Beginner Module B14
Beginner Defensive Practice Labs
Apply beginner defensive skills through fictional identity, email, endpoint, network, backup, and multi-alert practice labs built around authorization, evidence, documentation, and safe escalation.
Module Snapshot
Module Mission
Turn beginner cybersecurity knowledge into careful defensive decisions.
This module brings together the beginner track through safe, fictional labs. Students practice reviewing evidence, prioritizing risk, following scope, protecting privacy, documenting reasoning, and escalating cases without touching real systems.
Lab Safety Rule
Every system, user, account, message, log, file, network, alert, and organization in these labs is fictional. Never scan, access, test, change, or investigate a real system without explicit authorization and approved scope.
Visual Framework
The safe defensive-lab workflow
Each lab follows the same disciplined process from authorization to evidence review, action, documentation, and reflection.
Confirm scope
Review the fictional environment, approved actions, prohibited actions, tools, data, owners, and stop conditions.
Collect evidence
Use provided logs, dashboards, tickets, alerts, diagrams, and reports without changing or inventing evidence.
Analyze safely
Separate facts from assumptions, identify missing context, and compare activity with approved expectations.
Choose action
Decide whether to close, monitor, investigate, contain, recover, or escalate according to evidence and authority.
Document and review
Record timestamps, reasoning, owners, limitations, unresolved questions, and the next defensive step.
Fake Lab Queue
Defensive Review Examples
The strongest defensive decision is supported by evidence, authorization, context, clear ownership, and documented reasoning.
Practice Path
B14 Lessons
Each lesson uses fictional dashboards, alerts, logs, tickets, diagrams, messages, and case notes. Students choose actions before revealing outcomes and explanations.
B14.1
Lesson 1
Lab Safety, Scope, and Authorization
Learn how defensive labs use written scope, fictional data, isolated environments, approved tools, evidence preservation, and stop conditions.
Safe Lab
Review a fictional lab brief and decide which systems, actions, data, tools, and evidence are inside or outside the approved scope.
B14.2
Lesson 2
Identity and Access Review Lab
Practice reviewing fictional account roles, authentication events, access levels, MFA status, and least-privilege decisions.
Safe Lab
Analyze a fictional access review and recommend safer role assignments, account actions, documentation, and escalation.
B14.3
Lesson 3
Phishing and Email Triage Lab
Practice identifying suspicious email indicators, separating evidence from assumptions, and choosing safe reporting and response actions.
Safe Lab
Review fictional message headers, links, sender details, attachment warnings, and user reports without opening dangerous content.
B14.4
Lesson 4
Endpoint Alert Analysis Lab
Learn how defenders review fictional endpoint alerts, device context, file events, process activity, and containment decisions.
Safe Lab
Triage a fictional endpoint alert queue and decide which cases should be closed, monitored, isolated, or escalated.
B14.5
Lesson 5
Network Traffic Review Lab
Practice reading safe fictional network summaries, connection patterns, service usage, timing, and segmentation evidence.
Safe Lab
Compare fictional traffic patterns with approved business activity and identify which events need further investigation.
B14.6
Lesson 6
Backup and Recovery Validation Lab
Learn how defenders verify backup coverage, restore readiness, ownership, retention, testing, and recovery priorities.
Safe Lab
Review a fictional backup dashboard and build a safe validation plan for missing copies, failed jobs, and untested restores.
B14.7
Lesson 7
Multi-Alert Defensive Challenge
Combine identity, email, endpoint, network, backup, documentation, and escalation skills in one fictional incident queue.
Safe Lab
Prioritize a fictional shift of related alerts, document evidence, assign owners, and choose the safest response sequence.
Objectives
By the end, students can:
Apply authorization, scope, evidence, privacy, and stop-condition rules to defensive labs.
Review fictional identity, email, endpoint, network, and backup evidence safely.
Separate facts, assumptions, missing context, and justified conclusions.
Prioritize alerts and choose close, monitor, investigate, contain, or escalate decisions.
Write clear defensive notes that preserve evidence, ownership, timing, and next actions.
Module Assessment
B14 Module Test
The module ends with a 25-question scored test covering scope, authorization, evidence, identity review, email triage, endpoint alerts, network analysis, backup validation, documentation, prioritization, and escalation. Answers and explanations remain hidden until submission.
Open Module Test →