Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Incident Response Foundations
TheoryBeginner12 minIncident Triage

Foundations Review — Declare or Not?

What is it?

A working review of Module 1 — event/alert/incident, lifecycle, severity, evidence-first, roles — applied to three short Marasi situations that each demand a declaration decision.

Why it matters

The declaration decision is the gateway to everything else in this path — practicing it cheap, here, beats practicing it expensive, live.

Where you see it

Every shift, at the boundary between SOC triage and incident response.

What normal looks like

Declarations backed by validated facts, declined escalations backed by validated absence, and both recorded.

What suspicious looks like

Not applicable at review level — the goal is judgment practice.

How analysts investigate

By naming, for each situation: what is validated, what is suspected, and which side of the declaration line the validated part falls on.

Common beginner mistakes

  • Letting the third situation inherit the verdict of the first two — each situation gets its own evidence-based decision.
SituationValidated facts
A — Antivirus quarantined a known-bad file on arrival; no execution recordedBlocked before running
B — Service account logged in interactively at 03:00 and read 40k customer rowsInteractive use + bulk read both confirmed in logs
C — One user reports their mouse 'moved by itself' once; no remote session in logsReport only; telemetry shows nothing

Quick check

Which situation must be declared an incident right now?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.