When we built the Ethical Hacking Fundamentals course, the one thing we refused to do was grade with multiple-choice questions. Security is a practical skill, and we wanted a practical exam.
The final assessment for our first cohort was a live, deliberately vulnerable range built specifically for the course — a small network with a handful of intentional misconfigurations and vulnerable services, no writeup or hints. Students had four hours to find and document as many findings as they could, written up the way a real report would be structured.
The results told us more than a quiz ever could: which concepts stuck, which didn’t, and exactly where the curriculum needed to go deeper for the next cohort.