๐Ÿšจ Problem โ€” Cumulative: draws on all of Unit 1

A Dangerous Situation

The Unit 1 Cyber Case, finally investigated for real ย ยทย  Approx. 3โ€“4 class days

StarringIdentify (given) โ†’ Detect โ†’ Respond โ†’ Recover โ†’ Protect

๐ŸŽฌ The Cyber Case, Revisited

You've been carrying the same cyber case since the start of this unit: a student steps away from their laptop in a crowded cafeteria for just a couple of minutes โ€” long enough to grab a drink and say hello to friends who've just shown up. Nothing seems wrong at the time.

It's not until later, opening the laptop again before the next class, that something's off: a file on the desktop that wasn't there before, one nobody remembers downloading. Suddenly every device, account, and piece of personal information that laptop had access to during those unattended minutes is worth asking about.

Every activity and project in this unit has been building toward this exact moment. Now you actually investigate it.

๐Ÿงญ What You're Actually Doing

This is a Problem, not an Activity or a Project โ€” which means it's cumulative. There's no new content to learn here. Instead, you and your cyber team investigate a compromised machine from scratch, using every skill from this entire unit at once: social engineering awareness, password and authentication habits, malware and firewall defense, file recovery, process monitoring, and safe browsing.

The asset is already identified for you โ€” it's the computer and its data. Your job is to build out the rest of the Cybersecurity Lifecycle yourselves: Detect what happened, Respond to stop it, Recover anything lost, and Protect against it happening again. Then you'll write it all up as a real Incident Response report and present it to the class.

Everything this problem pulls from

๐Ÿ’ก Tips & Tricks for Moving Forward

Start with your plan of action, not the lab
Build out what you'll do for Detect, Respond, Recover, and Protect before you ever launch the security lab. Identify is already done for you โ€” the asset is the computer and its data.
Never accept default firewall settings here
In this specific lab, default or 'recommended' settings will cut off your own connection. Everything needs to be configured manually โ€” this trips up more teams than the actual investigation does.
Write for a stranger, not for yourself
Your documentation standard is the same as the last project: another team should be able to read your notes and do exactly what you did, with zero extra context from you.
Let the IR report drive your presentation
Build the Incident Response report first, using the template. Your presentation should walk through that report โ€” not exist as a separate thing you build afterward.
Revisit your very first self-assessment
Go back to what you answered in 1.1.1 before you knew anything. Updating it now is a fast, honest way to see how far you've actually come.

โœ… Self-Check Before You Roll On

Check off each item as you get there. These are not grades โ€” they are your own signal.