Computer & Information Sciences
Cyber Security Challenges
Real cyber-security challenges on Ewance — assess risk, harden systems, and respond to threats the way a working security professional does. Solve them to build a portfolio of verified, recruiter-checkable proof you can do the work — not just describe it.
Recommended challenges
- DesignSeniorNew
Design a Confidential-Computing Architecture for a Genomics Workflow
Receive the workflow description (per-hospital genome BAM files uploaded to S3, processed by a variant-calling pipeline, results returned per-hospital), the partner-hospital leg…
- Confidential Computing
- Remote Attestation
- Secure Architectures
Computer Systems Security - DesignBeginnerNew
Threat-Model the Patient-Intake App for a Telemedicine Startup
Working only from the three materials provided — the system architecture overview, the patient-intake data-flow description, and the SOC 2 control-mapping table — produce a STRI…
- Threat Modeling
- STRIDE
- Risk Assessment
Open coursework - AnalysisIntermediateNew
Penetration-Test the TLS Configuration of an Edge Fleet
Receive read-only access to a 50-node representative sample (anonymized). Scan with testssl.sh + Qualys SSL Labs (where reachable) + a custom Go tool you write to test specific …
- Tls
- Applied Cryptography
- Penetration Testing
Applied Cryptography - CodeIntermediateNew
Add Differential Privacy to a Mental-Health App's Analytics Dashboard
Wrap the analytics module in `analytics_module.py` (provided) with a differential-privacy layer built on OpenDP. Implement epsilon-delta accounting: add Laplace noise to counts …
- Differential Privacy
- Privacy Budget
- Python Programming
Open coursework Develop in-demand professional skills.
Each challenge names the skills it strengthens. Over time, your profile fills with the competences a hiring manager would actually look for.
Why Ewance
- DesignBeginnerNew
Propose a Cryptographic Target State for a Checkout Stack
Working solely from the four supplied materials — the stack architecture case file, the testssl.sh export corpus, the cryptographic configuration specification, and the best-pra…
- Cryptography
- Tls
- Pci Dss
Open coursework - StrategyBeginnerNew
Build a Tiered Vendor-Security Review Program, Validated by a 12-Vendor Pilot
Using the de-identified subprocessor inventory and the twelve-vendor pilot dossier provided, design a three-tier risk program (critical, important, low-risk) with explicit, obse…
- Third Party Risk
- Security Governance
- Compliance
Open coursework - CodeIntermediateNew
Fuzz a Memory-Unsafe Image-Parsing Library
Identify 3 critical parser entry points (DICOM dataset parser, JPEG 2000 decoder, TIFF directory parser) and write a libFuzzer harness + an AFL++ harness for each. Build with AS…
- Fuzzing
- Memory Safety
- Address Sanitizer
Open coursework - AnalysisBeginnerNew
Wireless Security Audit and Hardening for a Telco's Public Wi-Fi
Your analysis task is built entirely on three provided materials: the 80-access-point configuration inventory, the 30-day authentication (RADIUS) log extract for those same acce…
- Wireless Security
- Wpa3
- Eap
Open coursework - Browse challenges
Explore role
Strategy Analyst
Frame the business question, model the options, build the recommendation. From market sizing to competitive analysis, this role is where strategy consulting meets in-house decision-making.
- DesignIntermediateNew
Threat Model a HealthTech Patient-Portal Web App
Read the 25-page redesign architecture document (auth via Clerk, Next.js front-end, FastAPI backend, Postgres, S3 for documents, webhook integration with EMRs). Build data-flow …
- Threat Modeling
- STRIDE
- Secure Design
Software Security - StrategySeniorNew
Post-Quantum TLS and PKI Migration Plan for a Cross-Border Bank
Working only from the materials provided, complete three connected tasks. First, using the anonymized TLS endpoint inventory and the PKI hierarchy diagram, score all endpoints o…
- Tls
- Pki
- Post Quantum Cryptography
Open coursework - CodeIntermediateNew
Implement Authenticated Encryption for a Document Service
Design the envelope-encryption hierarchy: customer Key Encryption Key (KEK) held in AWS KMS (Key Management Service), Data Encryption Keys (DEKs) wrapped per document. Use AES-2…
- Applied Cryptography
- Aead
- Key Management
Applied Cryptography - CodeSeniorNew
Assess Secure Cross-Bank Fraud Computation for a Four-Bank Consortium
Using the de-identified situation in the consortium case file and the two synthetic per-bank datasets (the bank suspicious-account lists and the merchant fraud-marker tallies), …
- Secure Computation
- Mpc
- Cryptography
Open coursework Get recognized by recruiters and employers.
Credentials are blockchain-anchored via LearnCoin — tamper-evident, portable, link-shareable on LinkedIn and beyond.
Why Ewance
- CodeBeginnerNew
Build a Secure-Coding Linter Ruleset for a Backend Team
Using the findings log, study the twelve documented security-review findings and confirm the three repeat patterns. Then build a custom linter ruleset — choose Semgrep or custom…
- Secure Coding
- Static Analysis
- Semgrep
Open coursework - CodeBeginnerNew
Implement Authentication and Access Control for a Civic Portal
Receive the current Next.js + Express prototype, the data model (residents, requests, documents, audit log), and the 4 staff roles (resident, clerk, supervisor, auditor) with th…
- Authentication
- Authorization
- Rbac
Introduction to Computer Security - AnalysisIntermediateNew
Threat Model a Water-Utility SCADA Network Before a Migration
Review provided network diagrams (current and proposed), the asset inventory (around 180 PLCs (programmable logic controllers), 22 engineering workstations, 6 historian servers)…
- Threat Modeling
- Ics Security
- Scada
Cyber-Physical and Cybercrime Topics - CodeSeniorNew
Reverse-Engineer and Patch an N-Day Vulnerability in a Vendor Binary
Receive the vulnerable binary (Linux ELF, x86-64), the public CVE-2025-XXXX advisory + PoC, and the bank's deployment context (RHEL 9, the binary runs as a non-root service). Lo…
- Reverse Engineering
- Binary Exploitation
- Ghidra
Open coursework
How it works
From brief to credential, in six steps.
Step 01
Browse challenges aligned to your studies.
Step 02
Accept the one that fits your goals.
Step 03
Work through it with AI Copilot guidance.
Step 04
Submit for structured evaluation.
Step 05
Earn a verified credential.
Step 06
Add it to LinkedIn with one click.
Industry teams behind a decade of practitioner briefs
Hiring from this pool?
Sponsor a challenge and meet candidates through actual work.
Industry teams can shape briefs around the skills they hire for, then evaluate students on rubric-scored deliverables — not resumes.



















































































