# Read the offer. Work the lab. Earn the certificate.

Source: https://ai.techclick.in/blog_cybersecurity_academic_internship
Markdown: https://ai.techclick.in/blog_cybersecurity_academic_internship.md
Publisher: Techclick Infosec Pvt Ltd

Read a Techclick academic internship offer, accept it with college ID, run 45-day authorized network-security and VAPT labs, and collect evidence that earns the completion certificate.

## The TPO ticket

 College Training and Placement Office (TPO) message, Friday 4 p.m.: “Bring the internship offer letter and college ID before the file closes.” Same week, a classmate runs  nmap -sS  on the hostel Wi-Fi “because the letter says VAPT.” One of those two students finishes with a completion certificate. The other gets a conduct case.

 The Techclick academic letter is explicit. Duration is  45 days , extendable on performance. Mode is  hybrid  (online plus onsite as applicable). Domain is  Cybersecurity — Network Security and VAPT . Type is  academic internship . Start date is confirmed only after you accept.

   Hero · campus to lab to certificate

   Notice the order: college proof first, lab second, certificate last. Skipping the first step, or scanning the wrong network, breaks the last step.

   Quick answer

   An academic internship is supervised college-credit learning. You accept by signing the letter and attaching a copy of your college ID. You then work only in the authorized lab: network fundamentals, firewalls, VAPT with Kali / Nmap / Nessus, and tool labs on Wireshark, Burp Suite and Metasploit. Weekly review plus a project earn the completion certificate. It is not employment, not a public-internet pentest, and not a free CEH or Security+ voucher.

   Hard words before the runbook

    Academic internship  — college-credit learning under a company; the letter says it does not constitute employment.  Scope of work  — the list of topics and labs you are allowed to do.  VAPT  — Vulnerability Assessment and Penetration Testing; assessment finds, pentest attempts to exploit, both need written authorization.  Hybrid  — online classes plus onsite when the batch calls you in.  Completion certificate  — issued after attendance and satisfactory performance, not on calendar day 45.

## Three things this letter is not

 Hold three boxes in your head. Mix them and you will argue with TPO, HR, and your mentor in the same week.

#### 1. Not a job

 Term 1: the internship is academic and does not constitute employment. No employee ID, no salary expectation from this letter, no “I work at Techclick” on a resume until you actually do.

#### 2. Not a hunting licence

 VAPT in the scope means authorized lab ranges and assigned targets. Campus Wi-Fi, a neighbour’s router, and random public websites are out of scope even if the tool names are in the letter.

#### 3. Not a vendor voucher

 The letter offers  preparation support  for CEH / CompTIA Security+ / Cisco security. Pearson VUE fees and official badges are separate. Techclick does not sell fake certificates.

#### 4. Not automatic

 Term 4: a completion certificate is issued upon successful completion and satisfactory performance. Miss weekly reviews or violate conduct (term 5) and the file stops.

   Decision · authorized lab vs public scan

   Path A is the written lab range. Path B is “the letter mentioned Nmap so I scanned the hostel.” Interviewers and TPO both treat Path B as a conduct failure, not extra initiative.

   Say this out loud

   The offer lists tools. Authorization lists targets. I only run the tools against the targets my mentor put in this week’s scope.

   Flow 1 · what the letter actually binds

       Academic internship sits between college credit and authorized lab, not employment or public scanning

- College credit + ID Academic intern 45 days · hybrid Authorized lab Nmap · Nessus · Burp Certificate Not employment · not a public scan · not a voucher Read left → right. The letter connects college identity to a scoped lab. Skip college ID or skip scope and the certificate box never turns green. ## How the 45 days actually run The letter’s start date is “to be confirmed upon acceptance.” Nothing in the lab starts until the signed letter and college ID are back. After that the clock is 45 days, extendable if both sides agree (term 6). Journey · offer to certificate Offer is paperwork. Labs are the work. Review is the weekly proof. Certificate is the output. Posting the offer on LinkedIn is none of those four. Flow 2 · 45-day learning path Six blocks of the 45-day academic internship from network fundamentals to project Days 1–7 Network + ethics Days 8–14 Firewalls intro Days 15–21 Kali + Nmap Days 22–28 Nessus VA Days 29–35 Wireshark · Burp · MSF Days 36–42 Incident case + project Days 43–45 Evidence pack + certificate Weekly progress review sits on every block — not only at the end This week map is how the letter’s scope of work is taught in 45 days. Your mentor may shift a block; they will not add the public internet as a target. Letter scope, in the order you should be able to demo: Network security and cybersecurity concepts.

- Firewall technologies — Palo Alto, FortiGate, or Cisco ASA introduction (policy, zones, what a deny log looks like).

- VAPT basics on Kali Linux with Nmap and Nessus.

