Week 08 · lesson

Checkpoint 3: CVE Applicability + Hardening Report

Use the fictional workstation profile from Week 8. Do not scan or modify a real school system.

Submit

Your hardening package must include:

  • asset/configuration inventory;
  • CVE applicability reasoning based on the supplied product/version evidence;
  • separation of vulnerability findings from configuration findings;
  • prioritized findings: fix first, schedule soon, monitor/review;
  • a change plan with current state, desired state, reason, side effect, rollback, and verification;
  • before/after evidence for approved simulated changes;
  • second-assessment/rescan interpretation;
  • backup restore evidence;
  • at least two remaining risks.

Defense question

Answer in 3-5 sentences:

Which recommendation has the strongest evidence behind it, and what evidence would make your weakest recommendation stronger?

Scoring

This is a teacher-reviewed mastery checkpoint.

The common GSC I rubric scores five areas from 0-4:

  • technical accuracy
  • evidence quality and reproducibility
  • reasoning and trade-offs
  • safety and authorization
  • communication

Maximum: 20 points.

The Robotnix mastery target is 15/20 or higher with no criterion below 2. If the evidence is incomplete or a claim reaches beyond what the evidence supports, revise and resubmit.