The question this module answers
How do you see, measure and prove what privileged users are doing, and respond fast when something goes wrong?
On the Tuesday of Ahmed's incident, Amara could see the smoke but never the fire: no session data, no baseline. With Grace's rollout live, she builds the watch: three monitoring lenses, 19 KPIs, a full evidence base, and an incident response and forensics discipline. Six months on, a phished credential is contained in eleven minutes.
Module curriculum
1
Part 1: The Watch Begins: Three Lenses
Coming soon
2
Part 2: The Scoreboard: 19 KPIs
Coming soon
3
Part 3: The Evidence Base: Audit Data Points
Coming soon
4
Part 4: Incident Response and Forensics
Coming soon
5
Part 5: Use Case: The Suspicious Database Modification
Coming soon
6
Part 6: The Audit Dividend: GDPR and SOX
Coming soon
7
Part 7: The Monitoring and Auditing Playbooks
Coming soon
8
Part 8: Incident Response Best Practice and Handover
Coming soon
9
Knowledge Check10 questions · pass mark 8/10
Quiz
Knowledge Check
Q1: Which three lenses does Module 7 combine to decide what to monitor?
Firewalls, antivirus and patching
User behaviour, access patterns and system interactions
People, process and technology
Identity, device and network location
Q2: A US-based administrator's account logs in from another country. When is this not necessarily a red flag?
When the login happens during business hours
When the password was recently rotated
When the administrator is known to be travelling
When the session is shorter than ten minutes
Q3: Why is the 'percentage of reviewed audit logs' tracked as a KPI?
Collecting logs without reviewing them is theatre, so a low percentage signals weak oversight
It measures how much storage the logs consume
It shows how many users have MFA enabled
It proves the logs have been encrypted
Q4: According to the IBM figure Module 7 uses, how long does it take on average to identify and contain a breach involving stolen credentials?
30 days
292 days
180 days
365 days
Q5: In the suspicious database modification use case, what containment step was taken once analysts confirmed the anomaly was real?
The database was permanently deleted
Customers were notified before any other action
The SIEM was switched off to stop further alerts
The implicated account was temporarily disabled
Q6: What did forensic attribution reveal about the origin of the suspicious database activity?
The user's credentials had been phished a week earlier and used remotely to get round geography-based restrictions
A scheduled maintenance script had malfunctioned
A disgruntled administrator acted alone from the office
A vendor had been given permanent administrator rights
Q7: What is the difference between incident response and forensics in Module 7?
They are two names for the same activity
Forensics happens first; response happens only after legal approval
Response detects, contains and mitigates; forensics establishes the nature, origin and impact so the incident doesn't recur
Response is handled by auditors; forensics by the help desk
Q8: Which evidence does Module 7 say demonstrates SOX controls over financial systems?
Marketing consent records
Data deletion logs for the right to be forgotten
Customer satisfaction surveys
Session recordings, command logs and access review reports
Q9: If the 'number of orphaned accounts' KPI starts rising again, what does Module 7 say this indicates?
The SIEM needs more storage
Discovery is decaying
MFA has been switched off
Too many audits are being run
Q10: What culture should the post-incident review reflect, according to Module 7's best practice?
Identifying the individual at fault
Keeping lessons confidential to the security team only
Lessons learned, not blame assigned
Closing the incident as quickly as possible without review
Requirements
Completion of Module 6 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral