Pillar A: CybersecurityA2

Network Security

Firewalls, IDS/IPS, network segmentation, DNS security, SD-WAN, VPN, traffic analysis, wireless security.

Part of Pillar A: Cybersecurity · Cybersecurity groups the disciplines that share methods, tools, and threat models with Network Security.

What is Network Security?

Network security is the practice of protecting the integrity, confidentiality, and availability of data as it traverses or resides on computer networks. It encompasses the hardware, software, and policies designed to prevent unauthorized access, misuse, or denial of network resources — from perimeter firewalls and intrusion detection systems to modern SD-WAN architectures and encrypted tunnels.

The network remains the primary attack surface for most organizations. Adversaries exploit misconfigured firewalls, unmonitored DNS traffic, weak wireless security, and flat network architectures to gain initial access and move laterally. Effective network security requires defense in depth: segmenting networks to contain breaches, inspecting traffic at multiple layers, encrypting data in transit, and continuously monitoring for anomalous behavior.

Modern network security has evolved far beyond traditional perimeter defense. Software-defined networking, cloud-native network controls, encrypted DNS (DoH/DoT), and the dissolution of the corporate perimeter have forced a fundamental rethinking of how networks are secured. Network detection and response (NDR) platforms use behavioral analytics and machine learning to identify threats that signature-based tools miss.

Why it matters

The network is the connective tissue of every organization. If it is compromised, every system, application, and data store connected to it is at risk. Network security is the first and most fundamental layer of defense.

Network security provides the infrastructure-level controls that all other security domains depend on. Identity, application, and cloud security all ultimately rely on the network being trustworthy and resilient.

Standards and frameworks

Curated resources

Authoritative sources we ground Network Security questions in — frameworks, research, guides, and tools.

Certifications that signal this domain

Credentials whose blueprint meaningfully covers this domain. Core means centrally covered; also touched means present in the blueprint but not the primary focus.

Core coverage

A+Professional·CompTIAOfficial page →

CompTIA A+

CompTIA A+

CCProfessional·ISC2Official page →

ISC2 Certified in Cybersecurity

The CC is ISC2's entry-level certification without experience requirements and explicitly targets career starters, career changers, and students. Notably, ISC2 periodically offers CC training and the exam for free (as part of the 'One Million Certified' initiative), which has significantly increased market penetration. Content covers five domains: Security Principles, Incident Response, Access Control, Network Security, and Security Operations – at a solid but intentionally broad entry level. As a stepping stone to SSCP or CISSP it is well-suited; as a standalone credential it carries less weight than Security+. From September 2026, a new Exam Outline applies.

CCDEExpert·CiscoOfficial page →

Cisco Certified Design Expert

Cisco Certified Design Expert

CCIE EntExpert·CiscoOfficial page →

Cisco Certified Internetwork Expert - Enterprise Infrastructure

Cisco Certified Internetwork Expert - Enterprise Infrastructure

CCIE SecExpert·CiscoOfficial page →

Cisco Certified Implementation Expert - Security

Cisco Certified Implementation Expert - Security

CCNAAssociate·CiscoOfficial page →

Cisco Certified Network Associate

The CCNA is the most well-known entry-level certification in networking and provides a broad foundation: network fundamentals, routing & switching, IP services, security basics, as well as automation and cloud. Although primarily a networking certificate, it covers security fundamentals and is therefore also relevant for security beginners. The job market for CCNA holders is stable with consistently over 6,500 open positions per week (as of spring 2026). With version 1.1 (August 2024), AI/ML and cloud management topics were incorporated for the first time. Without hands-on experience in Cisco environments, completion remains rather theoretical.

CCNP EntProfessional·CiscoOfficial page →

Cisco Certified Network Professional - Enterprise

Cisco Certified Network Professional - Enterprise

CCNP SecProfessional·CiscoOfficial page →

Cisco Certified Network Professional - Security

Cisco Certified Network Professional - Security

CCTProfessional·CiscoOfficial page →

Cisco Certified Technician

Cisco Certified Technician

CEHAssociate·EC-CouncilOfficial page →

Certified Ethical Hacker

Offensive-concepts breadth; light on hands-on rigor compared to OSCP.

