Querytech Academy Querytech Academy Academy
Part of the Cybersecurity Defense Architect Pathway

Cybersecurity Defense Professional (Foundation Certificate)

Become a cyber defender: protect systems, detect threats and respond to incidents. Networking, endpoints and cryptography, then detection and vulnerability work, then security architecture and incident response -- across three progressive terms.

About 452 hours of real coursework

Enroll in this Pathway
The Credential

Cybersecurity Defense Professional (Foundation Certificate)

Finishing every course is not what earns this credential. You earn it by demonstrating all 13 required competencies through real, assessed evidence, then bringing them together in the Project below — reviewed end to end, not graded on attendance.

Professional & Solution Architecture

  • Identify the Underlying Problem
  • Elicit Functional Requirements

Cybersecurity and Digital Defense

  • Network Security Fundamentals
  • Threat Detection & Monitoring
  • Threat Reconnaissance & Analysis
  • Enterprise Security Architecture
  • Incident Response & Forensics
  • Networking for Defenders
  • Operating Systems & Endpoint Security
  • Security Fundamentals & Cryptography
  • Attack Techniques & the Kill Chain
  • Vulnerability Assessment & Management
  • Security Operations & Governance
Term 1 of 3 ₦300,000 / term

Fundamentals

Build the essential knowledge of a defender: how a network carries data, how operating systems and endpoints work, the cryptography you must reason about, and how an attack actually unfolds. You finish able to read traffic and investigate an endpoint.

"A short orientation. What defensive ("blue team") security is, the CIA triad, the defender's job across protect / detect / respond, how blue and red team work relate, and the ethics and law that bound the work. How the three levels build and where the pathway leads."

Included Modules
What Defensive Security Is
The CIA Triad & Core Concepts
Ethics & Law
How This Program Works & Where It Leads

"You cannot defend a network you do not understand. TCP/IP and the protocols, reading packets in Wireshark, how the common network attacks look on the wire, and how normal-vs-abnormal traffic is the first signal of a compromise."

Included Modules
TCP/IP & the Protocols
Reading Packets with Wireshark
DNS, HTTP & TLS on the Wire
Common Network Attacks
Network Architecture & Segmentation
Baseline & Anomaly

"The endpoint is where most attacks land. Windows and Linux internals for defenders -- users and privileges, processes, services, the registry and the filesystem, and the logs that matter -- then persistence mechanisms, endpoint hardening, and what EDR does."

Included Modules
Windows Internals for Defenders
Linux Internals for Defenders
Authentication & Privilege
Persistence Mechanisms
Endpoint Hardening
Endpoint Detection & Response

"The security principles and the cryptography a defender must be able to reason about -- not implement. Authentication vs authorization, hashing vs encryption, symmetric vs asymmetric, PKI and certificates, TLS, password storage and cracking, and the crypto mistakes that become vulnerabilities."

Included Modules
Security Principles
Hashing & Integrity
Encryption
PKI, Certificates & TLS
Passwords & Authentication

"You defend better when you understand the attack. The attack lifecycle -- reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement, exfiltration -- mapped to the MITRE ATT&CK framework, with the defensive control that counters each stage. Thinking like an attacker, to defend."

Included Modules
The Attack Lifecycle
Reconnaissance & Initial Access
Execution, Persistence & Escalation
Lateral Movement & Exfiltration
MITRE ATT&CK
Mapping Attacks to Defenses

Skills Gained at This Stage

  • Reading network traffic in Wireshark
  • Investigating a Windows or Linux endpoint
  • Reasoning about hashing, encryption and certificates
  • Mapping an attack to the kill chain and MITRE ATT&CK

Professional Competencies

  • • Networking for Defenders
  • • Operating Systems & Endpoint Security
  • • Security Fundamentals & Cryptography
  • • Attack Techniques & the Kill Chain

Industry Tools

Wireshark A Windows & Linux VM The event log / syslog MITRE ATT&CK
Term 2 of 3 ₦400,000 / term

Applied

Do the daily work of defense. Design network controls, build SIEM detections, run and prioritise a vulnerability scan, profile a threat, and bring it all together in a hands-on lab investigation. You finish able to detect and investigate an intrusion.

"Defending the network in practice. Firewalls and rule design, network segmentation and zero-trust segmentation, VPNs and secure remote access, IDS/IPS deployment and tuning, and network security monitoring -- the sensors, the traffic, and what to alert on."

Included Modules
Firewalls & Rule Design
Segmentation & Micro-segmentation
VPNs & Secure Remote Access
IDS / IPS
Network Security Monitoring
Defending Against the Common Attacks

"Turning logs into detections. Log sources and collection, a SIEM in practice (searching, correlating, dashboards), writing and testing detection rules against ATT&CK techniques, alert triage and prioritisation, and the discipline of tuning so the signal survives."

Included Modules
Log Sources & Collection
SIEM in Practice
Writing Detection Rules
Alert Triage & Prioritisation
Tuning & Noise
Detection Coverage

"Finding the weaknesses before an attacker does, and driving them down. Scanning with a real scanner (Nessus / OpenVAS), reading and validating results, CVSS and risk-based prioritisation, patch and remediation management, and running a vulnerability-management cycle that actually closes findings."