- Tool labs: Wireshark, Metasploit, Burp Suite — authorized targets only.

- Study of real-world incidents and case analysis.

- Certification prep support: CEH, CompTIA Security+, Cisco security track (the letter still names CCNA Security; that exam is retired — current Cisco entry paths are CCNA and CCST Cybersecurity).

- Assigned project and weekly progress review.

   Primary source · offer letter

   Techclick Infosec academic internship offer (program text, 27 May 2026 template). Domain: Cybersecurity (Network Security &amp; VAPT). Duration: 45 days, extendable. Mode: hybrid. Confirm by signing and returning with a copy of college ID. Queries:  support@techclick.in  ·  ai.techclick.in  · +91 92772 29456.

## Letter vs 12-week course vs vendor batch

 Students mix three Techclick products because they all say “internship” or “cybersecurity.” Pick from the paper in your hand, not from a WhatsApp rumour.

   Pipeline · journal, review, certificate

   If the journal is empty, review has nothing to score, and the certificate has nothing to issue. Attendance without artefacts is not satisfactory performance.

        If you hold…  What it is  Clock  What TPO wants  What you do not claim

         Academic offer letter (this lesson)
         College-credit intern, hybrid, Network Security &amp; VAPT
         45 days, extendable
         Signed letter, college seal if they ask, completion certificate
         Employee, stipend (unless a later addendum says so), vendor badge

         Enrolled  B.Tech internship course
         Mentored 12-week plan with recordings on My Courses
         12 weeks / 24 sessions
         Attendance, weekly evidence, capstone, viva
         That the 45-day letter automatically became 12 weeks

         Paid vendor batch (Palo Alto, Zscaler, F5…)
         Operator training for a product
         Batch calendar
         Usually nothing for college credit unless TPO pre-approved it
         That it is an academic internship

   Classic mix-up

   Your letter says 45 days. The public syllabus page says 12 weeks. Both can be true for different cohorts. The paper you signed is the contract for  your  file. Ask the training team which plan you are on before you tell TPO a duration.

## Runbook: college → Techclick → lab

 Three sides, in this order. Skipping Side A is how files get stuck at TPO. Skipping Side C authorization is how internships get terminated (letter term 5).

### Side A — College / TPO

 Primary source: Techclick offer letter, Intern Acceptance block + terms 1–6.

- #### Read the type line Confirm it says Academic Internship and does not constitute employment . If TPO needs an employment letter, this document will not satisfy them — raise it before you sign, do not rewrite the PDF.

- #### Fill intern acceptance Sign, date, attach a copy of your college ID. If your college requires a seal and authorised signature, take the letter to TPO — the template has a college-seal block for that.

- #### Keep a clean copy Store the signed PDF for your file. Do not publish classmate names, mobile numbers, or the full letter on LinkedIn. The public fact is “academic intern, cybersecurity, Techclick Infosec.” The rest is administrative.

     docs · Internship Offer Letter · training mock

     Training mock · not live

       Offer letter → Internship details

### Internship details

          Intern name  Student Name (sample)

          Internship type  Academic Internship

          Domain  Cybersecurity (Network Security &amp; VAPT)

          Duration  45 Days (extendable)

          Mode  Hybrid (Online + Onsite as applicable)

          Start date  Confirmed upon acceptance

        Acceptance required  Signed letter + copy of college ID card

         Save draft
         Mark accepted

   Sample fields only. A live letter carries a real name, college, and reference number — those stay in your TPO file, not on a public post.

### Side B — Techclick training team

 Primary source:  ai.techclick.in/syllabus/btech-internship  and student dashboard  /my-courses .

- #### Return the signed pack Email support@techclick.in or WhatsApp +91 92772 29456 with the signed letter and college ID. Start date is confirmed after that pack lands — the letter says so.

- #### Get portal access Once enrolled, class recordings for the internship course live under My Courses. Unauthenticated playback is supposed to fail closed. If you cannot see the course, that is an enrollment issue, not a “the lab is down” issue.

- #### Lock your reporting line The letter’s reporting line is the Techclick Infosec training team. Weekly progress review is a scheduled artefact, not a chat ping when you remember.

     ai.techclick.in/my-courses

     Training mock · not live

       My Courses → B.Tech Cybersecurity Internship

### B.Tech Cybersecurity Internship

        Access  Enrolled · recordings gated

          This week  Network fundamentals + ethics

          Evidence due  Journal page + sanitized screenshot

        Lab range (sample)  10.10.10.0/24 · intern-lab only

         Open workbook
         Play class 1

   Live students see their own enrollment. This mock uses RFC 1918 lab addresses only. Never paste a real Graph item ID, password, or classmate email into a screenshot you share.

