24,428 courses · 2,504 curriculum guides Sponsored by eAgentic Software Sponsored by eAgentic Software

Cyber War Gaming

CNT4416 — Cyber War Gaming
← Course Modules
3 credit hours 45 contact hours Prerequisites: UWF: (CIS 4385 OR CIS 4221) AND CNT 4403. The STATEWIDE version names CNT4403, CIS4385 AND CDA3101 at C-minus - but UWF does NOT carry CIS4385 (public carriers: Pensacola State, FSU), which is why UWF wrote an OR into its own prerequisite. Take your own catalogue. Do not attempt this without the network security gate; it is a capstone. *** AUTHORISATION IS THE WHOLE PROFESSIONAL BOUNDARY. These techniques are lawful inside a range you have WRITTEN permission to operate in and are felonies outside it, under the federal CFAA and Fla. Stat. ch. 815. "I was only looking", "I did no damage" and "I work in IT here" are NOT defences. Authorisation is WRITTEN, from someone who can grant it, with a defined scope. *** Keep your after-action reports - they are the portfolio. NEVER paste real configurations, topologies, captures or findings into a consumer AI tool - a configuration is a map of how to attack the network it runs. v1.0

Course Description

CNT4416 is the cyber exercise course — the capstone of a security sequence, where students defend and attack networks in a controlled range rather than reading about it.

Florida's statewide description explains the rationale directly: "Every organization, whether part of the government or the private sector, needs battle-tested IT personnel in order to defend its networks against attack. The most effective way to provide this experience is to recreate the exact scenarios… they will see in the real world. This course provides exercises that use different specialties (network, security, visualization, software) into colour-coded RED and BLUE teams that perform specific roles in attacking and defending IT infrastructures."

The colours are the field's standard vocabulary. A red team emulates an adversary. A blue team defends, detects and responds. A purple team is the two working together deliberately so that each attack technique is matched against whether the defence actually detected it — which is where most of the learning happens, because an attack nobody noticed is the most important finding of any exercise.

UWF's version carries the same structure and adds a dimension: titled Cyber Operations with Defensive AI, it covers "the authorities, roles and steps associated with cyber operations," red team and blue team work, and then "the application of AI in strengthening defensive cybersecurity measures. Students will learn how AI-driven tools and techniques can improve the detection, analysis, and response to cyber threats." It ends: "Welcome to Purple Team!"

⚠⚠⚠ Before anything else, the thing this course exists to establish: AUTHORISATION. UWF's description leads with "authorities" and that word is doing heavy lifting. The techniques taught here are lawful inside a range you have written permission to operate in, and are serious criminal offences outside it. There is no grey area, no "I was only testing," and no informal permission. See Special Informationit is the most important section on this page and it is not a formality.

Learning Outcomes

Required Outcomes

Optional Outcomes

Major Topics

Required Topics

Optional Topics

Resources & Tools

Career Pathways

Special Information

⚠⚠⚠ Authorisation is the whole professional boundary — understand it before the first exercise

This is the most important thing in the course, and UWF puts it first in its description for good reason.

The techniques taught here are lawful in one circumstance only: inside a system you own, or one you have explicit written authorisation to test, within a defined scope. ⚠⚠⚠ Outside that, the same actions are criminal offences — under the federal Computer Fraud and Abuse Act and under Florida's own computer crimes provisions in Chapter 815 of the Florida Statutes. Consequences include felony prosecution, and for a student also expulsion and the permanent loss of any prospect of a security clearance.

⚠⚠ The specific misunderstandings that get people into trouble are worth naming, because they are common and they sound reasonable:

The professional habit to build now: never touch a system without written scope, and when in doubt, ask and wait. Every legitimate employer in this field will respect that; none will respect the alternative. Your institution's range exists precisely so you can learn these techniques lawfully — use it, and only it.

⚠⚠ UWF adds defensive AI — a course whose subject is AI, not a course that mentions it

The two carriers differ, and the difference is an addition rather than a substitution.

FAMU — Cyber War GamingUWF — Cyber Operations with Defensive AI
Matches the statewide description: red and blue team exercises recreating real-world attack scenarios across network, security, visualisation and software specialities.That, plus the "authorities, roles and steps associated with cyber operations", explicit red and blue team operations, and the application of AI to detection, analysis and response. Explicitly purple team.

This is scope breadth rather than divergence — UWF's version fully contains the statewide subject. A syllabus test: look for machine learning content as its own unit, and for the word "purple."

⚠⚠ The AI content is worth seeking out rather than tolerating. Security operations is one of the few fields where machine learning is genuinely load-bearing in production today — alert triage, anomaly detection and automated response are deployed at scale because the volume of events exceeds what humans can review. A graduate who understands both how those systems help and how they fail is more employable than one who knows only the traditional toolset.

