High School IntermediateModule I1 of 17Defensive Only

I1: Networking for Defenders

Move beyond basic network vocabulary and learn how defenders organize, monitor, segment, analyze, and document fictional network activity.

Module Snapshot

Intermediate

Track

I1 of 17

Module

8

Lessons

25 questions

Module test

Intermediate begins here

This module expects Beginner networking knowledge and adds subnet context, service review, firewall logic, segmentation, diagrams, and evidence-based analysis.

Main Question

How do defenders understand network activity well enough to protect systems and make safe decisions?

Students will connect architecture, address boundaries, services, access rules, logs, and approved purpose instead of judging a connection from one alert or one technical detail.

Safety Boundary

Every address, domain, network, firewall rule, log, diagram, device, user, and organization in this module is fictional. Students never scan, probe, test, or change real systems.

Professional Workflow

Observe, Correlate, Compare, Decide, and Document

1

Observe

Collect fictional diagrams, address records, service inventories, firewall rules, and network logs.

2

Correlate

Connect sources, destinations, users, devices, ports, services, and timestamps.

3

Compare

Check activity against expected architecture, approved changes, baselines, and business purpose.

4

Decide

Choose a proportionate defensive action and state what is confirmed, likely, or uncertain.

5

Document

Record evidence, impact, ownership, recommendation, limitations, and follow-up.

Learning Objectives

What Students Will Be Able to Do

Use network models to organize defensive evidence and explain where controls operate.

Interpret fictional IP addresses, subnet boundaries, ports, protocols, and services.

Connect DNS and DHCP records with devices, users, destinations, and timestamps.

Review firewall access rules using source, destination, service, direction, purpose, and least privilege.

Explain how segmentation and trust boundaries reduce unnecessary access and possible spread.

Read safe network diagrams and identify monitoring points, control gaps, and unclear assumptions.

Module Path

Eight Intermediate Lessons

Each lesson includes professional hooks, fictional technical evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.

I1.1

Lesson 1

Network Models and Defensive Thinking

Compare layered network models and use them to organize defensive evidence, controls, and troubleshooting decisions.

Defensive Lab

Map a fictional connection across layers and identify where monitoring and protection belong.

Open →

I1.2

Lesson 2

IP Addressing, Subnets, and Network Boundaries

Review IPv4 structure, private addressing, subnet concepts, network boundaries, and how defenders interpret address context.

Defensive Lab

Classify fictional addresses and explain which systems share or cross a network boundary.

Open →

I1.3

Lesson 3

Ports, Protocols, and Services

Connect common ports and protocols with services, expected behavior, exposure, and defensive review.

Defensive Lab

Analyze a fictional service inventory and identify unnecessary, expected, and review-required services.

Open →

I1.4

Lesson 4

DNS, DHCP, and Common Network Services

Understand how DNS, DHCP, and other core services support networks and create useful defensive evidence.

Defensive Lab

Correlate fictional DNS and DHCP records with users, devices, destinations, and timestamps.

Open →

I1.5

Lesson 5

Firewalls and Network Access Rules

Interpret allow and deny logic, traffic direction, source, destination, service, purpose, and change control.

Defensive Lab

Review fictional firewall rules and recommend safer, narrower access decisions.

Open →

I1.6

Lesson 6

Network Segmentation Concepts

Learn how zones, trust boundaries, role separation, and restricted pathways can reduce unnecessary access and incident spread.

Defensive Lab

Redesign a fictional flat network into safer defensive zones.

Open →

I1.7

Lesson 7

Reading Safe Network Diagrams

Read symbols, labels, trust boundaries, traffic paths, security controls, and evidence points in fictional diagrams.

Defensive Lab

Evaluate a fictional network diagram for missing labels, unclear ownership, and defensive blind spots.

Open →

I1.8

Lesson 8

Network Defense Analysis Lab

Combine addressing, services, DNS, DHCP, firewall rules, segmentation, logs, and diagrams into one defensive case.

Defensive Lab

Complete a multi-source fictional network investigation and write an evidence-based recommendation.

Open →

Fake Evidence Preview

How Intermediate Network Evidence Connects

09:12:08

DHCP

Device student-lab-17 receives 10.24.18.44

Connects the fictional device to an address during the review window.

09:14:31

DNS

Device requests updates.training-cloud.test

Provides destination-name context but does not prove the activity is safe.

09:14:33

Firewall

Outbound HTTPS connection allowed

Shows the rule decision, direction, service, and destination context.

09:16:02

Inventory

Approved learning application update window begins

Business context may explain the new destination and timing.

A strong conclusion uses the records together: address assignment, destination name, access decision, approved application, timing, and expected purpose.

Portfolio Outcome

Network Defense Analysis Report

Students will build a fictional report containing a labeled network diagram, address and service context, evidence timeline, firewall review, segmentation recommendation, uncertainty, and next actions.

Module Assessment

25-Question I1 Module Test

The test will cover models, subnet concepts, ports, protocols, services, DNS, DHCP, firewalls, segmentation, diagrams, and evidence-based network decisions. Answers stay hidden until submission.

Open Module Test
← Intermediate TrackStart I1.1 →