Lesson 7 of 7 · 0%Rehearse incident response and assemble the hardening dossierAssessment
Course map

Security Hardening and Threat Boundaries

0 of 7 complete0 of 7

Lesson 7.1 · 90 minutes

Rehearse incident response and assemble the hardening dossier

Practice a bounded credential and boundary incident, then deliver evidence, residual risk, and an improvement plan.

Skip course map
Current lessonRehearse incident response and assemble the hardening dossier0% complete · 0/7 lessons

Security Hardening and Threat Boundaries

0% complete · Current: Rehearse incident response and assemble the hardening dossier

Verifiedon 2026.7.1

Action boundary

Before you act

Expected result
A hardening dossier proves two controls, records one rehearsal, and states residual risks without overclaiming.
Failure mode
The team performs real destructive actions or declares recovery without verifying containment and credential replacement.
Rollback
Use only a sandbox and disposable credential; stop the exercise and restore the pre-exercise sandbox snapshot if impact exceeds the plan.

Capstone scenario

A disposable service credential may have appeared in an untrusted-content test, and a new plugin was enabled shortly before the discovery. Run a tabletop first; execute only the revocation portion in a sandbox with disposable credentials. Your goal is a credible response, not theatrical speed.

One-page incident runbook

Define: trigger; incident lead; containment authority; safe stop conditions; evidence custodian; credential revocation/rotation order; plugin/skill disable path; communication owner; recovery criteria; and post-incident review date. Preserve timestamps and minimal redacted evidence. Do not copy secrets into a ticket or lesson submission.

Dossier deliverable

Submit:

  1. The deployment threat model and prioritized threats.
  2. A least-privilege matrix and tool/network allowlist.
  3. Redacted evidence for two tested controls, including the adversarial boundary pack.
  4. The reproducible audit record and its source revision.
  5. The incident runbook, rehearsal timeline, recovery verification, and residual risks.

Rubric

  • Realistic, deployment-specific threats — 25%
  • Effective and scoped controls — 30%
  • Test evidence and reproducibility — 25%
  • Honest residual-risk statement and workable recovery plan — 20%

A dossier fails if it contains a secret, claims a control was tested when it was not, or lacks an accountable owner.

Final check

Before sign-off, ask a reviewer to pick one control at random. They must be able to identify its purpose, authority boundary, test evidence, owner, rollback, and next review date. If they cannot, the hardening work is incomplete.

Check your understanding

Knowledge check · security

Pass mark 100% · Attempt 1 of 3 · Not passed

A capstone rehearsal exposes a disposable credential outside its planned sandbox boundary. What must happen next?
Why this matters

A bounded exercise cannot continue after its authority or data boundary fails.

Evidence last verified 2026-07-30

Source provenanceVerification and sources

Review receipt rr_security_incident_capstone

Outcome
approved
Method
source-review
Reviewer
academy-security-source-review
Reviewed

Evidence

Limitations

  • Approval covers the bounded 2026.7.1 learning exercises and cited security guidance; operators must validate controls against their own deployment and use disposable credentials in labs.

Open the public evidence snapshot

Lesson checkpoint

Ready to move on?

Mark this lesson complete when you can apply its outcome without relying on the examples above.