CertClue
Courses · Security
Network Security Administrator

Network Security Administration

Learn to own the controls on a real network: segmentation, firewall rule bases, ACLs, VPNs, IDS and IPS, NAC and device hardening, and leave holding a change request, a rule base audit, a segmentation design and a hardening checklist.
5.5 hrs taught · 5.5 to 10 hrs applied 7 modules 28 lessons 6 portfolio artifacts Completion certificate Updated August 2026
Created by the CertClue team
What you'll build

Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.

  • Firewall change requestOne change to a production rule base written so a board can approve it without asking you a question: the rules in the order they will sit, a sentence of justification per rule naming the system and its owner, the flows you were asked for and refused with where each requirement went instead, the risk stated plainly rather than scored, a backout somebody else could run with a time on it, and a test plan containing a flow that must fail.
  • Rule base audit worksheetAn inherited rule base reviewed row by row: what each rule permits with every group and service object resolved to real addresses and ports, the hit count beside the rule that shadows it so a zero cannot be misread, the owner or the blank where one should be, and a recommended action on every line, with a summary page separating what is safe to remove this week from what needs a fortnight of logging first.
  • Segmentation design for one applicationOne application segmented properly: the zones and what each holds, the policy written as who may initiate into this zone and what it may initiate out to with everything else denied, the flows resolved to hosts and services, the requested flows you refused with where they were solved instead, which device actually enforces each boundary, and an honest statement of what the flow data does and does not cover.
  • Access control list with a test planAn extended access control list as it will be configured, with the interface and direction it belongs on and a written reason for both, and a test plan somebody else could run at three in the morning: counters and bindings recorded before, a flow that must pass, a flow that must fail, an unrelated flow on the same interface, the deny counter rising afterwards, and a backout with a time on it.
  • Device hardening checklistThe management plane of a network device checked against a written standard, with an evidence column that makes each line provable: management reachability, transport, named administrator accounts through TACACS+, the break glass account and how its use is alarmed, accounting, a tested out-of-band path, configuration backup and restore, firmware, time and logging, each row passing, failing or not applicable with a reason.
  • Exception register with decisionsAn inherited exception register worked entry by entry rather than emptied or frozen: what each one permits now with the objects resolved to real addresses and ports, its approval and expiry dates read against its hit count over ninety days, a decision with the reason it differs from the others, what is watching it in the meantime and what that does not cover, and the condition that would make it unnecessary with the person who owns making that true. Including the two day approval from 2024 that is still carrying traffic.

What you'll learn

Fundamentals, kept short
The role decoded
A day in the role
The recurring calendar
Live simulation · five days on a segmentation programme
Artifacts
Handoff

Course content · 7 modules, 28 lessons

Sign up to unlock every lesson - the titles below show exactly what is inside.

Six ideas the rest of the course stands on: blast radius and why a flat network fails, segmentation that actually isolates, zero trust read honestly, the stateful rule base and its order, the access control list and where it goes, and the encrypted tunnel. It assumes you can already subnet and already read a network diagram.

The network as a security surface
Segmentation: VLANs, subnets and the DMZ
Zero trust, read honestly
Stateful firewalls, rule order and implicit deny
Access control lists: standard, extended, and where they go
Remote access: site-to-site, remote-access, and what MFA changes

Requirements

  • Comfortable with the fundamentals this course's own Module 1 covers, or equivalent experience.
  • No prior experience in this field is required to start.
  • A computer with a reliable internet connection.
  • Comfortable using a web browser - no software to install.

Description

Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for network security administrator.

Who this course is for

Anyone aiming to become a network security administrator, including career changers with no background in it yet. This is the entry rung of a realistic ladder:

entry
Network Security Administrator

Manages firewall rules, monitors for anomalies, and follows change control for network security changes.

Firewall managementAnomaly monitoringChange control
mid
Network Security Engineer

Designs segmentation and access policies, and leads incident response for network-layer threats.

SegmentationPolicy designIncident response
senior
Senior Network Security Engineer

Owns network security architecture across the org, and advises on major infrastructure changes.

ArchitectureInfrastructure advisoryTeam leadership

Where it leads

This course prepares you for the Cisco CCNA, then CompTIA Security+ role or credential path. Named for preparation only - no partnership or endorsement is implied.

Reviews

No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.

Sign in to leave a review.

Students also explore