I3 Module Test: Windows Security Basics
Demonstrate your ability to analyze Windows accounts, permissions, updates, security settings, Microsoft Defender, Event Viewer, startup apps, services, local habits, and integrated defensive evidence.
Readiness Check
Module Test Readiness
0/5 ready
25
Questions
8
Domains
1
Best answer each
Hidden
Answers until review
Assessment Instructions
How to Complete the I3 Module Test
Read the entire scenario before choosing an answer.
Select the option best supported by the supplied fictional evidence.
Prefer narrow, authorized, owned, testable, and reversible defensive actions.
Do not assume that one alert, event, username, or severity proves intent or complete compromise.
Check account, permission, application, service, backup, user, and network dependencies.
Use the explanations after submission to identify which lesson needs review.
Assessment Blueprint
Eight Windows Security Domains
Domain 1
Windows Accounts and Profiles
Focus
Account types, administrator access, temporary accounts, lifecycle review, profiles, ownership, sign-in evidence, and dependency checks.
Evidence
Account inventory, local groups, owner records, expiration, profile paths, last sign-in, services, tasks, and file ownership.
Domain 2
File Permissions and Shared Folders
Focus
Read, write, modify, full control, inheritance, explicit permissions, nested groups, shares, ownership, and effective access.
Evidence
Local permissions, share permissions, group membership, ownership, classification, role need, and effective-access results.
Domain 3
Windows Updates and Security Settings
Focus
Security updates, restart state, support lifecycle, firewall profiles, encryption, maintenance windows, compatibility, and validation.
Evidence
Update history, pending restart, support status, firewall configuration, encryption state, backup, test, rollback, and monitoring.
Domain 4
Microsoft Defender Concepts
Focus
Real-time protection, scans, detections, quarantine, remediation, reputation, cloud protection, exclusions, and alert limitations.
Evidence
Protection state, detection name, severity, path, process, user, action, quarantine, exclusion, source, publisher, and follow-up.
Domain 5
Event Viewer and Windows Logs
Focus
Security, System, Application, Setup, Defender, and operational logs; timestamps, providers, event IDs, users, processes, services, and correlation.
Evidence
Multi-channel event records, normalized time, correlation identifiers, change records, owner reports, and evidence gaps.
Domain 6
Startup Apps and Services
Focus
Startup applications, services, tasks, triggers, executable paths, publishers, accounts, dependencies, resource use, and approved baselines.
Evidence
Startup inventory, service state, task results, process data, event records, package metadata, owner records, and controlled test results.
Domain 7
Local Security Habits
Focus
Locking, standard-user use, trusted downloads, browser warnings, removable media, protected storage, backup, privacy, and reporting.
Evidence
Session records, download warnings, Defender history, media records, backup scope, user reports, training, and approved procedures.
Domain 8
Integrated Windows Security Review
Focus
Authorization, scope, evidence strength, confidence, prioritization, dependencies, change readiness, remediation, validation, and residual risk.
Evidence
Correlated evidence from all seven lesson domains plus governance, ownership, testing, rollback, monitoring, and review dates.
Exam Skills
What Strong Answers Have in Common
Identify confirmed facts
Recognize what a fictional account record, permission entry, alert, event, service state, or update history directly proves.
Respect evidence limits
Avoid treating one event, username, alert severity, scan result, or dashboard metric as a complete conclusion.
Correlate multiple sources
Connect users, groups, paths, processes, services, events, updates, protection records, owner reports, and change history.
Apply least privilege
Choose the narrowest account, permission, service, firewall, exclusion, and user-access design that supports approved work.
Protect continuity
Check applications, services, tasks, backups, recovery, files, users, and network dependencies before changing a Windows system.
Use controlled change
Include authorization, owner, testing, backup, rollback, validation, monitoring, residual risk, and review dates.
Final Review
Eight Things to Check Before Starting
Decision Standard
How to Choose Between Similar Answers
Prefer evidence over appearance
Choose the answer supported by account, permission, alert, event, service, owner, timeline, or change evidence—not by a familiar name, warning color, or assumption.
Prefer narrow action over broad disruption
Correct the exact account, group, rule, exclusion, service, file path, or workflow instead of disabling protection or removing all access.
Preserve required work
Check files, profiles, applications, services, tasks, backups, recovery, users, and network dependencies before remediation.
State uncertainty honestly
When evidence is incomplete, preserve the finding, identify the gap, reduce exposure if needed, and obtain authorized evidence before claiming certainty.
Include ownership and approval
The strongest response names who is responsible and uses an approved ticket, maintenance window, exception, or reporting process.
Validate the final state
A change is not complete until required access, applications, services, protection, logs, backups, recovery, and user workflows are checked.
Check Your Understanding
I3 Module Test: Windows Security Basics
Choose your answers first. Explanations appear only after submission.
1. A fictional temporary support account expired ten days ago, remains enabled, belongs to the local Administrators group, has no active ticket, and has no service or scheduled-task dependency. What is the strongest response?
2. Which statement about an inactive Windows account is most accurate?
3. Why should a retired Windows profile be reviewed before removal?
4. What is effective access?
5. A fictional internal folder gives All Staff modify access through inheritance, but only Project Editors need to change files. What is the strongest correction?
6. Why should both share permissions and local file permissions be reviewed?
7. A fictional Windows security update says installed, but a restart is still required. What is the strongest conclusion?
8. Why should Windows support lifecycle be included in a security review?
9. An approved application needs one inbound network service. Which firewall response is strongest?
10. What does Defender quarantine prove?
11. Why is a broad Downloads-folder Defender exclusion risky?
12. A blocked installer is required for a fictional classroom application, but it came from an unofficial mirror. What is the strongest response?
13. Why must a Windows event ID be interpreted with its provider and log channel?
14. A centralized collector receives no Windows events from one fictional device for thirty minutes. What is the strongest conclusion?
15. Which evidence best supports the conclusion that a permission change caused a Windows service failure?
16. What does high CPU use by a Windows process prove?
17. A fictional service starts automatically, its project ended months ago, no active dependency remains, controlled stop testing passes, and rollback works. What is the strongest next action?
18. Why should startup and service changes be made one at a time?
19. Why should users lock a Windows device before stepping away?
20. A fictional user sees a school sign-in page after following a shortened link, but the address is unfamiliar and the browser warns about the page. What is the strongest response?
21. Why is saving required work only to a local Desktop folder risky?
22. What should be confirmed before beginning an integrated Windows security review?
23. Why should a finding include a confidence rating?
24. Which finding should usually receive the highest priority?
25. Which recommendation is the most professional?
Scoring Guide
Use Your Results to Plan the Next Review
23–25 correct
Advanced readinessYou consistently connect Windows evidence, context, risk, dependencies, and controlled response.
Next step
Review any missed explanation, finalize the I3 portfolio report, and continue to Module I4.
19–22 correct
Strong readinessYou understand most Windows security concepts but should review the domains connected to missed questions.
Next step
Revisit the relevant lesson evidence model, scenario lab, checklist, and portfolio prompt.
15–18 correct
Developing readinessYou understand important ideas but need more practice correlating evidence and selecting controlled actions.
Next step
Review I3.1–I3.8, especially evidence limits, dependencies, prioritization, and validation.
0–14 correct
Rebuild the foundationCore Windows identity, access, maintenance, protection, logging, service, and review concepts need reinforcement.
Next step
Return to the module homepage and complete each lesson's readiness check, lab, quiz, checklist, and takeaways.
Defender Habits
Post-Test Review Checklist
Key Takeaways
What You Should Remember
Module Completion
Finish the Full I3 Review
After completing the test, return to the module homepage and open all eight lessons plus this assessment. Confirm that every route loads and that the top and bottom navigation work correctly.