Week 13 · lesson

Lesson 4: Secure Endpoint Configuration Lab

Core path: 42 minutes

You are reviewing a fictional staff laptop, mobile device, and wireless-access requirement before deployment.

Nothing in this lab changes a real account, endpoint, or network.

Workstation baseline

Daily user: local administrator
Guest account: enabled
Screen lock: never
BIOS/UEFI password: not configured
AutoRun: enabled
Several unused services: enabled
BitLocker: disabled
Defender AV: enabled/current
Firewall: enabled
MFA: enabled for cloud identity

Mobile baseline

Ownership: corporate
Device encryption: enabled
Screen lock: simple swipe
OS/apps: updates pending
MDM profile: missing
Remote backup: disabled
Locator/remote wipe: unavailable until management enrollment
Failed-login restriction: not configured

Wireless requirement

Staff network: WPA3-capable infrastructure
Central user authentication required
Guest network: separated from staff resources
One legacy endpoint supports only old/weak wireless settings

Station A: account privilege

Permanent daily administrator access is broader than normal work requires.

Propose a standard-user baseline and an approved elevation/support process.

Station B: session protection

Add an appropriate screen-lock/timeout rule. Explain why a strong password does not protect an already unlocked session.

Station C: workstation hardening

Review:

  • BIOS/UEFI password need;
  • AutoRun;
  • unused services;
  • guest account;
  • failed-login lockout;
  • account expiration/login-time concepts where policy applies;
  • password-manager use;
  • encryption/recovery planning.

Do not enable BitLocker without defining recovery-key handling.

Station D: Windows protection

Verify:

  • Defender AV state/definitions;
  • firewall state;
  • whether a specific application needs a rule;
  • UAC/elevation behavior;
  • share/NTFS permission boundary for a supplied folder scenario.

Station E: mobile hardening

Create a target state covering:

  • strong screen lock;
  • encryption;
  • OS/application patching;
  • MDM/configuration profile;
  • content/endpoint protection where required;
  • remote backup;
  • locator/remote wipe;
  • failed-login restriction.

Station F: wireless authentication

Design the staff network using modern WPA2/WPA3 protection with AES-based security and centralized authentication where required.

Explain where RADIUS, Kerberos, MFA, or TACACS+ fit conceptually and where they do not substitute for wireless encryption.

Station G: legacy wireless device

The legacy endpoint cannot support the required modern security configuration.

Do not weaken the entire staff network for one old client. Document replacement, isolation, or an explicitly approved compatibility exception.

Station H: physical control

The laptop is used in a shared office and stored overnight.

Select two physical controls such as:

  • equipment lock;
  • controlled room/door access;
  • badge reader;
  • surveillance;
  • locked storage.

Explain the risk each addresses.

Lab deliverable

For every station record:

asset/risk:
current state:
selected control:
objective boundary:
tradeoff:
recovery/management dependency:
verification:

Success criteria

A passing design reduces unnecessary privilege/exposure without destroying usability, recoverability, or organizational management.

Read it. Prove it.

Lesson knowledge checks

Answer from the lesson you just completed. Results stay in this browser and are not submitted.
Knowledge check 1

A workstation is used for sensitive data. Which combination is strongest?

Knowledge check 2

Why should recovery information be considered when enabling disk encryption?