Concordia University Wisconsin  ·  School of Arts and Sciences  ·  B.S. Computer Science Curriculum proposal draft
Computer Science Curriculum Evolution
CSC 4600 3 Credits 4000 level Substantial AI weight

Penetration Testing

Offensive security now faces two AI-shaped fronts: AI-enabled and agentic applications are themselves a live target class whose failure modes — prompt injection, tool-call abuse, excessive agency, poisoned retrieval — are invisible to traditional network and web testing, and testers increasingly work with AI-assisted reconnaissance, payload generation, and report drafting whose output must be verified before it is executed or delivered. The course keeps its red team identity and adds those targets and that verification discipline rather than becoming an AI course.

Current catalog prerequisites — (CSC 250 or 2050).

The revision

Current description → proposed description

Current — CUW catalogverbatim

This course provides students with an introduction to the principles and techniques associated with the cybersecurity topics of penetration testing and ethical hacking. The course covers planning, reconnaissance, scanning, exploitation, and reporting from a "red team" offensive security posture. Students will learn how system vulnerabilities can be exploited and defended against in a variety of environments and operating systems. Students will develop an understanding of current cybersecurity issues and ways that human errors, system errors, and programming errors can lead to vulnerabilities in systems and organizations. The course will be divided between theoretical classroom learning and practical, hands-on lab and possible project work. Course topics include: Email security, application security. Incident response, computer forensics, fuzzing, malware, ransomware, mobile malware, honeypots, cryptography, and change management.

Prerequisites: (CSC 250 or 2050).

Proposed — revised for the AI eradraft

This course introduces the principles and techniques of penetration testing and ethical hacking from a red team offensive posture. Students carry authorized engagements through planning and rules of engagement, reconnaissance, scanning, exploitation, privilege escalation, and reporting across operating systems, networks, and applications, and examine how human, system, and programming errors become exploitable weaknesses. Hands-on laboratory work in isolated ranges accompanies classroom study of application and email security, fuzzing, malware, ransomware, and mobile malware, cryptography, honeypots, incident response, computer forensics, and change management. Because AI-enabled and agentic software is now widely deployed, the course adds a target class of its own: direct and indirect prompt injection, abuse of tool and function calls, excessive agency, insecure output handling, poisoned retrieval corpora, and model and connector supply chain risk. Students also work with AI-assisted offensive tooling under supervision, verifying machine-drafted payloads, findings, and report language before anything is executed or delivered. Authorization, scope, responsible disclosure, and the stewardship of dual-use capability are treated as professional and Christian obligations throughout.

Note. Two items worth surfacing. First, the catalog topic list for CSC 4600 extends past offensive testing into defensive and investigative subjects (incident response, computer forensics, honeypots, change management) that adjoin the scope of CSC 3600 Cybersecurity, whose catalog text covers attacks and related defense measures, risk analysis, and backup and recovery; the department may wish to confirm the intended boundary between the two courses. The proposed description retains all eleven catalog topics rather than silently dropping any of them. Second, CSC 4600 has no department-authored proposed description in the workbook and no row in the workbook's curriculum map, so the PLO mapping above is proposed rather than workbook-confirmed and contradicts nothing the workbook asserts.

What changes

  • Agentic and LLM applications added as a target class
  • Prompt injection, tool-call abuse, and excessive agency testing
  • AI-assisted offensive tooling verified in a controlled range before use
  • Report findings and vulnerability references verified against primary sources
  • Authorization, responsible disclosure, and dual-use stewardship made explicit
Course learning outcomes

6 proposed outcomes, mapped to 11 program outcomes

Each outcome below is written to be observable and assessable, and each is mapped to the program learning outcomes for which it produces evidence.

1

Students will be able to execute an authorized penetration test across the full engagement lifecycle, from scoping and rules of engagement through reconnaissance, scanning, exploitation, privilege escalation, and reporting, against host, network, and web application targets in an isolated laboratory range.

Maps to

PLO 3.2 is supported here only in its law-and-discipline dimension: the scoping and rules of engagement this CLO requires force the student to apply legal and contractual constraints, not just technical method, to a live engagement, while the human-centered AI application half of PLO 3.2 is evidenced by CLO 3 rather than by this conventional host, network, and web application work.

2

Students will be able to analyze scanner and tooling output, separating verified, reproducible findings from false positives and ranking confirmed weaknesses by exploitability and business risk.

Maps to

PLO 6.2 is supported by the separation of reproducible findings from false positives and the ranking by exploitability, which is precisely the quantitative and qualitative analysis of evidence needed to draw defensible conclusions; PLO 4.1 is supported by the ranking by business risk, which demands critical judgment about data-driven outcomes and their consequences for the organization and the people whose information it holds.

3

Students will be able to design adversarial tests for AI-enabled and agentic applications that probe direct and indirect prompt injection, abuse of tool and function calls, excessive agency, insecure output handling, poisoned retrieval corpora, and data exfiltration paths.

Maps to

PLO 6.3 is supported by the probing of excessive agency and data exfiltration paths, which is a direct assessment of whether a deployed AI system can cause moral and material harm to those it touches; PLO 3.2 is supported by the adversarial test design itself, which is applied to real-world AI-enabled and agentic applications and brings legal and disclosure judgment to bear on making them human-centered by surfacing injection, agency, and exfiltration harms before users meet them; PLO 4.1 is supported by the prompt-injection and poisoned-corpus testing, which analyzes how data-driven systems fail and what those failures cost the people who rely on them.

4

Students will be able to evaluate AI-assisted offensive tooling by verifying machine-drafted reconnaissance, payloads, and exploit code in a controlled range before use and by documenting the provenance of work the tester did not personally write.

Maps to

PLO 2.3 is supported by the requirement to verify machine-drafted payloads in a controlled range before use, which is the responsible-use discipline owed to powerful automated capability; PLO 4.3 is supported by the documentation of provenance for work the tester did not write, which forces continuous self-assessment of when an assistant should be relied upon at all.

5

Students will be able to construct a professional penetration test report presenting reproducible evidence, prioritized remediation guidance, and an executive summary intelligible to non-technical stakeholders, with every machine-drafted passage and vulnerability reference verified against primary sources.

Maps to

PLO 5.1 is supported by the requirement that the report present reproducible evidence and that every machine-drafted passage and vulnerability reference be verified against primary sources, which is written communication conducted transparently and with integrity; PLO 5.3 is supported by the executive summary, which requires translating technical findings for a non-specialist audience.

6

Students will be able to critique the legal and ethical boundaries of offensive security work, including authorization, scope, responsible disclosure, and dual-use capability, in light of a Christian account of vocation and stewardship.

Maps to

PLO 1.2 is supported by the judgments this CLO requires about authorization, scope, and responsible disclosure, which are exactly the privacy, transparency, and accountability decisions of professional practice; PLO 1.3 is supported by the treatment of dual-use capability as stewardship exercised under authority for the protection of neighbor; PLO 3.1 is supported by the critique itself, which combines legal, technical, and theological reasoning on a single question.

Coverage

Program outcomes this course reaches

Filled cells are program learning outcomes with at least one supporting course learning outcome in this course. Sparse coverage is expected — no single course carries all eighteen.

ULO1
1.11.21.3
ULO2
2.12.22.3
ULO3
3.13.23.3
ULO4
4.14.24.3
ULO5
5.15.25.3
ULO6
6.16.26.3