🎯 Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk +200 XP · 🎯 Junior Pen-Tester
Pen-Testing Lab 🎓 Advanced 🕒30 min Ages 14–18

🎯 Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk

Triage dozens of findings by CVSS + EPSS + blast-radius, not by raw CVE count

"Every scanning run produces dozens — sometimes thousands — of findings; the senior skill is prioritizing them. Read real CVE entries on cve.mitre.org, map them to CVSS vectors, and apply the "fix-now-vs-fix-later" framework. CVSS alone is not enough: an unauthenticated RCE on an internet-facing host scores 9.8 even if no exploit code exists, while an authenticated bug on an internal-only service scores 7.0 but is rarely the actual entry vector. Pass 5 of 6 to earn the Vuln Analysis 301 step and 200 XP."

🎯
Junior Pen-Tester Badge
Earned on completion
+200 XP
📜 Certificate included
PREVIEW
🎯
Badge Unlocked
Junior Pen-Tester
Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk
+200 XP · Ages 14–18
📜 Shareable certificate included
LEARNING OBJECTIVES

What your child will learn

Locate a CVE entry on cve.mitre.org or NVD and identify the description, affected-versions list, CVSS base score, and references

Explain the CVSS vector string and apply it to prioritization

Apply the prioritization rule: internet-facing un-auth RCE with public exploit code outranks internal-only authenticated bug by raw CVSS

Distinguish "patch" / "mitigate" / "accept" / "transfer" — the four remediation patterns professional programs use

Reconstruct an attack chain — phishing → credential theft → privilege escalation → data exfil — and identify which link the CVE applies to

MISSION OVERVIEW

How this mission works

Now you triage. Read real CVE entries, map them to CVSS vectors, and apply the "fix-now-vs-fix-later" framework. CVSS is one input; the real prioritization weights combine internet-facing-ness, authentication requirement, exploit-availability, and in-the-wild signals. Map findings to remediation patterns: patch, mitigate, accept, transfer. Aligned to CSTA + AP CSP + AP Cybersecurity.

SAMPLE SCENARIOS

What students actually encounter

🎯

Which CVE entry field tells you whether exploitation requires user interaction (e.g. victim must click a link)?

🎯

You have two findings — an unauth-RCE on an internet-facing host (CVSS 9.8, public exploit code) and an authenticated SSRF on an internal tool (CVSS 7.5, no public exploit). Which do you fix first and why?

🎯

You map a finding to a CWE. What is a CWE?

🤖
AI MENTOR

Cipher is with them the whole way

When a student gets stuck on Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk, Cipher appears with a mission-specific nudge — no spoilers, just a hint toward the right thinking. Make a wrong choice, and Cipher explains the real-world consequence. Finish the mission, and Cipher generates a personalized performance debrief based on exactly how the student played it.

💡 3-tier hints (nudge → teach → reveal)
🎯 Wrong-answer concept explanations
📊 Personalized debrief on completion
⏱️ Auto-triggers after 30 seconds idle
STANDARDS ALIGNMENT

ISTE alignment

CSTA 3A-NI-08 + AP Cybersecurity + AP CSP + ISTE Digital Citizen 2a/2d + NICE-SU-PEN-01/02

Triage dozens of findings by CVSS + EPSS + blast-radius, not by raw CVE count. Senior pentesters think in dollars and blast-radius, not raw CVE counts. The "14 critical findings, one of which could exfiltrate the customer database at $4M regulatory fine + $8M reputational cost" framing is the executive-summary level. Aligned to NICE-SU-PEN-02 ("apply formal methods of risk analysis").

Digital Citizen 2a Digital Citizen 2d

Ready to start Pen-Test Vuln Analysis 301 — Reading CVEs & Prioritizing Risk?

Unlock all 16 missions with a Family Plan. Educators get a free pilot for their entire classroom.