What your child will learn
Apply the "stop and document" rule when you find a chance-find OUT of your engagement scope — you stop probing, screenshot, log timestamp + page + evidence hash, then notify the asset owner
Distinguish coordinated disclosure (notify vendor privately, allow 90 days) from full disclosure (publish immediately) and when each is appropriate
Apply the responsible-disclosure rule for personal-data leaks: a leaked customer database is NOT for you to read or download to assess severity — you notify the data owner
Recognize that "I was just testing" is not a legal defense — CFAA's "exceeds authorized access" test scopes against the RoE, not against intent
Identify a phishing email with a real C2 callback and apply "do not click further, screenshot, forward to IT"
How this mission works
The most important mission in the track. You WILL find a vulnerability you were not looking for. Work through five realistic scenarios and apply the rule: stop, log, notify. Recognizing that the "exploit it" instinct is the wrong instinct in every scenario is what separates a junior from a senior red-teamer. Pass 5 of 6 to earn 200 XP AND unlock the capstone (mentor-gated).
What students actually encounter
While authorized-reconning, you find an out-of-scope customer database in the customer's S3 bucket. What do you do?
You accidentally crash the customer's login server with a load test during business hours. What is the right move?
You receive a phishing email with a C2 callback URL at your school email. What do you do?
Cipher is with them the whole way
When a student gets stuck on Pen-Test Exploit Ethics 401 — When You Find Something You Did Not Expect, Cipher appears with a mission-specific nudge — no spoilers, just a hint toward the right thinking. Make a wrong choice, and Cipher explains the real-world consequence. Finish the mission, and Cipher generates a personalized performance debrief based on exactly how the student played it.
ISTE alignment
The load-bearing ethics mission. CFAA's test is "exceeding authorized access," not intent. Verbal permission, hallway waivers, "we're friends," and post-hoc notifications are NOT authorization. Aligned to AP Cybersecurity's "Ethics in Cybersecurity" topic, CSTA 3A-NI-08 (cryptographic-ethics tradeoffs in real-world contexts), and ISTE Digital Citizen 2a (positive, safe, legal, and ethical digital behaviors).