Cybersecurity Fundamentals · Course lab · about 120 minutes · 7 tasks · marked out of 100, pass at 60

Secure one person's digital life, with proof

The situation

Pick one person — yourself, or a family member who trusts you with their phone. In one sitting you will find every account that touches money, close the doors the course showed you, back up the one thing they cannot lose, and leave them with a rule that defeats the scam calls that hit Pakistan every day.

Every step produces proof: a screenshot, a restored file, a written rule in their own words.

What you'll be able to show

  • Inventory the accounts that matter and know why each one does
  • Turn on two-factor authentication and remove reused passwords
  • Recognise a real phishing attempt and name its technique
  • Prove a backup by restoring it, and lock a SIM and the money apps

What you need

  • The person's phone and email
  • A notes file for the inventory and the proof screenshots
  • The lesson 3 list of four phishing techniques

Tasks

  1. 1The money inventory
    List every account that has money attached or could be used to ask the person's contacts for money: bank apps, JazzCash/Easypaisa, email, WhatsApp, social accounts, marketplace accounts. For each, note whether 2FA is on and whether the password is unique.
    A correct result: A table — most people are surprised by its length — with two yes/no columns.
  2. 2Close the front door
    Turn on two-factor authentication for the primary email and every money app that offers it. Change every password that appears twice in your table to a unique one.
    A correct result: Screenshots of 2FA enabled on email and at least two other accounts; no password reused.
  3. 3Catch a real phishing attempt
    Find a real suspicious message in the inbox or WhatsApp. Without clicking anything, write which of the four techniques it uses and where the link actually points (long-press or hover). Then delete it.
    A correct result: A screenshot of the message, the technique named, the real destination written down.
  4. 4Updates, then a backup you have tested
    Check when the phone and computer last updated; update if needed. Back up one folder or the phone's photos somewhere separate. Then restore one file to a different location to prove the backup works.
    A correct result: Update dates recorded, and a restored file that opens.
  5. 5SIM, alerts, permissions
    Set a SIM PIN. Turn on transaction alerts in every money app. Review the permissions of five apps and remove every permission that has no reason to exist (a torch app with contacts access, say).
    A correct result: SIM PIN set, alerts on, and a list of removed permissions.
  6. 6The padlock, read
    Open one site the person uses. Click the padlock. Record who issued the certificate and what it certifies. Write one sentence on what the padlock proves and what it does not.
    A correct result: Issuer name, and a sentence that does not overclaim.
  7. 7The rule they keep
    Teach the OTP rule — nobody legitimate ever needs your code — and the two-question test for calls claiming to be a bank. Have the person say both back in their own words and write down what they said.
    A correct result: The person's own wording of both rules, written down.

What to hand in

The inventory table, the proof screenshots (2FA, phishing, restore, SIM PIN, alerts), the permissions list, the padlock note, and the two rules in the person's own words.

How it is marked

CriterionPoints
Inventory is complete with 2FA and password columns 15
2FA on and reused passwords gone, with proof 20
Phishing attempt identified by technique and real destination 15
Backup proven by a restore 15
SIM PIN, alerts and permission review done 15
Padlock note is accurate and the rules are in the person's words 20
Total · pass at 60 100

Hand in your lab

Create a free BvLogic ID to hand in your lab, get it marked, and have it on your certificate.

Create your BvLogic ID

Already have one? Sign in and this course will be added to it.