High School BeginnerModule B7Lesson 6 of 7

B7.6 Account Security Checklist

Combine unique credentials, password managers, MFA, recovery readiness, trusted devices, active sessions, and login alerts into one repeatable defensive account review.

Lesson Progress

Account Security Checklist

High School BeginnerB7: Passwords, Authentication, and Account Security • Lesson 6 of 7

86% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

A Checklist Prevents Important Steps From Being Forgotten

Account security involves several connected settings. A user may remember to change a password but forget an unknown session, an old recovery email, disabled alerts, or missing MFA. A checklist turns separate protections into a reliable process.

Safety reminder: never enter real credentials, recovery information, backup codes, or account details into a lesson. Use fictional examples only.

Learning Objective

Build a complete account security checklist using layered protections.

Learning Objective

Review fake credentials, MFA, recovery methods, devices, sessions, and alerts.

Learning Objective

Prioritize the safest next action when one checklist item fails.

Why This Matters

Security Fails When One Important Layer Is Ignored

A strong password cannot protect an account if an old recovery email is controlled by someone else. MFA cannot fully help if repeated prompts are approved. Alerts cannot protect the user if they are ignored. A checklist helps every layer support the others.

Visual Diagram

The Four-Part Account Security Review

A complete review checks credentials, MFA, recovery readiness, and account activity instead of focusing on only one setting.

1

Review credentials

Confirm that every important account uses a long, unique credential stored safely.

2

Verify MFA

Check that MFA is enabled, expected prompts are understood, and backup methods are protected.

3

Inspect recovery

Confirm recovery email, phone, backup codes, and trusted devices are current.

4

Review activity

Check active sessions, connected devices, login alerts, and recent security events.

Defender rule: an account is only as strong as its weakest important layer, so review every part instead of stopping after the password.

Core Concept

Review Prevention, Verification, Recovery, and Monitoring

Prevention uses strong unique credentials. Verification uses MFA and safe login decisions. Recovery keeps legitimate access possible. Monitoring uses alerts, sessions, and device review to detect unusual activity. A complete checklist includes all four areas.

Key Vocabulary

Terms for Account Security Review

Account security review

A structured check of credentials, MFA, recovery options, devices, sessions, alerts, and account settings.

Security baseline

The minimum protections that should be enabled before an account is considered ready for normal use.

Active session

A signed-in connection between an account and a browser, app, or device.

Trusted device

A device the account owner recognizes, controls, and has approved for account access.

Security alert

A notification about important account events such as sign-ins, password changes, recovery changes, or unusual activity.

Layered security

Using several protections together so one failure does not automatically expose the account.

Technical Breakdown

Layered Account Security Board

Strong account security comes from several connected layers that support prevention, verification, recovery, and monitoring.

Credential layer

Review question

Is the password or passphrase long, unique, private, and stored safely?

Safer choice

Replace reused credentials and use a trusted password manager.

Verification layer

Review question

Is MFA enabled with a protected primary method and backup option?

Safer choice

Use MFA and deny any prompt that does not match a login you started.

Recovery layer

Review question

Are recovery email, phone, backup codes, and trusted devices current?

Safer choice

Update old methods and store recovery secrets privately.

Monitoring layer

Review question

Are active sessions, connected devices, login alerts, and recent events reviewed?

Safer choice

Remove unknown access and respond quickly to unusual alerts.

Fake Dashboard

Account Security Checklist Panel

This fictional panel combines the main protections from Module B7 into one complete account review.

Fake Data

Primary password

Unique passphrase stored in password manager

Meets the baseline. Confirm it is used nowhere else and remains private.

MFA

Authenticator app enabled with protected backup codes

Strong setup. Review backup storage and deny unexpected prompts.

Recovery email

Current address with its own MFA

Safer recovery path. Confirm the address remains accessible and protected.

Active sessions

One recognized phone and one unknown browser

Remove the unknown session and review recent activity.

Login alerts

Enabled for new devices and password changes

Useful monitoring layer. Review alerts promptly instead of dismissing them.

Fake Dashboard

Fake Account Security Scoreboard

Training dashboard combining fictional credentials, MFA, recovery, sessions, and alerts.

Checklist items

12

Four protection areas with three review items each.

Items complete

9

Credentials, MFA, and most recovery settings meet the baseline.

Items needing action

3

One unknown session, one old device, and one outdated recovery method remain.

Fake SOC Alert

Account Review Incomplete

Source: Fake Account Security Training • Time: 11:52 AM

Medium Severity
A fictional account has a strong unique passphrase and MFA, but an unknown browser session and outdated recovery email remain active.
Defensive recommendation: Remove the unknown session, update the recovery email, review recent activity, and repeat the checklist after changes are saved.

Fake Log Panel

Fake Account Security Review Log

training-log-viewer.log
11:41:06 CREDENTIAL_CHECK unique='true' stored_in_manager='true' result='pass'
11:42:18 MFA_CHECK enabled='true' backup_method='protected' result='pass'
11:44:02 RECOVERY_EMAIL status='outdated' result='action_needed'
11:45:36 ACTIVE_SESSION browser='unknown' result='remove'
11:48:12 LOGIN_ALERTS new_device='enabled' password_change='enabled' result='pass'
11:52:03 SAFE_ACTION recommendation='fix failed items and repeat full checklist'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which Checklist Item Should Be Fixed First?

A fictional account uses a strong unique passphrase.
MFA is enabled with protected backup codes.
An unknown browser session is currently active.
The recovery email is old but still controlled by the student.

What is the safest priority?

Common Mistakes

Mistakes That Make Security Reviews Incomplete

Reviewing only the password while ignoring MFA, recovery, sessions, alerts, and connected devices.
Keeping unknown or unused devices signed in because the account still works.
Treating a checklist as complete without checking whether recovery information is current.
Saving backup codes in messages, screenshots, or public notes.
Approving repeated MFA prompts to stop the notifications.
Using one checklist once and never reviewing the account again after major changes or alerts.

Safe Defensive Lab

Complete a Fake Account Security Audit

Fake Account Scenario

SchoolCloud Security Review

A fictional account has a unique passphrase, MFA, one outdated recovery email, three active sessions, one unknown device, and login alerts enabled only for password changes.

Defensive Review Steps

  • Confirm the credential is unique and safely stored.
  • Review MFA and backup methods.
  • Update the recovery email.
  • Remove the unknown device and session.
  • Enable alerts for new-device sign-ins and security changes.

Scenario Decision Lab

A Checklist Finds Several Problems

A fictional student discovers a reused password, no MFA, an old recovery phone, and two unknown active sessions on an important account.

Defender Habits

Complete Account Security Checklist

Check Your Understanding

B7.6 Mini Quiz: Account Security Checklist

Choose your answers first. Explanations appear only after submission.

1. What is the purpose of an account security checklist?

2. Which item should be removed during an account review?

3. What does layered security mean?

4. When should an account review be repeated?

5. What is the safest response to an unknown connected device?

Portfolio Prompt

Portfolio Prompt

Create a one-page account security checklist for a fictional student account. Organize it into credential, MFA, recovery, and monitoring sections. Add a priority order for fixing failed items.

Use fictional settings and account data only.
Include checkboxes or status labels for each protection.
End with a schedule for repeating the review after important events.

Key Takeaways

What You Should Remember

1.A complete account review covers credentials, MFA, recovery, devices, sessions, and alerts.
2.Layered security reduces the chance that one failure will expose the entire account.
3.Unknown active sessions and devices should be investigated and removed promptly.
4.Recovery methods and backup codes must remain current and protected.
5.Account security checklists should be repeated after alerts, major changes, device loss, or credential exposure.

Navigation

Continue Module B7