High School IntermediateModule I16Applied Defensive Labs

I16 Intermediate Defensive Labs

Practice safe, fictional defender tasks across logs, phishing, identity and access, web security, cloud configuration, incident response, written reporting, and multi-step defensive analysis.

Module Snapshot

8

Lessons

1

Module Test

6

Core Workflow Steps

10

Portfolio Outcomes

Main Question

How Do Defenders Turn Mixed Evidence into Safe, Actionable Work?

Applied defensive analysis requires more than spotting a warning sign. Students must validate sources, define scope, compare evidence, preserve uncertainty, assign the correct owner, choose proportionate action, communicate clearly, and prove the result.

Safety Boundary

Fictional Evidence and Defensive Decisions Only

Use only the fictional logs, messages, identities, permissions, systems, websites, cloud resources, suppliers, cases, incidents, and reports supplied in the lessons. Never open real suspicious links or files, request credentials, access private systems, or expose school, employee, company, supplier, or incident data.

Defensive Lab Workflow

Six Steps from Lab Scope to Validated Improvement

1

Confirm scope and safety

Define the fictional systems, identities, services, suppliers, data, time window, approved evidence, privacy limits, authority, and decisions allowed.

2

Validate evidence quality

Check fictional source health, timestamps, parsing, ownership, coverage, completeness, duplicates, delays, conflicts, and known blind spots.

3

Analyze and prioritize

Compare fictional facts with context, business criticality, active exposure, expected behavior, alternate explanations, confidence, and urgency.

4

Decide and document

Record fictional findings, evidence references, owners, actions, authority, deadlines, rollback, communications, limitations, and residual risk.

5

Coordinate and communicate

Route fictional technical, service, supplier, risk, incident, leadership, and handoff decisions through the correct approved roles.

6

Validate and improve

Confirm fictional security outcome, business function, source health, control operation, owner signoff, closure criteria, metrics, and follow-up improvements.

Module Objectives

What You Will Be Able to Do

Objective 1

Analyze fictional logs and alerts through source health, timelines, identity, assets, services, behavior, confidence, and evidence limits.

Objective 2

Triage fictional phishing safely without opening real suspicious links, attachments, files, accounts, messages, or private evidence.

Objective 3

Review fictional identity and access permissions using business need, least privilege, ownership, approvals, exceptions, validation, and residual risk.

Objective 4

Evaluate fictional web and cloud defensive evidence while separating configuration risk, possible exposure, confirmed impact, missing evidence, and owner decisions.

Objective 5

Coordinate a fictional incident-response tabletop through authority, containment concepts, service continuity, communication, recovery, closure, and lessons learned.

Objective 6

Write accurate fictional defensive reports and combine multiple evidence sources into a complete portfolio-ready investigation package.

Lessons

Eight Intermediate Defensive Labs

1
I16.1Start Here

Fake Log Investigation Lab

Lesson focus

Analyze fictional authentication, endpoint, network, service, and source-health records while separating direct observations, supported conclusions, alternate explanations, missing evidence, and unsupported claims.

Defensive lab

Build a fictional log-investigation package with a scope statement, evidence register, normalized timeline, source-health review, findings, confidence, limitations, owners, and next actions.

Open I16.1
2
I16.2

Fake Phishing Triage Lab

Lesson focus

Review fictional email headers, sender context, message language, links, attachment descriptions, identity activity, reporting history, and user impact without opening real suspicious content.

Defensive lab

Create a fictional phishing-triage worksheet, message disposition, evidence matrix, user guidance, escalation path, communication record, and defensive improvement plan.

Open I16.2
3
I16.3

Fake IAM Permission Review Lab

Lesson focus

Evaluate fictional identities, roles, group membership, privileged access, service accounts, supplier access, exceptions, approvals, business need, and separation of duties.

Defensive lab

Produce a fictional permission-review package with an identity inventory, entitlement matrix, owner decisions, access changes, exceptions, validation, residual risk, and review dates.

Open I16.3
4
I16.4

Fake Web Defense Review Lab

Lesson focus

Assess fictional web alerts, application behavior, authentication records, input-handling evidence, security headers, configuration, source health, business context, and defensive controls.

Defensive lab

Build a fictional web-defense review with evidence-limited findings, owner questions, monitoring improvements, secure-coding recommendations, validation, and safe communication.

Open I16.4
5
I16.5

Fake Cloud Misconfiguration Review Lab

Lesson focus

Review fictional cloud identities, storage policies, network exposure, logging, encryption concepts, resource ownership, changes, suppliers, shared responsibility, and monitoring gaps.

Defensive lab

Create a fictional cloud-misconfiguration case with scope, evidence, effective-access review, rollback decision, owner map, source-health checks, validation, and residual risk.

Open I16.5
6
I16.6

Fake Incident Response Tabletop

Lesson focus

Coordinate a fictional incident-response scenario through readiness, detection, triage, declaration criteria, containment concepts, recovery, communication, evidence preservation, and lessons learned.

Defensive lab

Complete a fictional tabletop package with inject decisions, authority, actions, service impact, communications, handoffs, recovery validation, closure criteria, and improvement actions.

Open I16.6
7
I16.7

Writing a Defensive Report

Lesson focus

Turn fictional technical evidence into accurate analyst notes, case findings, owner requests, leadership summaries, recommendations, limitations, and portfolio-safe defensive reports.

Defensive lab

Write a fictional professional report with an executive summary, scope, methods, evidence, findings, alternatives, risk, recommendations, validation, limitations, and appendices.

Open I16.7
8
I16.8

Intermediate Multi-Step Lab

Lesson focus

Integrate fictional logs, alerts, phishing, IAM, web, cloud, incident response, reporting, communication, metrics, ownership, authority, validation, and continuous improvement.

Defensive lab

Complete a fictional multi-stage defensive investigation and produce one decision-ready case package and portfolio artifact.

Open I16.8

Fictional Evidence Preview

One Shift, Several Defensive Questions

1

A fictional supplier identity accessed a confidential support service after its documented exception expired.

2

A fictional email message used urgent language and an unfamiliar sign-in link, but no attachment was opened.

3

A fictional web alert occurred during approved maintenance while one supporting source was delayed.

4

A fictional cloud storage policy changed outside the approved window, but data access is not confirmed.

5

A fictional critical audit source stopped reporting for thirty-five minutes while compensating evidence remained available.

6

The records require separate owners, priorities, actions, confidence statements, validation steps, and evidence-limited conclusions.

The safest approach is to separate the records, validate each source, assign the correct owner, preserve limitations, and avoid combining unrelated evidence into one unsupported incident claim.

Professional Standard

Every Lab Must Produce a Reviewable Decision Trail

Another authorized reviewer should be able to follow the scope, evidence, source health, timeline, findings, alternatives, confidence, owners, actions, authority, communications, validation, residual risk, and closure without guessing.

Portfolio Outcome

Ten Artifacts You Will Build

1

Fake log investigation package

2

Phishing triage and reporting worksheet

3

IAM permission and exception review

4

Web defense evidence review

5

Cloud misconfiguration assessment

6

Incident response tabletop record

7

Professional defensive report

8

Evidence and decision register

9

Leadership and technical summaries

10

Intermediate multi-step lab portfolio artifact

Module Assessment

I16 Intermediate Defensive Labs Module Test

After all eight labs, complete one exact twenty-five-question module test covering applied defensive analysis using fictional logs, alerts, phishing, IAM, web, cloud, incident response, written reports, evidence limits, ownership, validation, and improvement.

Module Navigation

Begin Module I16