Skip to main content
CYB-0324ExpertCurrent Intake
XNDS

Xcademia Network and Cloud Defence Specialist

6-Day Instructor-Led Programme

The XNDS Certification Programme is the practitioner standard for network and cloud defence engineers who design secure network architectures, implement zero trust controls, govern cloud security posture, detect advanced network threats, and respond to network-layer incidents across enterprise environments. Assessed on Day 6 through a supervised network defence and threat detection exercise. No MCQs. No exam.

Duration

6 Days

Price

$4,995

Xcademia Network and Cloud Defence Specialist
Duration
6 Days
Complete in 6 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Modern enterprise networks are not bounded by a perimeter. Cloud workloads, remote users, SaaS applications, and OT convergence have dissolved the traditional network edge. The network defender who still thinks in perimeter terms will miss the attacker who moves laterally inside the trusted zone after phishing one user. XNDS is built for the defender who wants to operate at the architecture and detection level.

Across six instructor-led days, participants build capability across modern network defence: secure network architecture design with zero trust principles, next-generation firewall and IPS deployment and tuning, network traffic analysis and threat hunting, cloud network security across AWS, Azure, and GCP, zero trust network access implementation, endpoint detection and response integration with network visibility, DNS security and web filtering, network incident response, and network forensics from PCAP through to investigative timeline. Every session uses real network traffic, real attack scenarios, and current adversary techniques.

On Day 6, participants conduct a supervised network defence exercise: analysing a live threat scenario from network telemetry, identifying the attack, containing it at the network layer, and producing a structured incident and defence improvement report. A senior practitioner assesses detection methodology, containment decisions, and reporting quality. XNDS certificate and Practitioner Assessment Report issued together.

Hands-On Learning

Hands-on next-gen firewall rule analysis, IPS signature tuning, Zeek and Suricata network detection, cloud security group review across AWS and Azure, zero trust ZTNA design, DNS security configuration, and a full network defence and detection scenario on Day 6.

Mentor-Led Sessions

Mentor-led sessions examining real network attack campaigns from the defender perspective: what signals were present, which were missed, and how network architecture changes would have reduced the attack surface.

Career-Ready Skills

Design and operate enterprise network and cloud security controls, detect advanced threats from network telemetry, implement zero trust network access, and respond to network-layer incidents with professional investigation methodology.

Learning Outcomes

Design secure network architectures applying defence-in-depth, DMZ design, VLAN segmentation, and zero trust principles aligned to NIST SP 800-207

Deploy and tune next-generation firewalls, IPS, Zeek, and Suricata for enterprise network threat detection with ATT&CK-aligned detection coverage

Implement cloud network security controls across AWS VPC, Azure Virtual Networks, and GCP VPCs with cloud-native monitoring integration

Conduct network threat hunting using hypothesis-driven methodology applied to Zeek, NetFlow, and SIEM network telemetry

Investigate network-layer security incidents using PCAP analysis, network timeline reconstruction, and cloud flow log forensics

Design and implement ZTNA replacing legacy VPN architectures with identity-driven, device-posture-aware network access control

Prerequisites

1

Minimum 12 months in a network engineering, network security, or SOC role with hands-on firewall and network monitoring experience

2

Working knowledge of TCP/IP networking, firewall concepts, and at least one network monitoring tool

3

Basic familiarity with at least one cloud platform: AWS, Azure, or GCP at administrator level

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • Network security architecture principles: defence in depth, least privilege, and network segmentation methodology
  • DMZ design patterns: one-leg, two-leg, and screened subnet models for different organisational contexts
  • VLAN segmentation strategy: separating user, server, OT, IoT, and management traffic for containment
  • Software-defined networking security: control plane and data plane separation and SDN attack surface
  • Network architecture review methodology: identifying flat network risks, implicit trust, and segmentation gaps
Stage 5Final Capstone

Xcademia Network and Cloud Defence Specialist — Capstone Project

On Day 6, participants receive access to a simulated enterprise environment containing active malicious network traffic alongside normal baseline traffic. They must identify the attack from network telemetry using Zeek, Suricata, and SIEM correlation, contain it through network-layer controls, and produce a structured incident report with recommended network architecture improvements. The senior practitioner assesses detection methodology, containment decisions, and report quality.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • NIST SP 800-207

    Global

    Zero Trust Architecture: ZTNA implementation and microsegmentation throughout Days 3 and 4

  • MITRE ATT&CK v14

    Global

    Network-layer technique detection: C2, lateral movement, and exfiltration mapped to Zeek and Suricata rules

  • NCSC Cyber Essentials Plus

    Global

    UK government baseline network security controls: boundary firewalls, patching, and access control

  • NIS2 Article 21

    Global

    Security measures for essential entities: network monitoring and intrusion detection obligations

  • DORA Article 10

    Global

    ICT-related incident detection requirements: network monitoring obligations for EU financial entities

  • CIS Controls v8

    Global

    Safeguards 12 to 14: network infrastructure management, network monitoring, and service provider management

  • PCI DSS v4

    Global

    Network segmentation requirements for cardholder data environments: Requirement 1 and Requirement 10

Skills You'll Gain

Master these in-demand skills through hands-on practice

Network security architectureNGFW policy design (Palo Alto/Fortinet)Zeek network monitoringSuricata IDS/IPSZero trust network access (NIST 800-207)Cloud network security (AWS/Azure/GCP)DNS security and DGA detectionNetwork threat huntingPCAP forensicsNetwork incident containmentXDR platform operationNetwork security metrics

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Network Security EngineerCloud Security EngineerSOC Network AnalystNetwork Architect (Security)Zero Trust EngineerSecurity Operations Engineer
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

6 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,995+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Xcademia Network and Cloud Defence Specialist learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of Xcademia Network and Cloud Defence Specialist, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

CND is a $499 MCQ exam. SANS GDAT with SEC530 training totals approximately $9,779. XNDS is 6 instructor-led days covering modern network defence including zero trust, cloud network security across three platforms, and network forensics, assessed on Day 6 through a live detection and containment exercise. Less than half the GDAT total cost. Practitioner-assessed.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options