Week 08 · overview
Week 8: Vulnerabilities, CVEs, and System Hardening
This week connects public vulnerability information to practical defensive configuration.
Garden State Cyber I asks students to distinguish vulnerabilities from exploits, use CVE information as a research tool, review recommended PC configurations, and practice system hardening.
This week
Lesson 1: Vulnerability, Exploit, and CVE: Name the Weakness Precisely
Determine whether a CVE actually applies to a product and version. Separate published severity from local risk and identify fixes, mitigations, and verification evidence.
Lesson 2: System Hardening: Reduce What Can Go Wrong
Build a baseline, analyze synthetic benchmark findings, review users, privileges, services, updates, firewalls, screen locks, and backups, then prioritize changes.
Lesson 3: Hardening Review: Turn Findings Into Evidence
Perform a fictional workstation hardening review with inventory, prioritization, simulated changes, rescan evidence, and backup recovery testing.
What you will produce
- CVE applicability table
- vulnerability brief
- hardening worksheet
- prioritized change plan
- before/after verification record
- final hardening report
The standard is:
Do not chase vulnerability names or benchmark scores. Verify the system state, explain the risk, make the smallest defensible change, and prove the result.