Lab-based learning · Updated weekly

Network security & SASE, decoded for L1–L3 engineers.

Start with one product (how it works, then evidence). Then follow a course path so a student can actually finish Zscaler, Palo Alto, Fortinet, Cisco, F5 or CISSP.

80
Course lessons
7
Course paths
1,400+
Practice MCQs
Free
Forever

Loading product directory…

💼
Crack the interview · Tag-wise

Interview Q&A Hub

34 question banks across 10 tracks — Palo Alto, Zscaler, FortiGate, CCNA, BGP, SOC, VAPT and more. Real questions, model answers & an assessment in every set.

Browse Q&A
🎮
New · Learn by playing

Cyber Arena

Race the clock against 1,400+ real exam-style questions across 16 tracks. Daily Challenge, combos, XP & ranks — the science-backed way to make it stick.

Play now

Finish a course, not a random page

Course paths students actually complete

Each path is a classroom sequence: concept, packet path, config, proof, then interview. Old mass-generated pages are off this library.

Complete the ZIA + ZPA course

Zscaler

Fourteen classroom lessons plus the gold authentication and tunnel runbooks. Read in order.

Lessons in the library

Only course-complete lessons. Pick a vendor chip, then read in path order.

Curated 2026-08-15
ZS

Start · How the exchange works

Zscaler · ZIA / ZPA · How it works

How the Zscaler exchange actually works: who is the user, how traffic arrived, which window (ZIA, ZPA, ZDX, Branch) touched the flow, then prove the app answered. Location vs user auth,…

Course path· How it works
Read lesson
ZS

Start · Prove it in logs

Zscaler · ZIA / ZPA · Evidence

Night-shift Zscaler evidence desk: dummy CLI from the Techclick lab, what you say, the next command, and when to isolate versus open change-control. ZIA inspect vs pin, ZPA allow vs…

Course path· Evidence
Read lesson
ZS

01 · Zero Trust foundation

Zscaler · ZIA / ZPA · Foundation

Lesson 1 of the Zscaler Batch 11 course. Zero Trust Architecture, SASE vs SSE, Zscaler Zero Trust Exchange, ZIA vs ZPA vs ZDX, Public Service Edge, Central Authority and Nanolog —…

Course path· Foundation
Read lesson
ZS

02 · ZIA architecture

Zscaler · ZIA / ZPA · Architecture

Lesson 2 of Zscaler Batch 11. Deep dive into ZIA architecture — every cloud component (CA, PSE, Nanolog), Sub-Clouds, Trust Pools, the full user request packet walkthrough, and a guided…

Course path· Architecture
Read lesson
ZS

03 · Traffic forwarding

Zscaler · ZIA / ZPA · Forwarding

Lesson 3 of Zscaler Batch 11. The 5 ways to forward user traffic into ZIA — GRE, IPSec, PAC, ZCC (Z-Tunnel 1.0/2.0), DNS — when to pick each, real MTU/NAT-T/PAC gotchas, and a…

Course path· Forwarding
Read lesson
ZS

GRE and IPSec tunnels

Zscaler · ZIA / ZPA · Forwarding

Learn Zscaler ZIA GRE and IPSec tunnel setup end-to-end: when to use GRE vs IPSec, dual-DC HA, Admin Console steps, router-side config, lab portal screenshots, free practice simulator…

Course path· Forwarding
Read lesson
ZS

ZIA traffic flow end to end

Zscaler · ZIA / ZPA · Forwarding

Follow one normal website request through Zscaler ZIA in plain English, then practise with matching, flip cards, a short lab, and a 10-question test.

