Google Cybersecurity Certificate, Course 3: Connect and Protect: Networks and Network Security (Study Notes)
Plain-English notes on TCP/IP, the OSI model, ports, DNS, firewalls, VPNs, network attacks, segmentation and hardening. Includes practice questions with explanations.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.
1. Course overview
Almost every attack travels over a network, so analysts need to know how data moves and where it can be intercepted, flooded or faked. This course explains how networks are built, how the common protocols work, which attacks target them, and which defences (firewalls, VPNs, segmentation, hardening) reduce the damage.
Core idea
Know normal traffic first. You cannot spot abnormal traffic without it.
Builds on
Risk and controls from Course 2.
Study tip
Trace one web page load from your browser to the server, naming each protocol on the way.
2. Weekly breakdown (study plan)
A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.
Part 1: Network architecture and models
- A network is devices (hosts) connected to share data. Common pieces: switches (connect devices in a LAN), routers (connect networks), modems, access points.
- LAN is local, WAN is wide area; the internet is a network of networks.
- TCP/IP model has four layers: network access, internet, transport, application. The OSI model splits it into seven for finer troubleshooting.
- Packets carry a header (addresses, control data) and a payload (the actual data).
| OSI layer | Plain meaning | Examples |
|---|---|---|
| 7 Application | What the user’s software uses | HTTP, DNS, SMTP |
| 6 Presentation | Format and encryption | TLS |
| 5 Session | Opening and closing conversations | Session control |
| 4 Transport | Delivery between programs | TCP, UDP |
| 3 Network | Addressing and routing | IP, routers |
| 2 Data link | Local delivery | MAC, switches, ARP |
| 1 Physical | Signals and cables | Ethernet, Wi-Fi |
Part 2: Protocols, ports, addresses and DNS
- IP address identifies a device on a network (IPv4 like 192.168.1.10; IPv6 is longer). MAC address identifies the network card locally.
- TCP is reliable and uses a three-step handshake (SYN, SYN-ACK, ACK). UDP is faster with no handshake.
- Ports direct traffic to the right program on a device. Think of the IP as the building and the port as the apartment number.
- DNS turns names into IP addresses. DHCP hands out addresses automatically. ARP maps IP addresses to MAC addresses on a local network.
- Subnets split a network into smaller parts; CIDR notation like /24 shows how many bits belong to the network part.
| Port | Service | Port | Service |
|---|---|---|---|
| 22 | SSH | 80 | HTTP |
| 25 | SMTP | 443 | HTTPS |
| 53 | DNS | 3389 | RDP |
Part 3: Network attacks
| Attack | What happens | Typical defence |
|---|---|---|
| DoS / DDoS | Overwhelms a service so real users cannot reach it | Rate limits, traffic scrubbing, redundancy |
| SYN flood | Many half-open TCP handshakes exhaust the server | SYN cookies, firewall limits |
| Packet sniffing | Capturing traffic to read it | Encryption (HTTPS, VPN) |
| On-path attack | Attacker sits between two parties to read or change traffic | TLS, certificate checks |
| IP / ARP / DNS spoofing | Faking an address or record to redirect or impersonate | Filtering, DNSSEC, ARP inspection |
| Smurf / ping of death | Abusing ICMP to flood or crash a target | Block or limit ICMP, patch |
Only test attacks on systems you own or have written permission to test.
Part 4: Defences, segmentation and hardening
- Firewall: allows or blocks traffic by rules (addresses, ports, protocols). Stateless checks each packet alone; stateful tracks the connection; next-generation firewalls also inspect applications.
- IDS detects and alerts; IPS detects and blocks. A proxy relays requests on a client’s behalf. A VPN creates an encrypted tunnel across an untrusted network.
- Segmentation: divide the network into zones (VLANs, subnets, a DMZ for public servers) so a breach in one area cannot freely spread.
- Hardening: reduce weak spots by patching, disabling unused services and ports, removing default passwords, enforcing MFA, using secure configuration baselines, and backing up.
- Cloud networks: use the same ideas (virtual networks, security groups, least privilege) and remember the shared responsibility between provider and customer.
3. 15 must-know terms
| Term | Plain meaning |
|---|---|
| Packet | Small unit of data sent over a network |
| IP address | Logical address of a device |
| MAC address | Hardware address of a network card |
| Port | Numbered doorway to a service on a device |
| TCP / UDP | Reliable delivery / fast, no-guarantee delivery |
| DNS | Phone book turning names into IPs |
| DHCP | Automatic address assignment |
| ARP | Finds the MAC for an IP locally |
| Subnet | A smaller slice of a network |
| Firewall | Rule-based traffic filter |
| VPN | Encrypted tunnel over an untrusted network |
| Proxy server | Middleman for requests |
| DMZ | Semi-isolated zone for public-facing servers |
| Network segmentation | Splitting a network into isolated zones |
| Hardening | Tightening configuration to cut weaknesses |
4. Three worked examples
Example 1: Trace a web request
Scenario: You open a secure website by name.
Steps: (1) DNS converts the name to an IP. (2) Your device opens a TCP connection to port 443 using the three-way handshake. (3) TLS sets up encryption. (4) Your browser sends an HTTPS request; the server replies. (5) Routers forward packets between networks; ARP and switches handle the local hop. Takeaway: several layers cooperate, so a fault or attack can sit at any of them.
Example 2: Write firewall rules
Scenario: A small office runs a public web server and wants staff to reach it only through the office network for admin.
Rules (in order): allow inbound TCP 443 from anywhere to the web server; allow inbound TCP 22 only from the office IP range; deny everything else inbound. Why: allow what is needed, deny by default, and restrict admin access.
Example 3: Spot a SYN flood in logs
Scenario: A server log shows thousands of SYN packets per second from many addresses, with almost no ACKs completing, and legitimate users time out.
Reasoning: handshakes are starting but never finishing, which ties up resources. Answer: SYN flood, a type of DoS. Response: enable SYN cookies or rate limits, ask the upstream provider for DDoS filtering, and record the event for the incident report.
5. Common mistakes
- Mixing up IP and MAC addresses. IPs route between networks; MACs deliver on the local segment.
- Memorising OSI layers without examples. Tie each layer to one protocol or device.
- Thinking a VPN makes you anonymous or safe. It encrypts the tunnel; the endpoint and your device still matter.
- Allow-all firewall rules “just to test”. Temporary rules often stay forever. Default deny is safer.
- Confusing IDS and IPS. Detection alerts; prevention blocks.
- Skipping the basics of hardening. Default passwords and unneeded open ports are among the easiest wins for attackers.
6. 10 practice questions (tap to reveal)
Q1. Which OSI layer handles routing between networks?
Layer 3, Network. Routers use IP addresses to forward packets.
Q2. Why does TCP use a handshake and UDP does not?
TCP confirms both sides are ready and tracks delivery for reliability. UDP skips this to be faster, which suits streaming and DNS lookups.
Q3. What does DNS do when you type a website name?
It translates the name into an IP address so your device knows where to send traffic.
Q4. Which port normally carries HTTPS traffic?
443. HTTP uses 80 and is not encrypted.
Q5. How is a stateful firewall different from a stateless one?
A stateful firewall remembers active connections and allows return traffic for them; a stateless firewall judges every packet on its own rules only.
Q6. What problem does a VPN solve on public Wi-Fi?
It encrypts traffic between your device and the VPN endpoint, making sniffing on the local network much less useful.
Q7. An attacker sends forged ARP replies so your traffic passes through their laptop. Name the attack.
ARP spoofing, which enables an on-path attack. Defences include ARP inspection and encrypted protocols.
Q8. How does segmentation limit damage from a compromised workstation?
It places systems in separate zones with controlled paths between them, so the attacker cannot reach sensitive servers freely.
Q9. Why put a public web server in a DMZ?
If it is compromised, the attacker is still outside the internal network, which has stricter rules.
Q10. List three simple hardening steps for a new server.
Apply patches, disable unused services and ports, replace default credentials. Enabling MFA and logging are also good answers.
7. YouTube search links
- OSI model explained
- TCP/IP model explained
- DNS, DHCP and ARP explained
- Firewalls and VPNs explained
- Network attacks explained
8. One-screen revision summary
- Models: TCP/IP (4 layers) and OSI (7 layers).
- Addresses: IP routes between networks; MAC delivers locally; ports pick the service.
- Protocols: TCP reliable (SYN, SYN-ACK, ACK); UDP fast; DNS names to IPs; DHCP assigns IPs; ARP maps IP to MAC.
- Key ports: 22 SSH, 53 DNS, 80 HTTP, 443 HTTPS, 3389 RDP.
- Attacks: DoS/DDoS, SYN flood, sniffing, on-path, spoofing, ICMP abuse.
- Defences: firewall (stateless, stateful, next-gen), IDS/IPS, VPN, proxy.
- Segmentation: zones, VLANs, DMZ limit spread.
- Hardening: patch, close ports, change defaults, MFA, baselines, backups.
9. What you should be able to do
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.
