Y3-P07 · Phase 7 of 8
IAM Incident Response
Respond to identity-related security incidents.
Incident responseIdentity attacksCredential compromiseDetectionContainmentEradicationLessons learned
Objectives
- 1.Detect identity-related security incidents
- 2.Execute containment and eradication steps
- 3.Preserve forensic evidence
- 4.Conduct post-incident review
- 5.Document lessons learned
Student Outcomes
- Detect and respond to identity incidents
- Preserve evidence properly
- Conduct post-incident reviews
- Document lessons learned
Evidence Requirements
- •Incident response playbook
- •Detection and containment evidence
- •Forensic evidence preservation
- •Post-incident review document
Acceptance Criteria
- Student detects identity incidents
- Student executes response steps
- Student conducts post-incident review
Evidence & Scoring
Passing: 80%
Tutor — Y3-P07
Tutor Offline. Ollama is not running. Install from ollama.com, then run
ollama serve and ollama pull llama3.1.Ask the tutor a question about your current lab.
The tutor uses progressive hints — it won't give you the answer immediately.