Course path· Forwarding
Read lesson
ZS

04 · Authentication and ZCC

Zscaler · ZIA / ZPA · Identity

Lesson 4 of Zscaler Batch 11. Authentication options (Hosted DB / SAML / Kerberos), IdP integration with Azure AD / Okta / Ping, full SAML assertion walkthrough, SCIM provisioning,…

Course path· Identity
Read lesson
ZS

SAML + SCIM with Entra ID

Zscaler · ZIA / ZPA · Identity

Best-practice ZIA authentication lesson: why identity matters, decision flow, method choice, full Microsoft Entra ID (Azure AD) SAML+SCIM runbook, PAC…

Course path· Identity
Read lesson
ZS

05 · URL and Cloud App control

Zscaler · ZIA / ZPA · Policy

Lesson 5 of Zscaler Batch 11. URL Filtering policy (categories, custom URLs, time quotas, super-categories) + Cloud App Control (sanctioned/unsanctioned SaaS, tenant restrictions) +…

Course path· Policy
Read lesson
ZS

06 · SSL inspection

Zscaler · ZIA / ZPA · Policy

Lesson 6 of Zscaler Batch 11. SSL Inspection deep dive — why inspect, cert chain, Zscaler Root CA distribution, MITM concept, pinned-app exemptions, common SSL break troubleshooting —…

Course path· Policy
Read lesson
ZS

07 · Threat protection

Zscaler · ZIA / ZPA · Policy

ZIA

Course path· Policy
Read lesson
ZS

08 · DLP and CASB

Zscaler · ZIA / ZPA · Data

Lesson 8 of Zscaler Batch 11. ZIA Data Protection deep dive — DLP dictionaries, EDM and IDM fingerprinting, composite rules, and CASB Inline vs Out-of-Band — with two SVGs and a…

Course path· Data
Read lesson
ZS

09 · ZPA architecture

Zscaler · ZIA / ZPA · ZPA

Lesson 9 of Zscaler Batch 11. ZPA architecture from the inside — the four moving parts, the double inside-out tunnel, why your private apps stop having public IPs, and how ZPA replaces…

Course path· ZPA
Read lesson
ZS

10 · App / Branch / Cloud Connector

Zscaler · ZIA / ZPA · ZPA

Lesson 10 of Zscaler Batch 11. Deploy ZPA App, Branch, and Cloud Connectors in production — sizing, HA pairing, AWS/Azure/VMware install, registration, and the boot-time firewall + OS…

Course path· ZPA
Read lesson
ZS

11 · ZPA policy and segments

Zscaler · ZIA / ZPA · ZPA

Lesson 11 of Zscaler Batch 11. Build real Zero Trust with the ZPA 4-tier hierarchy — App Segments, Segment Groups, Server Groups, Access Policy — plus Posture, Timeout, and App…

Course path· ZPA
Read lesson
ZS

12 · CBI and SIPA

Zscaler · ZIA / ZPA · ZPA

Lesson 12 of Zscaler Batch 11. CBI pixel-streams risky web to unmanaged devices; SIPA pins egress to stable IPs your SaaS admin can whitelist. Diagrams, war-stories, 10 scenario MCQs.

Course path· ZPA
Read lesson
ZS

13 · Logs, ZDX, five tickets

Zscaler · ZIA / ZPA · Troubleshoot

Lesson 13 of Zscaler Batch 11. ZIA Insights, ZPA Diagnostics, NSS streaming to SIEM, ZDX user-experience monitoring, and the 5 production troubleshooting patterns L3 engineers diagnose…

Course path· Troubleshoot
Read lesson
ZS

14 · ZDTA and interview

Zscaler · ZIA / ZPA · Interview

The ZDTA blueprint by domain weight, a 4-week study plan, exam-day tactics, and the 25 real scenario interview questions L3 SASE candidates actually face — with model answers.

Course path· Interview
Read lesson
PA

Start · Session factory

Palo Alto · PAN-OS · How it works

PAN-OS session factory lesson: first-packet path, c2s/s2c, App-ID incomplete trap, application-default, NAT vs policy, finance-saas runbook, and a scored quiz.

Course path· How it works
Read lesson
PA

Start · Evidence desk

Palo Alto · PAN-OS · Evidence

PAN-OS evidence desk: night-shift tickets with dummy CLI from the Techclick simulator. Predicted vs live rule, 0 s2c, stale User-ID, HA green, isolate vs change-control.

