Y3-P07 · Phase 7 of 8

IAM Incident Response

Respond to identity-related security incidents.

Incident responseIdentity attacksCredential compromiseDetectionContainmentEradicationLessons learned

Objectives

  • 1.Detect identity-related security incidents
  • 2.Execute containment and eradication steps
  • 3.Preserve forensic evidence
  • 4.Conduct post-incident review
  • 5.Document lessons learned

Student Outcomes

  • Detect and respond to identity incidents
  • Preserve evidence properly
  • Conduct post-incident reviews
  • Document lessons learned

Evidence Requirements

  • Incident response playbook
  • Detection and containment evidence
  • Forensic evidence preservation
  • Post-incident review document

Acceptance Criteria

  • Student detects identity incidents
  • Student executes response steps
  • Student conducts post-incident review

Evidence & Scoring

Passing: 80%

Tutor — Y3-P07

Tutor Offline. Ollama is not running. Install from ollama.com, then run ollama serve and ollama pull llama3.1.

Ask the tutor a question about your current lab.

The tutor uses progressive hints — it won't give you the answer immediately.