High School IntermediateModule I325-Question Assessment

I3 Module Test: Windows Security Basics

Demonstrate your ability to analyze Windows accounts, permissions, updates, security settings, Microsoft Defender, Event Viewer, startup apps, services, local habits, and integrated defensive evidence.

Readiness Check

Module Test Readiness

0/5 ready

25

Questions

8

Domains

1

Best answer each

Hidden

Answers until review

Assessment Instructions

How to Complete the I3 Module Test

1

Read the entire scenario before choosing an answer.

2

Select the option best supported by the supplied fictional evidence.

3

Prefer narrow, authorized, owned, testable, and reversible defensive actions.

4

Do not assume that one alert, event, username, or severity proves intent or complete compromise.

5

Check account, permission, application, service, backup, user, and network dependencies.

6

Use the explanations after submission to identify which lesson needs review.

Assessment Blueprint

Eight Windows Security Domains

Domain 1

Windows Accounts and Profiles

Questions 1–3

Focus

Account types, administrator access, temporary accounts, lifecycle review, profiles, ownership, sign-in evidence, and dependency checks.

Evidence

Account inventory, local groups, owner records, expiration, profile paths, last sign-in, services, tasks, and file ownership.

Domain 2

File Permissions and Shared Folders

Questions 4–6

Focus

Read, write, modify, full control, inheritance, explicit permissions, nested groups, shares, ownership, and effective access.

Evidence

Local permissions, share permissions, group membership, ownership, classification, role need, and effective-access results.

Domain 3

Windows Updates and Security Settings

Questions 7–9

Focus

Security updates, restart state, support lifecycle, firewall profiles, encryption, maintenance windows, compatibility, and validation.

Evidence

Update history, pending restart, support status, firewall configuration, encryption state, backup, test, rollback, and monitoring.

Domain 4

Microsoft Defender Concepts

Questions 10–12

Focus

Real-time protection, scans, detections, quarantine, remediation, reputation, cloud protection, exclusions, and alert limitations.

Evidence

Protection state, detection name, severity, path, process, user, action, quarantine, exclusion, source, publisher, and follow-up.

Domain 5

Event Viewer and Windows Logs

Questions 13–15

Focus

Security, System, Application, Setup, Defender, and operational logs; timestamps, providers, event IDs, users, processes, services, and correlation.

Evidence

Multi-channel event records, normalized time, correlation identifiers, change records, owner reports, and evidence gaps.

Domain 6

Startup Apps and Services

Questions 16–18

Focus

Startup applications, services, tasks, triggers, executable paths, publishers, accounts, dependencies, resource use, and approved baselines.

Evidence

Startup inventory, service state, task results, process data, event records, package metadata, owner records, and controlled test results.

Domain 7

Local Security Habits

Questions 19–21

Focus

Locking, standard-user use, trusted downloads, browser warnings, removable media, protected storage, backup, privacy, and reporting.

Evidence

Session records, download warnings, Defender history, media records, backup scope, user reports, training, and approved procedures.

Domain 8

Integrated Windows Security Review

Questions 22–25

Focus

Authorization, scope, evidence strength, confidence, prioritization, dependencies, change readiness, remediation, validation, and residual risk.

Evidence

Correlated evidence from all seven lesson domains plus governance, ownership, testing, rollback, monitoring, and review dates.

Exam Skills

What Strong Answers Have in Common

Identify confirmed facts

Recognize what a fictional account record, permission entry, alert, event, service state, or update history directly proves.

Respect evidence limits

Avoid treating one event, username, alert severity, scan result, or dashboard metric as a complete conclusion.

Correlate multiple sources

Connect users, groups, paths, processes, services, events, updates, protection records, owner reports, and change history.

Apply least privilege

Choose the narrowest account, permission, service, firewall, exclusion, and user-access design that supports approved work.

Protect continuity

Check applications, services, tasks, backups, recovery, files, users, and network dependencies before changing a Windows system.

Use controlled change

Include authorization, owner, testing, backup, rollback, validation, monitoring, residual risk, and review dates.

Final Review

Eight Things to Check Before Starting

Review the difference between standard users, administrators, service identities, temporary accounts, disabled accounts, and user profiles.
Review ownership, inheritance, explicit permissions, nested groups, share permissions, and effective access.
Review update installation, restart activation, support lifecycle, firewall profiles, encryption, backup, and secure maintenance.
Review Defender detections, quarantine, scans, exclusions, process context, publisher, source, and alert limitations.
Review Windows log channels, timestamps, providers, event IDs, users, processes, services, results, and evidence gaps.
Review startup applications, services, tasks, triggers, paths, publishers, accounts, dependencies, and baselines.
Review locking, standard-account use, trusted sources, browser warnings, removable media, backups, and reporting.
Review authorization, scope, confidence, prioritization, change readiness, remediation, validation, monitoring, and residual risk.