Course path· Evidence
Read lesson
PA

Architecture and SP3

Palo Alto · PAN-OS · Architecture

Deep-dive into Palo Alto NGFW architecture — SP3 design, management vs dataplane, the 6-stage packet flow, session offload, and the production gotchas that interviewers love to ask.…

Course path· Architecture
Read lesson
PA

Zones, interfaces, VR

Palo Alto · PAN-OS · Forwarding

The forwarding skeleton of every PAN-OS firewall — interface modes (L3, L2, vwire, tap, sub-IF, tunnel, loopback, aggregate), security zones with intrazone-allow / interzone-deny…

Course path· Forwarding
Read lesson
PA

Security policy

Palo Alto · PAN-OS · Policy

How PAN-OS security policy rules actually evaluate — top-down, first-match wins, intrazone-allow / interzone-deny defaults. The application-default vs service-port distinction,…

Course path· Policy
Read lesson
PA

Security profiles

Palo Alto · PAN-OS · Policy

Palo Alto Security Profiles & Profile Groups for PCNSE/PCNSA: the six profiles on an allow rule, default vs strict, profile actions, and a profile group on every rule.

Course path· Policy
Read lesson
PA

NAT

Palo Alto · PAN-OS · Forwarding

Palo Alto NAT explained the AI-era way — pick a NAT type, watch the packet header transform live, run the in-page packet builder, and learn NAT order-of-operations + port-exhaustion…

Course path· Forwarding
Read lesson
PA

SSL decryption

Palo Alto · PAN-OS · Policy

Palo Alto SSL/TLS decryption — Forward Proxy vs Inbound Inspection, Decryption Profiles, the No-Decrypt list, TLS 1.3 and cert-pinning breakage, taught the AI-era way. Pick a path, watch…

Course path· Policy
Read lesson
PA

URL filtering

Palo Alto · PAN-OS · Policy

Palo Alto Advanced URL Filtering for L1/L2 & PCNSE: URL categories, the 5 site-access actions, credential-phishing prevention, inline ML and SSL decryption.

Course path· Policy
Read lesson
PA

Threat prevention

Palo Alto · PAN-OS · Policy

Palo Alto Threat Prevention for PCNSE/PCNSA: Anti-Spyware vs Vulnerability Protection, per-severity actions, DNS sinkhole, threat-ID exceptions, Threat Vault and inline cloud ML.

Course path· Policy
Read lesson
PA

GlobalProtect

Palo Alto · PAN-OS · VPN

Palo Alto GlobalProtect explained the AI-era way — watch a GP client log in step by step, master Portal vs Gateway roles, HIP enforcement, SAML SSO with Entra ID, split-tunnel routes and the

Course path· VPN
Read lesson
PA

IPSec site-to-site

Palo Alto · PAN-OS · VPN

Palo Alto IPSec site-to-site VPN explained the AI-era way — watch IKE Phase 1 + Phase 2 SA establishment animate live, fix the AWS / Azure proxy-ID mismatch trap, master DPD vs…

Course path· VPN
Read lesson
PA

PBF and multi-VR

Palo Alto · PAN-OS · Routing

Palo Alto PBF + Multi-VR explained the AI-era way — watch a PBF rule override the FIB live, learn when Symmetric Return is mandatory, see multi-VR with next-vr powering dual-ISP designs,…

Course path· Routing
Read lesson
PA

HA A/P vs A/A

Palo Alto · PAN-OS · HA

Palo Alto HA explained the AI-era way — watch an Active/Passive failover animate live, see how Active/Active floating IPs and session owners actually work, and master the election,…

Course path· HA
Read lesson
PA

Session table and flow

Palo Alto · PAN-OS · Operations

The Palo Alto session lifecycle — animated. State machine, hardware offload, predict sessions, ageout, and full show session id field decoding. 13 minutes to mastery.

Course path· Operations
Read lesson
PA

Interview Q&A

Palo Alto · PAN-OS · Interview

Palo Alto firewall interview questions and answers (2026, PCNSE-aligned) — SP3 architecture, the PAN-OS packet flow, App-ID/Content-ID/User-ID, NAT…

Course path· Interview
Read lesson
FG

Start · Session + VDOM

Fortinet · FortiOS · How it works

FortiGate session factory: VDOM, zone, policy, SNAT and SD-WAN stamp one session. Read proto_state before you add another accept.

