High School BeginnerModule B1425 Questions

B14 Module Test: Beginner Defensive Practice Labs

Test your understanding of lab safety, authorization, identity and access, phishing triage, endpoint alerts, network traffic, backup validation, correlation, prioritization, ownership, and escalation.

Readiness Check

Before You Begin

0/3 ready

Test Instructions

Complete All 25 Questions

Step 1

Read each question and all answer choices carefully.

Step 2

Select the strongest defensive answer based on the lessons.

Step 3

Submit the test to reveal your score and explanations.

Answers and explanations remain hidden until you submit the test.

Check Your Understanding

B14 Scored Module Test

Choose your answers first. Explanations appear only after submission.

1. What must happen before any defensive lab activity begins?

2. What does scope define in a defensive lab?

3. What should happen when unexpected real personal data appears in a fictional lab?

4. Why should original evidence be preserved?

5. Which statement about public systems is correct?

6. What is least privilege?

7. What is the difference between authentication and authorization?

8. What is the safest response to a former contractor account that remains enabled?

9. Why are shared administrator accounts risky?

10. What is the strongest access-review decision?

11. What is email triage?

12. Why is a familiar display name not enough to trust an email?

13. What should a defender do with an unexpected attachment?

14. What is the safest response to a suspicious password-reset link?

15. Why should the original suspicious email be preserved?

16. What is an endpoint alert?

17. What is containment?

18. Why is device context important during endpoint analysis?

19. What should happen to a suspicious file during beginner endpoint triage?

20. What is a network baseline?

21. Why is an unusual network connection not automatic proof of an attack?

22. What is network segmentation?

23. What is restore validation?

24. What do recovery point and recovery time objectives describe?

25. What is the strongest multi-alert defensive response?

Key Takeaways

What You Should Remember

1.Defensive practice begins with explicit authorization, clear scope, safe evidence handling, and stop conditions.
2.Identity and access decisions should follow current business need, least privilege, accountability, and documentation.
3.Phishing triage should preserve the message and avoid suspicious links, attachments, forms, and reply instructions.
4.Endpoint and network alerts require context, related evidence, proportionate containment, and approved escalation.
5.Backup success does not prove recovery readiness; restore testing and ownership are essential.
6.Multi-alert defense depends on correlation, prioritization, case ownership, honest uncertainty, and one clear timeline.

Module Complete

Review Your Results and Continue

Review any missed questions, revisit the matching practice labs, and return to the Beginner Track when you are ready.