Decision Standard

How to Choose Between Similar Answers

Prefer evidence over appearance

Choose the answer supported by account, permission, alert, event, service, owner, timeline, or change evidence—not by a familiar name, warning color, or assumption.

Prefer narrow action over broad disruption

Correct the exact account, group, rule, exclusion, service, file path, or workflow instead of disabling protection or removing all access.

Preserve required work

Check files, profiles, applications, services, tasks, backups, recovery, users, and network dependencies before remediation.

State uncertainty honestly

When evidence is incomplete, preserve the finding, identify the gap, reduce exposure if needed, and obtain authorized evidence before claiming certainty.

Include ownership and approval

The strongest response names who is responsible and uses an approved ticket, maintenance window, exception, or reporting process.

Validate the final state

A change is not complete until required access, applications, services, protection, logs, backups, recovery, and user workflows are checked.

Check Your Understanding

I3 Module Test: Windows Security Basics

Choose your answers first. Explanations appear only after submission.

1. A fictional temporary support account expired ten days ago, remains enabled, belongs to the local Administrators group, has no active ticket, and has no service or scheduled-task dependency. What is the strongest response?

2. Which statement about an inactive Windows account is most accurate?

3. Why should a retired Windows profile be reviewed before removal?

4. What is effective access?

5. A fictional internal folder gives All Staff modify access through inheritance, but only Project Editors need to change files. What is the strongest correction?

6. Why should both share permissions and local file permissions be reviewed?

7. A fictional Windows security update says installed, but a restart is still required. What is the strongest conclusion?

8. Why should Windows support lifecycle be included in a security review?

9. An approved application needs one inbound network service. Which firewall response is strongest?

10. What does Defender quarantine prove?

11. Why is a broad Downloads-folder Defender exclusion risky?

12. A blocked installer is required for a fictional classroom application, but it came from an unofficial mirror. What is the strongest response?

13. Why must a Windows event ID be interpreted with its provider and log channel?

14. A centralized collector receives no Windows events from one fictional device for thirty minutes. What is the strongest conclusion?

15. Which evidence best supports the conclusion that a permission change caused a Windows service failure?

16. What does high CPU use by a Windows process prove?

17. A fictional service starts automatically, its project ended months ago, no active dependency remains, controlled stop testing passes, and rollback works. What is the strongest next action?

18. Why should startup and service changes be made one at a time?

19. Why should users lock a Windows device before stepping away?

20. A fictional user sees a school sign-in page after following a shortened link, but the address is unfamiliar and the browser warns about the page. What is the strongest response?

21. Why is saving required work only to a local Desktop folder risky?

22. What should be confirmed before beginning an integrated Windows security review?

23. Why should a finding include a confidence rating?

24. Which finding should usually receive the highest priority?

25. Which recommendation is the most professional?

Scoring Guide

Use Your Results to Plan the Next Review

23–25 correct

Advanced readiness

You consistently connect Windows evidence, context, risk, dependencies, and controlled response.

Next step

Review any missed explanation, finalize the I3 portfolio report, and continue to Module I4.

19–22 correct

Strong readiness

You understand most Windows security concepts but should review the domains connected to missed questions.

Next step

Revisit the relevant lesson evidence model, scenario lab, checklist, and portfolio prompt.

15–18 correct

Developing readiness

You understand important ideas but need more practice correlating evidence and selecting controlled actions.

Next step

Review I3.1–I3.8, especially evidence limits, dependencies, prioritization, and validation.

0–14 correct

Rebuild the foundation

Core Windows identity, access, maintenance, protection, logging, service, and review concepts need reinforcement.

Next step

Return to the module homepage and complete each lesson's readiness check, lab, quiz, checklist, and takeaways.

Defender Habits

Post-Test Review Checklist

Key Takeaways

What You Should Remember

1.Windows security is a connected system of identity, access, maintenance, protection, logging, software, user behavior, and governance.
2.Strong answers use multiple evidence sources and respect what each source cannot prove.
3.Least privilege applies to users, administrators, services, tasks, permissions, firewall rules, and Defender exclusions.
4.Defensive changes should preserve required applications, services, backups, recovery, users, and network functions.
5.Professional recommendations are authorized, owned, specific, tested, reversible, validated, monitored, and reviewed.
6.The strongest Windows report clearly separates facts, conclusions, gaps, risk, actions, and residual risk.

Module Completion

Finish the Full I3 Review

After completing the test, return to the module homepage and open all eight lessons plus this assessment. Confirm that every route loads and that the top and bottom navigation work correctly.