Foundations Review — Declare or Not?
What is it?
A working review of Module 1 — event/alert/incident, lifecycle, severity, evidence-first, roles — applied to three short Marasi situations that each demand a declaration decision.
Why it matters
The declaration decision is the gateway to everything else in this path — practicing it cheap, here, beats practicing it expensive, live.
Where you see it
Every shift, at the boundary between SOC triage and incident response.
What normal looks like
Declarations backed by validated facts, declined escalations backed by validated absence, and both recorded.
What suspicious looks like
Not applicable at review level — the goal is judgment practice.
How analysts investigate
By naming, for each situation: what is validated, what is suspected, and which side of the declaration line the validated part falls on.
Common beginner mistakes
- Letting the third situation inherit the verdict of the first two — each situation gets its own evidence-based decision.
| Situation | Validated facts |
|---|---|
| A — Antivirus quarantined a known-bad file on arrival; no execution recorded | Blocked before running |
| B — Service account logged in interactively at 03:00 and read 40k customer rows | Interactive use + bulk read both confirmed in logs |
| C — One user reports their mouse 'moved by itself' once; no remote session in logs | Report only; telemetry shows nothing |
Quick check
Which situation must be declared an incident right now?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.