Network and Endpoint Security Foundations Training Course
| Course code | SD-CS-041 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Network and endpoint security failures rarely begin with a single dramatic breach. They emerge through exposed services, unmanaged laptops, weak segmentation, inconsistent patching, excessive administrative rights, and alerts that are never investigated. IT professionals responsible for networks, devices, and operational resilience need to recognise how these weaknesses connect, prioritise practical controls, and explain risk in terms that technical teams and managers can act on. This course provides the security grounding needed to reduce attack surface across corporate networks and user endpoints without treating every issue as a separate technology problem.
Participants learn how to map network assets and data flows, apply secure network design principles, harden Windows and Linux endpoints, and select preventative and detective controls. The course covers network segmentation, firewalls, secure remote access, DNS and email protections, vulnerability and patch management, endpoint detection and response, log collection, alert triage, and incident containment. Participants work with the NIST Cybersecurity Framework 2.0 and CIS Controls v8 to translate technical findings into a prioritised improvement plan.
Delivery combines instructor-led technical explanation with guided analysis of realistic network diagrams, endpoint configurations, packet captures, event logs, and security alerts. In a controlled lab environment, participants investigate suspicious activity using Wireshark and Microsoft Defender for Endpoint concepts, then decide how to contain and recover from an endpoint-led intrusion. Each participant leaves with a completed network and endpoint security baseline: an asset and exposure map, control-gap assessment, incident response actions, and a 90-day improvement roadmap suitable for adapting to their own environment.
The course is well suited to infrastructure, support, systems, and security professionals who already work with business networks or endpoints and now need a structured security operating model. It also gives technical team leads a sound basis for reviewing security priorities, control implementation, and operational evidence.
Course objectives
By the end of this course, participants will be able to:
- Map network assets, trust boundaries, critical data flows, and externally exposed services using an attack-surface worksheet
- Apply network segmentation principles to design VLAN, firewall, and least-privilege access rules for a business environment
- Harden Windows and Linux endpoints using CIS Controls v8-aligned configuration, patching, and privilege-management practices
- Configure and assess endpoint protection controls including antivirus, endpoint detection and response, and device encryption
- Analyse packet captures in Wireshark to identify suspicious DNS, web, and lateral-movement traffic
- Triage endpoint and network security alerts using severity, scope, evidence, and containment decision criteria
- Conduct a vulnerability remediation prioritisation exercise using asset criticality, exploitability, and control gaps
- Produce a 90-day network and endpoint security improvement roadmap aligned to NIST Cybersecurity Framework 2.0 functions
Benefits of attending
For you
- Build the confidence to identify whether a network or endpoint weakness requires urgent containment, routine remediation, or further investigation
- Gain practical experience interpreting packet captures, endpoint alerts, and security logs rather than relying only on theoretical security terminology
- Create evidence-based security recommendations that connect technical controls to business assets and operational risk
- Develop a reusable endpoint-hardening and network-control checklist for infrastructure or security responsibilities
- Strengthen readiness for roles involving security operations, infrastructure security, endpoint management, or technical risk assessment
For your organisation
- Establish a more consistent baseline for endpoint configuration, patching, encryption, malware protection, and privileged access
- Reduce opportunities for lateral movement by improving asset visibility, segmentation decisions, and access-control rules
- Improve alert handling by giving staff a shared method for triage, evidence gathering, escalation, and containment
- Produce a prioritised 90-day remediation plan that focuses security effort on critical assets and realistic control gaps
- Create stronger alignment between network, infrastructure, support, and security teams through common frameworks and terminology
Target competencies
Who should attend
- Network Administrators — who configure connectivity and need to reduce exposure from services, remote access, and weak segmentation
- Systems Administrators — who manage Windows or Linux estates and need repeatable endpoint hardening and patching practices
- IT Support Leads — who oversee device deployment, user access, and escalation of suspected endpoint compromises
- Junior Security Analysts — who need practical grounding in network telemetry, endpoint alerts, and incident containment
- Infrastructure Engineers — who design or maintain core platforms and must embed security controls into operational changes
- IT Managers — who prioritise security investment and need to assess control gaps, ownership, and remediation plans
Requirements and prerequisites
Participants should be comfortable using a Windows workstation and navigating basic IT administration concepts, including IP addresses, subnets, DNS, user accounts, operating-system updates, and client-server services. Familiarity with a firewall interface, Active Directory or Entra ID, Windows Event Viewer, or Linux command-line navigation is useful but not essential. Attendees should have at least six months of experience in IT support, systems, network, or infrastructure work. Prior cyber security certification, programming ability, penetration-testing experience, and prior use of Wireshark or Microsoft Defender for Endpoint are not required. A complete beginner to IT should first gain basic networking and operating-system administration knowledge.
