Ethical Hacking
2026/2027- Purpose and learning objectives
The course aims to develop students' professional competencies within offensive security testing of systems and the ethical and legal frameworks surrounding it. The course focuses on practical exploration of vulnerabilities, exploitation techniques, and reporting using a controlled testing environment.
KnowledgeThe student has knowledge of:
Skills
• Ethical and legal frameworks for ethical hacking, including accountability, contractual matters, and legal limitations.
• The key phases of a penetration test, including reconnaissance, scanning, exploitation, and reporting.
• Fundamental vulnerability types in modern systems (e.g. service vulnerabilities, misconfigurations, web vulnerabilities, brute force, etc.), as well as an overview of the OWASP Top 10.
• Relevant models such as the Cyber Kill Chain and basic attack methods applied in practice.The student is able to:
Competences
• Conduct a structured penetration test in a controlled environment with a focus on reconnaissance, scanning, and exploitation of simple vulnerabilities.
• Gather and analyse information about a target using recognised tools (e.g. Nmap, Burp Suite, Metasploit, etc.).
• Identify and verify vulnerabilities in smaller systems, including web applications.
• Develop attack plans, carry out simple exploit scenarios, and document results.
• Produce a concise penetration test report including findings, evidence, and remediation recommendations.The student is able to:
• Work independently, ethically, and responsibly with offensive security techniques within a defined and approved testing environment.
• Plan and structure a simple end-to-end penetration test and reflect on the applicability and limitations of the methods used.
• Assess the security posture of smaller systems through practical testing and reporting.
• Collaborate on solving practical challenges, including the production of group reports and joint problem-solving.
• Identify their own development needs in relation to offensive security techniques and further specialization. - Type of instruction
Teaching in the Cybersecurity programme is conducted as a dynamic and interactive process, with a strong emphasis on active student participation. The teaching is based on relevant industry practices and combines practical experience with theoretical knowledge. Problems and cases from different types of companies within the IT industry are incorporated into the learning activities. Students are expected to take responsibility for their own learning, and both students and lecturers contribute constructively to the learning process.
To ensure optimal academic learning and personal development for each student, the programme applies a varied pedagogical approach with emphasis on dialogue, discussion, and project-based learning.
Teaching is organized through a variety of learning activities, including classroom teaching, guest lectures, company visits, group project work, and individual assignments — often involving interdisciplinary challenges and always with an application-oriented perspective. In addition to the academic content, these different learning methods help develop the students’ ability to work both independently and collaboratively.
Common to all these activities is that EK consistently aims to establish clear objectives for the learning activities. - Exam
The learning outcomes of the exam are identical with the learning outcomes of the subject(s)/modul(es)
Prerequisites for access to the examinationIt is a prerequisite for being admitted to the exam that the student submits 2–4 written assignments, which must be approved before the student takes the exam for the first time.
The assignments will be described during the semester.
Failure to fulfill this prerequisite means that the student will have used one exam attempt.Exam in one or more subjectsSubject/module is tested standaloneType of examCombined written and oral examinationType of assignmentA written submission must be handed in that meets the requirements described in the examination project. The written submission and the technical document may be prepared individually or in groups of up to 4 students.Formal requirementsMax. 10 pages + 3 pages per additional student in the group (excluding: cover page, table of contents, appendices).
The submission must include:
• Names of group members
• Cover page
• Table of contents
• Executive Summary
• Findings & Technical Analysis
• RecommendationsIndividual exam or group examIndividualExam languagesEnglishDuration30 minutes, including deliberation.
The student starts with a 10 minutes presentation.Type of evaluation7-point grading scaleExaminersInternal censure
In the subject Ethical Hacking you will receive 53 hours of instruction, which corresponds to 70 lessons (1 lesson = 45 min.) and 19% of your total workload for the subject.
The teaching primarily consists of the following activities: classroom teaching, group work, exercises.
The preparation primarily consists of the following activities: group work, exercises.
Read about KEAs Study Activity Model
*KEA can deviate from the number of hours if this is justified by special circumstances