Set ALLOW/DENY on six rules covering least privilege, encrypted management access, and threat-intel blocking.
Identify SQL injection attempts and trace the beaconing workstation back to Patient Zero.
Segment a web server, mail relay, DNS, database, mailbox, and file share correctly.
Drag-reorder Preparation through Post-Incident Activity into the right chronological order.
SAML vs. OAuth vs. RADIUS vs. Kerberos, plus full wipe vs. selective/container wipe.