TB.

Security+ SY0-701 · Foundations

Networking Primer — From Scratch

Who this is for: You — assuming zero networking knowledge. Prior certifications don't matter here; this primer teaches from absolute scratch exactly the networking foundation Security+ assumes, no more, no less. Nothing in the study packs requires anything beyond what's on this page.

How to work through it: Not in one sitting. Take it in 3 short sessions of about an hour (sections 1–3, then 4–5, then 6–8), re-doing the previous session's part of the self-check each time.

Ports (section 5) are pure memorisation — put them straight into daily flashcard rotation from the first session.

Finish, and pass the full self-check, before starting Domain 3.

1. The OSI Model — the exam's favourite way to organise everything

The 7-layer OSI stack — L2 = MAC/switch, L3 = IP/router, L4 = port/TCP-UDP

Seven layers; data moves down the stack when sending, up when receiving. Security+ mostly cares about which layer a device or attack operates at.

#LayerWhat it handlesSecurity+ examples living here
7ApplicationThe actual service (web, mail, DNS)WAF, Layer 7 firewall, HTTP attacks (SQLi/XSS arrive here)
6PresentationData formats, encryption/decryptionTLS encryption (commonly placed here/L7)
5SessionEstablishing/managing sessionsSession hijacking
4TransportEnd-to-end delivery: TCP/UDP, port numbersLayer 4 firewall, port scanning
3NetworkIP addresses, routing between networksRouters, IPsec, IP spoofing
2Data LinkMAC addresses, switching within a networkSwitches, VLANs, ARP poisoning, 802.1X
1PhysicalCables, radio, electrical signalsCable taps, jamming

Memory hook: Please Do Not Throw Sausage Pizza Away (L1→L7). The three layers that matter most for the exam: L2 = MAC/switch, L3 = IP/router, L4 = port/TCP-UDP.

2. TCP vs UDP — the two transport protocols

The TCP three-way handshake — the exam tell for "reliable" / "connection-oriented"

TCPUDP
ConnectionConnection-oriented — three-way handshake (SYN → SYN/ACK → ACK) before dataConnectionless — just sends
ReliabilityGuaranteed delivery, ordering, retransmissionBest effort, no guarantees
SpeedSlower (overhead)Faster (no overhead)
Used byWeb (HTTP/S), email, file transfer — anything that must arrive intactDNS queries, streaming, VoIP — anything where speed beats completeness
Exam tell"Handshake", "reliable", "session established""Fast", "no connection", "tolerates loss"

The SYN flood attack (Domain 2) abuses the TCP handshake:

  • send thousands of SYNs
  • never complete the handshake
  • exhaust the server's connection table

3. IP Addressing — who you are on the network

IPv4: four numbers 0-255 separated by dots — 192.168.1.50. 32 bits total.

**IPv6:

  • ** eight hex groups — 2001:db8::1. 128 bits
  • effectively inexhaustible
  • no NAT needed

Private IPv4 ranges (never routed on the internet — memorise all three):

  • 10.0.0.0 – 10.255.255.255
  • 172.16.0.0 – 172.31.255.255
  • 192.168.0.0 – 192.168.255.255

CIDR notation: /24 after an address says how many leading bits are the network part. 192.168.1.0/24 = one network of 254 usable hosts (192.168.1.1–254). Smaller number after the slash = bigger network.

The exam rarely makes you subnet by hand — it wants you to recognise that /24 describes a network segment's size.

NAT (Network Address Translation): your router rewrites private internal addresses to its one public address for outbound traffic. Why it matters for security: internal addresses are invisible from outside — a mild layer of obscurity, not a real security control.

4. Switches, Routers, VLANs — moving traffic

  • Switch (Layer 2): connects devices within one network, forwards frames by MAC address (the burned-in hardware address, e.g. AA:BB:CC:11:22:33).
  • Router (Layer 3): connects different networks, forwards packets by IP address. Your default gateway is a router.
  • VLAN: slices one physical switch into multiple isolated logical networks. Finance on VLAN 10 can't reach IT on VLAN 20 unless traffic passes a router/firewall — which is where you enforce policy. This is what "logical segmentation" means throughout Security+.
  • ARP: the protocol that translates "who has IP 192.168.1.1?" into a MAC address. ARP poisoning (Domain 2) forges those answers so traffic flows through the attacker — the classic on-path attack inside a LAN.

