Week 08 · lesson
Checkpoint 3: CVE Applicability + Hardening Report
Use the fictional workstation profile from Week 8. Do not scan or modify a real school system.
Submit
Your hardening package must include:
- asset/configuration inventory;
- CVE applicability reasoning based on the supplied product/version evidence;
- separation of vulnerability findings from configuration findings;
- prioritized findings: fix first, schedule soon, monitor/review;
- a change plan with current state, desired state, reason, side effect, rollback, and verification;
- before/after evidence for approved simulated changes;
- second-assessment/rescan interpretation;
- backup restore evidence;
- at least two remaining risks.
Defense question
Answer in 3-5 sentences:
Which recommendation has the strongest evidence behind it, and what evidence would make your weakest recommendation stronger?
Scoring
This is a teacher-reviewed mastery checkpoint.
The common GSC I rubric scores five areas from 0-4:
- technical accuracy
- evidence quality and reproducibility
- reasoning and trade-offs
- safety and authorization
- communication
Maximum: 20 points.
The Robotnix mastery target is 15/20 or higher with no criterion below 2. If the evidence is incomplete or a claim reaches beyond what the evidence supports, revise and resubmit.