Oh come on... I like ISC... but they are making a leap here...
The prof doesn't ask for any information about vulnerabilities, (at least not from what is quoted), he asks for information about a publicly available target with publicly available tools....
So, what are we looking at? Let's start by NMaping the target... Not illegal in the USA. Then let's grab some banners.... Not illegal in the USA... Let's pull a whole web site and look through it's source... Not illegal in the USA... There's a whole lot of things that _can_ be done to provide the prof with the information he's looking for that is not illegal in the USA.
Then, what does he ask for? He asks for a properly documented "penetration test", (though what he asks for isn't really a pen test). Hmm... Seems to me like he's trying to teach them how to write a report... Not much more...
