CASE FILE #0705-A TechAcademy SOC — Access Control & Security Fundamentals Audit
EVIDENCE LOGGED: 0/20
Briefing
Part 1 · Access Control Review
Part 2 · Controls & Crypto Review
Debrief Quiz
Case Report
◆ CONFIDENTIAL — TRAINEE ANALYST

Incident Briefing

A foundations review — no active incident, just first principles put to the test.

Before TechAcademy rolls out a new campus-wide access system, leadership wants a sanity check on the fundamentals: how access is granted and tracked, and whether the organization's existing security controls and cryptography choices actually hold up.

Your job has two parts:

  1. Part 1 — Access Control & AAA Review: Read each scenario describing how authentication and access decisions are made across campus systems. Identify the access control model or AAA concept in play — and whether it's being applied well.
  2. Part 2 — Controls & Cryptography Review: Read each scenario describing a security control or a cryptographic choice in use. Classify the control type, or the cryptographic concept, it represents.

Close the case with a debrief quiz connecting your findings to Security+ SY0-701 Domain 1.0 — General Security Concepts.

Investigator's rule: this case is about naming things correctly. The same underlying idea (say, "restrict access by role") can be applied well or applied carelessly — read for which one you're looking at before you classify it.
Before you start — sign the case log:
Your name and email are only used to send your result to your instructor when you finish the case.
Case ID: 0705-A
Scope: Access control, AAA, security controls, cryptography
Trigger: Pre-rollout fundamentals review
Evidence items: 10 (Part 1) + 10 (Part 2)
Objective mapping: 1.0 General Security Concepts

Part 1 — Access Control & AAA Review

Here's a quick reference on AAA, and the reviewer's raw notes below it. Click each note and classify it.

AUTHENTICATIONproving who you are
AUTHORIZATIONwhat you're allowed to do
ACCOUNTINGrecording what you did
📝 access-control-notes.txt

Part 2 — Security Controls & Cryptography Review

Here's a quick reference on control types, and the reviewer's raw notes below it. Click each note and classify it.

PREVENTIVEstops it before it happens
DETECTIVEidentifies it as/after it happens
CORRECTIVErestores things after impact
DETERRENTdiscourages the attempt
COMPENSATINGan alternative when the ideal control isn't possible
📝 controls-and-crypto-notes.txt

Debrief Quiz

Tie your findings back to Security+ SY0-701 Domain 1.0 concepts. Answer each, then check it.

◆ CASE CLOSED

Investigation Summary

0%

Findings and quiz breakdown will appear here.

Submitting your results to your instructor…