Hogeschool West-Vlaanderen
Howest Brugge
Spoorwegstraat 4 - 8200 Brugge
Tel: 050 682666
studentadmin@howest.be - Website: www.howest.be
Web Security and Honeypot12772/2013/2627/1/34
Study guide

Web Security and Honeypot

12772/2013/2627/1/34
Academic year 2026-27
Is found in:
  • Bachelor of Cybersecurity, programme stage 4
This is a single course unit.
Study load: 6 credits
Total study time: 150,00 hours
Re-sit exam: is possible.
It is not possible to enrol in this course unit under
  • exam contract (to obtain a credit).
  • exam contract (to obtain a degree).
Co-ordinator: Audenaert Ann
Other teaching staff: De Bock Douwe, Koreman Koen
Language course: No
Languages: English

Omschrijving Volgtijdelijkheid (VT) (EN)

previously registered for Linux for ethical hackers AND (previously registered for Web Backend OR previously registered for Web Development Essentials) AND (previously registered for Web Pentesting Fundamentals OR previously registered for Web Pentesting Fundamentals).

Omschrijving Doelstellingen (EN)

LR01:

01.2.1 Analyzes the threats to a defined system to determine associated cybersecurity requirements

01.3.1 Selects appropriate measures to mitigate risks

LR02:

02.2.3 Translates threat intelligence information into detection rules

LR03:

03.2.4 Minimizes digital footprint based on forensic techniques in a constrained context

LR04:

04.2.4 Secures a web application

04.3.1 Selects optimal security techniques in a combination of simulated contexts

04.3.2 Configures selected security techniques in a combination of simulated contexts

LR05:

05.2.3 Configures selected security techniques in a combination of simulated contexts

05.3.1 Installs and secures a web server

05.3.2 Integrates tools and attack techniques into an effective web pentesting campaign

LR07:

07.1.3 Explains the principles of network and host-based monitoring

07.2.3 Creates an effective network monitoring environment

07.3.1 Selects appropriate cryptographic and privacy enhancing techniques and protocols in a simulated realistic context

LR08:

08.3.1 Communicates and reports in writing and orally in a structured and unambiguous manner tailored to the interlocutor, pays attention to the avoidance of language errors and the correct use of jargon

LR10:

10.2.1 Executes a simple cybersecurity project within the preconditions

10.2.2 Executes a simple cybersecurity project within the preconditions

10.2.3 Adapts his/her behavior in relation to an optimal collaboration and acts upon team goals

10.2.4 Uses the appropriate feedback techniques

Omschrijving Inhoud (EN)

Setting up and securing a web environment with HTTPS, WAF and authentication in different types of web servers (Apache, NGINX,...).

Besides setting up this web environment, a logging environment will be set up to monitor the activities.

The second part of the module is about setting up a Honeypot in a group project.

Omschrijving Studiematerialen (lijst) (EN)

CasesMandatory
PresentationMandatory
TutorialsMandatory

Omschrijving Eindcompetenties (lijst) (EN)

PBACS001: Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
CodeDescription
PBACS001Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
PBACS002: Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
CodeDescription
PBACS002Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
PBACS003: Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
CodeDescription
PBACS003Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
PBACS004: Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
CodeDescription
PBACS004Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
PBACS005: Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
CodeDescription
PBACS005Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
PBACS007: Achieves prevention, detection, response, recovery and investigation of cyber threats and attacks through selecting, applying and interpreting the appropriate techniques.
CodeDescription
PBACS007Achieves prevention, detection, response, recovery and investigation of cyber threats and attacks through selecting, applying and interpreting the appropriate techniques.
PBACS008: Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
CodeDescription
PBACS008Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
PBACS010: Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.
CodeDescription
PBACS010Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.

Omschrijving Onderwijsvorm (EN)

  • Lecture
  • Project
  • Exercise class

Omschrijving Evaluatie (lijst) (EN)

Evaluation(s) for first exam chance
MomentForm%Remark
exam period 2 (2nd sem) (regular exam schedule)assignment: specific method or combination of methods50,00
Evaluation(s) for re-sit exam
MomentForm%Remark
exam period 3 (august/september) (regular exam schedule)assignment: specific method or combination of methods50,00
Evaluation(s) for both exam chances, not reproducible in re-sit exam
MomentForm%Remark
exam period 2 (outside exam schedule)assignment: specific method or combination of methods50,00