CS50 video library
Use as a broad CS lecture and section companion where students need another pass through core ideas.
A defensive cybersecurity course covering threat modeling, authentication, systems, networks, web security, cryptography, privacy, incident response, secure development, and ethical practice.
A defensive cybersecurity course covering threat modeling, authentication, systems, networks, web security, cryptography, privacy, incident response, secure development, and ethical practice.
This track is organized as a mastery loop: source study, sequenced checks, Khan report evidence, then tutor handoff only when the data shows a real stuck point.
Use linked OER and companion sources before attempting checks.
Move through numbered PeerTutor problems without skipping failed gates.
Enter Khan report evidence and let the adaptive plan rank repair units.
Bring exact misses, notes, and one sharp question to a tutor.
The bank is intentionally mixed across facets and difficulty so high scores cannot come from one narrow question style.
Use these linked courses for video instruction and mastery practice, then return here for PeerTutor original checks and tutor help on the exact unit that got stuck.
External video content is linked or embedded through provider-hosted players, not copied. PeerTutor practice is original and cites each source path separately.
Watch the strongest public video path inside PeerTutor, then use the unit checks below to prove the student can actually do the work.
Use as a broad CS lecture and section companion where students need another pass through core ideas.
Use as a fast conceptual overview for computing systems, algorithms, data, and programming context.
Khan Academy progress has to be entered from the student or tutor report. Khan does not provide a supported public progress API, so this mirror stores unit status locally and uses it to target PeerTutor checks.
Khan Academy does not provide a supported public progress API or external API keys. PeerTutor stores student-provided report evidence and maps it to original practice instead.
0 repair units and 5 practice units need attention before extension.
No Khan mirror data yet; this is a normal practice candidate, not a proven weakness.
Complete 12 sequenced checks and advance only after misses are corrected.
No Khan mirror data yet; this is a normal practice candidate, not a proven weakness.
Complete 12 sequenced checks and advance only after misses are corrected.
No Khan mirror data yet; this is a normal practice candidate, not a proven weakness.
Complete 12 sequenced checks and advance only after misses are corrected.
No Khan mirror data yet; this is a normal practice candidate, not a proven weakness.
Complete 12 sequenced checks and advance only after misses are corrected.
No Khan mirror data yet; this is a normal practice candidate, not a proven weakness.
Complete 12 sequenced checks and advance only after misses are corrected.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Security foundations and threat modeling", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Accounts, authentication, and authorization", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Systems and endpoint defense", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Network security", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Web and application security", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Cryptography and data protection", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Privacy, social engineering, and human risk", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Rebuild the unit: do 12 PeerTutor checks, log every miss, then ask a tutor from the error log.
Khan evidence to mirror: percent/mastery for "Incident response and security capstone", missed skill, last activity date, and the next Khan item assigned by the teacher report.
Built for independent progress first, then tutor support where the student gets stuck.
Practice: Create a threat model for a familiar application with ranked risks and mapped mitigations.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Use confidentiality, integrity, availability, assets, threats, vulnerabilities, likelihood, impact, and controls.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Create a threat model for a familiar application with ranked risks and mapped mitigations.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Draw trust boundaries and attack surfaces.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Security foundations and threat modeling runs once for each value 0 through 3. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Security foundations and threat modeling"?
Which practice artifact should you produce for "Security foundations and threat modeling" before asking a tutor for help?
Which target best proves readiness for "Security foundations and threat modeling"?
Which second target belongs to "Security foundations and threat modeling"?
Practice: Audit an account lifecycle and design enrollment, login, recovery, revocation, and abuse controls.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Use password managers, MFA, recovery, sessions, least privilege, and access-control models.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Audit an account lifecycle and design enrollment, login, recovery, revocation, and abuse controls.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Distinguish authentication from authorization.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Accounts, authentication, and authorization runs once for each value 0 through 4. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Accounts, authentication, and authorization"?
Which practice artifact should you produce for "Accounts, authentication, and authorization" before asking a tutor for help?
Which target best proves readiness for "Accounts, authentication, and authorization"?
Which second target belongs to "Accounts, authentication, and authorization"?
Practice: Build a defensive hardening checklist for a personal or lab system and verify each control safely.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Use patching, permissions, process isolation, malware defenses, backups, and secure configuration.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Build a defensive hardening checklist for a personal or lab system and verify each control safely.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Recognize persistence and privilege risks.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Systems and endpoint defense runs once for each value 0 through 5. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Systems and endpoint defense"?