5. Common Ports — memorise this table cold

Port numbers identify which service on a machine traffic is for. These come up constantly in exam questions and PBQs:

PortProtocolServiceSecure version
21TCPFTP (file transfer)22 (SFTP via SSH) or 990 (FTPS)
22TCPSSH (secure remote shell), SFTP, SCPalready secure
23TCPTelnet (insecure remote shell)replace with SSH 22
25TCPSMTP (mail between servers)587 (submission w/ STARTTLS)
53TCP/UDPDNS (name → IP lookup)853 (DNS over TLS)
67/68UDPDHCP (hands out IP addresses)—
80TCPHTTP (web, cleartext)443 HTTPS
88TCP/UDPKerberos (AD authentication)already secure
110TCPPOP3 (mail retrieval)995 (POP3S)
123UDPNTP (time sync)—
143TCPIMAP (mail retrieval)993 (IMAPS)
161/162UDPSNMP (device monitoring / traps)use SNMPv3 (adds auth+encryption)
389TCP/UDPLDAP (directory lookups)636 LDAPS
443TCPHTTPS (web over TLS)already secure
445TCPSMB (Windows file shares)— (a favourite ransomware pathway)
1433TCPMicrosoft SQL Server—
3389TCPRDP (Windows remote desktop)already encrypted; still gate behind VPN/MFA

Exam pattern: "Which port should be blocked/allowed?" — the answer is nearly always about replacing an insecure service with its secure twin (23→22, 80→443, 389→636, 21→22).

6. Core network services

  • DNS — the internet's phonebook: translates claude.ai → an IP address. Attacked via poisoning/hijacking (Domain 2); defended via DNS filtering (Domain 4) which blocks lookups of known-bad domains.
  • DHCP — automatically hands devices an IP address, gateway, and DNS server when they join a network. A rogue DHCP server can silently hand out a malicious DNS/gateway.
  • NTP — synchronises clocks. Security relevance: if clocks drift, log timestamps can't be correlated across systems and Kerberos authentication starts failing.

7. Wireless essentials

  • WPA3 — current Wi-Fi encryption standard (WPA2 is the still-common predecessor; WEP is ancient and broken — instant wrong answer unless the question asks for the insecure option).
  • Enterprise vs Personal mode: Personal = one shared passphrase; Enterprise = each user authenticates individually via 802.1X → RADIUS server (this trio appears throughout Domains 3-4).
  • Rogue AP — an unauthorised access point on your network; an evil twin is a rogue AP impersonating your legitimate SSID to harvest credentials.

8. Putting it together — one mental picture

The same segmented-network picture, drawn out

Internet (untrusted)
   │
[Firewall/NGFW]  ← perimeter: filters by IP/port (L3/L4) and content (L7)
   │
 DMZ / screened subnet  ← public-facing servers live here
   │
[Firewall]
   │
Internal LAN ── switch ── VLAN 10 (staff PCs)
                   │        ← 802.1X: no port access until authenticated
                   └────── VLAN 20 (servers)
                              ← jump server = only admin path in

Every Domain 3 architecture question is some variation of this picture. Every Domain 1 "zero trust" question says: stop assuming the Internal LAN is trustworthy just because it's inside.

Self-check

Answer without looking up

10 questions. Miss more than 3 and it's worth another pass before Domain 3.

1Which layer do switches operate at, and what address do they use?

2Which layer do routers operate at, and what address do they use?

3What three steps make up the TCP handshake?

4Is 172.20.5.9 a public or private address?

5Ports: SSH? HTTPS? DNS? RDP? LDAPS?

6What's the secure replacement for Telnet?

7What does a VLAN do, in one sentence?

8What does DHCP hand out?

9WPA3 Enterprise authenticates users via which two components?

10What sits in a DMZ/screened subnet and why?