Network+ Week 7 Domain 3: Network Operations
How Real Networks Are Managed
Up to now, we've learned how networks work.
This week is about how organizations operate, monitor, maintain, and recover networks.
Think of it this way:
Weeks 1–6 = Building the network
Week 7 = Running the network
This is where IT Administrators, Network Engineers, and SOC Analysts spend much of their time.
Lesson 1: Network Documentation
Why Documentation Matters
Imagine you're hired by a company with:
50 switches
10 routers
500 computers
20 servers
What happens if nobody knows:
Which IP addresses are assigned?
Which VLANs exist?
What ports are connected where?
The network becomes a nightmare.
Types of Documentation
Network Diagram
Shows how devices connect.
Example:
Internet
|
pfSense
|
Switch
/ \
Kali WindowsA diagram helps engineers understand the network quickly.
IP Address Documentation
Example:
Device | IP Address |
|---|---|
pfSense | 192.168.10.1 |
Kali | 192.168.10.10 |
Windows | 192.168.10.20 |
Without documentation:
"What IP is the DNS server?"Nobody knows.
VLAN Documentation
Example:
VLAN | Purpose |
|---|---|
10 | Workstations |
20 | Servers |
30 | Guests |
This becomes extremely important in large environments.
Home Lab Application
Create a document containing:
VLANs
IP ranges
Device names
Operating systems
Switch ports
This is exactly what real organizations do.
Knowledge Check
Why is documentation important?
What information should a network diagram contain?
Lesson 2: Change Management
The Biggest Cause of Outages
Many outages happen because someone changed something.
Example:
Admin changes firewall rule
↓
Internet breaks
↓
Entire company affectedWhat Is Change Management?
A process used to control changes.
Instead of:
"Let's change it and see what happens."Organizations follow a procedure.
Typical Change Process
Request change
Review risk
Approve change
Schedule change
Implement change
Verify results
Document outcome
Example
Suppose you want to create VLAN 30 in your lab.
Bad approach:
Create VLAN
Hope it worksGood approach:
Document
Backup pfSense
Implement
Test
Document resultsKnowledge Check
Why is change management important?
What should happen before implementing major changes?
Lesson 3: Backups
What Is a Backup?
A backup is a copy of important data.
Examples:
Firewall configuration
Server files
Databases
User data
Why Backups Matter
Imagine:
pfSense crashesWithout backup:
Rebuild everythingWith backup:
Restore configurationMuch faster.
Types of Backups
Full Backup
Copies everything.
Advantages:
Easy restore
Disadvantages:
Large storage requirements
Incremental Backup
Copies only changes since last backup.
Advantages:
Small
Fast
Disadvantages:
More complicated restore
Differential Backup
Copies changes since last full backup.
Sits between full and incremental.
Home Lab Application
Back up:
pfSense config
Splunk config
Virtual machines
Important notes
Knowledge Check
What is a backup?
Which backup type copies everything?
Lesson 4: Disaster Recovery
What Is a Disaster?
Anything causing major disruption.
Examples:
Hardware failure
Fire
Flood
Ransomware
Power outage
Disaster Recovery
The plan used to restore operations.
Example:
Server fails
↓
Restore from backup
↓
Operations resumeImportant Terms
RTO
Recovery Time Objective
Question:
How quickly must we recover?
Example:
4 hoursMaximum acceptable downtime.
RPO
Recovery Point Objective
Question:
How much data can we lose?
Example:
30 minutesMaximum acceptable data loss.
Example
Backups occur every hour.
Server crashes.
Worst-case loss:
1 hourThat is the RPO.
Knowledge Check
What is RTO?
What is RPO?
Lesson 5: High Availability
Goal
Prevent downtime.
Single Point of Failure (SPOF)
A device whose failure breaks everything.
Example:
Internet
|
Router
|
Entire NetworkIf router dies:
Network diesRouter = SPOF
Redundancy
Add backup devices.
Example:
Internet
|
Router A
Router B
|
NetworkIf one fails:
The other continues working.
High Availability Benefits
Less downtime
Better reliability
Improved business continuity
Knowledge Check
What is a single point of failure?
What is redundancy?
Lesson 6: Syslog
One of the Most Important Lessons
Every network device creates logs.
Examples:
User logged in
Firewall blocked traffic
VPN connectedThese events are recorded.
What Is Syslog?
A standard way for devices to send logs.
Examples:
Routers
Firewalls
Switches
Linux servers
Home Lab Example
pfSense
|
Syslog
|
SplunkpfSense sends logs.
Splunk collects them.
Why SOC Analysts Love Logs
Logs help answer:
Who logged in?
What happened?
When did it happen?Knowledge Check
What is Syslog?
Why are logs important?
Lesson 7: SNMP
What Is SNMP?
Simple Network Management Protocol
Used to monitor network devices.
Example
SNMP can tell you:
CPU usage
Memory usage
Interface status
Uptime
Device health
Real Example
Network engineer asks:
Is Switch 5 overloaded?SNMP provides the answer.
SNMP Components
Managed Device
The device being monitored.
Example:
Switch
Router
FirewallSNMP Manager
The monitoring system.
Example:
Monitoring ServerAgent
Software running on the device.
The agent provides information to the manager.
Home Lab Application
Future setup:
Switch
pfSense
Windows
|
SNMP
|
Monitoring SystemKnowledge Check
What does SNMP stand for?
What is SNMP used for?
Week 7 Final Quiz
Why is network documentation important?
What should a network diagram show?
What is change management?
Why are backups important?
What is a full backup?
What is disaster recovery?
What does RTO measure?
What does RPO measure?
What is a single point of failure?
What is redundancy?
What is Syslog?
Why are logs important?
What does SNMP stand for?
What is SNMP used for?
In your home lab, what device could send Syslog data to Splunk?
Lab Mission After Week 7
Your goal is to understand this flow:
Kali
Windows
pfSense
Switch
|
Logs (Syslog)
|
SplunkThis is the beginning of a SOC environment.
Instead of just building networks, you're now learning how organizations:
Document them
Monitor them
Log activity
Recover from failures
Keep services available
Those are the skills that connect networking to cybersecurity and will help when you start working with SIEMs, incident response, and eventually CySA+.