Which practice artifact should you produce for "Systems and endpoint defense" before asking a tutor for help?
Which target best proves readiness for "Systems and endpoint defense"?
Which second target belongs to "Systems and endpoint defense"?
Practice: Diagram a small network, mark trust boundaries, and propose segmentation and monitoring controls.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Explain addressing, ports, DNS, routing, firewalls, segmentation, TLS, wireless risks, and monitoring.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Diagram a small network, mark trust boundaries, and propose segmentation and monitoring controls.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Read basic network evidence defensively.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Network security runs once for each value 0 through 6. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Network security"?
Which practice artifact should you produce for "Network security" before asking a tutor for help?
Which target best proves readiness for "Network security"?
Which second target belongs to "Network security"?
Practice: Review a toy application's data flow and write defensive fixes for each identified weakness.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Recognize injection, cross-site scripting, request forgery, broken access control, insecure dependencies, and unsafe secrets.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Review a toy application's data flow and write defensive fixes for each identified weakness.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Use validation, encoding, parameterization, and secure defaults.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Web and application security runs once for each value 0 through 7. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Web and application security"?
Which practice artifact should you produce for "Web and application security" before asking a tutor for help?
Which target best proves readiness for "Web and application security"?
Which second target belongs to "Web and application security"?
Practice: Map confidentiality, integrity, and authenticity requirements to appropriate cryptographic tools and key handling.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Distinguish hashing, encryption, signatures, keys, randomness, and certificates.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Map confidentiality, integrity, and authenticity requirements to appropriate cryptographic tools and key handling.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Choose established primitives without inventing cryptography.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Cryptography and data protection runs once for each value 0 through 8. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Cryptography and data protection"?
Which practice artifact should you produce for "Cryptography and data protection" before asking a tutor for help?
Which target best proves readiness for "Cryptography and data protection"?
Which second target belongs to "Cryptography and data protection"?
Practice: Create a privacy and phishing-resistance plan that accounts for both technology and human behavior.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Analyze tracking, metadata, phishing, persuasion, oversharing, and organizational incentives.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Create a privacy and phishing-resistance plan that accounts for both technology and human behavior.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Design usable controls and reporting paths.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Privacy, social engineering, and human risk runs once for each value 0 through 9. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Privacy, social engineering, and human risk"?
Which practice artifact should you produce for "Privacy, social engineering, and human risk" before asking a tutor for help?
Which target best proves readiness for "Privacy, social engineering, and human risk"?
Which second target belongs to "Privacy, social engineering, and human risk"?
Practice: Run a tabletop incident scenario and produce a timeline, decision log, containment plan, and post-incident improvements.
Start with CS50's Introduction to Cybersecurity and Introduction to cyber security: stay safe online. Take notes until you can explain: Use preparation, detection, containment, eradication, recovery, evidence preservation, and lessons learned.
Do the first sequenced checks until the definitions, vocabulary, and setup are correct without hints.
Produce the assignment artifact, then pass the application and analysis checks tied to: Run a tabletop incident scenario and produce a timeline, decision log, containment plan, and post-incident improvements.
Any miss becomes an error-log entry, a clean redo, and one nearby transfer problem before advancing.
Bring your attempted work, the exact missed check, and one question about: Communicate severity, uncertainty, and next actions.
Move in order: foundation, transfer, analysis, timed readiness, then metacognitive repair.
Start the next sequenced check: #1 Trace check. Do not jump ahead until this one is correct.
Weakest facet: Concept
A loop for Incident response and security capstone runs once for each value 0 through 10. How many times does it run?
Which implementation is easiest to test?
Which target best matches the Cybersecurity unit "Incident response and security capstone"?
Which practice artifact should you produce for "Incident response and security capstone" before asking a tutor for help?
Which target best proves readiness for "Incident response and security capstone"?
Which second target belongs to "Incident response and security capstone"?
These are source links, not scraped course copies. Licenses differ, so the label tells students how each source is used.
View the full citation indexFree cybersecurity course covering accounts, systems, software, privacy, security tradeoffs, and practical defense.
OpenLearn course on threats, authentication, malware, networking, cryptography, privacy, and personal security practice.
Harvard CS50 sections and course materials for programming, algorithms, data structures, Python, SQL, and web foundations.
Searchable library of open educational resources across K-12 and higher education.