Goal
Practice FIRST/NEXT decisions without touching production systems.
Estimated cost: Free when performed with local diagrams, exports, or test data. If you use a real cloud, lab, or SaaS environment, verify cost and authorization first.
Concepts Reinforced
- incident response lifecycle
- forensics
- chain of custody
Prerequisites
- A non-production lab, diagram, or exported sample data.
- Authorization to review the data or configuration.
- A text editor or spreadsheet for notes.
Exact Steps
- Pick a ransomware or compromised-admin scenario.
- List volatile and durable evidence sources.
- Write the first five responder actions.
- Identify which actions could destroy evidence.
- Create a one-page post-incident lesson list.
Verification
The action sequence preserves evidence before destructive remediation.
Cleanup
Archive the tabletop notes with training records or delete local drafts.