Vulnerability Analysis
Name risk with CVE/CVSS, read a report, and choose patch/compensate/accept — not “run every exploit.”
1. CVE, Advisories, and What Vulnerable Means
A CVE is a named bug. Presence in a scanner is not automatic remote code execution.
15 min
+40 XP
2. Scanner Reports vs Real Risk
False positives, missing context, and why you verify on systems you own.
15 min
+40 XP
3. Patch, Compensate, or Accept
Risk treatment for a finding — with a written owner, not a screenshot of Metasploit.
15 min
+40 XP
4. Lab — Read a Sample CVE and Write a Fix Note
Pick a public CVE page, summarize impact and a defensive fix in cyberlium-lab.
25 min
+40 XP
5. Quiz — Vulnerability Analysis
10 APPLY questions on CVE/CVSS and ethical handling of findings.
10 min
+40 XP