Foundry Academy · Cybersecurity Fundamentals · Lesson 2 of 6

Passwords, MFA, and account recovery

Apply organization-approved authentication, recovery, access, and offboarding controls to high-value accounts and eliminate insecure credential handling.

Start the lesson

Your learning work, on this device

No signup, cloud storage, cross-device sync or verified completion. Saving is optional. This browser profile is shared with anyone who can use it; private mode, browser cleanup or storage limits may remove work. Use only fictional or non-sensitive material. Export a copy before relying on this device.

Not saved. Worksheets, answers and practice notes currently last only in this tab.

Practice markers are self-reported, never credentials.

01 · Explanation

Passwords, MFA, and account recovery

Objective: Apply organization-approved authentication, recovery, access, and offboarding controls to high-value accounts and eliminate insecure credential handling.

Start with the accounts that can change money, identity, email, domains, cloud configuration, customer data, payroll, source code, or other access. Use unique passwords generated and stored in an organization-approved password manager, and enable the strongest practical multi-factor method approved for the service. Phishing-resistant methods such as hardware-backed authenticators or passkeys can provide stronger protection than codes that users may be tricked into relaying. Never share passwords or one-time codes by email, chat, phone, or document. Service and shared accounts require named ownership, scoped permissions, monitored use, and a controlled alternative to informal shared credentials.

Recovery is part of authentication. Inventory recovery email, phone, backup codes, administrators, vendor support routes, and proof required for high-value services. Protect recovery channels at least as carefully as the account they restore. Test the documented process without locking out production work, and store emergency material securely with limited, auditable access. Joiner, role-change, and leaver workflows should grant, review, and revoke access promptly. Review privileged access and inactive accounts on a schedule. Exact authentication requirements depend on risk, service capabilities, and applicable obligations; security and identity specialists should approve high-assurance or regulated implementations.

Before you begin

  • Confirm F03-F09; record that the identity provider, affected account list, approved incident playbook, clean administrative workstation, session/token inventory, forensic direction, and containment results are not supplied.
  • STOP. If the identity provider, affected accounts, approved playbook, trusted workstation, session/token inventory, or forensic direction is missing or conflicts across F03–F09, route containment to authorized security leadership and the incident coordinator; do not claim approval or execute credential, session, mailbox, privilege, or device changes.

Original overview module anchor →

02 · Compare the artifacts

Supported work. Visible uncertainty.

This fictional, sanitized defensive-security case contains no real credentials, account numbers, personal data, or exploitable instructions. It is not legal, forensic, insurance, or cybersecurity assurance.

SilverPine payment-change incident

SilverPine Fabrication is a fictional 38-person manufacturer. At 9:12 a.m., accounts payable received an email inside an existing supplier thread requesting that the next $84,600 payment move to a new bank. The message used the supplier controller's display name and included an attached letter, but the phone number on the letter differs from the approved supplier record. At 9:26, an employee opened the attachment and entered a cloud password on a page that later disappeared. At 9:31, a push-notification approval arrived; the employee denied it and called the office manager. The manager told the employee to change the password from the same laptop but did not contact the incident lead. Email logs available to the internal administrator show a new forwarding rule created at 9:29 and a login from an unfamiliar region. The laptop reports that endpoint protection last checked in 11 days ago. The supplier master record can be changed by three accounts; one belongs to a former contractor and has no recorded multi-factor authentication. Backups run nightly to a connected network share. The dashboard is green, but the last documented restoration test occurred 14 months ago and recovered only one folder. The company's incident sheet lists names but no after-hours method, severity criteria, evidence-preservation steps, payment-hold authority, or customer and regulatory decision process. No payment has been released. Learners must map assets and responsibility, protect authentication and recovery, verify communication independently, manage device and software actions, assess data, vendor, and backup controls, and construct an authorized incident response. They must not investigate outside authorization, contact an attacker, destroy evidence, or declare breach scope and legal notification obligations without qualified review.

Supported example — reference only

Check ID
ID-01
Control or check
Review and contain the affected cloud identity through the approved incident process.
Evidence required
Identity-provider audit/session evidence plus qualified incident-owner direction.
Source input ID
F03, F04, F05, F06
Owner
Security/identity incident owner
Result
Pending - no containment action or result is supplied.
Exception or gap
Same possibly affected laptop was proposed for password change; approved clean administrative path is not supplied.
Status
Blocked - qualified direction required

A well-handled evidence gap

Check ID
ID-PRIV-02
Control or check
Review and disable or otherwise resolve obsolete privileged access only under approved authority.
Evidence required
Authoritative account ownership, HR/contractor status, access log, MFA record, and change evidence.
Source input ID
F08, F09
Owner
Identity and access owner with HR/contract owner as applicable
Result
Pending
Exception or gap
One privileged account belongs to a former contractor and lacks recorded MFA; no approved action record is supplied.
Status
Urgent review pending

Flawed approach — do not copy

Marking this identity-containment checklist “approved and complete” without the required evidence or reviewer is a flawed submission. Stop ad-hoc password, mailbox, privilege, or endpoint changes from a possibly affected device or without evidence-preservation and authority.

Repair: Rework the identity-containment checklist as an evidence-backed draft, not an approved result. Open an incident-scoped checklist without changing live systems in the exercise. Record credential entry, denied push, forwarding rule, unfamiliar login, same-laptop password advice, stale endpoint check-in, banking-change access, and former-contractor privilege. Order evidence preservation and qualified triage before destructive actions. Check the revision against this requirement: Evidence preservation, session/token, credential, MFA, mailbox, privilege, endpoint, and communication checks are ordered. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.

Full case record, ambiguities and all assignments →

03 · Bounded practice

Build the identity-containment checklist.

