READY
Skip to main content
READY
READYScoreCareer PathsFree TrainingLeaderboardsCommunityPricing
Sign inExplore Free Training
Explore Free Training
READYScoreCareer PathsFree TrainingLeaderboardsCommunityPricingSign inExplore Free Training
Free Training/Google Cybersecurity/Practice exercise

FREE PUBLIC PRACTICE · NO SIGN-IN REQUIRED

Alert prioritization: defend your next investigation

Rank three fictional security alerts using evidence, business impact, uncertainty, and authorized next steps rather than severity labels alone.

Original READY self-study material. Your work stays in your own document; this page does not save, grade, award credit or change READYScore.

Start the exerciseBack to Google Cybersecurity

What you will practise

  • Separate observed facts from unverified interpretations.
  • Justify an investigation order using impact and confidence.
  • Revise a decision when new evidence arrives.
In the exercise, alert B has a medium severity label but records privileged payroll access and export, so it needs investigation before high-label failed test-service logins or a reported lab port. If B is approved activity and A gains evidence of successful credentials and production trust, reassess A first.
Prioritize with evidence

An alert label is a starting point

Three alerts arrive while one analyst is available. A severity label helps route attention, but it cannot replace context. This original tabletop exercise asks which alert to investigate first, which fact to verify next, and what evidence would change your decision. There is no universal score or official response-time requirement hidden in the exercise. Use the fictional facts supplied, and state your assumptions.

NIST SP 800-61 Revision 3 places incident response within broader cybersecurity risk management. NIST IR 8286D connects business impact analysis with risk prioritization. Together these are useful background for asking what might be harmed and why it matters. The specific queue, choices, and timeboxes below are READY teaching examples, not a NIST-mandated ranking formula.

Read the fictional queue

Alert A is labeled high severity: 400 failed logins against a retired test service. The current record says the service contains synthetic data and has no production trust relationship; successful-login telemetry is delayed by ten minutes. Alert B is labeled medium severity: a privileged payroll account successfully authenticated from a new device, followed by a bulk export event. The payroll owner has not confirmed whether this was expected. Alert C is labeled high severity: a scanner reports an exposed administrative port on a training VM, but the firewall record says only the approved lab subnet can reach it.

These facts do not establish that any alert is harmless or that data theft occurred. Failed logins are observed; account compromise is an interpretation. A bulk export is observed; unauthorized disclosure remains unconfirmed. Record the timestamp and source behind each observation before allowing a persuasive label or an AI summary to become a conclusion.

Reprioritize when the facts change

New evidence now confirms B was an approved payroll export performed by its owner. At the same time, A has a successful login using a service credential, and the inventory reveals a production trust relationship omitted from the earlier record. Rewrite your queue. Explain which previous assumption failed and which new evidence changes the possible impact. Keep the earlier decision record rather than rewriting it as if you knew the new facts all along.

A later analyst should be able to follow your reasoning without seeing sensitive raw logs in a public document. Use the supplied fictional IDs, avoid real credentials or personal data, and state what remains unknown. More alarming language does not make the analysis better; a precise limitation is useful operational information.

Your exercise and self-review

Download the worksheet. For every alert, enter the observed fact, plausible harm, uncertainty, next authorized evidence check, acting owner role, and the condition for changing priority. Write a short handoff that distinguishes investigation from containment. Then correct this AI advice: “Always work the highest vendor severity first and close alerts from test systems.”

A strong response prioritizes B initially with a conditional rationale, keeps A and C under review, and revises the order after the changed evidence. Other defensible orders must state a concrete assumption supported by the case. This practice is not a certification test and does not change READYScore or course completion.

Worked decision with explicit uncertainty

A reasonable first investigation is B because successful privileged activity and a payroll export create a plausible high-impact scenario. The analyst should verify account-owner context and inspect the authorized audit evidence using the existing incident procedure. This is an investigation priority, not permission to disable an account or assert a breach. Preserve the relevant identifiers and route any containment decision to the authorized responder.

A remains open while delayed success telemetry is checked. C needs a reachability/configuration check rather than dismissal based only on the firewall description. Assign a next evidence request and review condition to each item. The explanation is stronger than simply sorting high above medium because it connects observed activity, potential consequence, missing information, and reversible next work.

Put it into practice

Complete the exercise

  1. Download the worksheet. For every alert, enter the observed fact, plausible harm, uncertainty, next authorized evidence check, acting owner role, and the condition for changing priority. Write a short handoff that distinguishes investigation from containment. Then correct this AI advice: “Always work the highest vendor severity first and close alerts from test systems.”
Alert ID:
Observed fact/source/time:
Potential harm:
Uncertainty:
Next authorized check:
Owner role:
Priority-change condition:

Download the practice files

  • alert-prioritization-worksheet.txt

Review your reasoning

Try the exercise first, then open these self-review hints. They are guidance, not an assessment result.

Did you separate facts, interpretations, and authorized next actions?

Explain what new evidence would reverse your initial order.

Independent learning, clear boundaries

Original independent READY learning. Not official Google or Coursera training or endorsed by either provider. All scenario data are fictional. This resource does not award a Google Professional Certificate, READY certification, course credit or READYScore. Written practice is self-reviewed, not automatically graded; this public page has no account save, submission or reward function.

These exercises use fictional examples. They do not replace production authorization, provider credentials, professional advice or certification requirements.

Official references

  • NIST SP 800-61 Revision 3, April 2025

    Current incident-response risk-management framing; supersedes Revision 2.

  • NIST IR 8286D update 1: Business Impact Analysis

    Business impact informs risk prioritization; no numeric scoring formula is attributed.

Explore Google CybersecurityExplore Free Training
READY
ExploreREADYScorePathwaysFree TrainingLeaderboardsCommunity
CompanyHow READY WorksPricingAbout READYInsights
SupportSign inHelpPrivacyTerms

READY Identity, LLC · 3769 Summerton St, Mount Pleasant, SC 29466