Week 15 · lesson

Lesson 4: PC Security Troubleshooting Lab

Core path: 42 minutes

PC security symptoms overlap with ordinary Windows, browser, network, and application failures.

Your job is to recognize the security possibility without skipping evidence.

All evidence in this lab is fictional or supplied.

Station A: unable to access the network

Evidence:

  • physical link is up;
  • valid IP configuration exists;
  • other devices work;
  • local security software recently changed network rules.

Investigate firewall/security configuration before replacing the NIC. Also keep ordinary gateway/DNS causes available until ruled out.

Station B: desktop alerts

Evidence:

  • repeated security-style alerts appear on the desktop;
  • source application is unfamiliar;
  • Windows Security does not report the same alert.

Determine which process/application generated the notification before trusting its message.

Station C: false antivirus alert

Evidence:

  • browser pop-up claims antivirus expired and demands immediate payment;
  • installed approved endpoint protection reports healthy/current state.

Do not click, call, or purchase through the pop-up. Close/report it and inspect browser notification/extension state.

Station D: altered system or personal files

Evidence:

  • file names/content changed unexpectedly;
  • user did not make the changes;
  • timeline overlaps an unknown application install.

Preserve affected-file evidence and escalate/scan under policy. Do not overwrite the files while investigating.

Station E: missing or renamed files

Possible causes include:

  • user move/rename;
  • sync behavior;
  • application action;
  • storage corruption;
  • malicious activity.

Check file history/sync/recycle/recovery evidence before declaring ransomware.

Station F: inability to access files

Separate:

file missing
vs
permission denied
vs
file encrypted/corrupted
vs
storage unavailable

Use the error and surrounding evidence to choose the next boundary.

Station G: unwanted OS notifications

Identify the notification source:

  • Windows component;
  • installed application;
  • browser/site notification;
  • security product;
  • potentially unwanted software.

Disable/remove the responsible source only after verifying what it is.

Station H: OS update failures

A failed Windows update can result from:

  • storage capacity;
  • network/service problems;
  • corrupted update state;
  • policy;
  • security software conflict;
  • malware/security interference.

Security is one hypothesis, not the default answer.

Station I: random/frequent pop-ups

Inspect:

  • site notification permission;
  • extension/plugin state;
  • browser startup/home/search configuration;
  • installed adware/PUP indicators.

Station J: certificate warnings

Check:

  • device date/time;
  • exact destination hostname;
  • trusted network/proxy path;
  • certificate validity;
  • whether redirection occurred.

Do not bypass a certificate warning to finish the lab.

Station K: browser redirection

Evidence can point toward:

  • unwanted extension;
  • changed search/home settings;
  • proxy/DNS configuration;
  • malicious/PUP behavior.

Compare another browser/profile and direct known destination to narrow scope.

Station L: degraded browser performance

Measure:

  • number/behavior of extensions;
  • CPU/memory use;
  • cache/profile size;
  • network/service performance;
  • security scanning or malicious activity.

Slow browsing is not proof of infection.

Lab record

Complete at least eight stations, including four browser/security cases:

symptom:
security concern plausible:
ordinary alternative:
first evidence source:
containment needed? why:
controlled correction:
verification:
escalation/documentation:

Success criteria

You pass when your diagnosis stays narrower than the symptom and your response protects data/evidence instead of destroying it.

Read it. Prove it.

Lesson knowledge checks

Answer from the lesson you just completed. Results stay in this browser and are not submitted.
Knowledge check 1

A browser shows constant fake antivirus alerts, but the installed endpoint protection reports no infection. What should the technician do?

Knowledge check 2

Files are unexpectedly renamed and inaccessible. Why should the technician preserve evidence before bulk changes?