Network Security Basics · Course lab · about 240 minutes · 6 tasks · marked out of 100, pass at 60
A real organisation audited on five controls, two fixed, one report
The situation
Pick an organisation that will let you — a family business, your own workplace, a small office. Inventory what it has, collect the phishing that actually reaches its people, score it on the five controls with evidence, write its one-page incident plan and its staff security card, test one alert path end to end, fix at least two things, and write the two-page report that becomes your first security portfolio piece.
What you'll be able to show
- Inventory devices, exposed services and admin accounts
- Score five controls with evidence and fix the cheapest failing one first
- Write an incident plan and a staff card people can actually follow
- Test an alert path and report what remains, honestly
What you need
- Access to the organisation's network and router, with permission in writing
- Three real phishing attempts from its people's phones or inboxes
- A document for the plan, the card and the report
Tasks
-
1InventoryList every device on the network (the router's client list), every service reachable from outside, and every account with admin rights. Note anything nobody could explain.A correct result: Three lists, and at least one item that surprised the owner.
-
2Real phishing, cataloguedCollect three real phishing attempts from the organisation's people this week (screenshots). For each: what it impersonates, what it wants, the one detail that gives it away, and the procedural rule that would have defeated it regardless of how convincing it looked.A correct result: Three catalogued attempts with a rule for each.
-
3Five controls, scoredScore out of five with evidence: MFA on email? Patched? Least privilege? Segmented (guest Wi-Fi separate)? Anything exposed to the internet? Fix the cheapest failing one today and record what you did.A correct result: Five scores with evidence, one fix done and recorded.
-
4The incident plan and the alert testOne page: who is called first, how a machine gets isolated, where backups are and when last tested, which credentials get reset, who tells customers. Then make one alert actually fire (a failed-login alert, a backup failure) and confirm a human saw it.A correct result: The one-page plan and proof a human received the test alert.
-
5The staff cardOne page for staff: the seven personal rules, the phishing examples they will actually receive (bank SMS, WhatsApp code request, fake job offer), and the exact name and number to report to. Give it to one person and ask them to explain it back; rewrite the parts they could not.A correct result: The card, and the parts rewritten after the read-back.
-
6Fix two, write the reportFix at least two things from your audit (one may be the task 3 fix). Write the two-page report: what you found, what you changed, what remains and why. Give it to the owner.A correct result: Two fixes done and a two-page report delivered.
What to hand in
The inventory, the phishing catalogue, the five-control scorecard, the incident plan with alert proof, the staff card, and the two-page report.
How it is marked
| Criterion | Points |
|---|---|
| Inventory complete across devices, services and admin accounts | 15 |
| Three real phishing attempts catalogued with defeating rules | 15 |
| Five controls scored with evidence and one fixed | 20 |
| Incident plan written and an alert path proven | 20 |
| Staff card tested by read-back and rewritten | 10 |
| Two fixes made and the report delivered | 20 |
| Total · pass at 60 | 100 |
صورتحال
کوئی ادارہ چنیں جو اجازت دے — خاندانی کاروبار، آپ کا اپنا دفتر، ایک چھوٹا office۔ اس کے پاس جو ہے اس کی فہرست بنائیں، وہ phishing جمع کریں جو واقعی اس کے لوگوں تک پہنچتی ہے، پانچ controls پر ثبوت کے ساتھ نمبر دیں، اس کا ایک صفحے کا incident plan اور staff security card لکھیں، ایک alert کا راستہ شروع سے آخر تک آزمائیں، کم از کم دو چیزیں ٹھیک کریں، اور وہ دو صفحوں کی رپورٹ لکھیں جو آپ کا پہلا security portfolio piece بنے۔
آپ کیا دکھا سکیں گے
- devices، exposed services اور admin accounts کی فہرست بنانا
- پانچ controls کو ثبوت کے ساتھ نمبر دینا اور سب سے سستی ناکام چیز پہلے ٹھیک کرنا
- ایسا incident plan اور staff card لکھنا جس پر لوگ واقعی عمل کر سکیں
- alert کا راستہ آزمانا اور جو باقی ہے اسے ایمانداری سے رپورٹ کرنا
آپ کو کیا چاہیے
- ادارے کے network اور router تک رسائی، تحریری اجازت کے ساتھ
- اس کے لوگوں کے phones یا inboxes سے تین حقیقی phishing کوششیں
- plan، card اور رپورٹ کے لیے ایک document
کام
-
1فہرستnetwork پر ہر device (router کی client list)، باہر سے پہنچنے کے قابل ہر service، اور admin حقوق والا ہر account لکھیں۔ جو کوئی نہ سمجھا سکے اسے نوٹ کریں۔درست نتیجہ: تین فہرستیں، اور کم از کم ایک چیز جس نے مالک کو حیران کیا۔
-
2حقیقی phishing، catalogue شدہاس ہفتے ادارے کے لوگوں سے تین حقیقی phishing کوششیں جمع کریں (screenshots)۔ ہر ایک کے لیے: یہ کس کی نقل ہے، کیا چاہتی ہے، وہ ایک تفصیل جو اسے پکڑواتی ہے، اور وہ طریقہ کار کا اصول جو اسے شکست دیتا چاہے وہ کتنی قائل کرنے والی لگتی۔درست نتیجہ: ہر ایک کے لیے اصول کے ساتھ تین catalogue شدہ کوششیں۔
-
3پانچ controls، نمبر شدہثبوت کے ساتھ پانچ میں سے نمبر دیں: email پر MFA؟ Patched؟ Least privilege؟ Segmented (guest Wi-Fi الگ)؟ کچھ internet پر exposed؟ سب سے سستی ناکام چیز آج ٹھیک کریں اور لکھیں کہ آپ نے کیا کیا۔درست نتیجہ: ثبوت کے ساتھ پانچ نمبر، ایک fix ہوا اور درج ہوا۔
-
4incident plan اور alert کا testایک صفحہ: پہلے کسے call کیا جائے، machine کو الگ کیسے کیا جائے، backups کہاں ہیں اور آخری بار کب test ہوئے، کون سی credentials reset ہوں، customers کو کون بتائے۔ پھر ایک alert واقعی fire کریں (failed-login alert، backup کی ناکامی) اور تصدیق کریں کہ ایک انسان نے اسے دیکھا۔درست نتیجہ: ایک صفحے کا plan اور ثبوت کہ ایک انسان کو test alert ملا۔
-
5staff cardstaff کے لیے ایک صفحہ: سات ذاتی اصول، وہ phishing مثالیں جو انہیں واقعی ملیں گی (bank کا SMS، WhatsApp code کی درخواست، جعلی job offer)، اور رپورٹ کرنے کے لیے صحیح نام اور نمبر۔ ایک شخص کو دیں اور کہیں کہ واپس سمجھا کر دکھائے؛ جو حصے وہ نہ سمجھا سکے انہیں دوبارہ لکھیں۔درست نتیجہ: card، اور واپس سمجھانے کے بعد دوبارہ لکھے ہوئے حصے۔
-
6دو ٹھیک کریں، رپورٹ لکھیںاپنے audit سے کم از کم دو چیزیں ٹھیک کریں (ایک task 3 والا fix ہو سکتا ہے)۔ دو صفحوں کی رپورٹ لکھیں: کیا ملا، کیا بدلا، کیا باقی ہے اور کیوں۔ مالک کو دیں۔درست نتیجہ: دو fixes ہوئے اور دو صفحوں کی رپورٹ پہنچائی گئی۔
کیا جمع کروانا ہے
فہرست، phishing کا catalogue، پانچ controls کا scorecard، alert کے ثبوت کے ساتھ incident plan، staff card، اور دو صفحوں کی رپورٹ۔
نمبر کیسے ملیں گے
| معیار | نمبر |
|---|---|
| devices، services اور admin accounts کی فہرست مکمل | 15 |
| تین حقیقی phishing کوششیں شکست دینے والے اصولوں کے ساتھ catalogue شدہ | 15 |
| پانچ controls ثبوت کے ساتھ نمبر شدہ اور ایک ٹھیک | 20 |
| incident plan لکھا اور alert کا راستہ ثابت | 20 |
| staff card واپس سمجھانے سے آزمایا اور دوبارہ لکھا گیا | 10 |
| دو fixes ہوئے اور رپورٹ پہنچائی گئی | 20 |
| کل · پاس 60 | 100 |
Hand in your lab
Create a free BvLogic ID to hand in your lab, get it marked, and have it on your certificate.
Create your BvLogic IDAlready have one? Sign in and this course will be added to it.