๐ Assessment Structure
This assessment combines AI-assisted evaluation and human academic review.
โ AI provides logical analysis and technical scoring.
โ Human lecturer remains final authority.
โ Practical reasoning is prioritized over memorization.
๐งช Scenario 1 โ Banking Login Attack
A banking system login page fails to validate user input properly. An attacker attempts SQL injection.
๐ค AI ANALYSIS:
- SQL injection understanding
- Authentication bypass reasoning
- Defense mechanism evaluation
Status: Pending AI evaluation
๐จโ๐ซ HUMAN REVIEW:
Lecturer validates technical depth and reasoning quality.
๐งช Scenario 2 โ Social Media Account Takeover
A user enters credentials into a fake phishing page.
๐ค AI CHECKS:
- Phishing awareness
- Credential theft analysis
- Attack chain understanding
๐จโ๐ซ HUMAN REVIEW:
Human confirms whether the student understands the full attack process.
๐งช Scenario 3 โ File Upload Compromise
A website accepts uploads without validating file type or execution permissions.
๐ค AI CHECKS:
- File upload vulnerabilities
- Web shell awareness
- Server compromise reasoning
๐จโ๐ซ HUMAN REVIEW:
Lecturer verifies understanding of server-level security risks.
๐งช Scenario 4 โ Public Wi-Fi Session Hijacking
A user logs into a system using insecure public Wi-Fi.
๐ค AI CHECKS:
- Session security understanding
- Cookie protection knowledge
- HTTPS awareness
๐จโ๐ซ HUMAN REVIEW:
Human confirms reasoning depth and cybersecurity awareness.
๐งช Scenario 5 โ Search Bar XSS Attack
A search bar reflects user input directly into the webpage without sanitization.
๐ค AI CHECKS:
- XSS understanding
- Browser-side impact reasoning
- Input sanitization awareness
๐จโ๐ซ HUMAN REVIEW:
Lecturer validates correctness of attack analysis.
๐ Hybrid Grading System
๐ค AI EVALUATION:
- Concept understanding
- Technical reasoning
- Defense knowledge
- Attack awareness
Output: Suggested performance level
๐จโ๐ซ HUMAN FINAL AUTHORITY:
- Lecturer reviews all responses
- AI remains advisory only
- Final academic decision belongs to human examiner
โ Maintains certification standards
โ Prevents AI grading errors
โ Ensures academic integrity