can reduce routing-table size and make network policy easier to manage. SOC APPLICATION Subnet knowledge helps analysts decide whether an IP is internal, whether two hosts are likely on the same subnet, whether a firewall rule is broad or narrow, and whether a source address is plausible for a given asset. Always preserve the original IP, prefix context and timestamp when investigating an event.

04

Part 4 — MAC, ARP, Switching, VLANs & STP

Part 4 explains Layer 2 behavior and the security controls used to protect switched networks.

STUDY NOTES

MAC ADDRESSES Ethernet interfaces use MAC addresses for local Layer 2 delivery. A typical MAC address is 48 bits and is displayed as six hexadecimal octets. The first 24 bits are commonly called the Organizationally Unique Identifier (OUI) and can identify the registered manufacturer. The Ethernet broadcast destination is FF:FF:FF:FF:FF:FF. SWITCHING AND CAM TABLES A switch learns the source MAC address of received frames and associates that address with the ingress port in its CAM/MAC table. When a frame is destined for a known MAC, the switch forwards it to the corresponding port. If the destination is unknown, the switch may flood the frame within the relevant VLAN. Broadcast frames are also flooded within the VLAN. COLLISION AND BROADCAST DOMAINS A hub creates one shared collision domain. A modern switch normally gives each physical port its own collision domain. VLANs and Layer 3 routing determine broadcast-domain boundaries. A router interface is normally a boundary between broadcast domains. ARP ARP maps an IPv4 address to a MAC address on a local Ethernet network. A host that needs a MAC for a local IPv4 destination sends an ARP request as an Ethernet broadcast. The owner normally replies with a unicast ARP response. ARP does not provide built-in cryptographic authentication, which makes spoofing possible. ARP SPOOFING AND DYNAMIC ARP INSPECTION An attacker can send forged ARP messages to associate their MAC with another host's IP address, potentially positioning themselves between systems or redirecting local traffic. Dynamic ARP Inspection (DAI), where supported, validates ARP packets against trusted bindings such as DHCP snooping information. Static bindings, segmentation and endpoint monitoring can provide additional controls. VLANs AND 802.1Q A VLAN logically separates Layer 2 traffic. Access ports normally carry traffic for one VLAN, while trunk links can carry multiple VLANs. IEEE 802.1Q provides VLAN tagging on trunk links. Incorrect trunk configuration can cause leakage between segments. VLAN hopping attacks are associated with misconfigured trunks, native VLAN behavior or switch negotiation weaknesses. STP Spanning Tree Protocol prevents Layer 2 loops by creating a loop-free logical topology while retaining redundant paths for resilience. Without loop prevention, redundant links can produce broadcast storms, MAC-table instability and severe network disruption. Security controls include BPDU Guard/Protection where appropriate, Root Guard, careful trunk configuration and strict management of switch ports. MAC FLOODING AND PORT SECURITY MAC flooding attempts to fill a switch CAM table with many bogus source MAC addresses. A switch may then flood unknown destinations more broadly than intended. Port security can limit the number or identity of MAC addresses permitted on an access port. Monitoring for sudden CAM growth and unexpected MAC movement can provide useful detection evidence.

05

Part 5 — Routing & Routing Protocols

Part 5 explains how routers choose paths and how routing behavior becomes security-relevant.

STUDY NOTES

ROUTING BASICS Routing determines how an IP packet travels from its source network toward its destination network. A router compares the destination address with entries in its routing table. When several entries match, the router selects the longest prefix match—the most specific route. For example, if a router has 10.1.0.0/16 and 10.1.1.0/24, traffic to 10.1.1.5 uses 10.1.1.0/24 because /24 is more specific than /16. ROUTE SOURCES AND ADMINISTRATIVE DISTANCE Administrative distance is a local measure used by many routing implementations to compare route sources. A common Cisco-style reference is static route = 1, EIGRP internal = 90, OSPF = 110 and RIP = 120. These values are implementation conventions, so analysts should confirm the platform and configuration when interpreting a routing table. STATIC ROUTING Static routes are manually configured and can be predictable and useful for small or controlled paths. They require maintenance when topology changes. A default route is used when no more-specific route exists. OSPF OSPF is a link-state routing protocol. Routers exchange link-state information, build a topology database and calculate shortest paths using the Shortest Path First algorithm associated with Dijkstra. OSPF uses cost as a primary path metric and supports hierarchical areas. BGP BGP is a path-vector protocol used to exchange routing information between autonomous systems. BGP uses TCP port 179. Internet-scale routing depends heavily on BGP, and route leaks, route hijacking and incorrect announcements can have major consequences. ROUTING SECURITY Routing attacks can attempt to inject false routes, manipulate path selection or disrupt reachability. Defenses include authenticated routing protocols where supported, route filtering, prefix limits, secure management, strict peering policies, monitoring for unexpected route changes and validating control-plane logs. ROUTING AND FIREWALL POLICY Security policies often depend on routed zones. An analyst should understand which interface or zone a packet enters and leaves, what route was selected, and whether a firewall rule or ACL should permit the flow. A routing error can look like a firewall failure, while a firewall block can look like an application outage. Correlating routing tables, firewall logs and packet captures helps separate these causes.

06

Part 6 — TCP, UDP, Ports & Common Services

Part 6 focuses on transport behavior and the ports and protocols commonly encountered in security operations.

STUDY NOTES

TCP TCP provides connection-oriented, reliable transport. A normal TCP connection begins with the three-way handshake: SYN, SYN-ACK, ACK. Sequence numbers track bytes and acknowledgements indicate the next byte expected. TCP flags include SYN, ACK, FIN, RST, PSH and URG. FIN supports graceful shutdown; RST abruptly resets a connection. UDP UDP is connectionless and has less protocol overhead. It does not provide TCP-style sequencing, retransmission or a three-way handshake. UDP is useful for services where low overhead or application-controlled reliability is desirable, including DNS queries and many streaming or real-time applications. PORTS AND PROTOCOLS FTP uses TCP 20/21 in traditional active/passive configurations. SSH uses TCP 22. Telnet uses TCP 23. SMTP commonly uses TCP 25 for server-to-server mail transport. DNS commonly uses UDP/TCP 53. DHCP uses UDP 67 for servers and 68 for clients. TFTP uses UDP 69. HTTP uses TCP 80. POP3 uses TCP 110. NTP uses UDP 123. RPC Endpoint Mapper commonly uses TCP 135. NetBIOS commonly uses UDP/TCP 137–139. IMAP uses TCP 143. SNMP commonly uses UDP 161. LDAP commonly uses TCP/UDP 389 depending on implementation. HTTPS commonly uses TCP 443, with modern HTTP/3 using QUIC over UDP 443. SMB commonly uses TCP 445. Syslog commonly uses UDP 514, though TCP/TLS variants exist. LDAPS commonly uses TCP 636. RDP commonly uses TCP/UDP 3389. SECURITY SIGNIFICANCE OF PORTS A port number identifies a transport endpoint, not automatically a trustworthy application. Malware can listen on an unusual port, and legitimate software can use non-default ports. Analysts should correlate ports with process information, DNS, certificates, HTTP hostnames, packet contents and endpoint telemetry. SYN FLOODS AND CONNECTION EXHAUSTION A SYN flood sends many connection initiation requests without completing the handshake, consuming server or intermediary resources. SYN cookies, connection-rate controls, upstream filtering and adequate capacity can reduce impact. Connection exhaustion can also occur when attackers create many legitimate-looking sessions; rate limits, timeouts, connection pools and application-aware controls are useful defenses. TCP RESET AND UDP FLOODS Forged TCP RST packets can disrupt connections. UDP floods can consume bandwidth or service resources. Detection should consider baseline traffic, source diversity, destination ports, packet rates and whether the application is actually processing the traffic.

07

Part 7 — DNS, DHCP & NAT

Part 7 covers the services that make networks usable and the security issues that arise when they are abused.