### Side C — Authorized lab (the actual work)

 Primary sources:  Nmap SYN scan ,  Nmap connect scan ,  NIST SP 800-115 .

   Lab · proof on the glass

   Green checks belong on lab findings you can re-run. A screenshot of someone else’s website with an open port is not internship evidence.

   Flow 3 · authorized VAPT path

       Authorized VAPT path from written scope to report

- Written scope this week’s range Nmap recon -sS or -sT Nessus VA find, don’t exploit In-scope exploit Burp / Metasploit lab Report NIST SP 800-115 is the planning spine: decide the test type, get authorization, then run the technique. Nmap before Nessus. Nessus before Metasploit. Report before LinkedIn. #### Write the week’s range at the top of the journal Sample lab only: 10.10.10.0/24 . If the mentor has not named a range, you do not scan. This is the same rule as a professional Rules of Engagement.

- #### Recon with Nmap With root on Kali, SYN scan is the default because it never completes the handshake. Without raw-packet rights, Nmap falls back to TCP connect ( -sT ), which is slower and more likely to be logged. Official: nmap.org SYN scan .

   Authorized intern-lab only · sample range
 sudo nmap -sS -sV -oA week3-lab 10.10.10.0/24
# no root / no raw sockets:
nmap -sT -sV -oA week3-lab 10.10.10.5

- #### Vulnerability assessment with Nessus Point Nessus at the same in-scope hosts. Export the scan PDF into the weekly folder. VA lists weaknesses; it is not a pentest. NIST SP 800-115 treats scanning and penetration testing as different techniques with different risk.

- #### Manual check, then lab exploit Wireshark on the lab interface to see the three-way handshake you just generated. Burp against the assigned web lab (not the college ERP). Metasploit only against the VM the mentor named. If you cannot name the target IP in one breath, you are not in scope.

- #### Firewall intro in the same week you talk policy On Palo Alto / FortiGate / ASA lab images: identify zones, a security policy, and one deny log. You are not expected to pass PCNSE in 45 days. You are expected to say “traffic died on policy, here is the log line.”

   Green success for one lab day

   Journal names the range. Nmap output file exists ( -oA ). Nessus export attached. One finding explained in two sentences (what, why it matters, who would patch). No campus or public IPs anywhere in the folder.

## Weekly review to certificate

 After go-live (start date confirmed), every week looks the same from the outside: attend, lab, write, review. The letter calls this “assigned project work and weekly progress review.”

- Attend the hybrid session (or watch the recording on My Courses the same week — late binge is not attendance).

- Run only that week’s in-scope lab.

- Drop artefacts in the journal: command, screenshot with PII cropped, two-sentence finding.

- Sit the weekly review. Bring the journal, not a verbal “I did Nmap.”

- Fold the week into the assigned project (topology, risk list, or supervised test) so day 45 is a pack, not a panic.

 Certificate rule, term 4: issued upon successful completion and satisfactory performance. Term 2: regular attendance and tasks on time. Term 3: confidentiality of organizational data, tools, and materials. Term 5: conduct or academic-integrity violations can end the internship immediately.

        Cert name in the letter  What prep support means  What it is not

         CompTIA Security+
         Core security functions. Current exam family is Security+ V7 (SY0-701) on CompTIA’s site.
         A voucher inside the internship letter

         CEH
         Ethical hacking exam prep after you already understand authorized scope
         Permission to scan live networks

         CCNA Security (named in letter)
         Historical Cisco security associate track. Cisco retired CCNA Security; current entry paths are CCNA and CCST Cybersecurity.
         A live 210-260 exam you can still book as “CCNA Security”

## Traps and proof

        Failure  What it looks like  First fix  Proof it is fixed

         Scanned the wrong network
         Hostel SSID, college ERP, or a public IP in your nmap output
         Stop the scan. Tell the mentor the same day. Do not “just finish the command.”
         Journal shows only the written lab range; mentor signs the week

         Treated it as a job
         Resume says “Software Engineer, Techclick” or you demand a salary from this letter
         Correct the title to Academic Intern (Cybersecurity). Re-read term 1.
         Resume line matches the letter type

         Empty journal
         You attended every class and have zero screenshots
         Backfill this week only with re-runnable lab commands. Do not invent old weeks.
         One artefact per attended week

         Leaked the letter
         Full offer with mobile, email, college, and ref number on Instagram
         Take it down. Public post = role + domain + company, no PII.
         Post contains no ID numbers or personal contacts

         Expected a voucher
         “Letter said CEH so where is my exam fee?”
         Prep support ≠ voucher. Ask support@techclick.in if a later batch addendum exists. Do not assume.
         Written addendum, or you buy the exam yourself

         Wrong duration told to TPO
         Letter 45 days, you reported 12 weeks from the syllabus page
         Quote the letter in your hand. Confirm cohort with training team.
         TPO file duration matches the signed letter

   Pilot checklist before you tell TPO “done”

- Signed letter + college ID copy stored (and college seal if TPO requires it).

