Module objectives
Networking
Almost every attack and every defence has to cross a network, so reading network evidence is a skill the rest of security rests on. This module builds it from the models up, then through the attacks that abuse trusting protocols and the controls that contain them.
By the end you will be able to:
- Place a header, a protocol or an attack at the right OSI layer, and follow data through encapsulation.
- Reason about TCP versus UDP, read a three-way handshake, and size a subnet from its CIDR block by hand.
- Recognise sniffing, spoofing, man-in-the-middle and the volumetric, protocol and application classes of DoS from the evidence.
- Tell ARP spoofing, SYN floods and DNS spoofing apart from the artifact in front of you.
- Choose between firewall generations, tell an IDS from an IPS, say what a VPN actually protects, and explain why segmentation contains blast radius.
The exam is practical: ten pieces of network evidence to read and classify, graded in your browser. Get seven of ten and the certificate is yours.