Week 15 · lesson

Lesson 5: Domain 3 Technician Practical

Core path: 42 minutes

No objective labels today.

You get a mixed help-desk queue. Decide whether the strongest boundary is Windows, mobile OS/application, mobile security, PC security, hardware, network, or policy.

Ticket A

Evidence:

  • Windows firmware detects the SSD;
  • boot process reports no operating system found;
  • storage was repartitioned yesterday.

Do not replace the drive until you distinguish boot/partition state from hardware detection.

Ticket B

Evidence:

  • Windows sign-in takes several minutes;
  • user has a roaming/domain profile;
  • network latency to identity/profile services is high;
  • local CPU/storage are normal.

The slow-profile path is stronger than a general hardware-performance claim.

Ticket C

Evidence:

  • phone has strong Wi-Fi association;
  • one application cannot update;
  • device storage is nearly full;
  • other applications use the network normally.

Stay at application/storage scope before resetting network settings.

Ticket D

Evidence:

  • mobile device shows unusually high data use and battery drain;
  • one recently installed app came from an unofficial source;
  • app has extensive permissions;
  • no proof yet shows what the traffic contains.

Treat this as a mobile-security concern, contain/manage according to policy, and preserve evidence.

Ticket E

Evidence:

  • PC browser shows repeated fake antivirus warnings;
  • approved endpoint protection reports healthy/current;
  • warnings originate from browser notifications.

Correct the browser notification/site/extension boundary and verify protection state. Do not purchase the advertised cleaner.

Ticket F

Evidence:

  • Windows service fails to start;
  • Event Viewer records a configuration/dependency error;
  • OS otherwise stable;
  • failure began after a configuration change.

Stay at service/configuration scope.

Ticket G

Evidence:

  • several USB devices work separately;
  • connecting all devices produces a controller resource warning;
  • devices have power;
  • moving one device to another controller group clears the warning.

The symptom is resource allocation, not a dead USB port.

Ticket H

Evidence:

  • mobile screen will not rotate;
  • rotation lock is enabled;
  • orientation sensor passes supplied test;
  • application supports rotation.

Correct the setting before replacing display hardware.

Ticket I

Evidence:

  • personal files are renamed and inaccessible;
  • ransom-style note appears;
  • network shares are mounted;
  • incident-response escalation is available.

Prioritize isolation, evidence/data preservation, and escalation. Do not reconnect shares or experiment with files.

Ticket J

Evidence:

  • Windows clock is wrong after every complete power loss;
  • automatic network time corrects it while running;
  • firmware clock also resets.

The evidence points toward firmware/RTC/CMOS-state investigation rather than a browser certificate problem, even though bad time could cause certificate symptoms later.

Practical requirements

Complete six tickets, including:

  • two Windows OS issues;
  • one mobile OS/application issue;
  • one mobile security issue;
  • one PC security issue;
  • one mixed-boundary ticket.

For each submit:

user-visible symptom:
objective category only after diagnosis:
last known change:
scope:
last proven-good boundary:
first failed/unproven boundary:
selected tool/evidence:
strongest theory:
alternative theory:
containment if required:
controlled correction or escalation:
rollback/data-recovery consideration:
verification:
remaining uncertainty:

Domain 3 defense

Choose one ticket and explain it in 90 seconds:

  1. What did the user report?
  2. What evidence survived?
  3. Which boundary failed first?
  4. What alternative did you reject?
  5. What was the least-destructive next action?
  6. How did you verify the result?

Week 15 completion checkpoint

You should now be able to troubleshoot the complete named symptom sets for:

  • Windows OS issues;
  • mobile OS/application issues;
  • mobile security issues;
  • PC security issues.

The course remains in repair mode until the Week 01–15 objective re-audit passes. Week 16 does not begin before that gate closes.

Read it. Prove it.

Lesson knowledge checks

Answer from the lesson you just completed. Results stay in this browser and are not submitted.
Knowledge check 1

What should come immediately after a controlled software troubleshooting correction?

Knowledge check 2

A symptom looks like malware, but resource monitoring proves storage is full and cleanup resolves the issue. What lesson does that demonstrate?