Training methodology
The instructor uses short technical briefings to establish each control area, followed by guided labs based on a simulated corporate network and endpoint estate. Participants inspect network diagrams, review firewall and endpoint configurations, analyse Wireshark packet captures, and triage realistic endpoint alerts. Small-group workshops require participants to justify containment and remediation choices against asset criticality and operational constraints. Daily debriefs connect lab decisions to NIST Cybersecurity Framework 2.0 and CIS Controls v8. The final session converts findings into an individual, workplace-ready 90-day security improvement plan.
Course outline
Day 1: Security architecture and attack surface
- Network and endpoint attack paths in corporate environments
- NIST Cybersecurity Framework 2.0 functions and profiles
- CIS Controls v8 safeguards for enterprise IT
- Asset inventory, ownership, and criticality classification
- Data-flow mapping and trust-boundary identification
- External exposure discovery for services and remote access
- Risk rating using likelihood, impact, and existing controls
Workshop: Participants create an asset, data-flow, trust-boundary, and exposure map for a simulated organisation, then identify its five highest-priority security gaps.
Day 2: Securing network access and traffic
- IPv4 addressing, routing, and security-relevant network services
- VLAN segmentation and zone-based network design
- Firewall rule design, review, and least-privilege principles
- Secure remote access using VPN, MFA, and privileged administration paths
- DNS security, secure web gateways, and email authentication controls
- Network access control and device admission concepts
- Wireshark filters for DNS, HTTP, TLS, and suspicious connections
Workshop: Participants analyse a packet capture in Wireshark and redesign a flat-network diagram into segmented zones with documented firewall rules.
Day 3: Endpoint hardening and vulnerability control
- Endpoint attack surface across Windows, Linux, and mobile devices
- Secure configuration baselines and CIS Benchmarks concepts
- Patch management workflows and vulnerability remediation windows
- Privilege management, local administrator control, and least privilege
- Disk encryption, secure boot, and device health controls
- Application allowlisting, browser hardening, and macro restrictions
- Endpoint protection platforms and Microsoft Defender for Endpoint capabilities
Workshop: Participants assess a workstation build against an endpoint-hardening checklist and produce a remediation sequence for its configuration and patching gaps.
Day 4: Detection, triage, and incident containment
- Log sources from endpoints, firewalls, DNS, identity systems, and proxies
- Security event normalisation and correlation concepts
- Microsoft Defender for Endpoint alert investigation workflow
- Indicators of compromise and evidence preservation
- Alert severity, false-positive assessment, and case prioritisation
- Endpoint isolation, credential reset, and network containment actions
- Incident communication, escalation, and recovery decision records
Workshop: Participants investigate a simulated phishing-to-endpoint compromise, document evidence, classify scope, and produce a containment and escalation decision record.
Day 5: Control assurance and improvement planning
- Security control testing and evidence collection
- Vulnerability prioritisation using exploitability and asset criticality
- Network and endpoint security metrics for management reporting
- Exception management and compensating controls
- Third-party device and remote-worker security considerations
- 90-day remediation roadmap design and control ownership
- Security improvement review against NIST Cybersecurity Framework 2.0
Workshop: Participants consolidate their findings into a network and endpoint security baseline, including prioritised actions, owners, measures, and a 90-day improvement roadmap.
Tools & standards covered
Wireshark, Microsoft Defender for Endpoint, NIST Cybersecurity Framework 2.0, CIS Controls v8
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Tenable Nessus Professional Vulnerability Assessment Training Course
Vulnerability assessment programmes often fail not because organisations lack a scanner, but because scan scope is incomplete, credentials a…
NIST Cybersecurity Framework Implementation Training Course
Organisations often have security controls, policies, audit findings and risk registers in separate places, yet cannot clearly show how thos…
Kali Linux Penetration Testing Techniques Training Course
Security teams need evidence-based answers to practical questions: which systems are exposed, how an attacker could move from an initial foo…
COBIT 2019 Cyber Risk Governance Training Course
Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …