Security+ SY0-701 · Foundations
Networking Primer — From Scratch
Who this is for: You — assuming zero networking knowledge. Prior certifications don't matter here; this primer teaches from absolute scratch exactly the networking foundation Security+ assumes, no more, no less. Nothing in the study packs requires anything beyond what's on this page.
How to work through it: Not in one sitting. Take it in 3 short sessions of about an hour (sections 1–3, then 4–5, then 6–8), re-doing the previous session's part of the self-check each time.
Ports (section 5) are pure memorisation — put them straight into daily flashcard rotation from the first session.
Finish, and pass the full self-check, before starting Domain 3.
1. The OSI Model — the exam's favourite way to organise everything
The 7-layer OSI stack — L2 = MAC/switch, L3 = IP/router, L4 = port/TCP-UDP
Seven layers; data moves down the stack when sending, up when receiving. Security+ mostly cares about which layer a device or attack operates at.
| # | Layer | What it handles | Security+ examples living here |
|---|---|---|---|
| 7 | Application | The actual service (web, mail, DNS) | WAF, Layer 7 firewall, HTTP attacks (SQLi/XSS arrive here) |
| 6 | Presentation | Data formats, encryption/decryption | TLS encryption (commonly placed here/L7) |
| 5 | Session | Establishing/managing sessions | Session hijacking |
| 4 | Transport | End-to-end delivery: TCP/UDP, port numbers | Layer 4 firewall, port scanning |
| 3 | Network | IP addresses, routing between networks | Routers, IPsec, IP spoofing |
| 2 | Data Link | MAC addresses, switching within a network | Switches, VLANs, ARP poisoning, 802.1X |
| 1 | Physical | Cables, radio, electrical signals | Cable taps, jamming |
Memory hook: Please Do Not Throw Sausage Pizza Away (L1→L7). The three layers that matter most for the exam: L2 = MAC/switch, L3 = IP/router, L4 = port/TCP-UDP.
2. TCP vs UDP — the two transport protocols
The TCP three-way handshake — the exam tell for "reliable" / "connection-oriented"
| TCP | UDP | |
|---|---|---|
| Connection | Connection-oriented — three-way handshake (SYN → SYN/ACK → ACK) before data | Connectionless — just sends |
| Reliability | Guaranteed delivery, ordering, retransmission | Best effort, no guarantees |
| Speed | Slower (overhead) | Faster (no overhead) |
| Used by | Web (HTTP/S), email, file transfer — anything that must arrive intact | DNS queries, streaming, VoIP — anything where speed beats completeness |
| Exam tell | "Handshake", "reliable", "session established" | "Fast", "no connection", "tolerates loss" |
The SYN flood attack (Domain 2) abuses the TCP handshake:
- send thousands of SYNs
- never complete the handshake
- exhaust the server's connection table
3. IP Addressing — who you are on the network
IPv4: four numbers 0-255 separated by dots — 192.168.1.50. 32 bits total.
**IPv6:
- ** eight hex groups —
2001:db8::1. 128 bits - effectively inexhaustible
- no NAT needed
Private IPv4 ranges (never routed on the internet — memorise all three):
10.0.0.0 – 10.255.255.255172.16.0.0 – 172.31.255.255192.168.0.0 – 192.168.255.255
CIDR notation: /24 after an address says how many leading bits are the network part. 192.168.1.0/24 = one network of 254 usable hosts (192.168.1.1–254). Smaller number after the slash = bigger network.
The exam rarely makes you subnet by hand — it wants you to recognise that /24 describes a network segment's size.
NAT (Network Address Translation): your router rewrites private internal addresses to its one public address for outbound traffic. Why it matters for security: internal addresses are invisible from outside — a mild layer of obscurity, not a real security control.
4. Switches, Routers, VLANs — moving traffic
- Switch (Layer 2): connects devices within one network, forwards frames by MAC address (the burned-in hardware address, e.g.
AA:BB:CC:11:22:33). - Router (Layer 3): connects different networks, forwards packets by IP address. Your default gateway is a router.
- VLAN: slices one physical switch into multiple isolated logical networks. Finance on VLAN 10 can't reach IT on VLAN 20 unless traffic passes a router/firewall — which is where you enforce policy. This is what "logical segmentation" means throughout Security+.
