Google Cybersecurity Certificate, Course 3: Connect and Protect: Networks and Network Security (Study Notes)

    Plain-English notes on TCP/IP, the OSI model, ports, DNS, firewalls, VPNs, network attacks, segmentation and hardening. Includes practice questions with explanations.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.

    1. Course overview

    Almost every attack travels over a network, so analysts need to know how data moves and where it can be intercepted, flooded or faked. This course explains how networks are built, how the common protocols work, which attacks target them, and which defences (firewalls, VPNs, segmentation, hardening) reduce the damage.

    Core idea

    Know normal traffic first. You cannot spot abnormal traffic without it.

    Builds on

    Risk and controls from Course 2.

    Study tip

    Trace one web page load from your browser to the server, naming each protocol on the way.

    2. Weekly breakdown (study plan)

    A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.

    Part 1: Network architecture and models
    • A network is devices (hosts) connected to share data. Common pieces: switches (connect devices in a LAN), routers (connect networks), modems, access points.
    • LAN is local, WAN is wide area; the internet is a network of networks.
    • TCP/IP model has four layers: network access, internet, transport, application. The OSI model splits it into seven for finer troubleshooting.
    • Packets carry a header (addresses, control data) and a payload (the actual data).
    OSI layerPlain meaningExamples
    7 ApplicationWhat the user’s software usesHTTP, DNS, SMTP
    6 PresentationFormat and encryptionTLS
    5 SessionOpening and closing conversationsSession control
    4 TransportDelivery between programsTCP, UDP
    3 NetworkAddressing and routingIP, routers
    2 Data linkLocal deliveryMAC, switches, ARP
    1 PhysicalSignals and cablesEthernet, Wi-Fi
    Part 2: Protocols, ports, addresses and DNS
    • IP address identifies a device on a network (IPv4 like 192.168.1.10; IPv6 is longer). MAC address identifies the network card locally.
    • TCP is reliable and uses a three-step handshake (SYN, SYN-ACK, ACK). UDP is faster with no handshake.
    • Ports direct traffic to the right program on a device. Think of the IP as the building and the port as the apartment number.
    • DNS turns names into IP addresses. DHCP hands out addresses automatically. ARP maps IP addresses to MAC addresses on a local network.
    • Subnets split a network into smaller parts; CIDR notation like /24 shows how many bits belong to the network part.
    PortServicePortService
    22SSH80HTTP
    25SMTP443HTTPS
    53DNS3389RDP
    Part 3: Network attacks
    AttackWhat happensTypical defence
    DoS / DDoSOverwhelms a service so real users cannot reach itRate limits, traffic scrubbing, redundancy
    SYN floodMany half-open TCP handshakes exhaust the serverSYN cookies, firewall limits
    Packet sniffingCapturing traffic to read itEncryption (HTTPS, VPN)
    On-path attackAttacker sits between two parties to read or change trafficTLS, certificate checks
    IP / ARP / DNS spoofingFaking an address or record to redirect or impersonateFiltering, DNSSEC, ARP inspection
    Smurf / ping of deathAbusing ICMP to flood or crash a targetBlock or limit ICMP, patch

    Only test attacks on systems you own or have written permission to test.

    Part 4: Defences, segmentation and hardening
    • Firewall: allows or blocks traffic by rules (addresses, ports, protocols). Stateless checks each packet alone; stateful tracks the connection; next-generation firewalls also inspect applications.
    • IDS detects and alerts; IPS detects and blocks. A proxy relays requests on a client’s behalf. A VPN creates an encrypted tunnel across an untrusted network.
    • Segmentation: divide the network into zones (VLANs, subnets, a DMZ for public servers) so a breach in one area cannot freely spread.
    • Hardening: reduce weak spots by patching, disabling unused services and ports, removing default passwords, enforcing MFA, using secure configuration baselines, and backing up.
    • Cloud networks: use the same ideas (virtual networks, security groups, least privilege) and remember the shared responsibility between provider and customer.

    3. 15 must-know terms

    TermPlain meaning
    PacketSmall unit of data sent over a network
    IP addressLogical address of a device
    MAC addressHardware address of a network card
    PortNumbered doorway to a service on a device
    TCP / UDPReliable delivery / fast, no-guarantee delivery
    DNSPhone book turning names into IPs
    DHCPAutomatic address assignment
    ARPFinds the MAC for an IP locally
    SubnetA smaller slice of a network
    FirewallRule-based traffic filter
    VPNEncrypted tunnel over an untrusted network
    Proxy serverMiddleman for requests
    DMZSemi-isolated zone for public-facing servers
    Network segmentationSplitting a network into isolated zones
    HardeningTightening configuration to cut weaknesses

    4. Three worked examples

    Example 1: Trace a web request

    Scenario: You open a secure website by name.