Course path· How it works
Read lesson
FG

Start · Evidence desk

Fortinet · FortiOS · Evidence

FortiGate evidence desk: night-shift tickets closed with dummy diagnose output. proto_state, SLA vs up, HA standby. Isolate before you change.

Course path· Evidence
Read lesson
FG

Policies and NAT

Fortinet · FortiOS · Policy

FortiGate firewall policies + NAT explained the AI-era way — watch the policy lookup live, decode Central NAT vs per-policy NAT, VIP and IP Pool, and ace the implicit-deny interview…

Course path· Policy
Read lesson
FG

Security profiles

Fortinet · FortiOS · Policy

FortiGate security profiles in 11 visual minutes — flow vs proxy inspection, Web Filter, App Control, IPS, AV, SSL deep-inspection done right, and the CVE-2024-21762 sig check L2s must know.

Course path· Policy
Read lesson
FG

Routing OSPF/BGP

Fortinet · FortiOS · Routing

FortiGate routing demystified — lookup order, static + policy route, ISDB, OSPF and BGP — with hand-drawn SVGs, packet visualizers, and 10 interview-grade scenarios in 11 minutes.

Course path· Routing
Read lesson
FG

IPsec and SSL VPN

Fortinet · FortiOS · VPN

FortiGate IPsec site-to-site and SSL VPN explained the AI-era way — IKE Phase 1+2 visualised, NAT-T, DPD, FortiToken 2FA, CVE-2024-21762 + symlink persistence audit, in 11 minutes.

Course path· VPN
Read lesson
FG

SD-WAN SLA rules

Fortinet · FortiOS · SD-WAN

FortiGate SD-WAN explained — performance SLA tuning, 5 rule strategies (Manual, Best Quality, Lowest Cost SLA, Maximize Bandwidth, Auto), ISDB path selection, and the FortiSASE bridge in…

Course path· SD-WAN
Read lesson
FG

SD-WAN + ZTNA

Fortinet · FortiOS · SD-WAN

FortiGate SD-WAN + ZTNA end-to-end: zones, members, performance SLAs, application steering rules, BGP-over-IPsec overlay, ZTNA Access Proxy with FortiClient EMS posture tags, and the…

Course path· SD-WAN
Read lesson
FG

VDOMs

Fortinet · FortiOS · Architecture

FortiGate VDOMs — split-task vs multi-VDOM, inter-VDOM links, NPU offload, MSP multi-tenancy, admin scopes, the FortiJump ADOM lesson, in 11 minutes.

Course path· Architecture
Read lesson
FG

FGCP HA

Fortinet · FortiOS · HA

FortiGate HA explained the AI-era way — FGCP Active-Passive vs Active-Active, split-brain recovery, session-pickup, override priority and an HA-aware upgrade in 11 minutes.

Course path· HA
Read lesson
FG

Interview Q&A

Fortinet · FortiOS · Interview

80 evidence-based FortiGate interview questions from beginner to L3, with FortiOS commands, packet flow, NAT, VPN, SD-WAN, HA, FortiManager, FortiAnalyzer…

Course path· Interview
Read lesson
CS

Start · LINA + Snort

Cisco · FTD / ISE · How it works

Interactive Cisco Secure Firewall lesson: FTD is LINA plus Snort. Never troubleshoot standby. packet-tracer is predicted; show conn flags are live. ACP Allow can still die in IPS.

Course path· How it works
Read lesson
CS

Start · Evidence desk

Cisco · FTD / ISE · Evidence

Night-shift Cisco Secure Firewall evidence desk. Dummy ciscoftd CLI: show failover, packet-tracer, show conn flags saA vs UIO, ACP Allow plus IPS. Isolate before you change.