- ARP: the protocol that translates "who has IP 192.168.1.1?" into a MAC address. ARP poisoning (Domain 2) forges those answers so traffic flows through the attacker — the classic on-path attack inside a LAN.
5. Common Ports — memorise this table cold
Port numbers identify which service on a machine traffic is for. These come up constantly in exam questions and PBQs:
| Port | Protocol | Service | Secure version |
|---|---|---|---|
| 21 | TCP | FTP (file transfer) | 22 (SFTP via SSH) or 990 (FTPS) |
| 22 | TCP | SSH (secure remote shell), SFTP, SCP | already secure |
| 23 | TCP | Telnet (insecure remote shell) | replace with SSH 22 |
| 25 | TCP | SMTP (mail between servers) | 587 (submission w/ STARTTLS) |
| 53 | TCP/UDP | DNS (name → IP lookup) | 853 (DNS over TLS) |
| 67/68 | UDP | DHCP (hands out IP addresses) | — |
| 80 | TCP | HTTP (web, cleartext) | 443 HTTPS |
| 88 | TCP/UDP | Kerberos (AD authentication) | already secure |
| 110 | TCP | POP3 (mail retrieval) | 995 (POP3S) |
| 123 | UDP | NTP (time sync) | — |
| 143 | TCP | IMAP (mail retrieval) | 993 (IMAPS) |
| 161/162 | UDP | SNMP (device monitoring / traps) | use SNMPv3 (adds auth+encryption) |
| 389 | TCP/UDP | LDAP (directory lookups) | 636 LDAPS |
| 443 | TCP | HTTPS (web over TLS) | already secure |
| 445 | TCP | SMB (Windows file shares) | — (a favourite ransomware pathway) |
| 1433 | TCP | Microsoft SQL Server | — |
| 3389 | TCP | RDP (Windows remote desktop) | already encrypted; still gate behind VPN/MFA |
Exam pattern: "Which port should be blocked/allowed?" — the answer is nearly always about replacing an insecure service with its secure twin (23→22, 80→443, 389→636, 21→22).
6. Core network services
- DNS — the internet's phonebook: translates
claude.ai→ an IP address. Attacked via poisoning/hijacking (Domain 2); defended via DNS filtering (Domain 4) which blocks lookups of known-bad domains. - DHCP — automatically hands devices an IP address, gateway, and DNS server when they join a network. A rogue DHCP server can silently hand out a malicious DNS/gateway.
- NTP — synchronises clocks. Security relevance: if clocks drift, log timestamps can't be correlated across systems and Kerberos authentication starts failing.
7. Wireless essentials
- WPA3 — current Wi-Fi encryption standard (WPA2 is the still-common predecessor; WEP is ancient and broken — instant wrong answer unless the question asks for the insecure option).
- Enterprise vs Personal mode: Personal = one shared passphrase; Enterprise = each user authenticates individually via 802.1X → RADIUS server (this trio appears throughout Domains 3-4).
- Rogue AP — an unauthorised access point on your network; an evil twin is a rogue AP impersonating your legitimate SSID to harvest credentials.
8. Putting it together — one mental picture
The same segmented-network picture, drawn out
Internet (untrusted)
│
[Firewall/NGFW] ← perimeter: filters by IP/port (L3/L4) and content (L7)
│
DMZ / screened subnet ← public-facing servers live here
│
[Firewall]
│
Internal LAN ── switch ── VLAN 10 (staff PCs)
│ ← 802.1X: no port access until authenticated
└────── VLAN 20 (servers)
← jump server = only admin path inEvery Domain 3 architecture question is some variation of this picture. Every Domain 1 "zero trust" question says: stop assuming the Internal LAN is trustworthy just because it's inside.
Self-check
Answer without looking up
10 questions. Miss more than 3 and it's worth another pass before Domain 3.
1Which layer do switches operate at, and what address do they use?
2Which layer do routers operate at, and what address do they use?
3What three steps make up the TCP handshake?
4Is 172.20.5.9 a public or private address?
5Ports: SSH? HTTPS? DNS? RDP? LDAPS?
6What's the secure replacement for Telnet?
7What does a VLAN do, in one sentence?
8What does DHCP hand out?
9WPA3 Enterprise authenticates users via which two components?
10What sits in a DMZ/screened subnet and why?