Exam WeekFour structured review days · One exam day

Six weeks of services, built by hand — now proven under exam conditions

The final exam uses each student's own S1/S2/S3 VM environment as the exam platform. Unlike the earlier mini-assessments, the written and practical portions run back-to-back in a single sitting on Friday: 20 minutes of theory, collected, then straight into 100 minutes of scenario-based terminal work. There is no separate written day and practical day — students need everything sharp on the same morning.

Monday through Thursday are structured review, not new content. Each day walks back through one or two weeks' worth of services, with an emphasis on the diagnostic habits the course has built all term: check the logs, test the config before reloading, verify with the client-side tool as well as the server-side one. Thursday closes with a full VM health check — every service from Weeks 1–6 confirmed running before the exam.

Week at a glance

Monday
Review — Weeks 1–2

SSH, packet analysis, firewalling, NTP, logging

Tuesday
Review — Weeks 3–4

DHCP, DNS, Nginx, SSL, log-based troubleshooting

Wednesday
Review — Week 5

IPSec, PKI, WireGuard, ipsec status / wg show drills

Thursday
Review — Week 6 + Exam Walkthrough

Docker, capstone recap, exam format, full VM health check

Friday
Final Exam

Single sitting · 20 min written + 100 min practical · No notes, no internet

FridayWritten Exam · 20 min · 17% of final mark

Written exam — quick identification, not long-form essays

Written exam topic coverage

Topic AreaWeightWeek Covered
SSH hardening, fail2ban10%Week 1
Packet analysis, firewalling, NTP, rsyslog20%Week 2
DHCP, DNS zones and records20%Week 3
DNS views, Nginx, SSL/TLS20%Week 4
IPSec, PKI/CA, WireGuard20%Week 5
Docker, docker-compose10%Week 6
FridayTerminal Practical · 100 min · 83% of final mark

Terminal practical — building out a branch office's infrastructure, task by task

Practical exam task areas

Task AreaMarksExample verification
Secure remote access12Key-auth SSH on a custom port, fail2ban active
Firewall implementation15Rule set matches spec, verified live with tcpdump
NTP & centralised logging13Stratum hierarchy correct, forwarded log entry appears within 10s
DHCP & DNS zone build18Reservation active, zone validated and resolving both ways
Nginx, SSL & DNS views17Split-horizon resolution correct, HTTPS redirect working
WireGuard VPN tunnel15Peer handshake current, traffic verified over the tunnel
Docker & reverse proxy10Container running, proxied end-to-end and confirmed in logs
VM preparation note: Ensure all student VMs have a clean, known-good state at the start of the exam — services in the correct states, no leftover test files from earlier labs. A snapshot taken at the end of Thursday's VM health check is ideal.
Mon–ThuReview days · Structured, instructor-led

Making the most of the four review days

Suggested self-test before Friday
  • Can you generate an SSH key pair, install it, and disable password auth without locking yourself out — from memory?
  • Can you write and verify a firewall rule set against a written spec, using tcpdump to confirm each rule?
  • Can you build a forward and reverse DNS zone from a blank BIND9 install and validate it with named-checkzone?
  • Can you bring up a WireGuard tunnel between two VMs and prove traffic is actually crossing it?
  • Can you configure Nginx to proxy_pass to a Docker container and trace a request through the full chain?
← Week 6 Day 1 Lesson Plan → Course Outline