WEEK 04

Network & Security Equipment

Operational scenario

A new switch arrived with default credentials and three-year-old firmware. Baseline it before it goes in the rack.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 4; acronym quiz 3
Deliverable: Secure architecture doc
Learning objectives
  • Explain purpose, configuration and risks of core IT/OT devices
  • Apply a secure baseline
  • Review firmware
Classroom topics
  • Switches, routers, firewalls
  • VPN concentrators & taps
  • Data diodes / unidirectional gateways
  • SIEM / EDR / XDR
  • HSMs
Standards · vocabulary
NIST SP 800-53 (SC/AC)ISA/IEC 62443
NACDLPHSMSIEMEDRXDR
Open glossary
Competency demonstrated: Documents secure network architecture.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Apply a secure baseline to a switch; review firmware versions.

~2 h
Docker container lab

Lab 5 — Map container communications to OSI and TCP/IP.

~0.5 h
AR/VR immersive scenario

Inspect switches, routers, firewalls, servers and a data diode. Role: Network engineer.

No headset? Printed device-inspection cards. Printed and mobile versions are also available.

Individual technical assignment

Secure-baseline a device and document the deltas.

Team exercise

Design & document a secure small-network architecture.

Required hardware
  • Managed switch
  • Firewall appliance / VM
  • Raspberry Pi or mini-PC
Required software
  • Docker
  • Vendor CLI / web UI
Workplace application

Default configurations are the most common audit finding; baselines prove due care.

Docker progression step
L5 Mapping container communications to OSI and TCP/IP

For three flows, name the layer, protocol, data unit and control at each step.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Identity & access controlData protection & cryptographySecure configuration & hardeningMalware & endpoint defense
See the full crosswalk