Individual Practical Defense Protocol
Author & Course Lead — Badr Tajini · ESILV · 2026–2027
Defense window: 30 November–4 December 2026. Appointments and submission deadline are announced separately. Keep the existing 8–10 minutes per student; the reference walkthrough does not replace individual explanation or observed evidence.
Purpose
The defense verifies individual ownership and applied reasoning. It is not a command-memory contest, an English-accent assessment, or a second team presentation. It is a separate 10% course component, scored out of 20 and then normalized; it is not part of the 50% team Delivery Pack score.
Format
Recommended duration: 8-10 minutes per student.
- Claim trace (2 minutes): the instructor selects one submitted claim. The student identifies its definition, test, primary evidence, observed result, and limitation.
- Diagnostic sequence (3 minutes): the instructor injects one prepared, bounded fault. The student preserves the symptom, states falsifiable hypotheses, and chooses one discriminating test before changing state.
- Recovery or rollback (2 minutes): the student performs or precisely specifies the safe bounded action, known-good identity, stop condition, and verification test.
- Limitations and ownership (1-3 minutes): the student states one residual risk, their personal contribution, and any AI-assisted work relevant to the selected artifact.
The instructor may provide a command reference sheet. A student earns credit for a sound diagnostic path even when the fault cannot be fully repaired in the available time. Unsafe improvisation, unsupported certainty, and concealed limitations reduce the score.
Prepared fault bank
Use only a disposable copy of the student’s laptop/cloud stack or an instructor-owned replica. Confirm the selected Docker context before any mutation.
- Wrong host port or unexpected port collision.
delivery-apipoints to a non-existent database hostname.- PostgreSQL is running but not ready.
- Secret file is missing or has unusable permissions.
- API filesystem write attempted under
read_only. - Health path is correct but readiness path is misconfigured.
- New image is healthy but reports the wrong Git SHA.
- New image fails smoke tests and requires rollback.
- Named volume is absent from a proposed Compose change.
- Proxy is healthy internally but bound to the wrong host interface.
Do not inject destructive volume deletion, credential disclosure, public Docker API exposure, or faults outside the allocated environment.
Instructor consistency
- Draw the claim and fault categories randomly from the same bank across all four TD groups.
- Use the four 5-point criteria in
PROJECT_RUBRIC.md. - Record concise evidence for each awarded score.
- Calibrate both instructors on at least three sample defenses before final grading.
- Provide reasonable accommodations without changing the learning outcome.
Scoring contract - 20 points
This is the same four-criterion contract published in PROJECT_RUBRIC.md and
used in the instructor record. Each criterion is scored out of 5. Four core
points assess the mandatory behavior; one depth point rewards precise
mechanism, falsification, or judgment after the core gate passes.
| Criterion | Core | Depth | Total |
|---|---|---|---|
Explains one selected claim from definition through evidence (claim-trace) |
4 | 1 | 5 |
Uses a disciplined symptom → hypothesis → test sequence (diagnostic-sequence) |
4 | 1 | 5 |
Performs or specifies safe recovery and rollback (recovery-rollback) |
4 | 1 | 5 |
States limitations, residual risk, and personal contribution honestly (limitations-ownership) |
4 | 1 | 5 |
| Total | 16 | 4 | 20 |
Depth is zero for a criterion whose mandatory core behavior is not demonstrated. Consultation of the submitted runbook or command cards does not reduce the score; the defense assesses reasoning and safe action, not recall.
Stop conditions
Stop the practical action and move to verbal reasoning if the student is about to expose a credential, delete a persistent volume, operate outside the selected disposable runtime, or execute a command with an unresolved destructive target.