Module 1: Wireless Network Fundamentals — Architecture, Standards and Signal Behavior
- Types of wireless networks (WLAN, WPAN, WMAN), infrastructure vs. ad hoc modes, and the roles of access points and clients
- The IEEE 802.11 standards family, frequency bands, spectrum usage, range, and throughput
- Signal propagation characteristics, common interference sources, and attenuation and multipath issues
Module 2: Security Fundamentals, Threats and Secure Design
- Confidentiality, integrity, and availability, and the principles of authentication, authorization, and secure communication
- Passive and active attacks, eavesdropping, man-in-the-middle threats, credential theft, and session hijacking
- Defense-in-depth, network segmentation strategies, and the secure design lifecycle for wireless projects
Module 3: Encryption and Authentication — WEP to WPA3, EAP/RADIUS and Key Management
- The evolution of WEP, WPA, WPA2, and WPA3, their known weaknesses, and transitioning to modern protocols
- EAP types, the role of RADIUS in enterprise authentication, and secure implementations such as PEAP and EAP-TLS
- Symmetric vs. asymmetric key usage, key distribution and rotation, and secure credential storage
Module 4: Access Control — MAC Filtering, Role-Based Access and NAC
- The limitations of MAC address filtering and the role of ACLs in wireless access control
- Assigning access by user role or device type, and integrating with identity providers
- Network Access Control: device posture checking, endpoint compliance, and guest/BYOD restrictions
Module 5: Hardening Access Points, Controllers and Physical Security
- Changing default configurations, controlling broadcast settings, and patching firmware vulnerabilities
- Centralized management, secure AP communication, and role-based administrative access
- Preventing unauthorized physical access, securing network closets and equipment, and removing rogue devices
Module 6: Detecting Threats — WIDS and Traffic Analysis
- Wireless Intrusion Detection System architecture, deployment options, and detection techniques
- Capturing and interpreting wireless packets to identify suspicious patterns
- Using open-source and commercial traffic-analysis tools
Module 7: Responding to Incidents — Alerting, Rogue Devices and Mitigation
- Configuring alert thresholds and integrating WIDS with SIEM platforms
- Active vs. passive scanning to identify and physically locate rogue access points
- Safely disconnecting rogue APs, isolating suspicious traffic, and containment best practices
Module 8: Wireless Security Policy, Compliance and Legal Requirements
- Defining policy scope, ownership, and approval, and building a no-tolerance wireless policy
- Acceptable-use guidelines: device rules, resource access controls, and sanctions for violations
- Regulatory frameworks such as GDPR and HIPAA, data retention mandates, and audit readiness
Module 9: Network Segmentation and Zero Trust Architecture
- Separating guest and internal networks using VLANs and SSID segmentation
- Containing high-risk zones through isolation
- Applying zero trust principles and continuous verification through micro-segmentation
Module 10: Cloud-Managed and Next-Generation Wireless
- The benefits and risks of cloud-based wireless controllers and the role of APIs and automation
- Securing communication with cloud management services
- Wi-Fi 6/6E/7 improvements in speed, security, and capacity, new encryption capabilities, and backward-compatibility concerns
Module 11: Emerging Threats — IoT and AI-Powered Attacks
- The growth of connected IoT devices and their authentication limitations
- Lightweight encryption approaches suited to constrained devices
- The role of automation in evolving attacks, the limits of behavior-based detection, and preparing for adaptive attack scenarios