I1: Networking for Defenders
Move beyond basic network vocabulary and learn how defenders organize, monitor, segment, analyze, and document fictional network activity.
Module Snapshot
Intermediate
Track
I1 of 17
Module
8
Lessons
25 questions
Module test
Intermediate begins here
This module expects Beginner networking knowledge and adds subnet context, service review, firewall logic, segmentation, diagrams, and evidence-based analysis.
Main Question
How do defenders understand network activity well enough to protect systems and make safe decisions?
Students will connect architecture, address boundaries, services, access rules, logs, and approved purpose instead of judging a connection from one alert or one technical detail.
Safety Boundary
Every address, domain, network, firewall rule, log, diagram, device, user, and organization in this module is fictional. Students never scan, probe, test, or change real systems.
Professional Workflow
Observe, Correlate, Compare, Decide, and Document
Observe
Collect fictional diagrams, address records, service inventories, firewall rules, and network logs.
Correlate
Connect sources, destinations, users, devices, ports, services, and timestamps.
Compare
Check activity against expected architecture, approved changes, baselines, and business purpose.
Decide
Choose a proportionate defensive action and state what is confirmed, likely, or uncertain.
Document
Record evidence, impact, ownership, recommendation, limitations, and follow-up.
Learning Objectives
What Students Will Be Able to Do
Use network models to organize defensive evidence and explain where controls operate.
Interpret fictional IP addresses, subnet boundaries, ports, protocols, and services.
Connect DNS and DHCP records with devices, users, destinations, and timestamps.
Review firewall access rules using source, destination, service, direction, purpose, and least privilege.
Explain how segmentation and trust boundaries reduce unnecessary access and possible spread.
Read safe network diagrams and identify monitoring points, control gaps, and unclear assumptions.
Module Path
Eight Intermediate Lessons
Each lesson includes professional hooks, fictional technical evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.
I1.1
Lesson 1
Network Models and Defensive Thinking
Compare layered network models and use them to organize defensive evidence, controls, and troubleshooting decisions.
Defensive Lab
Map a fictional connection across layers and identify where monitoring and protection belong.
I1.2
Lesson 2
IP Addressing, Subnets, and Network Boundaries
Review IPv4 structure, private addressing, subnet concepts, network boundaries, and how defenders interpret address context.
Defensive Lab
Classify fictional addresses and explain which systems share or cross a network boundary.
I1.3
Lesson 3
Ports, Protocols, and Services
Connect common ports and protocols with services, expected behavior, exposure, and defensive review.
Defensive Lab
Analyze a fictional service inventory and identify unnecessary, expected, and review-required services.
I1.4
Lesson 4
DNS, DHCP, and Common Network Services
Understand how DNS, DHCP, and other core services support networks and create useful defensive evidence.
Defensive Lab
Correlate fictional DNS and DHCP records with users, devices, destinations, and timestamps.
I1.5
Lesson 5
Firewalls and Network Access Rules
Interpret allow and deny logic, traffic direction, source, destination, service, purpose, and change control.
Defensive Lab
Review fictional firewall rules and recommend safer, narrower access decisions.
I1.6
Lesson 6
Network Segmentation Concepts
Learn how zones, trust boundaries, role separation, and restricted pathways can reduce unnecessary access and incident spread.
Defensive Lab
Redesign a fictional flat network into safer defensive zones.
I1.7
Lesson 7
Reading Safe Network Diagrams
Read symbols, labels, trust boundaries, traffic paths, security controls, and evidence points in fictional diagrams.
Defensive Lab
Evaluate a fictional network diagram for missing labels, unclear ownership, and defensive blind spots.
I1.8
Lesson 8
Network Defense Analysis Lab
Combine addressing, services, DNS, DHCP, firewall rules, segmentation, logs, and diagrams into one defensive case.
Defensive Lab
Complete a multi-source fictional network investigation and write an evidence-based recommendation.
Fake Evidence Preview
How Intermediate Network Evidence Connects
09:12:08
DHCP
Device student-lab-17 receives 10.24.18.44
Connects the fictional device to an address during the review window.
09:14:31
DNS
Device requests updates.training-cloud.test
Provides destination-name context but does not prove the activity is safe.
09:14:33
Firewall
Outbound HTTPS connection allowed
Shows the rule decision, direction, service, and destination context.
09:16:02
Inventory
Approved learning application update window begins
Business context may explain the new destination and timing.
Portfolio Outcome
Network Defense Analysis Report
Students will build a fictional report containing a labeled network diagram, address and service context, evidence timeline, firewall review, segmentation recommendation, uncertainty, and next actions.
Module Assessment
25-Question I1 Module Test
The test will cover models, subnet concepts, ports, protocols, services, DNS, DHCP, firewalls, segmentation, diagrams, and evidence-based network decisions. Answers stay hidden until submission.
Open Module Test