Included Modules
What a Vulnerability Is
Scanning
Reading & Validating Results
Prioritisation
Remediation & the Management Cycle

"Understanding the adversary. OSINT technique and tooling, mapping your own external attack surface the way an attacker would, threat-actor profiling, tracking vulnerabilities relevant to your stack, and turning it into threat intelligence a defender can act on."

Included Modules
OSINT Fundamentals & Tooling
Mapping Your Attack Surface
Threat-Actor Profiling
Vulnerability & Exploit Tracking
Threat Intelligence
Reporting

"A hands-on practicum in a virtual lab. Wireshark, Nmap, a SIEM (Splunk or ELK), Suricata / Snort, and an endpoint agent -- used together on a realistic scenario: a simulated intrusion, from first alert to a written finding. The course where the Applied skills come together before the Project."

Included Modules
Building the Lab
Reconnaissance & Scanning Tools
Traffic & Packet Analysis
The SIEM Investigation
End-to-End Scenario

Skills Gained at This Stage

  • Designing and tuning firewall and IDS rules
  • Writing SIEM detections against MITRE ATT&CK
  • Running and prioritising a vulnerability scan
  • OSINT on your own attack surface
  • A full lab investigation from alert to finding

Professional Competencies

  • • Network Security Fundamentals
  • • Threat Detection & Monitoring
  • • Vulnerability Assessment & Management
  • • Threat Reconnaissance & Analysis

Industry Tools

Nmap Suricata / Snort A SIEM (Splunk / ELK) A vulnerability scanner (Nessus / OpenVAS) A virtual lab
Term 3 of 3 ₦375,000 / term

Professional

Architect the defense and run the response. Threat-model an environment and write a security design, apply a framework at organisational scale, run an incident end to end with forensics, and operate security as a function -- then prove it in the Professional Cyber Defense Project.

"From "we need a firewall" to "what are we protecting, from whom, and what does the defense actually need to do?" Threat modelling, risk assessment, eliciting security requirements from a business context, and producing a defensible security design a team could implement and you could justify to a decision-maker. First in-program vehicle for the two Solution Architecture competencies."

Included Modules
Problem vs Proposed Solution
Threat Modelling
Risk Assessment
Eliciting Security Requirements
Designing the Control Set
The Security Design Document

"Defense at organisational scale. Defense in depth and zero-trust architecture, identity as the perimeter, the standard frameworks (NIST CSF, ISO 27001, CIS Controls) and how to use them without drowning, security policy, and threat modelling a whole environment rather than one system."

Included Modules
Security Architecture Principles
Defense in Depth
Zero Trust
Frameworks in Practice
Security Policy & Standards
Enterprise Threat Modelling

"When prevention fails. The incident-response lifecycle (prepare, detect, contain, eradicate, recover, learn), evidence collection and chain of custody, disk and memory forensics fundamentals, timeline analysis, post-incident reporting, and running a tabletop exercise."

Included Modules
The IR Lifecycle
Preparation
Containment & Eradication
Evidence & Chain of Custody
Forensics Fundamentals
Timeline & Root Cause
Reporting & the Tabletop

"How defensive security runs as a function, not a project. The SOC and its tiers, on-call and shift handover, runbooks and playbooks, the metrics that show whether the programme is working, security awareness, and the governance and compliance work that keeps it aligned with the business."

Included Modules
The SOC
Runbooks & Playbooks
Metrics & Reporting
Security Awareness
Governance & Compliance Operations

Skills Gained at This Stage

  • Threat-modelling an environment and writing a security design
  • Applying a framework (NIST CSF / ISO 27001)
  • Running an incident end to end with forensics
  • Operating security as a function

Professional Competencies

  • • Identify the Underlying Problem
  • • Elicit Functional Requirements
  • • Enterprise Security Architecture
  • • Incident Response & Forensics
  • • Security Operations & Governance

Industry Tools

A threat-modelling method (STRIDE) A risk register NIST CSF / ISO 27001 A forensics toolkit An incident-response playbook
The Project

Professional Cyber Defense Project

A realistic environment threat-modelled, monitored, then an incident investigated and reported: discover the assets and threats, define the defensive design, stand up the detection, and respond to a simulated intrusion end to end. This is where the program's capabilities come together as integrated evidence -- not one more course.

  1. 1

    Discover

    A realistic environment: assets, exposure, and the threats that matter to it.

  2. 2

    Define

    A threat model, a risk assessment, and a defensive design.

  3. 3

    Engineer

    Monitoring and detections stood up in the lab; coverage mapped to ATT&CK.

  4. 4

    Execute

    A simulated incident investigated end to end, with a post-incident report and recommendations.

Ready to Start?

This program is part of the Cybersecurity Defense Architect — Emergence Pathway. You'll pick your starting cohort for Cybersecurity Defense Professional (Foundation Certificate) — the first program in the pathway — on the next step.

Reserve Your Spot