Network and Endpoint Security Foundations Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-041
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Network and endpoint security failures rarely begin with a single dramatic breach. They emerge through exposed services, unmanaged laptops, weak segmentation, inconsistent patching, excessive administrative rights, and alerts that are never investigated. IT professionals responsible for networks, devices, and operational resilience need to recognise how these weaknesses connect, prioritise practical controls, and explain risk in terms that technical teams and managers can act on. This course provides the security grounding needed to reduce attack surface across corporate networks and user endpoints without treating every issue as a separate technology problem.

Participants learn how to map network assets and data flows, apply secure network design principles, harden Windows and Linux endpoints, and select preventative and detective controls. The course covers network segmentation, firewalls, secure remote access, DNS and email protections, vulnerability and patch management, endpoint detection and response, log collection, alert triage, and incident containment. Participants work with the NIST Cybersecurity Framework 2.0 and CIS Controls v8 to translate technical findings into a prioritised improvement plan.

Delivery combines instructor-led technical explanation with guided analysis of realistic network diagrams, endpoint configurations, packet captures, event logs, and security alerts. In a controlled lab environment, participants investigate suspicious activity using Wireshark and Microsoft Defender for Endpoint concepts, then decide how to contain and recover from an endpoint-led intrusion. Each participant leaves with a completed network and endpoint security baseline: an asset and exposure map, control-gap assessment, incident response actions, and a 90-day improvement roadmap suitable for adapting to their own environment.

The course is well suited to infrastructure, support, systems, and security professionals who already work with business networks or endpoints and now need a structured security operating model. It also gives technical team leads a sound basis for reviewing security priorities, control implementation, and operational evidence.

Course objectives

By the end of this course, participants will be able to:

  • Map network assets, trust boundaries, critical data flows, and externally exposed services using an attack-surface worksheet
  • Apply network segmentation principles to design VLAN, firewall, and least-privilege access rules for a business environment
  • Harden Windows and Linux endpoints using CIS Controls v8-aligned configuration, patching, and privilege-management practices
  • Configure and assess endpoint protection controls including antivirus, endpoint detection and response, and device encryption
  • Analyse packet captures in Wireshark to identify suspicious DNS, web, and lateral-movement traffic
  • Triage endpoint and network security alerts using severity, scope, evidence, and containment decision criteria
  • Conduct a vulnerability remediation prioritisation exercise using asset criticality, exploitability, and control gaps
  • Produce a 90-day network and endpoint security improvement roadmap aligned to NIST Cybersecurity Framework 2.0 functions

Benefits of attending

For you

  • Build the confidence to identify whether a network or endpoint weakness requires urgent containment, routine remediation, or further investigation
  • Gain practical experience interpreting packet captures, endpoint alerts, and security logs rather than relying only on theoretical security terminology
  • Create evidence-based security recommendations that connect technical controls to business assets and operational risk
  • Develop a reusable endpoint-hardening and network-control checklist for infrastructure or security responsibilities
  • Strengthen readiness for roles involving security operations, infrastructure security, endpoint management, or technical risk assessment

For your organisation

  • Establish a more consistent baseline for endpoint configuration, patching, encryption, malware protection, and privileged access
  • Reduce opportunities for lateral movement by improving asset visibility, segmentation decisions, and access-control rules
  • Improve alert handling by giving staff a shared method for triage, evidence gathering, escalation, and containment
  • Produce a prioritised 90-day remediation plan that focuses security effort on critical assets and realistic control gaps
  • Create stronger alignment between network, infrastructure, support, and security teams through common frameworks and terminology

Target competencies

Attack surface mappingNetwork segmentation designEndpoint hardeningPacket capture analysisAlert triageControl gap prioritisation

Who should attend

  • Network Administrators — who configure connectivity and need to reduce exposure from services, remote access, and weak segmentation
  • Systems Administrators — who manage Windows or Linux estates and need repeatable endpoint hardening and patching practices
  • IT Support Leads — who oversee device deployment, user access, and escalation of suspected endpoint compromises
  • Junior Security Analysts — who need practical grounding in network telemetry, endpoint alerts, and incident containment
  • Infrastructure Engineers — who design or maintain core platforms and must embed security controls into operational changes
  • IT Managers — who prioritise security investment and need to assess control gaps, ownership, and remediation plans

Requirements and prerequisites

Participants should be comfortable using a Windows workstation and navigating basic IT administration concepts, including IP addresses, subnets, DNS, user accounts, operating-system updates, and client-server services. Familiarity with a firewall interface, Active Directory or Entra ID, Windows Event Viewer, or Linux command-line navigation is useful but not essential. Attendees should have at least six months of experience in IT support, systems, network, or infrastructure work. Prior cyber security certification, programming ability, penetration-testing experience, and prior use of Wireshark or Microsoft Defender for Endpoint are not required. A complete beginner to IT should first gain basic networking and operating-system administration knowledge.

