High School AdvancedModule A7Detection and ResponseFictional Defensive Training

A7 Incident Response Lifecycle

Develop professional incident response thinking across preparation, roles, activation, detection, scoping, containment, communication, evidence preservation, eradication, recovery, post-incident review, metrics, continuous improvement, and safe tabletop simulation.

10 lessons

A complete professional response lifecycle

1 module test

25 hidden-answer assessment questions

1 connected portfolio

Incident response playbook and tabletop

100% fictional

No real incidents, systems, people, or data

Module Mission

Respond with Evidence, Authority, Continuity, and Control

Incident response is not simply reacting quickly or performing one technical action. A professional fictional response must coordinate mission priorities, roles, authority, evidence, source health, scoping, containment, communication, continuity, privacy, preservation, recovery, validation, leadership decisions, closure, reopening, and improvement.

Main question

How do professional defenders prepare for, coordinate, contain, communicate, recover from, review, and improve after a possible cybersecurity incident?

Safety boundary

All organizations, systems, alerts, records, identities, communications, containment choices, evidence, owners, actions, timelines, metrics, and outcomes are completely invented, defensive, authorized, inert, privacy-safe, and non-operational.

Module Entry Readiness

Before Beginning A7

I understand that a fictional alert or unusual event does not automatically prove an incident, harmful intent, impact, or complete scope.
I will separate confirmed facts, supported conclusions, hypotheses, alternatives, source-health limitations, decisions, actions, validation, outcomes, residual uncertainty, and residual risk.
I will define authority, owners, alternates, evidence, communications, continuity, containment, recovery, closure, and reopening before relying on a playbook.
I will choose only fictional authorized, narrow, reversible, evidence-preserving response options and will document validation plus rollback.
I will use purpose-limited fictional evidence and will not include real identities, private messages, internal diagrams, alerts, tickets, credentials, systems, suppliers, or incidents.
I will treat trusted adults, teachers, school technology staff, organizational owners, and authorized professionals as the proper escalation path for real concerns.

Professional Workflow

The Ten-Step Incident Response Lifecycle

1

Prepare mission, authority, and roles

Define fictional critical services, users, data, identity, suppliers, continuity needs, response authority, incident lead, technical leads, alternates, decision rights, privacy, communications, evidence, recovery, and leadership roles.

Required professional output

Incident response mission and authority charter

2

Design and test playbooks

Create fictional activation criteria, triage questions, evidence requirements, source-health checks, containment choices, communications, continuity, recovery gates, rollback, closure, reopening, owners, and exercise cases.

Required professional output

Versioned playbook and tabletop package

3

Detect and activate

Evaluate fictional alerts, user reports, service symptoms, supplier notices, source-health failures, and owner observations to decide whether routine triage, incident coordination, or another workflow is justified.

Required professional output

Activation decision and initial incident record

4

Scope with evidence

Identify fictional affected, possibly affected, unaffected, unknown, excluded, and out-of-scope identities, devices, services, destinations, data, suppliers, users, dependencies, periods, and evidence limitations.

Required professional output

Evidence-based scope and confidence map

5

Prioritize and coordinate

Assess fictional potential consequence, evidence confidence, active effect, mission impact, privacy, scope, time sensitivity, recoverability, source health, owner availability, and decision deadlines.

Required professional output

Severity-confidence-priority and coordination record

6

Contain narrowly and reversibly

Compare fictional identity, session, service, network, data, supplier, and communication containment choices using authority, evidence, continuity, preservation, user effect, validation, rollback, and residual risk.

Required professional output

Containment decision and validation plan

7

Communicate and preserve

Send fictional audience-specific updates and preserve purpose-limited evidence with provenance, timing, integrity, access, custody, retention, privacy, correction, and transfer controls.

Required professional output

Communication log and evidence register

8

Eradicate and recover

Address fictional confirmed causes, restore trustworthy identity, configuration, service, data, dependencies, supplier state, evidence capability, and continuity through staged recovery and validation.

Required professional output

Eradication, recovery, rollback, and monitoring plan

9

Close or reopen with evidence

Evaluate fictional question resolution, source health, scope, impact, actions, validation, continuity, residual uncertainty, residual risk, owner acceptance, observation periods, closure criteria, and reopen triggers.

Required professional output

Closure decision and reopening register

10

Review and improve

Conduct fictional post-incident review, measure readiness and response quality, assign corrective actions, test improvements, update playbooks, reduce debt, and communicate leadership decisions.

Required professional output

Post-incident review and continuous-improvement plan

Learning Outcomes

Eight Advanced Module Objectives

Objective 1

Explain the incident response lifecycle as a coordinated evidence, authority, continuity, communication, recovery, and improvement process rather than a single technical action.

Objective 2

Design fictional incident response roles with decision rights, alternates, separation of duties, handoff acceptance, escalation, availability, and one coordinating owner.

Objective 3

Create versioned fictional plans and playbooks with activation criteria, evidence requirements, source-health behavior, containment, communication, continuity, recovery, validation, rollback, closure, and reopening.

Objective 4

Scope fictional incidents using neutral observations, affected and possibly affected entities, time, relationships, source health, confidence, exclusions, alternatives, dependencies, active impact, and scope-change records.

Objective 5

Choose fictional containment strategies by balancing current risk, mission continuity, evidence preservation, privacy, authorization, reversibility, user impact, validation, rollback, and residual risk.

Objective 6

Plan fictional eradication and trustworthy recovery using root-cause evidence, approved changes, clean-state criteria, identity review, data integrity, dependencies, staged restoration, monitoring, and owner acceptance.

Objective 7

Write audience-specific fictional communications and evidence-preservation records that are factual, purpose-limited, privacy-aware, versioned, approved, traceable, and clear about uncertainty.

Objective 8

Conduct fictional post-incident review and continuous improvement using chronology, decision context, contributing conditions, metrics, corrective actions, owners, validation, debt, residual risk, and leadership communication.

Role Readiness Preview

Eight Roles That Keep a Response Coordinated

Incident lead

Mission

Coordinates the fictional response, preserves the decision timeline, confirms authority, maintains scope, assigns owners, resolves conflicts, and controls state transitions.

Does not replace

Technical, service, identity, privacy, evidence, communications, recovery, legal, supplier, or executive expertise.

Readiness requirement

Named primary, alternate, availability expectation, authority boundary, escalation path, and handoff checklist.

Technical analysis lead

Mission

Coordinates fictional evidence review, hypotheses, source health, technical questions, containment options, validation, and technical risk communication.

Does not replace

Incident command, service ownership, policy approval, legal review, or business acceptance.

Readiness requirement

Evidence access, source map, decision templates, alternate analyst, and validation responsibilities.

Service and continuity owner

Mission

Explains fictional service purpose, critical workflows, user effect, dependencies, acceptable interruption, continuity options, recovery priorities, and acceptance criteria.

Does not replace

Evidence interpretation, identity authority, privacy review, or executive risk acceptance.

Readiness requirement

Critical-service map, dependency register, continuity plan, recovery objectives, alternates, and approval authority.

Identity and access owner

Mission

Answers fictional account, role, group, session, approval, extension, revocation, effective access, recovery, and validation questions.

Does not replace

Complete incident scope, service impact, communications, or evidence custody.

Readiness requirement

Authority map, emergency process, alternate owner, evidence sources, response expectations, and validation checklist.

Evidence coordinator

Mission

Maintains fictional evidence identity, provenance, timing, integrity, purpose, custody, access, transfer, retention, privacy, limitations, and reporting records.

Does not replace

Technical conclusions, legal decisions, or incident command.

Readiness requirement

Preservation register, access model, custody form, storage model, integrity process, and retention rules.

Communications lead

Mission

Coordinates fictional audience, facts, uncertainty, approvals, timing, distribution, correction, next-update commitments, user guidance, and public-safe communication.

Does not replace

Technical investigation, legal advice, privacy authority, or executive decision rights.

Readiness requirement

Audience matrix, templates, approval chain, alternates, correction process, and communication log.

Privacy and governance reviewer

Mission

Evaluates fictional purpose limitation, minimization, access, sharing, retention, user effect, legal or policy triggers, evidence exposure, and residual privacy risk.

Does not replace

Incident command or technical analysis.

Readiness requirement

Escalation criteria, decision authority, alternates, data map, communication review, and documentation requirements.

Recovery and improvement owner

Mission

Coordinates fictional eradication, clean-state criteria, staged restoration, rollback, monitoring, business acceptance, post-incident actions, exercises, metrics, and debt reduction.

Does not replace

Service owner acceptance, source-owner validation, or incident closure authority.

Readiness requirement

Recovery plan, validation gates, fallback options, corrective-action register, metrics, and review schedule.

Lesson Roadmap

Complete All Ten A7 Lessons

Lesson 1 of 10

A7.1

Advanced Defensive Lesson

Advanced Incident Response Roles

Define how a fictional incident response program separates incident command, technical analysis, identity, service, infrastructure, communications, legal, privacy, continuity, recovery, supplier, evidence, and leadership responsibilities without allowing confusion, unsupported authority, or abandoned ownership.

Skills developed

  • Distinguish incident lead, technical lead, service owner, identity owner, evidence coordinator, communications lead, continuity owner, privacy reviewer, supplier owner, and executive decision roles
  • Document authority, alternates, availability, handoff acceptance, escalation paths, decision rights, and separation of duties
  • Keep one coordinating owner while specialists answer bounded questions
  • Recognize role conflicts, unavailable owners, unclear authority, duplicate command, and responsibility gaps

Safe fictional defensive lab

Create a fully fictional incident response role charter, authority matrix, alternate-owner map, handoff checklist, decision-rights table, and escalation-contact model for Northbridge.

Lesson 2 of 10

A7.2

Advanced Defensive Lesson

Preparation and Playbook Design

Design fictional incident response readiness through mission priorities, response criteria, playbook triggers, evidence needs, source-health checks, containment options, communication approvals, continuity requirements, recovery gates, exercises, ownership, expiration, and lifecycle review.

Skills developed

  • Separate policy, plan, playbook, checklist, reference, contact list, and decision record
  • Build scenario-specific playbooks with triggers, questions, owners, evidence, actions, validation, rollback, and closure
  • Prepare source-health, privacy, continuity, supplier, communication, and leadership dependencies
  • Test playbooks through safe fictional tabletop exercises and versioned improvement

Safe fictional defensive lab

Produce a fictional response-readiness package with mission priorities, activation criteria, playbook sections, authority, evidence, containment, continuity, communication, recovery, testing, and review.

Lesson 3 of 10

A7.3

Advanced Defensive Lesson

Detection and Scoping

Turn fictional alerts and reports into incident-response scope decisions by separating observation, confirmed facts, hypotheses, source health, affected identities, devices, services, destinations, data, suppliers, time periods, active impact, dependencies, uncertainty, and owner questions.

Skills developed

  • Distinguish an alert, event, issue, suspected incident, confirmed incident, and source-health problem
  • Create scope statements using evidence, time, relationships, confidence, exclusions, and change history
  • Avoid both premature broadening and dangerous under-scoping
  • Track affected, possibly affected, unaffected, unknown, and out-of-scope categories

Safe fictional defensive lab

Build a fictional detection-to-scope workbook containing an evidence matrix, chronology, affected-entity register, source-health map, alternative explanations, confidence, and scope-change log.

Lesson 4 of 10

A7.4

Advanced Defensive Lesson

Containment Strategy

Compare fictional containment choices using active harm, mission continuity, evidence preservation, identity, sessions, services, network boundaries, supplier dependencies, user safety, privacy, authorization, reversibility, validation, rollback, and residual risk.

Skills developed

  • Distinguish immediate, short-term, long-term, identity, session, service, network, data, supplier, and communication containment
  • Choose the narrowest authorized action that meaningfully reduces current risk
  • Document expected benefit, operational cost, evidence effect, owner, validation, rollback, and decision trigger
  • Avoid destructive, irreversible, unapproved, overly broad, or evidence-damaging actions

Safe fictional defensive lab

Create a fictional containment decision matrix and staged containment plan with options, owners, dependencies, continuity effects, validation, rollback, escalation, and residual risk.

Lesson 5 of 10

A7.5

Advanced Defensive Lesson

Eradication and Recovery Planning

Plan fictional removal of confirmed causes and restoration of trustworthy service using root-cause evidence, approved changes, clean-state criteria, identity review, configuration validation, data integrity, backups, dependencies, monitoring, rollback, business acceptance, and residual-risk review.

Skills developed

  • Separate containment, eradication, restoration, validation, monitoring, and closure
  • Define trustworthy recovery rather than treating connectivity or availability as proof
  • Coordinate identity, service, infrastructure, application, data, supplier, continuity, and risk owners
  • Use staged recovery, validation gates, fallback paths, observation periods, and reopen triggers

Safe fictional defensive lab

Develop a fictional eradication and recovery plan with root-cause requirements, clean-state criteria, restoration sequence, owner approvals, validation, rollback, monitoring, and closure boundaries.

Lesson 6 of 10

A7.6

Advanced Defensive Lesson

Stakeholder Communication

Create fictional incident communications that separate confirmed facts, supported conclusions, uncertainty, active impact, actions, decisions, owner needs, next updates, privacy, audience, timing, approvals, and legal or policy constraints without exaggeration or unnecessary disclosure.

Skills developed

  • Tailor analyst, service-owner, user, supplier, leadership, privacy, legal, recovery, and public-safe messages
  • Use bounded facts, non-proof statements, uncertainty, decisions, next steps, and update commitments
  • Prevent conflicting messages through ownership, approval, versioning, distribution, and correction records
  • Avoid blame, speculation, hidden uncertainty, excessive detail, and unsupported promises

Safe fictional defensive lab

Build a fictional stakeholder communication matrix, update template library, approval workflow, correction process, audience map, and leadership briefing.

Lesson 7 of 10

A7.7

Advanced Defensive Lesson

Evidence Preservation Concepts

Study fictional evidence preservation as a governed process involving purpose, authorization, scope, provenance, timing, integrity, source health, collection records, access, custody, storage, retention, privacy, review, transfer, and reporting without teaching invasive collection techniques.

Skills developed

  • Distinguish preservation, collection, analysis, interpretation, storage, transfer, and disposal
  • Document evidence identity, source, event time, collection time, handler, purpose, integrity checks, access, and limitations
  • Preserve original evidence and work from controlled copies conceptually
  • Recognize overcollection, missing authority, broken provenance, privacy exposure, silent modification, and unsupported conclusions

Safe fictional defensive lab

Create a fictional evidence preservation register, chain-of-custody model, access matrix, integrity record, retention schedule, transfer checklist, and public-safe evidence summary.

Lesson 8 of 10

A7.8

Advanced Defensive Lesson

Post-Incident Review

Conduct fictional post-incident review across preparation, detection, source health, scoping, prioritization, containment, communication, evidence, eradication, recovery, continuity, ownership, decisions, metrics, residual risk, and improvement without blame.

Skills developed

  • Separate timeline facts, decision context, outcomes, contributing conditions, root causes, and lessons
  • Evaluate what worked, what failed, what was unavailable, and which assumptions changed
  • Assign corrective actions with owners, due dates, evidence, validation, dependencies, and priority
  • Connect lessons to playbooks, architecture, detections, sources, training, governance, recovery, and leadership decisions

Safe fictional defensive lab

Produce a fictional post-incident review report with chronology, decision review, contributing conditions, strengths, gaps, actions, owners, metrics, residual risk, and follow-up.

Lesson 9 of 10

A7.9

Advanced Defensive Lesson

Metrics and Continuous Improvement

Design fictional incident response metrics that support readiness, evidence, detection, scoping, containment, communication, recovery, case quality, owner response, continuity, exercises, corrective actions, privacy, residual risk, and program learning without rewarding speed alone.

Skills developed

  • Define metric purpose, population, numerator, denominator, time range, source health, owner, limitation, and action
  • Balance timeliness with decision quality, containment with continuity, recovery speed with trustworthy validation, and closure with reopening
  • Measure readiness debt, source-health debt, playbook debt, owner delay, corrective-action aging, and exercise performance
  • Recognize averages, unstable denominators, scope changes, personal rankings, metric gaming, and false improvement

Safe fictional defensive lab

Create a fictional incident response dashboard, metric dictionary, quality-gate scorecard, corrective-action tracker, exercise dashboard, and leadership improvement brief.

Lesson 10 of 10

A7.10

Advanced Defensive Lesson

Incident Response Simulation Lab

Integrate the complete A7 lifecycle in a fictional tabletop simulation involving activation, roles, evidence, source health, scoping, severity, priority, containment, continuity, communication, preservation, recovery, validation, leadership decisions, post-incident review, metrics, and improvement.

Skills developed

  • Run a safe fictional incident response timeline using bounded decisions and documented owners
  • Update scope, confidence, priority, containment, communication, and recovery as evidence changes
  • Preserve chronology, decision rationale, alternatives, validation, residual uncertainty, residual risk, closure, and reopening
  • Deliver an executive-ready incident response package and public-safe portfolio artifact

Safe fictional defensive lab

Complete a fully fictional Northbridge Incident Response Simulation Package containing role charter, playbook, evidence register, scope, containment, communication, recovery, review, metrics, and reflection.

Fictional Evidence Preview

Incident Response Evidence You Will Learn to Analyze

IR-01

Fictional activation report

Observation

Northbridge receives one SIEM alert, two user reports, and a supplier notice involving the same student-support service within twenty minutes.

Supports

A coordinated response review may be justified because multiple evidence categories point to one mission service.

Does not prove

The reports do not prove one cause, complete scope, confirmed incident status, or current service impact.

Incident response use

Define activation criteria, initial owner, evidence needs, source health, and first scope statement.

IR-02

Fictional role and availability matrix

Observation

The primary incident lead is unavailable, the alternate is available, and the service owner has not acknowledged the activation request.

Supports

The alternate incident lead should activate and the service-owner deadline requires aging.

Does not prove

Owner nonresponse does not prove impact, negligence, or incident severity.

Incident response use

Use alternate authority, preserve one coordinator, and activate the documented escalation path.

IR-03

Fictional scope worksheet

Observation

One identity and one service are confirmed, two devices are possibly affected, a supplier connection is unknown, and one source is Degraded.

Supports

The incident scope should separate confirmed, possible, unknown, and evidence-limited categories.

Does not prove

The worksheet does not prove the two devices or supplier are affected.

Incident response use

Assign bounded evidence questions and maintain a versioned scope-change log.

IR-04

Fictional containment options

Observation

A broad service shutdown would remove current access but interrupt urgent support workflows and reduce evidence visibility; a narrow session and role restriction is reversible.

Supports

The narrow authorized option may better balance immediate risk, continuity, and preservation.

Does not prove

The comparison does not prove narrow containment will be sufficient.

Incident response use

Document decision criteria, owner approval, validation, monitoring, escalation, and rollback.

IR-05

Fictional recovery review

Observation

The service is reachable again, but identity state, configuration integrity, data reconciliation, supplier dependency, and evidence-source recovery remain incomplete.

Supports

Connectivity restoration is not trustworthy recovery.

Does not prove

The review does not prove restoration failed or further user impact exists.

Incident response use

Keep recovery Conditional until clean-state and validation gates pass.

IR-06

Fictional post-incident dashboard

Observation

Containment time improved, but owner-response delay, evidence-source Blind minutes, reopened actions, and untested playbook steps increased.

Supports

Speed alone does not demonstrate program improvement.

Does not prove

The dashboard does not identify every cause or corrective action.

Incident response use

Use balanced readiness, quality, continuity, recovery, ownership, privacy, and residual-risk metrics.

Response Decision Preview

Eight Questions Every Fictional Response Must Answer

Activation

Does fictional evidence justify incident coordination, routine triage, service management, source recovery, privacy review, or another workflow?

Authority

Who may declare, direct, contain, communicate, recover, accept risk, close, and reopen the fictional response?

Evidence

Which fictional facts, source-health states, timing, provenance, limitations, alternatives, and owner statements support the current decision?

Scope

Which fictional identities, devices, services, destinations, data, users, suppliers, dependencies, and periods are affected, possibly affected, unknown, excluded, or out of scope?

Containment

Which fictional authorized action reduces current risk while preserving continuity, evidence, privacy, reversibility, and recovery options?

Communication

Which fictional audience needs which confirmed facts, uncertainty, action, decision request, guidance, approval, and next-update time?

Recovery

Which fictional clean-state criteria, dependencies, data checks, identity reviews, source recovery, monitoring, rollback, and owner acceptance prove trustworthy restoration?

Improvement

Which fictional lessons require playbook, role, source, architecture, detection, training, continuity, supplier, privacy, metric, or governance changes?

Portfolio Outcome

Build a Complete Incident Response Playbook and Tabletop Package

By the end of A7, you will have one connected fictional package showing how a professional response moves from preparation and activation to evidence, scope, containment, communication, preservation, recovery, closure, review, metrics, and continuous improvement.

Artifact 1

Fictional incident response mission, scope, safety, authority, privacy, continuity, supplier, communication, evidence, recovery, and lifecycle charter

Artifact 2

Incident lead, technical lead, identity, service, evidence, communications, privacy, legal, continuity, recovery, supplier, and leadership role matrix

Artifact 3

Primary and alternate owner register with availability, authority, response expectations, decision rights, escalation, and handoff acceptance

Artifact 4

Versioned incident response plan, scenario playbooks, activation criteria, source-health requirements, containment options, communication approvals, recovery gates, and closure standards

Artifact 5

Fictional incident activation record, initial facts, primary questions, severity, confidence, priority, owner assignments, deadlines, and non-proof statements

Artifact 6

Evidence-based scope workbook with affected, possibly affected, unaffected, unknown, excluded, out-of-scope, and source-limited categories

Artifact 7

Chronology showing event time, collection time, processing time, report time, decision time, action time, validation time, communication time, recovery time, and closure time

Artifact 8

Containment decision matrix covering risk reduction, continuity, evidence, privacy, authority, operational cost, dependencies, validation, rollback, and residual risk

Artifact 9

Eradication and recovery plan with root-cause requirements, clean-state criteria, identity, configuration, data, dependencies, backups, staged restoration, monitoring, and owner acceptance

Artifact 10

Stakeholder communication matrix and template library for analysts, owners, users, suppliers, privacy, legal, leadership, recovery, and public-safe summaries

Artifact 11

Evidence preservation register with identity, source, provenance, purpose, timing, handler, integrity, access, custody, storage, retention, transfer, limitations, and disposal

Artifact 12

Case-management package containing notes, evidence references, hypotheses, decisions, actions, validation, state transitions, residual uncertainty, residual risk, closure, and reopening

Artifact 13

Post-incident review with facts, chronology, decisions, contributing conditions, strengths, gaps, root causes, lessons, corrective actions, owners, dependencies, and validation