- Start date confirmed in writing by the training team.

- Every lab folder uses only the mentor’s range.

- Weekly reviews exist as dated notes, not memory.

- Project artefact attached (diagram, risk list, or supervised test report).

- No passwords, no classmate PII, no Graph/SharePoint IDs in anything you submit to college.

- Completion certificate requested only after attendance + performance, not on calendar day 45.

   Interview angle

    Weak:  “I did ethical hacking for 45 days.”  Strong:  “Academic intern, authorized lab only. I can show an Nmap SYN vs connect difference, a Nessus finding I did not instantly exploit, and a weekly journal. The letter was not a job and not a licence to scan campus.”

## Knowledge check

   Six judgment items. If you miss the authorization or employment questions, re-read the mental model and Side C before you sit with TPO.

       Q1
       The offer letter says “academic internship.” What does that mean for your resume and HR?

           You are now a Techclick employee with a joining date
           College-credit learning; the letter says it does not constitute employment
           You may scan any public website to build a portfolio
           A CEH voucher is included automatically

       Correct:  b . Term 1 is the line TPO and HR both need. Re-read “Three things this letter is not.”

       Q2
       The letter asks you to confirm acceptance. What is the first complete proof?

           A WhatsApp “ok” to a classmate
           Signed letter returned with a copy of your college ID
           Posting the PDF on LinkedIn
           Buying a Security+ voucher today

       Correct:  b . Closing paragraph of the letter. Start date is confirmed only after acceptance. Side A of the runbook.

       Q3
       An intern runs  nmap -sS  on college hostel Wi-Fi because “VAPT is in the offer.” First action?

           Add  -T5  so it finishes before lights-out
           Launch Metasploit against the first open port
           Stop. Scope is the authorized lab range, not campus. Tell the mentor.
           Email the raw scan to TPO as evidence

       Correct:  c . Tools in the letter are not targets. Term 5 can end the internship. Re-read Flow 3 and the traps table.

       Q4
       In this internship, how do Nessus and Metasploit split?

           They are two names for the same scanner
           Nessus is vulnerability assessment; Metasploit is exploitation — both only on authorized lab hosts after that week’s scope
           Nessus is a firewall; Metasploit is Wireshark
           Use both on the public internet for the assigned project

       Correct:  b . NIST SP 800-115 separates scanning from penetration testing. Side C: Nmap → Nessus → in-scope exploit → report.

       Q5
       Why does  sudo nmap -sS  need root while  nmap -sT  does not?

           SYN scan crafts raw packets and never completes the handshake; connect scan uses the OS  connect()  call
            -sT  is illegal in India
            -sS  only works on UDP
           Root is required only for DNS

       Correct:  a . Official Nmap book: SYN scan is default with raw-packet privileges; TCP connect is the unprivileged fallback and is more likely to be logged. Re-read Side C.

       Q6
       When is the completion certificate issued?

           The day the offer PDF arrives
           After you post it on Instagram
           After successful completion and satisfactory performance (attendance + tasks)
           Automatically at 00:00 on calendar day 45 even if you were absent

       Correct:  c . Letter term 4. Term 2 is attendance. Calendar expiry without work is not performance. Re-read runtime + traps.

       Check answers
       Reset

## Sources

- Techclick Infosec Pvt. Ltd. — Academic Internship Offer Letter program text (45 days, hybrid, Network Security & VAPT, sign + college ID). Contact: support@techclick.in · techclick.in · +91 92772 29456. Individual intern names, mobiles, and college IDs are not published here.

- Techclick enrolled course plan: B.Tech Cybersecurity Internship syllabus (12-week mentored path — confirm which clock your cohort uses).

- AICTE Students Internship Policy: aicte.gov.in/content/aicte-students-internship-policy

- Nmap Network Scanning — TCP SYN scan ( -sS ): nmap.org/book/synscan.html

- Nmap Network Scanning — TCP connect scan ( -sT ): nmap.org/book/scan-methods-connect-scan.html

- NIST SP 800-115, Technical Guide to Information Security Testing and Assessment: csrc.nist.gov/pubs/sp/800/115/final

- CompTIA Security+ (prep target named in the letter; current V7 / SY0-701): comptia.org/en-us/certifications/security

- NIST NICE Framework Resource Center: nist.gov NICE

- CIS Critical Security Controls: cisecurity.org/controls

 Related:  B.Tech internship syllabus  ·  Computer hardware basics  ·  VAPT interview — lock scope first  ·  SOC analyst interview  ·  Apply / enroll  ·  My Courses

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
