Course code: TGS-2024043420
Version: v9.0
Release date: 7 September 2026
- LO1 Identify potential cyber security risks and threats, including internet frauds and scams.
- LO2 Protect personal and business information from internet frauds and scams.
- LO3 Interpret and escalate cyber frauds and scams to relevant authorities.
Classify a suspicious contact using channel, claim, pressure, requested action and payment route.
- Open the supplied message pack and assign each item an evidence ID.
- Record the claimed sender, channel, callback details, URL and requested action.
- Mark authority, urgency, scarcity, fear, reward and secrecy pressure cues.
- Identify the asset at risk: credentials, money, device access, identity or business data.
- Trace the proposed payment or access route and note reversibility.
- Score likelihood and impact from 1 to 5 using the worksheet rubric.
- Choose block, verify, monitor or escalate and state the evidence for the choice.
- Peer-review one classification and revise unsupported assumptions.
Evidence: Completed signal matrix with risk score and decision rationale. Acceptance: Every decision cites at least two observable indicators; no decision relies only on spelling or grammar.
Inspect a simulated phishing message without opening its link or attachment.
- Work only from the supplied offline email sample and URL text file.
- Compare the display name with the From and Reply-To domains.
- Read Received hops from bottom to top and identify the first untrusted handoff.
- Check SPF, DKIM and DMARC results recorded in Authentication-Results.
- Decompose the URL into scheme, host, registrable domain, path and query.
- Flag punycode, look-alike characters, subdomain deception and redirect parameters.
- Write an independent verification route using a known bookmark or official directory.
- Capture the findings in the evidence template and assign a disposition.
Evidence: Annotated header and URL decomposition with disposition. Acceptance: The registrable domain and authentication result are stated correctly and no live suspect link is opened.
Break the scammer-controlled channel and verify a claim through trusted contact data.
- Select one impersonation scenario from the activity pack.
- List every contact path supplied by the sender and treat it as untrusted.
- Locate an official contact route from a saved statement, app, card or typed official domain.
- Draft a neutral verification script that reveals no OTP, password or account PIN.
- Verify the claimed event, transaction or officer identity through the official route.
- Record who was contacted, when, which reference was checked and the response.
- Decide whether to block, continue cautiously or escalate.
- Explain which trust boundary changed when you moved to the independent channel.
Evidence: Verification log and trust-boundary explanation. Acceptance: No sender-provided telephone number, link or QR code is used for verification.
Apply layered safeguards that reduce credential, session and malware-enabled fraud.
- Inventory two high-value accounts and the recovery channels attached to them.
- Replace any reused password with unique password-manager-generated credentials.
- Enable a phishing-resistant sign-in method or app-based MFA where available.
- Review active sessions, trusted devices, forwarding rules and recovery details.
- Enable automatic updates and verify the operating system security patch level.
- Disable installation from unknown sources and remove unneeded remote-access tools.
- Configure transaction notifications and a low-risk transfer limit for the exercise account.
- Record before-and-after settings without exposing secrets or recovery codes.
Evidence: Hardening checklist with redacted screenshots and residual risks. Acceptance: Credentials and recovery codes are absent; each control names the attack path it interrupts.
Use ScamShield resources to check and report a simulated suspicious message safely.
- Open the official ScamShield site by typing the known government URL.
- Review the current Check for Scams and reporting options.
- Prepare the supplied simulated message, number and URL for checking.
- Submit only the fictional training data supplied in the activity pack.
- Record the result, confidence language and any follow-up advice.
- Create a report using the simulated screenshot and redact unrelated personal data.
- Compare the result with your own signal triage from Activity 1.
- Document what ScamShield can support and what still requires independent judgment.
Evidence: ScamShield check record, redacted report example and limitations note. Acceptance: Only simulated data is submitted; the learner distinguishes a tool result from proof of legitimacy.
Design preventive and detective controls for a personal or small-business payment workflow.
- Map the payment workflow from request to approval, authentication and settlement.
- Identify where sender identity, account details and payment purpose are verified.
- Add an independent callback for changed beneficiary or urgent payment requests.
- Set a maker-checker rule and escalation threshold for high-risk transfers.
- Choose notification, transfer-limit and Money Lock controls appropriate to the scenario.
- Document exceptions and who may approve them.
- Run the supplied fraudulent-invoice scenario through the revised workflow.
- Record the blocked point, remaining exposure and recovery options.
Evidence: Payment control map, approval matrix and scenario test result. Acceptance: The design separates request, verification and approval, and names at least one preventive and one detective control.
Preserve useful evidence and start containment without destroying the incident timeline.
- Start an incident log with date, time, timezone and reporter.
- Preserve the original message, sender identifiers, URLs, screenshots and transaction references.
- Record actions already taken, including clicks, downloads, credentials entered and transfers.
- If compromise is suspected, isolate the affected device without factory-resetting it.
- Use a separate trusted device to contact the bank and protect accounts.
- Change exposed credentials in priority order and revoke active sessions.
- List affected people, systems, data and financial accounts.
- Package evidence with neutral filenames and a chain-of-custody note.
Evidence: Incident timeline, evidence register and initial containment record. Acceptance: The chronology is complete, evidence remains unaltered, and containment actions are distinguished from eradication.
Route a scam incident to the right internal and external parties using severity and evidence.
- Read the capstone scenario and assign an initial severity.
- Identify immediate life-safety, financial, identity, device and business impacts.
- Choose internal recipients: manager, security, finance, legal, data protection or communications.
- Choose external recipients: bank, platform, ScamShield, Police or relevant dispute channel.
- Prepare a concise escalation brief with verified facts, unknowns and requested action.
- Sequence notifications to contain loss while preserving investigation options.
- Update severity when the scenario inject introduces a second victim and public exposure.
- Complete the after-action review with control improvements and owners.
Evidence: Escalation matrix, incident brief, notification sequence and after-action actions. Acceptance: The brief separates facts from assumptions and includes timestamps, evidence references, impact and a clear request.