Exercise 3: How the Capstone Embodies "Tools This Process Calls On, Not the Process Itself" — Possible Solution ==================================================================== THE ORIGINAL CLAIM FROM PENTEST1-1 ------------------------------ Per this chapter's own tip-box, pentest1-1 "opened this course by claiming that a pentest is a repeatable, disciplined process, and that the site's own vulnerability courses are tools this process calls on — not the process itself." HOW THE CHAPTER-ATTRIBUTION TABLE DEMONSTRATES THIS ------------------------------ The table shows nine distinct process steps (pentest1-1 through pentest1-9), each with its own specific job: signing an RoE (authorization), defining scope, adopting a framework, gathering recon, confirming an attack surface, matching findings, exploiting with restraint, checking lateral movement, and writing a report. None of these nine steps IS a vulnerability-specific course — dbsec1, sqli1, and bc1 are not listed as their own process steps at all. Instead, per the table's own "Matching findings to dbsec1/sqli1/bc1" row, they appear as something the PROCESS reaches for, specifically during pentest1-6's own matching step and again during pentest1-9's own remediation-writing step — used exactly when the process needs them, and set aside otherwise. WHY THIS IS THE CONCRETE PROOF OF THE CLAIM ------------------------------ If the vulnerability courses WERE the process itself, the capstone's own methodology walkthrough would have had to organize itself around "first do the SQLi course's own techniques, then the XSS course's techniques," and so on. Instead, the walkthrough organizes itself entirely around the nine PROCESS phases, and dbsec1/sqli1/bc1 only enter the walkthrough as tools invoked from WITHIN specific phases (step 5's vulnerability analysis, step 9's remediation) — exactly the relationship pentest1-1 originally described. The capstone doesn't just repeat pentest1-1's claim; it structurally demonstrates it, by building an entire real engagement where the process itself is the organizing skeleton and the vulnerability-specific courses are called in only at the two specific moments the process actually needs them. WHY THIS WORKS AS AN ANSWER ------------------------------ It distinguishes between the nine PROCESS steps (which are never themselves vulnerability-specific courses) and the two specific MOMENTS those courses get invoked from within the process, using the attribution table's own structure as the evidence, rather than simply restating pentest1-1's original claim without connecting it to the capstone's actual structure.