High School IntermediateModule I11Incident Response

I11: Incident Response Basics

Learn how defensive teams prepare for incidents, evaluate fictional alerts, build evidence-based scope, contain risk safely, preserve records, coordinate recovery, communicate accurately, review decisions, and close a case with accountable technical, business, monitoring, and governance evidence.

Module Snapshot

What You Will Complete

Track

High School Intermediate

Module

I11 of 17

Lessons

8 detailed lessons

Assessment

25-question module test

Primary skill

Evidence-based incident coordination

Portfolio artifact

Fictional incident-response case package

Main Question

How can a defensive team move from an uncertain signal to a safe, evidence-based, and reviewable incident decision?

The answer requires more than reacting to an alert. The team must validate sources, preserve evidence, establish scope, protect legitimate workflows, coordinate owners, separate fact from inference, restore service safely, communicate uncertainty, measure outcomes, and define what evidence supports closure or reopening.

Defensive Safety Boundary

Fictional Evidence Only

Every scenario, asset, identity, event, log, alert, file, route, user, owner, organization, and impact record in Module I11 is fictional. Students will not scan, probe, access, alter, test, identify, or publish real systems, accounts, networks, credentials, private data, or incident records.

Professional Workflow

Six Steps from Readiness to Improvement

1

Prepare

Define fictional authority, roles, severity rules, evidence sources, playbooks, continuity, communication, and closure before an event occurs.

2

Detect and triage

Preserve the original fictional signal, confirm source health, correlate independent evidence, assign confidence, and decide whether the record is operational, suspicious, or incident-related.

3

Scope and contain

Identify affected fictional assets, users, identities, data, workflows, environments, and time windows while applying narrow, reversible, evidence-preserving controls.

4

Investigate and coordinate

Build a fictional timeline, distinguish confirmed facts from supported conclusions, assign owners, communicate accurately, and preserve decision history.

5

Eradicate and recover

Correct the fictional root cause, restore approved services in stages, validate identities and configurations, test source health, monitor, and preserve rollback.

6

Review and improve

Document fictional lessons, residual risk, metrics, action owners, deadlines, governance decisions, reopen triggers, and closure evidence.

Learning Objectives

By the End of Module I11

Objective 1

Explain the fictional incident-response lifecycle from readiness through closure and continuous improvement.

Objective 2

Distinguish alerts, suspicious activity, confirmed security events, operational failures, evidence gaps, incidents, and business impacts.

Objective 3

Build defensible fictional scope using asset, identity, data, route, service, transaction, file, source-health, and business evidence.

Objective 4

Apply narrow fictional containment that reduces risk while preserving evidence, legitimate workflows, continuity, and rollback.

Objective 5

Create a fictional evidence index, correlated timeline, communication record, recovery plan, post-incident review, and closure package.

Objective 6

Use only supplied fictional evidence and never access, test, alter, identify, or publish real systems, people, credentials, logs, or private organizational records.

Lessons

Eight Detailed Lessons

I11.1

Incident Response Lifecycle and Readiness

Focus

Build a fictional response program with purpose, authority, roles, severity rules, evidence sources, playbooks, communication, continuity, and closure standards.

Defensive Lab

Create a fictional incident-response readiness charter, role matrix, evidence-source register, escalation map, and safe-lab boundary.

Open Lesson
I11.2

Detection, Triage, and Initial Assessment

Focus

Separate fictional alerts, suspicious activity, confirmed security events, operational failures, evidence gaps, and possible incidents using corroborated evidence.

Defensive Lab

Triage a fictional alert set and produce a defensible initial assessment with confidence, gaps, owners, and next actions.

Open Lesson
I11.3

Scoping, Containment, and Coordination

Focus

Map fictional affected assets, users, identities, data, services, workflows, and time windows while applying narrow, reversible, evidence-preserving containment.

Defensive Lab

Build a fictional scope-and-containment plan that protects legitimate school operations and avoids overbroad disruption.

Open Lesson
I11.4

Evidence Preservation and Timeline Building

Focus

Preserve fictional logs, alerts, transactions, files, identity events, source health, timestamps, ownership, and limitations in a reviewable evidence timeline.

Defensive Lab

Create a fictional evidence index and correlated timeline without changing or overstating the supplied records.

Open Lesson
I11.5

Eradication, Recovery, and Service Restoration

Focus

Remove fictional root causes, restore approved services safely, validate identities and configurations, monitor for recurrence, and preserve rollback and continuity.

Defensive Lab

Design a fictional staged recovery plan with positive and negative tests, source-health checks, business validation, and reopen triggers.

Open Lesson
I11.6

Communication, Escalation, and Documentation

Focus

Write accurate fictional technical, business, leadership, support, and closure updates that separate facts, conclusions, uncertainty, impact, actions, and decisions.

Defensive Lab

Produce a fictional stakeholder communication set and escalation record with privacy-aware detail and accountable owners.

Open Lesson
I11.7

Post-Incident Review and Lessons Learned

Focus

Review fictional causes, controls, evidence quality, decisions, recovery, communication, metrics, residual risk, and improvement actions without assigning blame.

Defensive Lab

Create a fictional post-incident review, action register, metric correction plan, and governance follow-up.

Open Lesson
I11.8

Incident Response Basics Lab

Focus

Integrate readiness, triage, scope, containment, evidence, recovery, communication, review, metrics, and closure into one fictional defensive case.

Defensive Lab

Complete a fictional end-to-end incident-response case package using only supplied evidence and safe, authorized training decisions.

Open Lesson

Fictional Evidence Preview

The Meadowbrook Student-Support Service Case

Across the module, students will review a fictional mixed evidence set involving an unusual support-service alert, identity events, file and queue activity, deployment records, runtime health, business transactions, source-health gaps, recovery dependencies, containment decisions, communication drafts, and post-incident actions. The evidence is designed to require correlation rather than guesswork.

Confirmed facts

Facts supported directly by supplied current records.

Supported conclusions

Narrow interpretations supported by several independent sources.

Evidence gaps

Missing or unreliable records that limit confidence and action.

Portfolio Outcome

Fictional Incident Response Case Package

By the end of Module I11, students will produce a portfolio-safe package containing a readiness charter, triage record, scope map, containment plan, evidence index, correlated timeline, recovery plan, stakeholder communication set, post-incident review, action register, governance dashboard, residual-risk statement, and closure checklist.

Module Assessment

I11 Incident Response Basics Module Test

Complete a 25-question assessment covering readiness, triage, scope, containment, evidence, recovery, communication, post-incident review, metrics, residual risk, and closure. Choices appear first, with explanations revealed afterward.

Open Module Test

Navigation

Begin Module I11