Course ID: #N/A

EC-Council Certified Network Defender (CND) v3

Duration: 5 days Dates: 2 November 2026 1 February 2027 10 May 2027 2 August 2027

Certified Network Defender (CND) is EC-Council’s vendor-neutral programme for defending enterprise networks. Version 3 follows an adaptive security strategy with the steps protect, detect, respond and predict, and covers virtual, cloud, wireless and IoT environments in addition to the perimeter and endpoints. More than half of the course consists of hands-on labs. The course prepares you for the CND (312-38) exam.

Module 1: Network Attacks and Defence Strategies

  • Attack techniques at the network, host and application level, social engineering, email, mobile, cloud and wireless attacks
  • Attacker methodologies and frameworks
  • Goals and challenges of network defence, adaptive security strategy and defence in depth

Module 2: Administrative Network Security

  • Regulatory frameworks, laws and compliance
  • Designing and developing security policies
  • Security awareness training and other administrative security measures

Module 3: Technical Network Security

  • Access control principles and models, identity and access management (IAM)
  • Cryptographic techniques and algorithms
  • Network segmentation, and key security solutions and protocols

Module 4: Network Perimeter Security

  • Firewall technologies and topologies, selection, implementation and administration
  • IDS/IPS: classification, components, deployment of network- and host-based systems, handling false positives
  • Securing routers and switches; Zero Trust with Software-Defined Perimeter (SDP)

Module 5: Endpoint Security – Windows Systems

  • Windows security components and features, security baselines
  • User accounts, passwords, access and patch management
  • OS hardening, Active Directory best practices, security of network services and protocols

Module 6: Endpoint Security – Linux Systems

  • Installing, patching and hardening Linux
  • User access and password management, network and remote access security
  • Security tools and frameworks for Linux

Module 7: Endpoint Security – Mobile Devices

  • Enterprise mobile usage policies, risks and countermeasures
  • Enterprise mobile device management solutions
  • Security policies and tools for Android and iOS

Module 8: Endpoint Security – IoT Devices

  • IoT ecosystem and communication models
  • Risks and security measures in IoT environments
  • IoT security tools, best practices and standards

Module 9: Administrative Application Security

  • Application whitelisting and blacklisting
  • Application sandboxing and patch management
  • Web Application Firewall (WAF)

Module 10: Data Security

  • Data access controls
  • Encryption of data at rest and in transit (browser and web server, database and web server, email)
  • Data masking, backup and retention, data destruction, Data Loss Prevention (DLP)

Module 11: Enterprise Virtual Network Security

  • Virtualisation fundamentals, network virtualisation, SDN and NFV
  • OS virtualisation security
  • Policies and best practices for containers, Docker and Kubernetes

Module 12: Enterprise Cloud Network Security

  • Cloud computing and cloud security fundamentals
  • Assessing cloud provider security before use
  • Security in AWS, Microsoft Azure and Google Cloud Platform, general best practices and tools

Module 13: Enterprise Wireless Network Security

  • Wireless network fundamentals
  • Wi-Fi encryption and authentication methods
  • Implementing security measures for wireless networks

Module 14: Network Traffic Monitoring and Analysis

  • Setting up a network monitoring environment
  • Determining baselines for normal and suspicious traffic, analysis with Wireshark
  • Performance and bandwidth monitoring

Module 15: Network Log Monitoring and Analysis

  • Logging fundamentals
  • Analysing logs from Windows, Linux, macOS, firewalls, routers and web servers
  • Centralised log monitoring and analysis

Module 16: Incident Response and Forensic Investigation

  • Incident response concepts and the role of the first responder
  • Security incident handling process
  • Forensic investigation process

Module 17: Business Continuity and Disaster Recovery

  • Business Continuity (BC) and Disaster Recovery (DR) fundamentals and activities
  • Business continuity plan and disaster recovery plan
  • BC/DR standards

Module 18: Anticipating Risk with Risk Management

  • Risk management programme and risk management frameworks
  • Vulnerability management
  • Vulnerability assessment and scanning

Module 19: Threat Assessment with Attack Surface Analysis

  • Understanding and visualising the attack surface
  • Identifying Indicators of Exposure (IoE) and simulating attacks
  • Reducing the attack surface

Module 20: Threat Prediction with Cyber Threat Intelligence

  • Role and types of threat intelligence in network defence
  • Indicators of Compromise (IoC) and Indicators of Attack (IoA)
  • Using threat intelligence for proactive defence
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/11/02, 2027/02/01, 2027/05/10, 2027/08/02, flexibel, auf Anfrage

Network and system administrators, network security engineers, security analysts and IT professionals looking to move into network defence or a blue team role.

Basic knowledge of networking (TCP/IP, network components) and experience administering Windows or Linux systems is required.

After the course you will be able to:

  • classify current attack techniques and build a multi-layered defence strategy
  • implement security policies, access control and perimeter protection with firewalls and IDS/IPS
  • secure Windows, Linux, mobile and IoT endpoints as well as applications and data
  • protect virtual environments, containers, cloud services and wireless networks
  • monitor network traffic and logs, detect incidents and respond to them
  • assess risks, attack surfaces and threats early using risk management and threat intelligence

CHF4'540 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation