This is the closing lesson of the course, and it is deliberately different from the rest.
You have spent the curriculum learning how to find and fix vulnerabilities. This lesson steps back to ask a broader question: where do these skills lead, and how do you keep growing once the course is over?
It is reflective rather than offensive — there is no payload to fire and no challenge to solve on the Score Board. Instead you will connect what you have already built to the shape of the profession.
In this lesson you will:
- See that cybersecurity is not one job but a wide field of complementary specialisms — the four role families: offensive (red), defensive (blue), governance/risk/compliance (GRC), and application security (AppSec).
- Meet the NICE Cybersecurity Workforce Framework (NIST SP 800-181) as a shared map of the work, and the certification routes that lead into each family.
- Understand bug bounties and the safe-harbour clause that makes them a legal way to practise — the same authorisation-first ethic the whole course rests on.
- Learn why a visible portfolio and a habit of continuous learning matter more than any single certificate.
Think of this as the moment you turn a pile of techniques into a direction.
Estimated time: ten minutes.
When you are ready, send the Continue signal.
Using the right panel: The NovaCart application on the right represents the type of web application you have been learning to attack throughout this course. Browsing through it freely in this final lesson is a reminder of how much ground you have covered — the SQL injection in the search bar, the XSS in the heading, and the file-upload endpoint are all vulnerabilities you can now identify, understand, and explain. Take a moment to explore it with the perspective of everything you have learned.