Cybersecurity Academy

Lesson 7 of 7

Become a Cyber Defender

Synthesise your cybersecurity skills: incident response, ethical hacking, threat hunting, and defensive careers.

🔴 Advanced 110 XP

Learn it

Congratulations on reaching the final mission! You now know how passwords protect data, how to spot phishing, how malware behaves, and how encryption keeps secrets safe.

Cyber defenders (also known as Blue Teams) are the digital protectors of hospitals, schools, companies, and governments. They constantly monitor networks to stop bad actors in their tracks.

Ethical hackers (or White Hat hackers) use their computer skills for good. They find security weaknesses before criminals can exploit them, helping fix bugs and making the digital world safer for everyone.

Key terms

Defence-in-Depth
A security strategy deploying multiple redundant defensive layers so that if one layer fails, others stop the attack.
SOC (Security Operations Centre)
A central command facility where cybersecurity teams monitor, detect, analyze, and respond to security incidents.
Indicator of Compromise (IoC)
Digital forensic evidence indicating that a system or network has suffered an unauthorised intrusion or malware infection.
Computer Misuse Act 1990
The foundational UK legislation making unauthorised access to computer systems and data illegal.

The Incident Response Lifecycle

Explore the standard NIST incident response phases followed by professional defenders during a cyber breach.

  1. 1Preparation: Equip the team with incident tools, policies, communication channels, and secure backup systems.
  2. 2Detection & Analysis: Detect unusual network alerts, examine logs, and determine whether a real security incident is underway.
  3. 3Containment: Isolate infected machines from the local network to stop the threat spreading to critical databases.
  4. 4Eradication & Recovery: Remove malware artifacts, patch exploited vulnerabilities, and restore clean systems from verified backups.
  5. 5Post-Incident Review: Hold a lessons-learned briefing to review what happened and strengthen future defences.

Automated Incident Log Analyser

pythonlog_entries = [
    {'ip': '192.168.1.5', 'status': 200, 'failed_attempts': 0},
    {'ip': '203.0.113.42', 'status': 401, 'failed_attempts': 15},
    {'ip': '192.168.1.12', 'status': 200, 'failed_attempts': 1}
]

THRESHOLD = 5
for log in log_entries:
    if log['failed_attempts'] >= THRESHOLD:
        print(f"INCIDENT ALERT: Potential brute-force attack detected from IP {log['ip']}!")
        print('Action: Automatically blacklisting IP and alerting SOC analyst.')

This Python script mimics a Security Information and Event Management (SIEM) rule by flagging IP addresses that exceed a failed login threshold and triggering an incident alert.

Try it

Match each cyber defence role with its main operational focus.

SOC Analyst
Penetration Tester
Incident Responder
Malware Analyst

Challenge

Develop an incident response checklist for a small company whose main customer database server was hit by ransomware.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/5 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.

Each clue costs 6 XP (never below 28 XP). You'd earn 55 XP right now.

Extension: Research what bug bounty programs are and explain how companies reward ethical hackers for discovering zero-day vulnerabilities.

Quiz time

Question 1 of 4Score 0

What is the primary principle behind 'Defence-in-Depth'?