The setting
Coastline Credit Union is a regional bank with 11 branches and an online banking platform. You are a security analyst on a three-person team, responsible for reviews, triage, and incident write-ups ahead of the annual regulator exam.
Every mission on this path happens at the same company, so context carries over the way it does in a real job: the data you cleaned in mission two is the data the finance lead questions in mission four.
The missions
1. risk scenariostarter
Assess the wire fraud risk scenario for Coastline's branches
Business email compromise is hitting credit unions, and Coastline moves member money by wire every day. Your manager wants a risk read on the current wire process before the exam.
You deliver: A risk scenario assessment rating likelihood and impact, naming the process gaps, and recommending controls.
Scored on: Likelihood and impact rated, Names the real gaps, Controls tied to gaps, Grounded in the numbers.
Working from: wire_process.md, threat_note.md.
2. access reviewstarter
Run the quarterly access review on Coastline's core banking app
It is the quarterly access review for the core banking application. The regulator expects proof that access is limited to who needs it, and the last review missed a terminated employee.
You deliver: An access review report listing every exception with usernames and a revocation and change list.
Scored on: Finds the over-privilege, Finds the terminated account, Finds MFA gaps and shared logins, Dormant accounts and action list.
Working from: access_review.csv.
3. vulnerability triagecore
Triage this week's vulnerability scan for Coastline's banking hosts
The weekly scan returned a long list and the team can only patch a handful before the next maintenance window. You decide the order. Raw CVSS is not the whole story here.
You deliver: A triage plan ordering the findings by real risk with the reasoning for each placement.
Scored on: Ranks by real risk, Explains the tradeoff, Handles the unpatchable finding, Complete ordered list.
Working from: vuln_scan.csv.
4. incident notecore
Write the incident note for Coastline's after-hours login spike
At 02:00 the login alerting fired: hundreds of failed logins across many usernames in minutes. By morning it is your incident to write up for the manager and the exam file.
You deliver: An incident note with timeline, impact, root cause, the compromised account, and follow-up actions.
Scored on: Identifies the attack pattern, Finds the compromised account, Accurate impact, Actions and follow-ups.
Working from: incident_timeline.md, auth_log.csv.
5. control mapstretch
Map Coastline's controls to the exam requirements and find the gaps
The regulator exam is six weeks out. Examiners work from a requirements list, and they will ask for evidence that each control exists and is tested. Your job is to map what Coastline has against what is required and surface the gaps before they do.
You deliver: A control map linking requirements to controls, with a gap list and stale-control flags.
Scored on: Finds the missing controls, Flags the stale control, Complete mapping, Ties to real risk.
Working from: controls_inventory.csv, requirements.md.
How the scoring works
Each deliverable is graded against the rubric written for that mission. Separately, every mission on every path is graded on how you used AI, against the same four criteria:
- Understood the task. The learner framed the goal for the assistant clearly instead of pasting the brief and hoping.
- Grounded in the material. The learner directed the assistant into the provided files and based the work on them, not on invented facts.
- Verified the output. The learner checked claims, numbers, or coverage against the source material before submitting.
- Iterated with judgment. The learner refined weak parts of the draft with specific follow-ups rather than accepting the first answer.
Both scores, with the work behind them, go on your proof profile. That is what makes a claim like "I can use AI for cybersecurity" something an employer can check.