Artifact 14

Incident response dashboard and metric dictionary covering readiness, activation, detection, scoping, owner delay, containment, continuity, communication, evidence, recovery, closure, reopening, privacy, and debt

Artifact 15

Corrective-action register with priority, mission effect, owner, due date, evidence, dependency, validation, aging, escalation, residual risk, and closure criteria

Artifact 16

Complete fictional Incident Response Simulation Package, leadership brief, technical appendix, tabletop record, public-safe portfolio summary, and reflection

Incident Response Risk Preview

Eight Mistakes This Module Will Teach You to Avoid

No clear incident authority

Why it is risky

Fictional analysts, service owners, and leaders may issue conflicting instructions, duplicate work, delay containment, or close the response without the required decision authority.

Professional correction

Define incident lead, alternates, decision rights, authority boundaries, handoff acceptance, escalation, and one coordinating owner before activation.

Playbooks become rigid scripts

Why it is risky

Fictional teams may follow steps even when scope, source health, continuity, privacy, supplier context, evidence, or mission impact differs from the assumptions.

Professional correction

Use decision points, conditions, alternatives, owner judgment, validation, rollback, expiration, and exercise-based revision.

The first alert defines the incident

Why it is risky

A fictional alert title or early hypothesis may become the final scope, cause, severity, or communication message before evidence is reviewed.

Professional correction

Use neutral observations, versioned scope, source-health review, alternatives, confidence, owner questions, and change history.

Containment causes greater harm

Why it is risky

A fictional broad or irreversible action may interrupt critical support, destroy evidence, block recovery, affect unrelated users, or create privacy and continuity problems.

Professional correction

Choose the narrowest authorized reversible action, document tradeoffs, validate outcomes, monitor effects, and preserve rollback.

Availability is treated as recovery

Why it is risky

A fictional service may be reachable while identity, configuration, data integrity, dependencies, supplier state, evidence sources, or monitoring remain untrustworthy.

Professional correction

Define clean-state criteria, staged restoration, independent validation, observation periods, business acceptance, residual risk, and reopen triggers.

Communication exceeds evidence

Why it is risky

Fictional messages may speculate, assign blame, expose unnecessary details, hide uncertainty, create conflicting promises, or use an audience that does not need the information.

Professional correction

Use confirmed facts, supported conclusions, non-proof statements, purpose limitation, approvals, versioning, correction records, and next-update commitments.

Evidence preservation becomes overcollection

Why it is risky

A fictional response may collect broad personal or operational information without a bounded question, authority, privacy purpose, retention rule, access model, or owner.

Professional correction

Use purpose limitation, minimization, scope, authorization, provenance, custody, access, retention, review, and disposal requirements.

Real incident material enters the portfolio

Why it is risky

Using real alerts, tickets, messages, timelines, owner names, service diagrams, supplier details, response decisions, or screenshots can expose people and defensive capabilities.

Professional correction

Invent every organization, identity, service, source, event, owner, message, action, metric, decision, date, and outcome from the beginning.

Module Test

A7 Incident Response Lifecycle Assessment

Complete a 25-question hidden-answer assessment covering incident response roles, authority, alternates, plans, playbooks, activation, detection, scoping, source health, containment, continuity, communication, evidence preservation, eradication, recovery, validation, post-incident review, metrics, corrective actions, closure, reopening, privacy, ownership, and simulation decisions.

25 questions

Answers and explanations remain hidden until the student submits the full assessment.

All ten lessons

The assessment covers the complete A7 Incident Response Lifecycle pathway.

Decision-focused

Questions measure evidence-aware coordination, containment, recovery, communication, and improvement judgment.

Module Navigation

Begin Incident Response Lifecycle

Start with A7.1 to learn how professional fictional response teams define leadership, technical ownership, service responsibility, evidence coordination, communication, privacy, continuity, recovery, alternates, authority, handoffs, and escalation before time pressure begins.