Training methodology

The instructor uses short technical briefings to establish each control area, followed by guided labs based on a simulated corporate network and endpoint estate. Participants inspect network diagrams, review firewall and endpoint configurations, analyse Wireshark packet captures, and triage realistic endpoint alerts. Small-group workshops require participants to justify containment and remediation choices against asset criticality and operational constraints. Daily debriefs connect lab decisions to NIST Cybersecurity Framework 2.0 and CIS Controls v8. The final session converts findings into an individual, workplace-ready 90-day security improvement plan.

Course outline

Day 1: Security architecture and attack surface

  • Network and endpoint attack paths in corporate environments
  • NIST Cybersecurity Framework 2.0 functions and profiles
  • CIS Controls v8 safeguards for enterprise IT
  • Asset inventory, ownership, and criticality classification
  • Data-flow mapping and trust-boundary identification
  • External exposure discovery for services and remote access
  • Risk rating using likelihood, impact, and existing controls

Workshop: Participants create an asset, data-flow, trust-boundary, and exposure map for a simulated organisation, then identify its five highest-priority security gaps.

Day 2: Securing network access and traffic

  • IPv4 addressing, routing, and security-relevant network services
  • VLAN segmentation and zone-based network design
  • Firewall rule design, review, and least-privilege principles
  • Secure remote access using VPN, MFA, and privileged administration paths
  • DNS security, secure web gateways, and email authentication controls
  • Network access control and device admission concepts
  • Wireshark filters for DNS, HTTP, TLS, and suspicious connections

Workshop: Participants analyse a packet capture in Wireshark and redesign a flat-network diagram into segmented zones with documented firewall rules.

Day 3: Endpoint hardening and vulnerability control

  • Endpoint attack surface across Windows, Linux, and mobile devices
  • Secure configuration baselines and CIS Benchmarks concepts
  • Patch management workflows and vulnerability remediation windows
  • Privilege management, local administrator control, and least privilege
  • Disk encryption, secure boot, and device health controls
  • Application allowlisting, browser hardening, and macro restrictions
  • Endpoint protection platforms and Microsoft Defender for Endpoint capabilities

Workshop: Participants assess a workstation build against an endpoint-hardening checklist and produce a remediation sequence for its configuration and patching gaps.

Day 4: Detection, triage, and incident containment

  • Log sources from endpoints, firewalls, DNS, identity systems, and proxies
  • Security event normalisation and correlation concepts
  • Microsoft Defender for Endpoint alert investigation workflow
  • Indicators of compromise and evidence preservation
  • Alert severity, false-positive assessment, and case prioritisation
  • Endpoint isolation, credential reset, and network containment actions
  • Incident communication, escalation, and recovery decision records

Workshop: Participants investigate a simulated phishing-to-endpoint compromise, document evidence, classify scope, and produce a containment and escalation decision record.

Day 5: Control assurance and improvement planning

  • Security control testing and evidence collection
  • Vulnerability prioritisation using exploitability and asset criticality
  • Network and endpoint security metrics for management reporting
  • Exception management and compensating controls
  • Third-party device and remote-worker security considerations
  • 90-day remediation roadmap design and control ownership
  • Security improvement review against NIST Cybersecurity Framework 2.0

Workshop: Participants consolidate their findings into a network and endpoint security baseline, including prioritised actions, owners, measures, and a 90-day improvement roadmap.

Tools & standards covered

Wireshark, Microsoft Defender for Endpoint, NIST Cybersecurity Framework 2.0, CIS Controls v8

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand basic IP networking, DNS, user accounts, operating-system updates, and everyday IT administration. You do not need prior cyber security certification, scripting expertise, penetration-testing experience, or previous use of Wireshark or Microsoft Defender for Endpoint.

For classroom delivery, a laptop is recommended if your organisation permits it; live online participants need a reliable computer, browser, and stable internet connection. Lab materials, sample logs, packet captures, network diagrams, and guided tool exercises are provided in the training environment.

No. It is designed for network, systems, infrastructure, and support professionals as well as early-career security analysts. The focus is on controls and operational decisions that these teams make together, rather than specialist offensive security techniques.

This course teaches how to reduce exposure, harden endpoints, monitor activity, and respond to incidents in an operational environment. It does not focus on exploiting systems, writing attack scripts, or conducting a formal penetration test.

The asset mapping, segmentation review, endpoint-hardening checklist, alert-triage method, and remediation prioritisation model can be applied to an existing estate immediately. Participants are encouraged to use their own environment as the reference point when building the final 90-day roadmap.

You leave with a completed security baseline containing an asset and exposure map, identified control gaps, endpoint and network remediation actions, and an incident containment record. The final 90-day roadmap provides a structured document for discussing priorities, ownership, and investment with managers.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Tenable Nessus Professional Vulnerability Assessment Training Course

Vulnerability assessment programmes often fail not because organisations lack a scanner, but because scan scope is incomplete, credentials a…

5 Days Certificate

NIST Cybersecurity Framework Implementation Training Course

Organisations often have security controls, policies, audit findings and risk registers in separate places, yet cannot clearly show how thos…

5 Days Certificate

Kali Linux Penetration Testing Techniques Training Course

Security teams need evidence-based answers to practical questions: which systems are exposed, how an attacker could move from an initial foo…

5 Days Certificate

COBIT 2019 Cyber Risk Governance Training Course

Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …