B9.7 Phishing Defense Lab
Apply manipulation, email, smishing, vishing, social media, impersonation, link, attachment, reporting, containment, and recovery skills to one fictional multi-stage incident.
Lesson Progress
Phishing Defense Lab
High School Beginner • B9: Phishing and Social Engineering Defense • Lesson 7 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
One Phishing Message Can Create Several Connected Problems
A single message may begin with urgency, lead to a fake login page, expose a password, trigger MFA prompts, create an unknown session, and later produce a fake support call. Defenders must connect the full chain of evidence.
Learning Objective
Classify fictional phishing, impersonation, credential, account, link, attachment, and support evidence.
Learning Objective
Prioritize immediate containment and safe official verification.
Learning Objective
Write a clear defender recommendation with reporting, escalation, recovery, and follow-up.
Why This Matters
Response Order Can Reduce the Impact
The best response is not simply “delete the message.” If credentials were entered, an MFA prompt appeared, a session became active, or a device changed behavior, the incident requires account or device containment, reporting, and recovery.
Visual Diagram
The Phishing Defense Lab Workflow
Strong defenders connect the evidence, classify the threat, prioritize the active risk, and respond through trusted official processes.
Detect
Notice suspicious sender, pressure, request, link, attachment, account, or device evidence.
Classify
Decide whether the evidence suggests phishing, impersonation, unsafe content, credential exposure, or account takeover.
Prioritize
Address active unauthorized access, serious device behavior, and exposed credentials before lower-risk cleanup.
Respond
Stop interaction, verify officially, report clearly, and complete trusted containment and recovery.
Core Concept
Evidence Clusters Matter More Than One Clue
One unusual detail may require verification. Several related details can reveal a larger phishing incident. Defenders connect the timeline, classify each clue, and choose the safest priority order.
Key Vocabulary
Terms for Multi-Stage Phishing Defense
Evidence cluster
Several related warning signs that become more meaningful when reviewed together.
Threat classification
The process of deciding whether evidence suggests phishing, impersonation, credential theft, unsafe content, or normal activity.
Priority
The order in which defensive actions should be completed based on urgency and possible impact.
Containment
Immediate action that limits possible harm, such as denying prompts, removing unknown sessions, or stopping device use.
Escalation
Reporting a serious or unclear event to a trusted adult, teacher, administrator, or technology team.
Recovery
Restoring trusted access, settings, devices, or data after the immediate risk is contained.
Technical Breakdown
Phishing Response Priority Board
The response should follow the evidence and address the most urgent active risk first.
Message and sender evidence
Review question
Does the sender, request, urgency, domain, link, attachment, or context suggest phishing?
Safer choice
Stop interaction and verify through a separate official channel.
Account evidence
Review question
Are there unexpected MFA prompts, unknown sessions, recovery changes, or sent messages?
Safer choice
Deny prompts, remove unknown access, replace exposed credentials, and review MFA and recovery.
Device and file evidence
Review question
Did a suspicious download lead to file changes, unusual warnings, crashes, or other abnormal behavior?
Safer choice
Stop using the device and involve trusted technology staff.
Reporting and recovery
Review question
What safe facts, trusted contacts, and approved recovery resources are available?
Safer choice
Report clearly, preserve safe evidence, and recover only after containment.
Fake Dashboard
Multi-Stage Phishing Incident Panel
This fictional panel combines email, link, attachment, MFA, session, support, and recovery evidence into one defender review.
Urgent teacher email
Unknown sender includes a link and attachment
Phishing warning. Do not click or open; verify with the teacher through the official school channel.
Unexpected MFA prompt
Student is not signing in
Possible credential or account risk. Deny the prompt and review official account activity.
Unknown browser session
New device appears in account settings
Possible account takeover. Remove the session, replace credentials, and review MFA and recovery.
Fake support call
Caller asks for a recovery code
Impersonation warning. End the call and contact support through a known official number.
Protected backup
Approved backup from the previous day is available
Recovery resource. Use only through trusted technology staff after containment.
Fake Dashboard
Fake Phishing Defense Dashboard
Training dashboard combining fictional message, link, attachment, MFA, session, support, and recovery evidence.
Evidence items
14
Sender, urgency, link, attachment, MFA, session, call, and backup evidence.
Immediate actions
5
Stop interaction, deny prompts, remove access, secure credentials, and report.
Recovery actions
6
Review MFA, recovery, sessions, devices, backups, and monitoring.
Fake SOC Alert
Phishing Link Followed by MFA Prompt and Fake Support Call
Source: Fake School Security Training • Time: 1:44 PM
Fake Log Panel
Fake Multi-Stage Phishing Incident Log
13:12:07 EMAIL display_name='Teacher' sender_domain='unrelated-example.test' 13:15:22 LINK action='opened' official_domain_match='false' 13:17:49 CREDENTIAL_EVENT password_entered='true' mfa_code_shared='false' 13:20:14 MFA_PROMPT expected='false' action='denied' 13:22:51 SESSION browser='unknown' status='active' 13:27:33 CALL claimed_identity='Account Support' recovery_code_requested='true' 13:31:48 CONTAINMENT unknown_session='removed' credential='replaced' 13:44:02 REPORT recipient='school_technology_staff' status='submitted'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Which Response Uses the Best Priority Order?
What should the student do next?
Common Mistakes
Mistakes That Weaken Multi-Stage Phishing Response
Safe Defensive Lab
Complete a Fictional Phishing Incident Investigation
Fake Incident File
SchoolCloud Phishing Chain
A fictional student receives an urgent teacher-style email, clicks a look-alike login link, enters a password, denies an MFA prompt, sees an unknown session, and receives a fake support call.
Defender Response Steps
- Identify the manipulation and phishing warning signs.
- Classify the credential and account evidence.
- Deny prompts and remove unknown sessions.
- Replace exposed credentials and review MFA and recovery.
- End fake support contact and report to trusted technology staff.
- Document the timeline, actions, impact, and follow-up.
Scenario Decision Lab
A Fake Teacher Email Leads to an Unknown Session
A fictional student clicks an urgent teacher-style email link, enters a password, denies an unexpected MFA prompt, and then sees an unfamiliar browser session.
Scenario Decision Lab
A Fake Support Caller Requests a Recovery Code
After the phishing event, a fictional caller claims to be account support and asks for a recovery code to secure the student’s account.
Defender Habits
Phishing Defense Lab Checklist
Check Your Understanding
B9.7 Mini Quiz: Phishing Defense Lab
Choose your answers first. Explanations appear only after submission.
1. What should happen first when a suspicious link, unexpected MFA prompt, and unknown session appear together?
2. Which clue is evidence of possible impersonation?
3. What is the safest response to an unexpected attachment from a familiar display name?
4. Why should recovery happen after containment?
5. What makes a strong phishing incident report?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional phishing incident report. Include the timeline, manipulation tactics, sender evidence, link or attachment clues, account evidence, support impersonation, containment, trusted reporting, recovery, and final recommendations.
Key Takeaways
What You Should Remember
Navigation