← Back to catalog
Zero Trust Network Architecture cover image
Cybersecurity Intermediate

Zero Trust Network Architecture

Implement 'never trust, always verify' security perimeters with microsegmentation and identity-aware proxies.

Instructor Sarah Jenkins
Duration 165 minutes (4 lessons)
Estimated Effort 2.5 hours total (1.25 hrs/week over 2 weeks)
Price USD 59.00
USD 59.00 Full Lifetime Access

Sign in to track your learning progress.

Course Overview

Design identity-centric access control, dynamic device health verification, and encrypted network tunnels to secure remote workforces against lateral intrusion.

What You Will Learn

Implement 'Never Trust, Always Verify' principles across corporate networks
Design identity-aware proxies (IAP) to replace legacy VPN perimeters
Enforce microsegmentation policies between backend microservices
Verify device posture health dynamically before granting resource access
Implement mTLS (Mutual TLS) authentication for inter-service communication

Tools & Technologies Used

WireGuard Envoy Proxy Smallstep CA Python 3.11 Docker

Structured Curriculum

2 Modules  ·  4 Lessons  ·  165 Minutes Total

Module 1

Module 1: Zero Trust Core Principles & Identity Proxies

2 lessons

Deconstruct perimeter defenses and deploy Identity-Aware Proxies.

  • 📄

    Perimeter Security Failures vs. Zero Trust Architecture

    Analyze why internal networks can no longer be assumed trustworthy.

    Architecture Overview 40 min
  • 📄

    Identity-Aware Proxy Configuration

    Route HTTP requests through identity verification proxies with JWT assertion headers.

    Code Workshop 40 min
Module 2

Module 2: Microsegmentation & Mutual TLS (mTLS)

2 lessons

Encrypt and authenticate service-to-service communication.

  • 📄

    Service Microsegmentation & Policy Guards

    Enforce strict network isolation rules between database instances and app servers.

    Hands-on Exercise 40 min
  • 📄

    Configuring Automatic mTLS with Envoy

    Issue ephemeral X.509 client certificates to establish mutual TLS between microservices.

    Security Lab 45 min

Practical Project & Capstone Outcome

🚀 Capstone Project

Zero Trust Private Application Access Gateway

Build an identity-authenticated gateway service that verifies user identity, checks device posture tokens, and opens mTLS tunnels to internal web applications.

Prerequisites

  • Networking basics (IPs, Subnets, TLS/SSL)
  • Basic understanding of authentication

Intended Audience

  • Network Security Engineers modernizing perimeter security
  • Systems Engineers securing remote employee access and microservices

Instructor Information

S

Sarah Jenkins

Course Author & Industry Expert

Sarah Jenkins is a Senior Cybersecurity Consultant specializing in Zero Trust network transformations for distributed remote engineering organizations.

Frequently Asked Questions

Can I set up the mTLS hands-on lab locally using Docker?

Yes! All mTLS and proxy labs run locally using Docker containers and Smallstep PKI tools.