⚠⚠⚠ And the part a good course will insist on: detection models are themselves a target. Adversarial machine learning — evading a classifier, poisoning its training data, or exploiting the fact that defenders now trust its output — is an attack surface that did not exist a decade ago. Red teaming an organisation's AI-based defences is becoming a real engagement type, and this is the course where a student should first meet the idea.

⚠⚠ The prerequisite chain is substantial, and the statewide version does not resolve

SourcePrerequisiteResolves at UWF?
Florida statewideCNT4403, CIS4385 AND CDA3101, minimum grade C-minus⚠⚠ No — UWF does not carry CIS4385 (its public carriers are Pensacola State and FSU)
UWF(CIS 4385 OR CIS 4221) AND CNT 4403yes — UWF wrote an alternative into its own prerequisite

This is a pattern seen repeatedly across Florida's course file: statewide prerequisites are contributed by institutions, and one written from another institution's curriculum does not resolve elsewhere. UWF handled it the sensible way, by offering an OR — which is worth noticing, because an institution hedging its own prerequisite is usually a sign it knows the numbering does not line up.

What you actually need, whichever institution you are at: ⚠⚠ network security (CNT4403, carried by seven Florida public institutions under seven different titles), plus either digital forensics or an equivalent security course. Take your own catalogue's version, and do not attempt this course without the security prerequisite — it is a capstone and it assumes you can already read traffic and configure a defence.

Offering Notes

InstitutionIts titleCreditsContact hoursNotes
University of West Florida (SUS)Cyber Operations with Defensive AI3not publishedPrerequisite (CIS 4385 OR CIS 4221) AND CNT 4403; may not be repeated for credit; Department of Cybersecurity and Information Technology, College of Science and Engineering
Florida A&M University (SUS)Cyber War Gaming3not published⚠ catalogue not readable — matches the statewide title and description

Both carriers award three credits and neither publishes a contact-hour figure, so the 45 hours recorded here is Florida's convention for a three-credit course with no C or L suffix.

⚠⚠ Treat that as a substantial understatement. Exercise-based courses do not fit a timetable. A scenario runs until it is resolved; range access is often outside scheduled hours; and an after-action report on an exercise you have just spent six hours inside takes as long again. Plan the term around this course rather than fitting it in.

FAMU's catalogue could not be read for this guide — it runs on a platform that serves front pages while returning empty responses for course content — so its own description and prerequisite are unavailable, and its title matching the statewide one is the basis for the characterisation above.

Position in the curriculum and transfer

A capstone-level course, taken last in a cybersecurity sequence after networking, network security and forensics. ⚠ It is where the separate courses are supposed to combine, and it will expose whichever of them you did not learn properly.

Florida's statewide record classifies it as transferable to an institution offering the same course, with no Gordon Rule designation and no general-education category, and marks it for dual enrolment with elective high-school credit — ⚠ boilerplate across the prefix. The (U) means upper division only.

⚠⚠ On transfer and on hiring, the artefacts matter more than the transcript. Keep your after-action reports, your detection rules and any competition resultsin security these are the portfolio, and an interviewer will ask what you found and how you found it rather than what grade you received.

AI Integration

⚠⚠⚠ This is the rare course where AI is simultaneously the subject, the tool and the threat — and a student should be able to distinguish the three by the end of it.

As the subject. UWF's version makes defensive AI explicit, and the reason is that security operations is genuinely dependent on machine learning in production: event volumes long ago exceeded human review capacity, so anomaly detection, alert triage and automated enrichment are load-bearing rather than experimental. ⚠ The professional skill is knowing what these systems are good at — finding statistical outliers across enormous data — and what they are bad at, which is anything novel, anything deliberately disguised, and explaining themselves.

As the tool, in your own coursework. Explaining an unfamiliar log format or protocol artefact; drafting a detection rule to then test and refine; summarising a long threat report; producing the routine sections of an after-action report; and ⚠ explaining an attack technique in terms a non-technical audience will follow, which is a genuinely hard writing task and a real part of the job.

⚠⚠⚠ As the threat, and this is the part that belongs to this course rather than any other.

⚠⚠ Two absolute limits on your own use, and they are professional rather than academic.

Finally, the honest career note. Routine triage is being automated, which affects the entry-level tier this course leads to. What is not being automated is investigating something nobody has seen before, deciding what an ambiguous signal means, and being accountable for the call. Those are what an exercise trains, and they are the reason this course is the most valuable one in the sequence.


Generated September 16, 2026 · Updated September 16, 2026