CISSPExpert·ISC2Official page →

Certified Information Systems Security Professional

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

CISSP-ISSAPExpert·ISC2Official page →

CISSP Information Systems Security Architecture Professional

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

CNDProfessional·EC-CouncilOfficial page →

EC Council Certified Network Defender

EC Council Certified Network Defender

CNDAProfessional·EC-CouncilOfficial page →

EC Council Certified Network Defense Architect

EC Council Certified Network Defense Architect

CPENTProfessional·EC-CouncilOfficial page →

EC Council Certified Penetration Testing Professional

EC Council Certified Penetration Testing Professional

CRTOProfessional·Zero-Point SecurityOfficial page →

Zero Point Security Certified Red Team Operator

The CRTO from Zero-Point Security has established itself as one of the most practice-oriented red team certifications on the market. The associated course 'Red Team Ops' focuses on Cobalt Strike, Active Directory attacks, and realistic adversary simulation with OPSEC considerations. The exam format is purely practical and evaluates not only objective achievement but also operational behavior – points are deducted for triggered detections. Particularly attractive is the price-performance ratio compared to SANS certifications, as the course and exam are significantly more affordable. For experienced pentesters looking to develop towards red teaming and C2 deployment, the CRTO is a highly relevant qualification.

DevNet AAssociate·CiscoOfficial page →

Cisco DevNet Associate

Cisco DevNet Associate

DevNet ProProfessional·CiscoOfficial page →

Cisco DevNet Professional

Cisco DevNet Professional

ECSSProfessional·EC-CouncilOfficial page →

EC Council Certified Security Specialist

EC Council Certified Security Specialist

eJPTEntry·INEOfficial page →

eLearnSecurity Junior Penetration Tester

Entry-level pentest — good first offensive signal.

F5 CAProfessional·F5Official page →

F5 Big-IP Certified Administrator

F5 Big-IP Certified Administrator

F5 CSE SecExpert·F5Official page →

F5 Big-IP Certified Solution Expert - Security

F5 Big-IP Certified Solution Expert - Security

FCAAssociate·FortinetOfficial page →

Fortinet Certificed Associate

Fortinet Certificed Associate

FCFAssociate·FortinetOfficial page →

Fortinet Certified Fundamentals Cybersecurity

Fortinet Certified Fundamentals Cybersecurity

FCP NSProfessional·FortinetOfficial page →

Fortinet Certified Professional - Network Security

Fortinet Certified Professional - Network Security

FCSS NSProfessional·FortinetOfficial page →

Fortinet Certificed Solution Specialist - Network Security

Fortinet Certified Solution Specialist - Network Security

FCSS PCSProfessional·FortinetOfficial page →

Fortinet Certified Solution Specialist - Public Cloud Security

Fortinet Certified Solution Specialist - Public Cloud Security

FCSS ZTAProfessional·FortinetOfficial page →

Fortinet Certified Solution Specialist - Zero Trust Access

Fortinet Certified Solution Specialist - Zero Trust Access

GAWNProfessional·GIACOfficial page →

GIAC Assessing Wireless Networks

GIAC Assessing Wireless Networks

GCIAProfessional·GIAC / SANSOfficial page →

GIAC Certified Intrusion Analyst

Packet and log analysis, detection engineering fundamentals.

GCWNProfessional·GIACOfficial page →

GIAC Certified Windows Security Administrator

GIAC Certified Windows Security Administrator

GFACTAssociate·GIACOfficial page →

GIAC Foundational Cybersecurity Technologies

GIAC Foundational Cybersecurity Technologies

GICSPProfessional·GIAC / SANSOfficial page →

Global Industrial Cyber Security Professional

IT + engineering overlap for industrial control systems.

GNFAProfessional·GIACOfficial page →

GIAC Network Forensic Analyst

GIAC Network Forensic Analyst

GPENProfessional·GIAC / SANSOfficial page →

GIAC Penetration Tester

Penetration testing methodology + documentation.

GSEExpert·GIACOfficial page →

GIAC Security Expert

The GIAC Security Expert (GSE) is the highest distinction in the GIAC certification system and was fundamentally reformed in 2023/2024: Instead of a single exam, it is now awarded as a portfolio certification. Those who demonstrate six Practitioner and four Applied Knowledge certifications (hands-on, proctored lab exams) automatically receive GSE status. The model enforces genuine breadth and depth – which increases credibility compared to earlier pure knowledge tests. However, the effort (cost, time, multiple exams) is considerable; the GSE is therefore clearly aimed at experienced experts pursuing SANS/GIAC as a career path. In Europe, awareness outside the SANS community is still limited.

GSECAssociate·GIAC / SANSOfficial page →

GIAC Security Essentials

Broad defender fundamentals. Often paired with SANS SEC401.

HTB CPTSProfessional·Hack The BoxOfficial page →

Hack the Box Certified Penetration Testing Specialist

Hack the Box Certified Penetration Testing Specialist

ISA CEExpert·ISAOfficial page →

ISA Cybersecurity Expert

ISA Cybersecurity Expert

JNCIA SecAssociate·JuniperOfficial page →

Juniper Networks Certified Internet Associate, Security

Juniper Networks Certified Internet Associate, Security

JNCIE SecExpert·JuniperOfficial page →

Juniper Networks Certified Internet Expert, Security

Juniper Networks Certified Internet Expert, Security

JNCIP SecProfessional·JuniperOfficial page →

Juniper Networks Certified Internet Professional, Security

Juniper Networks Certified Internet Professional, Security

JNCIS SecProfessional·JuniperOfficial page →

Juniper Networks Certified Internet Specialist, Security

Juniper Networks Certified Internet Specialist, Security

Linux+Professional·CompTIAOfficial page →

CompTIA Linux+

CompTIA Linux+

Net+Professional·CompTIAOfficial page →

CompTIA Network+

CompTIA Network+

OSCPProfessional·OffSecOfficial page →

Offensive Security Certified Professional

Hands-on penetration testing — exploitation, privilege escalation, AD attacks.

OSEPProfessional·OffSecOfficial page →

Offensive Security Experienced Penetration Tester

The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications—it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.

OSWPProfessional·OffSecOfficial page →

Offensive Security Wireless Professional

Offensive Security Wireless Professional

PCCETProfessional·Palo AltoOfficial page →

Palo Alto Networks Certified Cybersecurity Entry-level Technician

Palo Alto Networks Certified Cybersecurity Entry-level Technician

PCNSAProfessional·Palo AltoOfficial page →

Palo Alto Networks Certified Network Security Administrator

Palo Alto Networks Certified Network Security Administrator

PCNSEProfessional·Palo AltoOfficial page →

Palo Alto Networks Certified Network Security Engineer

Palo Alto Networks Certified Network Security Engineer

PNPTProfessional·TCM SecurityOfficial page →

Practical Network Penetration Tester

Hands-on network + AD pentesting with OSINT + reporting.

RHCAProfessional·Red HatOfficial page →

Red Hat Certified Architect

Red Hat Certified Architect

RHCEProfessional·Red HatOfficial page →

Red Hat Certified Engineer

Red Hat Certified Engineer

RHCSAProfessional·Red HatOfficial page →

Red Hat Certified System Administrator

Red Hat Certified System Administrator

Security+Entry·CompTIAOfficial page →

CompTIA Security+

Broad entry-level knowledge across threats, ops, IAM, network, and crypto basics.

Server+Professional·CompTIAOfficial page →

CompTIA Server+

CompTIA Server+

SSCPProfessional·ISC2Official page →

(ISC)2 Systems Security Certified Practitioner

The SSCP is ISC2's entry-level certification below the CISSP and targets technically active security professionals with initial work experience. Since October 2025, the exam uses Computerized Adaptive Testing (CAT), which customizes the exam experience individually and increases integrity. The SSCP covers seven technical domains, from access control through cryptography to network security, and positions itself as practical proof of operational security competence. It is less well-known than Security+ or GSEC, but benefits from ISC2's strong brand and serves well as an intermediate step toward the CISSP. The effort for annual certification maintenance (AMF + CPEs) is moderate.

VCIX NVExpert·VMwareOfficial page →

VMware Certified Implementation Expert in Network Virtualization

VMware Certified Implementation Expert in Network Virtualization

VCP DCVProfessional·VMwareOfficial page →

VMware Certified Professional in Datacenter Virtualization

VMware Certified Professional in Datacenter Virtualization

VCP NVProfessional·VMwareOfficial page →

VMware Certified Professional in Network Virtualization

VMware Certified Professional in Network Virtualization

Also touched

AZ-500Associate·MicrosoftOfficial page →

Microsoft Certified: Azure Security Engineer Associate

Azure-native security engineering: Entra ID, network controls, Defender, Sentinel.

CRTEExpert·Altered SecurityOfficial page →

Certified Red Team Expert

Multi-forest AD compromise — cross-trust abuse, advanced delegation, and persistence in hardened enterprise environments.

CRTPProfessional·Altered SecurityOfficial page →

Certified Red Team Professional

Hands-on Active Directory attacker — Kerberos abuse, trust attacks, and lateral movement against a real multi-domain forest.

CSA CZTProfessional·Cloud Security AllianceOfficial page →

Certified Zero Trust (CCZT)

Vendor-neutral Zero Trust architecture and governance — NIST SP 800-207, ZTA pillars, and program implementation.

Browse all certifications → — pick a cert on the interactive map to highlight every domain it covers.

Education and certifications

More in Cybersecurity

Test what you know about Network Security

41 questions available. Beginner to expert questions, scored against the global leaderboard.