Alignment: LO2 / A2 Objective: Apply layered safeguards that reduce credential, session and malware-enabled fraud.
Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.
- Inventory two high-value accounts and the recovery channels attached to them.
- Replace any reused password with unique password-manager-generated credentials.
- Enable a phishing-resistant sign-in method or app-based MFA where available.
- Review active sessions, trusted devices, forwarding rules and recovery details.
- Enable automatic updates and verify the operating system security patch level.
- Disable installation from unknown sources and remove unneeded remote-access tools.
- Configure transaction notifications and a low-risk transfer limit for the exercise account.
- Record before-and-after settings without exposing secrets or recovery codes.
Hardening checklist with redacted screenshots and residual risks.
Credentials and recovery codes are absent; each control names the attack path it interrupts.
Which observable fact most changed your decision, and which uncertainty remains?