    Steps: (1) DNS converts the name to an IP. (2) Your device opens a TCP connection to port 443 using the three-way handshake. (3) TLS sets up encryption. (4) Your browser sends an HTTPS request; the server replies. (5) Routers forward packets between networks; ARP and switches handle the local hop. Takeaway: several layers cooperate, so a fault or attack can sit at any of them.

    Example 2: Write firewall rules

    Scenario: A small office runs a public web server and wants staff to reach it only through the office network for admin.

    Rules (in order): allow inbound TCP 443 from anywhere to the web server; allow inbound TCP 22 only from the office IP range; deny everything else inbound. Why: allow what is needed, deny by default, and restrict admin access.

    Example 3: Spot a SYN flood in logs

    Scenario: A server log shows thousands of SYN packets per second from many addresses, with almost no ACKs completing, and legitimate users time out.

    Reasoning: handshakes are starting but never finishing, which ties up resources. Answer: SYN flood, a type of DoS. Response: enable SYN cookies or rate limits, ask the upstream provider for DDoS filtering, and record the event for the incident report.

    5. Common mistakes

    • Mixing up IP and MAC addresses. IPs route between networks; MACs deliver on the local segment.
    • Memorising OSI layers without examples. Tie each layer to one protocol or device.
    • Thinking a VPN makes you anonymous or safe. It encrypts the tunnel; the endpoint and your device still matter.
    • Allow-all firewall rules “just to test”. Temporary rules often stay forever. Default deny is safer.
    • Confusing IDS and IPS. Detection alerts; prevention blocks.
    • Skipping the basics of hardening. Default passwords and unneeded open ports are among the easiest wins for attackers.

    6. 10 practice questions (tap to reveal)

    Q1. Which OSI layer handles routing between networks?

    Layer 3, Network. Routers use IP addresses to forward packets.

    Q2. Why does TCP use a handshake and UDP does not?

    TCP confirms both sides are ready and tracks delivery for reliability. UDP skips this to be faster, which suits streaming and DNS lookups.

    Q3. What does DNS do when you type a website name?

    It translates the name into an IP address so your device knows where to send traffic.

    Q4. Which port normally carries HTTPS traffic?

    443. HTTP uses 80 and is not encrypted.

    Q5. How is a stateful firewall different from a stateless one?

    A stateful firewall remembers active connections and allows return traffic for them; a stateless firewall judges every packet on its own rules only.

    Q6. What problem does a VPN solve on public Wi-Fi?

    It encrypts traffic between your device and the VPN endpoint, making sniffing on the local network much less useful.

    Q7. An attacker sends forged ARP replies so your traffic passes through their laptop. Name the attack.

    ARP spoofing, which enables an on-path attack. Defences include ARP inspection and encrypted protocols.

    Q8. How does segmentation limit damage from a compromised workstation?

    It places systems in separate zones with controlled paths between them, so the attacker cannot reach sensitive servers freely.

    Q9. Why put a public web server in a DMZ?

    If it is compromised, the attacker is still outside the internal network, which has stricter rules.

    Q10. List three simple hardening steps for a new server.

    Apply patches, disable unused services and ports, replace default credentials. Enabling MFA and logging are also good answers.

    7. YouTube search links

    8. One-screen revision summary

    • Models: TCP/IP (4 layers) and OSI (7 layers).
    • Addresses: IP routes between networks; MAC delivers locally; ports pick the service.
    • Protocols: TCP reliable (SYN, SYN-ACK, ACK); UDP fast; DNS names to IPs; DHCP assigns IPs; ARP maps IP to MAC.
    • Key ports: 22 SSH, 53 DNS, 80 HTTP, 443 HTTPS, 3389 RDP.
    • Attacks: DoS/DDoS, SYN flood, sniffing, on-path, spoofing, ICMP abuse.
    • Defences: firewall (stateless, stateful, next-gen), IDS/IPS, VPN, proxy.
    • Segmentation: zones, VLANs, DMZ limit spread.
    • Hardening: patch, close ports, change defaults, MFA, baselines, backups.

    9. What you should be able to do

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.