Network Security Administration
Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.
- Firewall change requestOne change to a production rule base written so a board can approve it without asking you a question: the rules in the order they will sit, a sentence of justification per rule naming the system and its owner, the flows you were asked for and refused with where each requirement went instead, the risk stated plainly rather than scored, a backout somebody else could run with a time on it, and a test plan containing a flow that must fail.
- Rule base audit worksheetAn inherited rule base reviewed row by row: what each rule permits with every group and service object resolved to real addresses and ports, the hit count beside the rule that shadows it so a zero cannot be misread, the owner or the blank where one should be, and a recommended action on every line, with a summary page separating what is safe to remove this week from what needs a fortnight of logging first.
- Segmentation design for one applicationOne application segmented properly: the zones and what each holds, the policy written as who may initiate into this zone and what it may initiate out to with everything else denied, the flows resolved to hosts and services, the requested flows you refused with where they were solved instead, which device actually enforces each boundary, and an honest statement of what the flow data does and does not cover.
- Access control list with a test planAn extended access control list as it will be configured, with the interface and direction it belongs on and a written reason for both, and a test plan somebody else could run at three in the morning: counters and bindings recorded before, a flow that must pass, a flow that must fail, an unrelated flow on the same interface, the deny counter rising afterwards, and a backout with a time on it.
- Device hardening checklistThe management plane of a network device checked against a written standard, with an evidence column that makes each line provable: management reachability, transport, named administrator accounts through TACACS+, the break glass account and how its use is alarmed, accounting, a tested out-of-band path, configuration backup and restore, firmware, time and logging, each row passing, failing or not applicable with a reason.
- Exception register with decisionsAn inherited exception register worked entry by entry rather than emptied or frozen: what each one permits now with the objects resolved to real addresses and ports, its approval and expiry dates read against its hit count over ninety days, a decision with the reason it differs from the others, what is watching it in the meantime and what that does not cover, and the condition that would make it unnecessary with the person who owns making that true. Including the two day approval from 2024 that is still carrying traffic.
What you'll learn
Course content · 7 modules, 28 lessons
Sign up to unlock every lesson - the titles below show exactly what is inside.
Six ideas the rest of the course stands on: blast radius and why a flat network fails, segmentation that actually isolates, zero trust read honestly, the stateful rule base and its order, the access control list and where it goes, and the encrypted tunnel. It assumes you can already subnet and already read a network diagram.
Requirements
- Comfortable with the fundamentals this course's own Module 1 covers, or equivalent experience.
- No prior experience in this field is required to start.
- A computer with a reliable internet connection.
- Comfortable using a web browser - no software to install.
Description
Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for network security administrator.
Who this course is for
Anyone aiming to become a network security administrator, including career changers with no background in it yet. This is the entry rung of a realistic ladder:
Manages firewall rules, monitors for anomalies, and follows change control for network security changes.
Designs segmentation and access policies, and leads incident response for network-layer threats.
Owns network security architecture across the org, and advises on major infrastructure changes.
Where it leads
This course prepares you for the Cisco CCNA, then CompTIA Security+ role or credential path. Named for preparation only - no partnership or endorsement is implied.
No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.
Sign in to leave a review.



