About this interactive
Every vulnerability scanner in the world will sort its report by CVSS score for you, and every experienced analyst will tell you that order is wrong. The score describes the flaw; it has never met your network. This activity hands you five findings from one week of scanning and asks the question the scanner cannot: which do you fix first? A 9.8 Critical sits on a brochure website with no data behind it and a WAF signature already blocking the published exploit. A 6.5 Medium sits on the domain controller, is being used by ransomware crews this week, and has no patch at all. Each card gives you what real triage gives you — the base score and vector, what the asset is worth, whether the flaw is being exploited, whether a fix exists, and what compensating controls are already in the way — and the expert ordering is the CVSS v3.1 environmental score, the published mechanism for exactly that adjustment. Rank them, then read the reveal: every finding shows its environmental score and the sub-scores behind it, so you can see precisely which of the four contextual inputs moved it and by how much.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →