Cybersecurity Fundamentals · Course lab · about 120 minutes · 7 tasks · marked out of 100, pass at 60
Secure one person's digital life, with proof
The situation
Pick one person — yourself, or a family member who trusts you with their phone. In one sitting you will find every account that touches money, close the doors the course showed you, back up the one thing they cannot lose, and leave them with a rule that defeats the scam calls that hit Pakistan every day.
Every step produces proof: a screenshot, a restored file, a written rule in their own words.
What you'll be able to show
- Inventory the accounts that matter and know why each one does
- Turn on two-factor authentication and remove reused passwords
- Recognise a real phishing attempt and name its technique
- Prove a backup by restoring it, and lock a SIM and the money apps
What you need
- The person's phone and email
- A notes file for the inventory and the proof screenshots
- The lesson 3 list of four phishing techniques
Tasks
-
1The money inventoryList every account that has money attached or could be used to ask the person's contacts for money: bank apps, JazzCash/Easypaisa, email, WhatsApp, social accounts, marketplace accounts. For each, note whether 2FA is on and whether the password is unique.A correct result: A table — most people are surprised by its length — with two yes/no columns.
-
2Close the front doorTurn on two-factor authentication for the primary email and every money app that offers it. Change every password that appears twice in your table to a unique one.A correct result: Screenshots of 2FA enabled on email and at least two other accounts; no password reused.
-
3Catch a real phishing attemptFind a real suspicious message in the inbox or WhatsApp. Without clicking anything, write which of the four techniques it uses and where the link actually points (long-press or hover). Then delete it.A correct result: A screenshot of the message, the technique named, the real destination written down.
-
4Updates, then a backup you have testedCheck when the phone and computer last updated; update if needed. Back up one folder or the phone's photos somewhere separate. Then restore one file to a different location to prove the backup works.A correct result: Update dates recorded, and a restored file that opens.
-
5SIM, alerts, permissionsSet a SIM PIN. Turn on transaction alerts in every money app. Review the permissions of five apps and remove every permission that has no reason to exist (a torch app with contacts access, say).A correct result: SIM PIN set, alerts on, and a list of removed permissions.
-
6The padlock, readOpen one site the person uses. Click the padlock. Record who issued the certificate and what it certifies. Write one sentence on what the padlock proves and what it does not.A correct result: Issuer name, and a sentence that does not overclaim.
-
7The rule they keepTeach the OTP rule — nobody legitimate ever needs your code — and the two-question test for calls claiming to be a bank. Have the person say both back in their own words and write down what they said.A correct result: The person's own wording of both rules, written down.
What to hand in
The inventory table, the proof screenshots (2FA, phishing, restore, SIM PIN, alerts), the permissions list, the padlock note, and the two rules in the person's own words.
How it is marked
| Criterion | Points |
|---|---|
| Inventory is complete with 2FA and password columns | 15 |
| 2FA on and reused passwords gone, with proof | 20 |
| Phishing attempt identified by technique and real destination | 15 |
| Backup proven by a restore | 15 |
| SIM PIN, alerts and permission review done | 15 |
| Padlock note is accurate and the rules are in the person's words | 20 |
| Total · pass at 60 | 100 |
صورتحال
ایک شخص چنیں — خود کو، یا گھر کا کوئی فرد جو اپنا phone آپ کے بھروسے دے۔ ایک نشست میں آپ ہر وہ account ڈھونڈیں گے جس سے پیسہ جڑا ہے، وہ دروازے بند کریں گے جو کورس نے دکھائے، اُس ایک چیز کا backup لیں گے جو وہ کھو نہیں سکتے، اور انہیں ایک ایسا اصول دے کر جائیں گے جو پاکستان میں روز آنے والی دھوکے کی calls کو شکست دیتا ہے۔
ہر step ثبوت پیدا کرتا ہے: ایک screenshot، ایک restore کی ہوئی file، ان کے اپنے الفاظ میں لکھا ہوا اصول۔
آپ کیا دکھا سکیں گے
- اہم accounts کی فہرست بنانا اور جاننا کہ ہر ایک کیوں اہم ہے
- two-factor authentication چالو کرنا اور دہرائے گئے passwords ہٹانا
- حقیقی phishing کوشش پہچاننا اور اس کی تکنیک کا نام لینا
- backup کو restore کر کے ثابت کرنا، اور SIM اور money apps کو lock کرنا
آپ کو کیا چاہیے
- اس شخص کا phone اور email
- فہرست اور ثبوت کے screenshots کے لیے ایک notes file
- سبق 3 کی چار phishing تکنیکوں کی فہرست
کام
-
1پیسے کی فہرستہر وہ account لکھیں جس سے پیسہ جڑا ہے یا جو اس شخص کے contacts سے پیسے مانگنے کے لیے استعمال ہو سکتا ہے: bank apps، JazzCash/Easypaisa، email، WhatsApp، social accounts، marketplace accounts۔ ہر ایک کے لیے لکھیں کہ 2FA چالو ہے یا نہیں اور password منفرد ہے یا نہیں۔درست نتیجہ: ایک table — زیادہ تر لوگ اس کی لمبائی پر حیران ہوتے ہیں — دو yes/no columns کے ساتھ۔
-
2سامنے کا دروازہ بند کریںبنیادی email اور ہر اس money app پر two-factor authentication چالو کریں جو یہ سہولت دیتی ہے۔ آپ کی table میں دو بار آنے والا ہر password منفرد میں بدلیں۔درست نتیجہ: email اور کم از کم دو اور accounts پر 2FA چالو ہونے کے screenshots؛ کوئی password دہرایا ہوا نہیں۔
-
3حقیقی phishing کوشش پکڑیںinbox یا WhatsApp میں ایک حقیقی مشکوک پیغام ڈھونڈیں۔ کچھ click کیے بغیر لکھیں کہ یہ چار تکنیکوں میں سے کون سی استعمال کرتا ہے اور link اصل میں کہاں جاتا ہے (long-press یا hover)۔ پھر delete کریں۔درست نتیجہ: پیغام کا screenshot، تکنیک کا نام، اصل منزل لکھی ہوئی۔
-
4updates، پھر آزمایا ہوا backupچیک کریں کہ phone اور computer آخری بار کب update ہوئے؛ ضرورت ہو تو update کریں۔ ایک folder یا phone کی تصویروں کا backup کہیں الگ لیں۔ پھر ایک file کو دوسری جگہ restore کر کے ثابت کریں کہ backup کام کرتا ہے۔درست نتیجہ: update کی تاریخیں درج، اور ایک restore شدہ file جو کھلتی ہو۔
-
5SIM، alerts، permissionsSIM PIN set کریں۔ ہر money app میں transaction alerts چالو کریں۔ پانچ apps کی permissions کا جائزہ لیں اور ہر وہ permission ہٹائیں جس کے ہونے کی کوئی وجہ نہیں (مثلاً torch app کو contacts تک رسائی)۔درست نتیجہ: SIM PIN set، alerts چالو، اور ہٹائی گئی permissions کی فہرست۔
-
6padlock، پڑھا ہواایک site کھولیں جو یہ شخص استعمال کرتا ہے۔ padlock پر click کریں۔ لکھیں کہ certificate کس نے جاری کیا اور وہ کس چیز کی تصدیق کرتا ہے۔ ایک جملہ لکھیں کہ padlock کیا ثابت کرتا ہے اور کیا نہیں۔درست نتیجہ: جاری کرنے والے کا نام، اور ایک جملہ جو حد سے زیادہ دعویٰ نہ کرے۔
-
7وہ اصول جو وہ رکھیں گےOTP کا اصول سکھائیں — کسی جائز شخص کو کبھی آپ کا code نہیں چاہیے ہوتا — اور bank ہونے کا دعویٰ کرنے والی calls کے لیے دو سوالوں کا test۔ اس شخص سے دونوں اپنے الفاظ میں دہروائیں اور لکھیں کہ انہوں نے کیا کہا۔درست نتیجہ: دونوں اصولوں کی اس شخص کی اپنی عبارت، لکھی ہوئی۔
کیا جمع کروانا ہے
فہرست کی table، ثبوت کے screenshots (2FA، phishing، restore، SIM PIN، alerts)، permissions کی فہرست، padlock کا note، اور اس شخص کے اپنے الفاظ میں دونوں اصول۔
نمبر کیسے ملیں گے
| معیار | نمبر |
|---|---|
| فہرست 2FA اور password columns کے ساتھ مکمل ہے | 15 |
| 2FA چالو اور دہرائے گئے passwords ختم، ثبوت کے ساتھ | 20 |
| phishing کوشش تکنیک اور اصل منزل سے پہچانی گئی | 15 |
| backup restore سے ثابت ہوا | 15 |
| SIM PIN، alerts اور permissions کا جائزہ ہوا | 15 |
| padlock کا note درست ہے اور اصول اس شخص کے الفاظ میں ہیں | 20 |
| کل · پاس 60 | 100 |
Hand in your lab
Create a free BvLogic ID to hand in your lab, get it marked, and have it on your certificate.
Create your BvLogic IDAlready have one? Sign in and this course will be added to it.