0:00–0:20
Written
0:20–1:45
Practical
1:45–2:00
Review
0:00 – 0:20Written · 20 min

Short-answer and identification, closed-book

Instructor note: collect written papers at 0:20 sharp before releasing the practical scenario — the practical builds on nothing from the written half, so there's no reason to let them run long into lab time.
0:20 – 1:45Practical · 85 min

Implement, diagnose, repair — on S1

Before the practical starts: confirm the seeded auth.log and the broken rsyslog config are in place on every S1 — deploy them right after collecting written papers, not before, so no one gets a head start.
1:45 – 2:00Review + Week 3 Preview · 15 min

Mini-Assessment 2 — Topic Coverage

TopicWeightSource
tcpdump flags, BPF filters, capture vs. display15%Monday
Mausezahn syntax and packet crafting10%Monday
IPTables / NFTables / UFW rule syntax and DROP vs. REJECT25%Tuesday
NTP stratum hierarchy and ntpq -p columns15%Wednesday
Syslog facility/severity and rsyslog routing rules15%Thursday
Practical: firewall implementation + log diagnosis + rsyslog repair20%All week

What you need ready before class

Mini-Assessment 2 written papers printed Seeded auth.log staged, ready to deploy to each S1 Broken rsyslog config staged, ready to deploy to each S1 Firewall specification handout printed
←← Week 2 Overview ← Day 4 Week 3 →