Week 17 · lesson
Lesson 4: Mixed Incident Lab
Core path: 42 minutes
Five stations. No domain labels. No trick wording.
Your job is to determine the strongest failure boundary from the evidence, choose the next justified action, and produce a complete support record.
Station 1: hardware/platform fault
User report:
The desktop powers on but never gets to Windows.
Supplied evidence:
- fans and system power present;
- monitor and cable verified on another computer;
- firmware never reaches normal POST completion;
- board diagnostic indicator points to memory;
- one DIMM was installed immediately before the failure;
- no OS change occurred.
Required work:
- identify the last proven-good boundary;
- explain why Windows repair is not first;
- choose the smallest safe hardware check;
- state the service/safety boundary;
- define success verification.
Station 2: network/service fault
User report:
The internet works, but the class portal will not open by name.
Supplied evidence:
interface: connected
IP configuration: valid
gateway reachability: success
remote test IP: reachable
DNS lookup for portal hostname: fails
other locally cached app content: available
Required work:
- separate internet path from name-resolution failure;
- choose the next DNS-related evidence;
- reject at least one irrelevant physical-network tool;
- define recovery verification using hostname access.
Station 3: OS/software fault
User report:
My laptop crashes whenever I open the graphics application.
Supplied evidence:
- Windows boots and remains stable otherwise;
- other applications run normally;
- problem began after an application plugin update;
- application log identifies plugin load failure;
- previous approved plugin version/configuration is available.
Required work:
- establish application scope;
- reject whole-OS reinstall as premature;
- build the controlled rollback;
- verify both application startup and the required plugin feature.
Station 4: security/privacy fault
User report:
I keep getting sign-in approval prompts. Can you just turn MFA off?
Supplied evidence:
- user is not actively signing in;
- multiple unexpected approval prompts occurred;
- user did not approve them;
- endpoint protection is enabled;
- no supplied evidence proves device malware;
- organization has an account-security escalation process.
Required work:
- identify what is observed and what is not proven;
- preserve the authentication control;
- choose the safe account-security response/escalation path;
- explain the answer to the user without blame.
Station 5: operations/change/recovery fault
User report:
The update fixed the problem, but now we need to go back.
Supplied evidence:
- approved change ticket exists;
- update solved the original issue;
- a second business-critical application is now incompatible;
- rollback package/configuration is documented and available;
- verified backup was completed before change;
- maintenance window is still open.
Required work:
- identify the change-management decision;
- execute the supplied rollback plan conceptually;
- verify both the original system state and business-critical application;
- document outcome and follow-up/escalation.
Support record template
For every station submit:
user complaint:
observed symptom:
scope:
last known change:
safety/privacy/authorization boundary:
last proven-good layer:
first failed or unproven layer:
strongest theory:
rejected alternative:
best evidence/tool:
controlled action:
rollback/recovery:
verification:
customer-facing explanation:
documentation/escalation:
Peer review
Exchange one completed station with a partner.
The reviewer must answer:
- Does the evidence actually support the theory?
- Is the proposed action smaller than a wipe/reset/reinstall when a narrower fix exists?
- Is rollback/recovery realistic?
- Does verification test the required function?
- Did the technician respect safety, privacy, and authorization?
Success criteria
You pass when all five incident records are internally consistent and a reviewer can follow the reasoning without needing the domain label.
Read it. Prove it.