Skip to content

Latest commit

 

History

History
31 lines (20 loc) · 1.28 KB

File metadata and controls

31 lines (20 loc) · 1.28 KB

Activity 4: Account and Device Hardening

Alignment: LO2 / A2 Objective: Apply layered safeguards that reduce credential, session and malware-enabled fraud.

Safety and scope

Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.

Procedure

  1. Inventory two high-value accounts and the recovery channels attached to them.
  2. Replace any reused password with unique password-manager-generated credentials.
  3. Enable a phishing-resistant sign-in method or app-based MFA where available.
  4. Review active sessions, trusted devices, forwarding rules and recovery details.
  5. Enable automatic updates and verify the operating system security patch level.
  6. Disable installation from unknown sources and remove unneeded remote-access tools.
  7. Configure transaction notifications and a low-risk transfer limit for the exercise account.
  8. Record before-and-after settings without exposing secrets or recovery codes.

Evidence to submit

Hardening checklist with redacted screenshots and residual risks.

Acceptance check

Credentials and recovery codes are absent; each control names the attack path it interrupts.

Reflection

Which observable fact most changed your decision, and which uncertainty remains?