๐Ÿ“ Project โ€” Applies Activities 1.2.1โ€“1.2.3

It's a Trap!

Investigate and remediate a compromised machine, documented like a professional ย ยทย  Approx. 2โ€“3 class days

StarringDetect โ†’ Respond โ†’ Recover โ†’ Protect

A recap of Activities 1.2.1โ€“1.2.3, the Detect/Respond/Recover/Protect documentation framework, and the standard this project holds you to.

It's a Trap! remediation documentation infographic

๐Ÿงญ Recap & Application

Someone's machine has been compromised, and it's your team's job to investigate and fix it โ€” for real, on a live virtual machine. Nothing here is new security knowledge. It's everything from the last three activities, applied at once:

What's genuinely new is how rigorously you'll document it. You'll track every fix against four stages of the Cybersecurity Lifecycle:

DetectRespondRecoverProtect

The standard is high: another team should be able to read your notes and do exactly what you did. That's not a suggestion โ€” it's the actual rubric bar, and it's the same discipline the AP exam rewards.

What you will do in this project

  • Investigate a compromised virtual machine and build a plan of action before touching anything.
  • Apply your firewall, malware-removal, and file-recovery skills together on one real investigation.
  • Document every fix using the Detect โ†’ Respond โ†’ Recover โ†’ Protect Cybersecurity Lifecycle steps.
  • Build a how-to artifact and present it to another team.
  • Reflect on your team's collaboration and update your team norms.

Why it matters

This is the first project where mitigating risk is the entire point, not a side effect. Finding the problem is half the job โ€” writing it up so someone else could reproduce your fix is the other half, and it's the half people skip.

โœ… Self-Check Before You Roll On

Check off each item as you get there. These are not grades โ€” they are your own signal.