Exercises
Derive a use case; validate timestamps; write and replay a rule; tune noise; triage an alert; construct a timeline; preserve evidence; test hypotheses; assign incident roles; choose containment; revoke credentials; validate recovery; write a post-incident action; draw reference architecture; add a fitness function; run a tabletop; and respond to an external report.
Required evidence
Submit threat-linked rules, validated telemetry, replay and noise results, evidence provenance, timeline, decision log, containment and recovery proof, architecture correction, independent finding disposition, and residual risk. Protect sensitive incident data.
Oral defense
Triage one ambiguous signal, distinguish evidence from inference, demonstrate containment and trusted recovery, and defend the architecture or executive risk decision.
Source backbone
Use NIST SP 800-61, MITRE ATT&CK, NIST CSF, and Building Secure and Reliable Systems.