Week 08 · overview

Week 8: Vulnerabilities, CVEs, and System Hardening

This week connects public vulnerability information to practical defensive configuration.

Garden State Cyber I asks students to distinguish vulnerabilities from exploits, use CVE information as a research tool, review recommended PC configurations, and practice system hardening.

This week

Lesson 1: Vulnerability, Exploit, and CVE: Name the Weakness Precisely

Determine whether a CVE actually applies to a product and version. Separate published severity from local risk and identify fixes, mitigations, and verification evidence.

Lesson 2: System Hardening: Reduce What Can Go Wrong

Build a baseline, analyze synthetic benchmark findings, review users, privileges, services, updates, firewalls, screen locks, and backups, then prioritize changes.

Lesson 3: Hardening Review: Turn Findings Into Evidence

Perform a fictional workstation hardening review with inventory, prioritization, simulated changes, rescan evidence, and backup recovery testing.

What you will produce

  • CVE applicability table
  • vulnerability brief
  • hardening worksheet
  • prioritized change plan
  • before/after verification record
  • final hardening report

The standard is:

Do not chase vulnerability names or benchmark scores. Verify the system state, explain the risk, make the smallest defensible change, and prove the result.