0 · Firewall & ACL Configuration

Configure ACL rules against a healthcare network scenario

Set ALLOW/DENY on six rules covering least privilege, encrypted management access, and threat-intel blocking.

1 · Log Analysis & Incident Triage

Flag the attack pattern in a SIEM log excerpt

Identify SQL injection attempts and trace the beaconing workstation back to Patient Zero.

2 · Network Architecture & DMZ Placement

Drag servers into DMZ vs. internal zones

Segment a web server, mail relay, DNS, database, mailbox, and file share correctly.

3 · Incident Response Sequencing

Order eight response actions on the NIST IR lifecycle

Drag-reorder Preparation through Post-Incident Activity into the right chronological order.

4 · IAM / MDM

Match protocols and device policies to scenarios

SAML vs. OAuth vs. RADIUS vs. Kerberos, plus full wipe vs. selective/container wipe.