STUDY NOTES

DNS The Domain Name System translates names into records such as A, AAAA, MX, NS, CNAME and PTR. An A record maps a name to an IPv4 address. An AAAA record maps a name to IPv6. MX identifies mail-exchange hosts. NS identifies authoritative name servers. PTR supports reverse lookup from an IP address to a name. CNAME provides an alias to another canonical name. DNS LOOKUPS A client may ask a recursive resolver to resolve a name. The resolver can query authoritative servers and cache the answer according to its TTL. DNS normally uses UDP 53 for many queries and TCP 53 for cases such as large responses, zone transfers or fallback behavior. Modern DNS technologies may also use encrypted transports such as DoH or DoT, depending on deployment. DNS SECURITY DNS cache poisoning, malicious redirection, domain hijacking, DNS amplification and DNS tunneling are examples of abuse. DNSSEC adds cryptographic validation to help authenticate signed DNS data. DNS tunneling can be indicated by long, random-looking subdomains, unusual encoding and high-frequency queries to one domain. Analysts should correlate DNS logs with endpoint and proxy activity. DHCP DHCP dynamically provides network configuration such as an IP address, subnet mask/prefix, default gateway and DNS servers. The common DORA process is Discover, Offer, Request, Acknowledge. A client broadcasts a Discover, servers may Offer configuration, the client Requests one offer and the selected server Acknowledges the lease. DHCP SECURITY DHCP starvation attempts to consume the available address pool by generating many lease requests. A rogue DHCP server can provide malicious gateway or DNS settings. Switch controls such as DHCP snooping can restrict which ports may send DHCP server responses and can create trusted bindings used by Dynamic ARP Inspection. NAT AND PAT Network Address Translation changes address information as traffic crosses a translation boundary. Source NAT (SNAT) changes the source address. Destination NAT (DNAT) changes the destination address. Port Address Translation (PAT), also called NAT overload, allows many private hosts to share a public IPv4 address by differentiating connections with source ports. Port forwarding an inbound connection to an internal server is a common DNAT use case. SECURITY CONSIDERATIONS NAT is not a complete security control. Firewalls, access controls and segmentation are still required. Analysts should distinguish the original client address from the translated address by correlating timestamps, source ports, NAT logs and connection identifiers.

08

Part 8 — Firewalls, ACLs, IDS/IPS, VPN & Zero Trust

Part 8 introduces the major network security controls used to prevent, detect and contain unwanted traffic.

STUDY NOTES

FIREWALLS A firewall enforces traffic policy between zones or interfaces. A simple packet filter can make decisions using source/destination addresses, protocol and ports. A stateful firewall also tracks connection state, allowing legitimate return traffic according to the established session. Next-generation firewalls may add application identification, user identity, TLS inspection, malware prevention and intrusion-prevention capabilities. ACLs Access Control Lists define permit and deny rules. In many common implementations, rules are processed top-down and the first matching rule is applied, followed by an implicit deny if no rule matches. The exact behavior depends on the platform. Security analysts should document rule order, object groups, zones, logging behavior and the business reason for each rule. IDS AND IPS An Intrusion Detection System (IDS) monitors traffic or telemetry and generates alerts. An Intrusion Prevention System (IPS) is commonly deployed inline and can block or modify traffic according to its detection policy. Detection engines can use signatures, protocol analysis, reputation, anomaly detection and behavioral indicators. False positives and false negatives are both operational concerns, so alerts should be investigated with context. VPN A Virtual Private Network creates a protected communication path across an untrusted network. IPsec commonly uses IKE for negotiation and uses UDP 500 for IKE; UDP 4500 is commonly used for NAT traversal. SSL/TLS-based VPNs and WireGuard are other approaches. VPN security depends on strong authentication, secure cryptography, patching, access controls and monitoring. NAC AND PROXIES Network Access Control can evaluate endpoint identity and posture before granting network access. Proxies mediate client/server communication and can enforce web policy, logging, malware inspection or access control. Both can be used as additional policy enforcement points rather than relying on a single perimeter firewall. ZERO TRUST Zero Trust is based on the principle of continuously verifying access rather than automatically trusting a user or device because it is inside a network boundary. Identity, device posture, least privilege, segmentation, strong authentication and continuous monitoring are common elements. DEFENSE IN DEPTH Defense in depth uses multiple independent or complementary controls. For example, segmentation can limit lateral movement; endpoint security can detect a compromised process; a firewall can restrict outbound communication; DNS security can block malicious domains; and SIEM correlation can alert the SOC. No single control should be treated as a complete defense.

09

Part 9 — Network Attacks & Defensive Thinking

Part 9 maps common attacks to the network layers and focuses on recognition, indicators and defensive controls.

STUDY NOTES

LAYER 7 — APPLICATION ATTACKS Phishing uses deceptive communication to influence a victim into revealing information, opening a malicious attachment or visiting a malicious site. SQL injection manipulates application input so that unintended database commands are executed. XSS injects script content into a page or response so that a victim's browser executes it. CSRF tricks an authenticated browser into sending an unwanted request. Command injection causes application input to influence operating-system command execution. Directory traversal attempts to access files outside the intended application directory. Brute-force attacks repeatedly try credentials; credential stuffing reuses credentials exposed from other breaches. DNS attacks can abuse resolution or DNS infrastructure. HTTP floods send large volumes of web requests to exhaust application or intermediary resources. LAYER 6 — PRESENTATION ATTACKS TLS downgrade attacks attempt to force a weaker protocol or cipher choice. Certificate attacks can involve invalid, fraudulent, compromised or incorrectly trusted certificates. Weak-encryption attacks exploit outdated algorithms, short keys or insecure configurations. Encoding-based filter evasion changes the representation of input to bypass simplistic security filters. LAYER 5 — SESSION ATTACKS Session hijacking steals or predicts a valid session token. Session fixation forces a victim to use a session identifier known to the attacker. Replay attacks reuse previously captured valid authentication or protocol messages. Defenses include secure cookies, TLS, session rotation, expiration, anti-CSRF controls and replay-resistant protocol design. LAYER 4 — TRANSPORT ATTACKS TCP SYN floods abuse the connection-establishment process. UDP floods generate large volumes of UDP traffic. Port scanning probes services to discover reachable ports. TCP reset injection forges RST packets to disrupt connections. Connection exhaustion consumes state or application resources with many concurrent connections. LAYER 3 — NETWORK ATTACKS IP spoofing forges source addresses. ICMP floods generate excessive diagnostic traffic. Smurf attacks historically abused ICMP broadcast behavior with a spoofed source. Routing attacks manipulate or inject routing information. IP fragmentation attacks exploit fragment handling or resource consumption. LAYER 2 — DATA LINK ATTACKS ARP spoofing/poisoning manipulates local IP-to-MAC mappings. MAC flooding attempts to overwhelm switch CAM tables. VLAN hopping attempts to cross VLAN boundaries through misconfiguration or trunk behavior. DHCP starvation exhausts address pools. Rogue DHCP servers provide unauthorized network configuration. Wireless deauthentication forces clients off an access point and can be abused for disruption or to facilitate other attacks. LAYER 1 — PHYSICAL ATTACKS Cable tapping attempts to observe physical communications. Hardware tampering changes or implants components. Device theft removes equipment from organizational control. Physical port access allows an unauthorized person to connect to a network. Signal jamming interferes with wireless or radio communication. DEFENSIVE THINKING For every attack, separate prevention, detection and response. Prevention reduces exposure; detection identifies indicators; response contains and recovers. Useful evidence includes firewall logs, DNS logs, DHCP leases, switch CAM tables, ARP tables, wireless-controller logs, endpoint telemetry, packet captures and authentication records. Avoid treating an attack name as proof that an incident occurred: validate the indicators and the surrounding context.

010

Part 10 — SOC Networking Tools, Monitoring, Wi-Fi & Cloud

Part 10 connects networking knowledge to SOC operations, packet analysis, cloud networking, logging and monitoring.

