Beginner Module B14

Beginner Defensive Practice Labs

Apply beginner defensive skills through fictional identity, email, endpoint, network, backup, and multi-alert practice labs built around authorization, evidence, documentation, and safe escalation.

Module Snapshot

TrackHigh School Beginner
ModuleB14 of 15
Lessons7
Module Test25 questions

Module Mission

Turn beginner cybersecurity knowledge into careful defensive decisions.

This module brings together the beginner track through safe, fictional labs. Students practice reviewing evidence, prioritizing risk, following scope, protecting privacy, documenting reasoning, and escalating cases without touching real systems.

Lab Safety Rule

Every system, user, account, message, log, file, network, alert, and organization in these labs is fictional. Never scan, access, test, change, or investigate a real system without explicit authorization and approved scope.

Visual Framework

The safe defensive-lab workflow

Each lab follows the same disciplined process from authorization to evidence review, action, documentation, and reflection.

1

Confirm scope

Review the fictional environment, approved actions, prohibited actions, tools, data, owners, and stop conditions.

2

Collect evidence

Use provided logs, dashboards, tickets, alerts, diagrams, and reports without changing or inventing evidence.

3

Analyze safely

Separate facts from assumptions, identify missing context, and compare activity with approved expectations.

4

Choose action

Decide whether to close, monitor, investigate, contain, recover, or escalate according to evidence and authority.

5

Document and review

Record timestamps, reasoning, owners, limitations, unresolved questions, and the next defensive step.

Fake Lab Queue

Defensive Review Examples

Fake Data
IdentityNew admin login from an unfamiliar deviceVerify context and escalate if unconfirmed
EmailMessage uses urgent language and a mismatched linkReport safely and preserve evidence
EndpointSecurity tool blocks a suspicious fileFollow approved containment playbook
BackupCritical restore has never been testedSchedule validation and assign ownership

The strongest defensive decision is supported by evidence, authorization, context, clear ownership, and documented reasoning.

Practice Path

B14 Lessons

Each lesson uses fictional dashboards, alerts, logs, tickets, diagrams, messages, and case notes. Students choose actions before revealing outcomes and explanations.

B14.1

Lesson 1

Lab Safety, Scope, and Authorization

Learn how defensive labs use written scope, fictional data, isolated environments, approved tools, evidence preservation, and stop conditions.

Safe Lab

Review a fictional lab brief and decide which systems, actions, data, tools, and evidence are inside or outside the approved scope.

Open →

B14.2

Lesson 2

Identity and Access Review Lab

Practice reviewing fictional account roles, authentication events, access levels, MFA status, and least-privilege decisions.

Safe Lab

Analyze a fictional access review and recommend safer role assignments, account actions, documentation, and escalation.

Open →

B14.3

Lesson 3

Phishing and Email Triage Lab

Practice identifying suspicious email indicators, separating evidence from assumptions, and choosing safe reporting and response actions.

Safe Lab

Review fictional message headers, links, sender details, attachment warnings, and user reports without opening dangerous content.

Open →

B14.4

Lesson 4

Endpoint Alert Analysis Lab

Learn how defenders review fictional endpoint alerts, device context, file events, process activity, and containment decisions.

Safe Lab

Triage a fictional endpoint alert queue and decide which cases should be closed, monitored, isolated, or escalated.

Open →

B14.5

Lesson 5

Network Traffic Review Lab

Practice reading safe fictional network summaries, connection patterns, service usage, timing, and segmentation evidence.

Safe Lab

Compare fictional traffic patterns with approved business activity and identify which events need further investigation.

Open →

B14.6

Lesson 6

Backup and Recovery Validation Lab

Learn how defenders verify backup coverage, restore readiness, ownership, retention, testing, and recovery priorities.

Safe Lab

Review a fictional backup dashboard and build a safe validation plan for missing copies, failed jobs, and untested restores.

Open →

B14.7

Lesson 7

Multi-Alert Defensive Challenge

Combine identity, email, endpoint, network, backup, documentation, and escalation skills in one fictional incident queue.

Safe Lab

Prioritize a fictional shift of related alerts, document evidence, assign owners, and choose the safest response sequence.

Open →

Objectives

By the end, students can:

Apply authorization, scope, evidence, privacy, and stop-condition rules to defensive labs.

Review fictional identity, email, endpoint, network, and backup evidence safely.

Separate facts, assumptions, missing context, and justified conclusions.

Prioritize alerts and choose close, monitor, investigate, contain, or escalate decisions.

Write clear defensive notes that preserve evidence, ownership, timing, and next actions.

Module Assessment

B14 Module Test

The module ends with a 25-question scored test covering scope, authorization, evidence, identity review, email triage, endpoint alerts, network analysis, backup validation, documentation, prioritization, and escalation. Answers and explanations remain hidden until submission.

Open Module Test →