Skip to main content

Cybersecurity Education & Training Delivery II

Cybersecurity Education & Training Delivery II

Key information

Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: UPB
Awarding Institution: German University of Digital Science

Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350

Microcredential Information

In this module, students will learn how to design, implement, deploy and grade challenges as part of cybsersecurity contests (e.g. CTF – Capture the Flag). These are to be used as part of training and teaching activities that students will conduct themselves.

Key Details

The “Cybsersecurity Education and Training Delivery II” module aims to build the required skills for students to be creators of practical cybsersecurity contests and use competition-based learning in their educator role. Students will learn how to design, implement, deploy and grade challenges as part of cybsersecurity contests (e.g. CTF – Capture the Flag). These are to be used as part of training and teaching activities that students will conduct themselves.

Time commitment

  • (Estimated) Total workload: 125h
  • Contact hours: lecture: 12 hours, practice / laboratory session: 36 hours – each session consists of 1 hour lecture (mostly practical interactive demos) and 3 hours of assisted lab / practice session
  • Private study including examination preparation, specified in hours: 77 hours – used for preparing for sessions, solving assignments, preparing for examination, self-study

Assessment

Two take-home assignments (20% each)

  • Team projects – First assignment: Create and deploy 3 CTF challenges, review / solve other 3 CTF challenges (from other teams) – peer-review
  • Second assignment: Create and deploy a vulnerable virtual machine (vulnerable box); solve / review the deployment of another vulnerable box (from another team)
  • Final digitally proctored exam: 60% – practical exam (3 hours): setting up the infrastructure for a CTF-like contest and a vulnerable virtual machine
Register your interest

Subjects covered

1. Overview of cybersecurity practice activities: wargames, CTF contests & challenges, vulnerable boxes a. Typical structure of a practice activity: root account, the flag b. Types of challenges and structure: box, jeopardy, attack-defense (red team-blue team) c. Sample challenges, sample sites, walkthroughs

2. Pedagogical Considerations Related to Practical Activities a. Practical exercises: definitions and roles b. Structuring practical exercises c. Four-step approach to teaching practical exercises

3. Cybersecurity Practice Arsenal a. Web challenges arsenal b. Binary files arsenal c. Crypto arsenal d. Forensics arsenal

4. CTF Cybersecurity Challenges a. Contents of a cybersecurity challenge b. Lifetime of a cybersecurity challenge c. Use cases for challenges as services d. Tips and tricks for reliable challenges as services e. Aftermath of a contest including a CTF cybersecurity challenges

5. Deployment of CTF Challenges a. Scripting the deployment of challenges b. Deploying challenges on a remote system c. Using containers for deployment

6. CTF Engines – CTFd.io a. CTF engines for contests b. Features of CTFd c. Sample deployment of CTF challenges

7. Pedagogical Aspects of Contests and Competitions a. Contests, Competitions, Gamification, role in learning b. Competition-based learning c. Designing a competition for learning d. Assessing results

8. Organizing and Deploying a CTF Contest a. Setting up a contest: dates, accounts, challenge selection, storyline, announcements b. Deploying challenges c. Providing support, hints, maintaining active communication d. Presenting results, awards

9. Using Virtual Machines a. Virtual machines, benefits of virtual machines b. Automating work with virtual machines c. Using virtual machines as vulnerable boxes d. Validating a challenge inside the virtual machine

10. Designing a Vulnerable Box Challenge a. Identifying vulnerabilities for challenge b. Designing the challenge c. Validating a challenge d. Packing a challenge for deployment

11. Deploying Vulnerable Boxes a. Using a vulnerable box to set up the challenge b. Packing a virtual machine c. Publishing a virtual machine

12. Assessment of Results of Cybersecurity Practice Activities a. Scoreboards for results b. Statistics of results: times, challenges solved, hints c. Adjustments to difficulty (points, rating)

Register your interest

Learning objectives

On successful completion of this module the learner will be able to:

  • LO1: Design practical cybersecurity exercises that serve as both a learning and a (self)assessment platform for participants
  • LO2: Outline common patterns in cybersecurity attack and defense activities that can be replicated and integrated in cybersecurity exercises
  • LO3: Develop, employ and asses practical cybersecurity exercises, both as single-topic challenges and as vulnerable boxes that feature complex interconnected topics closer to a real-world setup
  • LO4: Combine patterns from existing cybersecurity exercises into new customized deployments
  • LO5: Assess student practical cybsersecurity knowledge and skills and revise exercises according to their current level
  • LO6: Design and set up cyber range-environments and CTF (Capture the Flag)-like contests, including setting up the platform, selecting challenges, grading, providing support
  • LO7: Summarize and interpret results and feedback of practice activities
Register your interest

Module leaders

Răzvan Deaconescu

Răzvan is an Associate Professor at POLITEHNICA Bucharest, the Computer Science and Engineering Department. He is primarily interested in operating systems and security, with a penchant for teaching and mentoring.

Răzvan is leading community activities in POLITEHNICA, centered around cybersecurity and open source. He has led the Security Summer School, a yearly 5-week summer school that has been running for 12 years and has generated over 500 graduates in cybersecurity. He is involved in mentoring students in cybersecurity topics and organizing and supporting local and national CTF contents. On the open source side, Răzvan is lead the ROSEdu (Romanian Open Source Education) association, organizing extracurricular classes and projects dealing with open source and by supporting students to take part in Google Summer of Code.

Răzvan’s research focus is on systems and software security, particularly Apple iOS security, cyber-reasoning systems and the Unikraft unikernel in recent years.

Register your interest

Making Europe cyber-aware

Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.

Download prospectus

FAQs

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle