Prepare
Define fictional authority, roles, severity rules, evidence sources, playbooks, continuity, communication, and closure before an event occurs.
Learn how defensive teams prepare for incidents, evaluate fictional alerts, build evidence-based scope, contain risk safely, preserve records, coordinate recovery, communicate accurately, review decisions, and close a case with accountable technical, business, monitoring, and governance evidence.
Module Snapshot
Track
High School Intermediate
Module
I11 of 17
Lessons
8 detailed lessons
Assessment
25-question module test
Primary skill
Evidence-based incident coordination
Portfolio artifact
Fictional incident-response case package
Main Question
The answer requires more than reacting to an alert. The team must validate sources, preserve evidence, establish scope, protect legitimate workflows, coordinate owners, separate fact from inference, restore service safely, communicate uncertainty, measure outcomes, and define what evidence supports closure or reopening.
Defensive Safety Boundary
Every scenario, asset, identity, event, log, alert, file, route, user, owner, organization, and impact record in Module I11 is fictional. Students will not scan, probe, access, alter, test, identify, or publish real systems, accounts, networks, credentials, private data, or incident records.
Professional Workflow
Define fictional authority, roles, severity rules, evidence sources, playbooks, continuity, communication, and closure before an event occurs.
Preserve the original fictional signal, confirm source health, correlate independent evidence, assign confidence, and decide whether the record is operational, suspicious, or incident-related.
Identify affected fictional assets, users, identities, data, workflows, environments, and time windows while applying narrow, reversible, evidence-preserving controls.
Build a fictional timeline, distinguish confirmed facts from supported conclusions, assign owners, communicate accurately, and preserve decision history.
Correct the fictional root cause, restore approved services in stages, validate identities and configurations, test source health, monitor, and preserve rollback.
Document fictional lessons, residual risk, metrics, action owners, deadlines, governance decisions, reopen triggers, and closure evidence.
Learning Objectives
Objective 1
Explain the fictional incident-response lifecycle from readiness through closure and continuous improvement.
Objective 2
Distinguish alerts, suspicious activity, confirmed security events, operational failures, evidence gaps, incidents, and business impacts.
Objective 3
Build defensible fictional scope using asset, identity, data, route, service, transaction, file, source-health, and business evidence.
Objective 4
Apply narrow fictional containment that reduces risk while preserving evidence, legitimate workflows, continuity, and rollback.
Objective 5
Create a fictional evidence index, correlated timeline, communication record, recovery plan, post-incident review, and closure package.
Objective 6
Use only supplied fictional evidence and never access, test, alter, identify, or publish real systems, people, credentials, logs, or private organizational records.
Lessons
Focus
Build a fictional response program with purpose, authority, roles, severity rules, evidence sources, playbooks, communication, continuity, and closure standards.
Defensive Lab
Create a fictional incident-response readiness charter, role matrix, evidence-source register, escalation map, and safe-lab boundary.
Focus
Separate fictional alerts, suspicious activity, confirmed security events, operational failures, evidence gaps, and possible incidents using corroborated evidence.
Defensive Lab
Triage a fictional alert set and produce a defensible initial assessment with confidence, gaps, owners, and next actions.
Focus
Map fictional affected assets, users, identities, data, services, workflows, and time windows while applying narrow, reversible, evidence-preserving containment.
Defensive Lab
Build a fictional scope-and-containment plan that protects legitimate school operations and avoids overbroad disruption.
Focus
Preserve fictional logs, alerts, transactions, files, identity events, source health, timestamps, ownership, and limitations in a reviewable evidence timeline.
Defensive Lab
Create a fictional evidence index and correlated timeline without changing or overstating the supplied records.
Focus
Remove fictional root causes, restore approved services safely, validate identities and configurations, monitor for recurrence, and preserve rollback and continuity.
Defensive Lab
Design a fictional staged recovery plan with positive and negative tests, source-health checks, business validation, and reopen triggers.
Focus
Write accurate fictional technical, business, leadership, support, and closure updates that separate facts, conclusions, uncertainty, impact, actions, and decisions.
Defensive Lab
Produce a fictional stakeholder communication set and escalation record with privacy-aware detail and accountable owners.
Focus
Review fictional causes, controls, evidence quality, decisions, recovery, communication, metrics, residual risk, and improvement actions without assigning blame.
Defensive Lab
Create a fictional post-incident review, action register, metric correction plan, and governance follow-up.
Focus
Integrate readiness, triage, scope, containment, evidence, recovery, communication, review, metrics, and closure into one fictional defensive case.
Defensive Lab
Complete a fictional end-to-end incident-response case package using only supplied evidence and safe, authorized training decisions.
Fictional Evidence Preview
Across the module, students will review a fictional mixed evidence set involving an unusual support-service alert, identity events, file and queue activity, deployment records, runtime health, business transactions, source-health gaps, recovery dependencies, containment decisions, communication drafts, and post-incident actions. The evidence is designed to require correlation rather than guesswork.
Confirmed facts
Facts supported directly by supplied current records.
Supported conclusions
Narrow interpretations supported by several independent sources.
Evidence gaps
Missing or unreliable records that limit confidence and action.
Portfolio Outcome
By the end of Module I11, students will produce a portfolio-safe package containing a readiness charter, triage record, scope map, containment plan, evidence index, correlated timeline, recovery plan, stakeholder communication set, post-incident review, action register, governance dashboard, residual-risk statement, and closure checklist.
Module Assessment
Complete a 25-question assessment covering readiness, triage, scope, containment, evidence, recovery, communication, post-incident review, metrics, residual risk, and closure. Choices appear first, with explanations revealed afterward.
Navigation