Defensive Security

CA402: Network Security

Course authored by:

Drinor Selmanaj, Perparim Mjeku, Rinor Shehu, Altin Gashi

35 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

23 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate level

Developing practical skills and deepening understanding of core concepts

Prerequisite

  • CA401 Linux Operations

Course Overview

Every attack travels through a network — and most defenses fail because operators don't understand what they're protecting. This course builds practical capability in securing modern network environments from the ground up, starting with core architectures, protocols, and models including OSI and TCP/IP. You move into applied defense covering segmentation, firewalls, IDS/IPS, and access control, and analyze real-world attacks including ARP poisoning, DNS spoofing, and DHCP abuse. Practical work includes VPNs, traffic analysis, logging, and SIEM integration. By the end, you can secure and defend networks under real-world conditions.

What You’ll Learn

* Understand network fundamentals including OSI, TCP/IP, IP addressing, and subnetting
* Design secure network architectures using segmentation, DMZ, and defense-in-depth
* Configure firewalls, IDS/IPS, and access control policies
* Detect and mitigate attacks including ARP poisoning, DNS spoofing, and DHCP abuse
* Analyze network traffic and integrate logging with SIEM platforms

Business Takeaways

* Strengthen network infrastructure against external and internal threats
* Improve visibility through logging, monitoring, and telemetry
* Enable secure remote access through VPN and access control policies
* Detect and respond to threats faster using IDS/IPS and SIEM integration

Syllabus: 6 Sections to Transformation

The CA402 program takes you deep into how networks actually function and how they are secured, attacked, and defended in real environments. You move from core connectivity concepts to designing architectures, enforcing controls, and monitoring live network activity.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: NETWORK BASICS & MODELS

Build a deep understanding of how networks operate, from devices to communication models.
Grasp how data flows across layers and why architecture decisions impact security.

TOPICS COVERED

  • Network devices (router, switch, hub, bridge, NIC).
  • LAN, WAN, MAN, PAN network types.
  • OSI vs TCP/IP models and layer functions.
  • Encapsulation and decapsulation process.
  • IP addressing basics and communication flow.

LABS

  • Cisco Packet Tracer
  • Router Basics
  • Calculating IPs and Subnets
  • ARP Tables

section 2

INFRASTRUCTURE: ETHERNET & NETWORK PROTOCOLS

Shift into how networks actually transmit data and communicate using protocols.
Explore addressing, routing, and the mechanics behind modern connectivity.

TOPICS COVERED

  • Ethernet standards, frames, and switching.
  • Cable types and network media.
  • Common protocols (HTTP, DNS, FTP, SMTP).
  • TCP vs UDP behavior and use cases.
  • NAT, PAT, and subnetting fundamentals.

LABS

  • Cisco Packet Tracer – Subnetting
  • Cisco Packet Tracer – DHCP & HTTP
  • Cisco Packet Tracer – DNS, Web, VLANs
  • Wireshark

section 3

ARCHITECTURE: SEGMENTATION & NETWORK DEFENSE DESIGN

Move into structured defense by designing secure network layouts and boundaries.
Understand how segmentation limits attacker movement and reduces risk.

TOPICS COVERED

  • Defense-in-depth architecture.
  • DMZ design and traffic flow.
  • Trust boundaries and segmentation strategies.
  • East-West vs North-South traffic.
  • Placement of security controls.

LABS

  • Kismet Tool
  • Network Segmentation Design & Implementation
  • DMZ Configuration & Traffic Flow Analysis

section 4

PROTECTION: NETWORK SECURITY CONTROLS & ACCESS

Dive into defensive mechanisms that actively protect and monitor networks.
Learn how attackers exploit protocols and how defenders detect and stop them.

TOPICS COVERED

  • DHCP, ARP, and DNS attacks (spoofing, poisoning).
  • VPN security and remote access risks.
  • NAC and 802.1X authentication.
  • VLANs, trunking, and segmentation controls.
  • Detection, telemetry, and response basics.

LABS

  • ARP Poisoning
  • DHCP Spoofing
  • DNS Spoofing

section 5

ENFORCEMENT: FIREWALLS, LOGGING & DETECTION

Focus on visibility and control how defenders enforce policies and detect threats.
Combine logging, monitoring, and intrusion detection into a unified defense strategy.

TOPICS COVERED

  • Firewall types and rule design.
  • Firewall misconfigurations and auditing.
  • Logging and centralized telemetry (Syslog).
  • NetFlow, packet capture, and monitoring.
  • IDS vs IPS and alert handling.

LABS

  • Configuring IPTABLES
  • Configuring UFW
  • Firewall Rule Testing & Log Correlation
  • Fail2ban

section 6

OPERATIONS: MONITORING, TROUBLESHOOTING & WIRELESS SECURITY

Bring everything together through real-world operations and incident handling.
Develop the ability to detect, investigate, and respond to network threats effectively.

TOPICS COVERED

  • Network troubleshooting using OSI model.
  • Wireshark packet analysis.
  • Monitoring tools (Nagios, SNMP, Netstat).
  • Wireless security (WEP, WPA2, WPA3).
  • Wireless attacks (deauth, rogue AP, evil twin).
  • Incident response and playbooks.

LABS

  • Cracking WiFi Passwords
  • VPS PIN Attack with Bully
  • DDOS Tools
  • Network Troubleshooting Scenario
  • Wireless Attack & Defense Simulation

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

How do attackers compromise networks in real-world scenarios?

Attackers exploit weaknesses across network layers. Common techniques include ARP poisoning to intercept internal traffic, DNS spoofing to redirect users to malicious servers, DHCP attacks to manipulate network configurations, and lateral movement after initial access.

You will develop hands-on skills in designing secure network architectures (DMZ, segmentation, VLANs), configuring and auditing firewalls, monitoring traffic using logs, NetFlow, and packet capture, using IDS/IPS for detection, and responding to network incidents with structured workflows.

Without segmentation, an attacker who compromises one system can move freely across the network. Segmentation techniques like DMZs and VLANs create controlled boundaries, limiting lateral movement and protecting critical assets.

Detection relies on analyzing network telemetry, including firewall and system logs, traffic flow data such as NetFlow and sFlow, packet captures through PCAP analysis, and IDS/IPS alerts.

Frequent weaknesses include overly permissive firewall rules, lack of outbound (egress) filtering, misconfigured VPN access with split tunneling risks, weak monitoring and logging, and poor network segmentation.