Course path· Evidence
Read lesson
CS

FTD / FMC fundamentals

Cisco · FTD / ISE · Foundation

A clear, interactive guide to what Cisco Secure Firewall really is (2026): FTD (Firepower Threat Defense) — one unified image with two engines, the ASA-derived LINA data plane plus the…

Course path· Foundation
Read lesson
CS

Architecture and platforms

Cisco · FTD / ISE · Architecture

A deeper, interactive guide to Cisco Secure Firewall architecture and the platform family (2026): the LINA data plane versus the Snort inspection engine and how a packet is handed…

Course path· Architecture
Read lesson
CS

Interface modes

Cisco · FTD / ISE · Deploy

A clear, interactive guide to Cisco Secure Firewall Threat Defense deployment and interface modes (2026): device-wide firewall mode (routed L3 vs transparent L2 bridging with a BVI), and…

Course path· Deploy
Read lesson
CS

Access control policy

Cisco · FTD / ISE · Policy

A clear, interactive guide to the Cisco FTD Access Control Policy (2026): security zones and rule anatomy, the rule actions (Block, Allow, Trust, Monitor, Interactive Block), top-down…

Course path· Policy
Read lesson
CS

NAT

Cisco · FTD / ISE · Forwarding

A clear, interactive guide to NAT on Cisco Secure Firewall Threat Defense (2026): how NAT runs in the LINA data plane, Auto NAT (object NAT) vs Manual NAT (twice NAT), the three rule…

Course path· Forwarding
Read lesson
CS

VPN

Cisco · FTD / ISE · VPN

A clear, interactive guide to VPN on Cisco Secure Firewall Threat Defense (2026): site-to-site IKEv2/IPsec — policy-based (crypto-map/ACL) vs route-based with a VTI — FMC topologies…

Course path· VPN
Read lesson
CS

Snort 3 IPS

Cisco · FTD / ISE · IPS

A clear, interactive guide to the Snort 3 NGIPS engine on Cisco Secure Firewall Threat Defense (FTD) in 2026: why Snort 3 replaced Snort 2, how an intrusion policy attaches per-rule to…

Course path· IPS
Read lesson
CS

FTD interview

Cisco · FTD / ISE · Interview

Prepare for Cisco Secure Firewall (FTD & FMC) interviews with 10 real questions and model answers covering the unified LINA + Snort architecture, FMC vs FDM vs CDO, the Access Control…

Course path· Interview
Read lesson
CS

ISE · reason code first

Cisco · FTD / ISE · Identity

Cisco ISE session factory: quote the Live Log reason code, not RADIUS failed. Policy set, identity store 22056, profiling, posture after Auth-Accept, CoA, and NAD — with flows, portal…

Course path· Identity
Read lesson
CS

ISE · evidence desk

Cisco · FTD / ISE · Evidence

Cisco ISE evidence desk: night-shift tickets decided by dummy lab output. Quote 22056, split process health from Live Logs, isolate vs change-control, posture after Auth-Accept.

Course path· Evidence
Read lesson
CS

ISE interview

Cisco · FTD / ISE · Interview

Cisco ISE interview Q&A — 71 senior-grade questions covering architecture, personas, 802.1X/MAB/WebAuth, TrustSec SGT/SGACL, profiling, posture, BYOD…

Course path· Interview
Read lesson
F5

Start · VIP is a listener

F5 · BIG-IP · How it works

F5 BIG-IP factory lesson: a virtual is a listener, not the app. Decide VIP vs pool vs persist vs client-ssl vs SNAT vs active unit, then prove it in dummy tmsh.

Course path· How it works
Read lesson
F5

Start · Evidence desk

F5 · BIG-IP · Evidence

Night-shift F5 evidence desk: dummy tmsh from the Techclick simulator. What you say, next command, isolate vs change-control, three full tickets.

