Foundations Review
What is it?
A working review of Module 1: the digital environment, assets, CIA, threats/vulnerabilities/risk, and the core security principles — applied to short scenarios instead of re-read as definitions.
Why it matters
Recognizing a concept in a scenario is a different skill from reciting its definition — and it is the skill every later module assumes you already have.
Where you see it
Every module from here on will hand you a short scenario and expect you to know which concept it is testing, without being told.
What normal looks like
Reading a short scenario and immediately naming the asset, the property at risk, or the principle involved.
What suspicious looks like
Not applicable at review level — this lesson is about recognition, not detection.
How analysts investigate
By pattern-matching new situations against the small vocabulary built in this module — asset, threat, vulnerability, risk, control, and the CIA properties.
Common beginner mistakes
- Re-reading definitions passively instead of testing yourself against a new scenario.
Three short NovaCore scenarios. For each one, apply what Module 1 taught you.
Quick check
Scenario 1: A support engineer keeps standing admin rights to every customer account 'in case a ticket needs it.' Which principle is missing?
A quick self-check — it doesn't affect your XP or progress.
Quick check
Scenario 2: A backup job silently fails for three weeks and nobody notices. One night, ransomware encrypts the production database. What is lost, beyond the data itself?
A quick self-check — it doesn't affect your XP or progress.
Quick check
Scenario 3: NovaCore's firewall alone stops most attacks, but an employee still gets phished because there was no MFA and no security-awareness training. What was missing?
A quick self-check — it doesn't affect your XP or progress.
One scenario, the whole vocabulary
A single NovaCore scenario, worked with every Module 1 concept at once: 'A former contractor's account was never disabled. Last night it logged in and downloaded the customer database.' Name each concept as it applies — this is the recognition skill later modules assume.
Name the asset and the CIA property first.
The asset is the customer database (and the identity that reached it). The property violated is confidentiality — customer data was read and copied by someone unauthorised. Naming this first, before 'how', tells you immediately this is a data-breach case, not an outage.
Separate the vulnerability from the threat.
The vulnerability is the account that was never disabled — a lingering, over-lived access. The threat is whoever still controlled that contractor's credentials. A beginner blurs these into 'a hack'; naming them separately shows the fix (disable stale accounts) is different from the response (investigate the actor).
Point to the principle that would have prevented it.
The missing control is an identity lifecycle applying least privilege over time — access should end when the job ends. Secure defaults and periodic access reviews would have caught the orphaned account. The risk was real because a live vulnerability (the enabled account) met a capable threat (whoever held the credentials) against a valuable asset. That single scenario exercised asset, CIA, vulnerability, threat, risk, control and principle — which is exactly what every later module will ask you to do without prompting.
Sign in to save your progress on the server.