STUDY NOTES

PACKET ANALYSIS Wireshark provides a graphical packet-analysis workflow. Analysts can inspect Ethernet, ARP, IP, TCP, UDP, DNS, HTTP and many other protocols. tcpdump provides command-line packet capture and filtering. Zeek generates structured network-security telemetry from traffic rather than simply presenting every packet. Packet analysis is most useful when combined with timestamps, endpoint information and application context. COMMON INVESTIGATION QUESTIONS When examining a suspicious connection, identify the source and destination IPs, source and destination ports, protocol, TCP flags, DNS name if available, packet timing, byte counts and whether the session completed. Look for retransmissions, unusual connection rates, unexpected services, long DNS labels, repeated authentication attempts, unexpected outbound destinations and traffic crossing a boundary it should not cross. NETFLOW AND FLOW TELEMETRY NetFlow-style data mainly contains flow metadata such as source and destination IPs, ports, protocol and packet/byte counts. It is not equivalent to a full packet capture. Flow records are valuable for identifying communication patterns, scanning, beaconing, large transfers and unusual east-west traffic while using less storage than complete payload captures. LOGGING AND MONITORING Important network logs include firewall events, VPN authentication, DNS requests, DHCP assignments, proxy activity, IDS/IPS alerts, router and switch events and wireless-controller logs. Windows Event Logs, Sysmon, Syslog, ELK/Elastic, Graylog, Splunk, Microsoft Sentinel and Wazuh can support centralized monitoring. Correlation is important because one event may be benign while a sequence across multiple sources can indicate compromise. WIRELESS NETWORKING Wireless LANs use access points and radio communication. WPA2 and WPA3 provide modern security options. WPA3-Personal uses SAE (Simultaneous Authentication of Equals). An evil twin is a rogue access point designed to imitate a legitimate SSID and attract clients. Wireless deauthentication can disrupt clients. Defenses include strong authentication, protected management frames where supported, segmentation, secure configuration, monitoring for rogue APs and avoiding legacy protocols such as WEP. CLOUD NETWORKING Cloud networking commonly includes virtual networks/VPCs, subnets, route tables, security groups, network ACLs, load balancers, gateways and private endpoints. A Security Group in AWS is a stateful, instance-level virtual firewall with allow rules; a Network ACL is a stateless subnet-level control with ordered allow/deny behavior. Cloud security also depends on IAM, logging and least privilege. AWS CloudTrail, Azure Monitor and Google Cloud Logging are examples of cloud logging services. NETWORKING TOOLS FOR CYBERSECURITY Nmap is used for authorized host and service discovery. Wireshark and tcpdump support packet analysis. Cisco Packet Tracer and GNS3 are useful for learning and simulating network configurations. Snort and Suricata provide IDS/IPS capabilities. Zeek provides network telemetry. PowerShell, Bash and Python can automate repetitive analysis. Regex helps extract indicators from logs. Always use scanning and testing tools only against systems for which you have authorization. CYBERSECURITY CONCEPTS The CIA triad describes Confidentiality, Integrity and Availability. Defense in depth uses multiple layers of controls. Least privilege gives users and services only the permissions required. Segmentation limits communication paths and blast radius. Zero Trust requires verification rather than implicit trust. An IOC (Indicator of Compromise) is observable evidence associated with malicious activity, such as a hash, domain or IP. An IOA (Indicator of Attack) focuses on behavior suggesting an attack, such as suspicious process execution or credential-access activity. SOC WORKFLOW A network alert should be validated, enriched and correlated before escalation. A practical workflow is: identify the asset and owner; determine source, destination and protocol; compare with normal behavior; check DNS and endpoint context; inspect relevant packets or flows; determine whether a control blocked or allowed the activity; contain when appropriate; preserve evidence; and document the timeline. Networking fundamentals turn raw alerts into evidence that can support a defensible incident decision.

Study progress is saved to your account. The final exam is Part 11.

PART 11 // FINAL EXAM

Loading exam…