Course path· Evidence
Read lesson
F5

Command ladder cheatsheet

F5 · BIG-IP · Troubleshoot

A printable F5 BIG-IP troubleshooting cheatsheet and command ladder for 2026: which tmsh command answers which question, how to read availability Reason lines, pool member status,…

Course path· Troubleshoot
Read lesson
F5

Interview Q&A

F5 · BIG-IP · Interview

71+ real F5 BIG-IP interview questions with detailed, student-friendly answers — LTM Virtual Servers, pools, load balancing, persistence, SNAT, SSL…

Course path· Interview
Read lesson
C8

All 8 domains map

CISSP · ISC2 · Overview

CISSP 2026 explained: all 8 domains, realistic India and global salaries, DoD 8140 value, plus the AI security risks now layered onto every domain. Start…

Course path· Overview
Read lesson
C8

Domain 1 · Risk

CISSP · ISC2 · Domain

CISSP Domain 1 (Security and Risk Management) explained: CIA triad, governance, risk management, DPDP/GDPR compliance, BCP, and the AI angle. Free quiz, objectives, and sources.

Course path· Domain
Read lesson
C8

Domain 2 · Assets

CISSP · ISC2 · Domain

CISSP Domain 2 Asset Security deep dive: data classification, owner vs custodian roles, data states, NIST 800-88 destruction, DLP, DPDP/GDPR privacy and AI assets.

Course path· Domain
Read lesson
C8

Domain 3 · Architecture

CISSP · ISC2 · Domain

CISSP Domain 3 deep-dive: secure design principles, Bell-LaPadula and Biba models, post-quantum cryptography (FIPS 203/204/205), and physical security. 13% of the exam.

Course path· Domain
Read lesson
C8

Domain 4 · Network

CISSP · ISC2 · Domain

CISSP Domain 4: Communication and Network Security (13%). Learn secure network design, zero trust segmentation, TLS 1.3/IPsec, and network attack defenses — exam-ready.

Course path· Domain
Read lesson
C8

Domain 5 · IAM

CISSP · ISC2 · Domain

Master CISSP Domain 5: Identity and Access Management (IAM). AAA, MFA factors, SAML/OIDC/SCIM federation, RBAC/ABAC and PAM — exam-ready, with NIST 800-63B and DPDP context.

Course path· Domain
Read lesson
C8

Domain 6 · Assessment

CISSP · ISC2 · Domain

CISSP Domain 6 Security Assessment and Testing deep-dive: assessment strategy, VA vs pen testing, SOC 1/2/3 audits, log review, code review and security metrics. Exam-ready.

Course path· Domain
Read lesson
C8

Domain 7 · Operations

CISSP · ISC2 · Domain

CISSP Domain 7 Security Operations deep-dive: SIEM monitoring, NIST SP 800-61r3 incident response, digital forensics chain of custody, and DR/BC resilience. Worth 13% of the exam.

Course path· Domain
Read lesson
C8

Domain 8 · Software

CISSP · ISC2 · Domain

CISSP Domain 8 deep-dive: secure SDLC, DevSecOps, OWASP Top 10:2025, SAST/DAST/SCA testing, and software supply chain, API and CI/CD security. Exam-ready with real-world examples.

Course path· Domain
Read lesson
SOC

SOC analyst interview

SOC · Operations · Interview

54+ real SOC Analyst & SIEM interview questions with detailed, student-friendly answers covering SOC tiers, alert triage, MITRE ATT&CK, the kill chain, SIEM…

Course path· Interview
Read lesson
SOC

Wireshark interview

SOC · Operations · Interview

63+ real Wireshark & Packet Analysis interview questions with detailed, student-friendly answers covering capture vs display filters, the TCP handshake…

Course path· Interview
Read lesson
SOC

Linux interview

SOC · Operations · Interview

59+ real Linux for Security & Network Engineers interview questions with detailed, student-friendly answers covering permissions, processes, networking…

Course path· Interview
Read lesson
SOC

VAPT interview

SOC · Operations · Interview

54+ real VAPT / Penetration Testing interview questions with detailed, student-friendly answers covering the pentest methodology, OWASP Top 10, tools (nmap…

Course path· Interview
Read lesson
SOC

22 browser CLI labs

SOC · Operations · Labs

You do not need a rack, a licence or a VM to build CLI muscle memory. Twenty-two browser simulators covering PAN-OS, FortiOS, Cisco, F5, Check Point, SRX and Zscaler, plus the…

Course path· Labs
Read lesson