Draft authorized account-protection and recovery steps that require a known-clean channel and administrator; do not execute containment from the training packet.

Deliverable: An identity-containment checklist and access-review record template with every action, owner, authorization, time, and result field pending.

Complete a bounded starter and gap analysis using only CB01, F03, F04, F05, F06, F07, F08, F09, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.

Exact supplied inputs for this assignment
  • M02-I01 · F03 — An employee entered a cloud password after opening the attachment.
  • M02-I02 · F04 — The employee denied an unexpected push notification and reported to the office manager.
  • M02-I03 · F05 — A new forwarding rule and unfamiliar-region login appear in administrative logs.
  • M02-I04 · F06 — The manager advised a password change from the same possibly affected laptop.
  • M02-I05 · F07 — Endpoint protection on the laptop last checked in eleven days ago.
  • M02-I06 · F08 — Three accounts can change supplier banking details.
  • M02-I07 · F09 — One privileged account belongs to a former contractor and lacks recorded multi-factor authentication.
  • M02-B01 · CB01 — Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment.
  • M02-S01 · F03, F04, F05, F06, F07, F08, F09 — Build a starter version of “An identity-containment checklist and access-review record template with every action, owner, authorization, time, and result field pending.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it.

Operating procedure

  1. Open an incident-scoped checklist without changing live systems in the exercise.
  2. Record credential entry, denied push, forwarding rule, unfamiliar login, same-laptop password advice, stale endpoint check-in, banking-change access, and former-contractor privilege.
  3. Order evidence preservation and qualified triage before destructive actions.
  4. Design identity actions for session/token revocation, credential reset from an approved clean path, MFA review, mailbox-rule review, and privileged-access review.
  5. Add endpoint isolation/collection dependencies and out-of-band communication.
  6. For every check, name required evidence, authorized owner, result as pending, and exception path.
  7. Final-QC sequence, source citations, account scope, evidence preservation, owner authority, and no execution claims.
Field-by-field guidance
Check ID
Use a stable identifier for the quality or control check. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Control or check
State one observable check in verb-first form. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Evidence required
Name the record or observation needed to pass the check. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Source input ID
Cite the exact Fxx or module input ID supporting the entry. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Owner
Name the authorized operating or specialist role. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Result
Record pending unless the packet explicitly supplies an observed result. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Exception or gap
Describe the missing or conflicting evidence and its consequence. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Status
Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the checklist to coordinate identity containment while avoiding unsafe same-device changes and preserving evidence.
Identity-containment checklist · learning draft
Check IDControl or checkEvidence requiredSource input IDOwnerResultException or gapStatus

Start with 6 rows; the complete workbook specifies 13 stable rows for this artifact. Add rows here or use the full download. No action is saved until you explicitly choose saving above.

Download complete six-module workbook (.md) · Structured case packet (.json)

Keep private client data, unpublished inventions, personal identifiers and credentials out of these public learning tools.

Module 2 · 2-item formative check

Passwords, MFA, and account recovery

Choose an answer and request feedback. Read why each option does or does not fit the evidence. Answers stay in this tab unless you choose device-only saving; they are never submitted.

Question 1 of 2 · MODULE 2 · knowledgeA caller requests a one-time MFA code for an urgent account repair. What should the employee do?
Question 2 of 2 · MODULE 2 · scenarioF03 confirms entered credentials, F05 confirms a forwarding rule and unfamiliar login, F06 confirms advice to change the password from the possibly affected laptop, F07 confirms stale endpoint status, and F09 confirms former-contractor privileged access without recorded MFA. Which proposed sequence is responsible?

Answer either question to review its reasoning.

Inspect the artifact, not just your quiz answers

  • Evidence preservation, session/token, credential, MFA, mailbox, privilege, endpoint, and communication checks are ordered.
  • F04-F09 all shape the checklist.
  • Every result stays pending unless directly supplied.

Stop: Stop ad-hoc password, mailbox, privilege, or endpoint changes from a possibly affected device or without evidence-preservation and authority.

Go: Proceed only under the approved incident process using a trusted administrative path and traceable evidence.

Escalate: Escalate suspected account compromise, privileged stale access, payment-system access, and unavailable clean administration to security leadership.

04 · Evidence to keep

Leave with usable work.

Submit account owners, roles, MFA methods, recovery channels, review frequency, offboarding actions, and unresolved high-risk gaps without including real credentials.

Download your artifact CSV and, if wanted, export the learning-work JSON above. Neither export is a reviewed submission or certificate. Device-only saving is optional; you must press Save my work now after edits.

When all six artifacts are ready, compare the full packet against the track rubric. Qualified human review is still required before real-world decisions.

Computer user working at a secured workstation during a cybersecurity exercise.
Learn the standard. Practice the work.
Technology professional reviewing account and device security controls.
Leave with evidence you can inspect.

Sources, scope and review boundaries

Curriculum 2026.10.08-learning-paths-1. External source dates below are record checks, not continuing guarantees. Verify current requirements before consequential use.

nist-csf-2-publication · Official guidance

The NIST Cybersecurity Framework (CSF) 2.0

Primary NIST framework for governing, identifying, protecting, detecting, responding to, and recovering from cybersecurity risk.

Open reviewed external source ↗

cisa-cross-sector-cpgs · Official guidance

CISA Cross-Sector Cybersecurity Performance Goals

CISA's prioritized voluntary baseline practices, designed to help organizations focus on high-impact risk reduction.

Open reviewed external source ↗

ws-cybersecurity-operating-standard · Academy internal operating standard

Wealth Synergy cybersecurity internal operating standard

Academy-selected asset, access, verification, device, backup, incident, and restoration controls; it does not authorize security testing. This is an internal operating standard selected by Foundry Academy; it is not law, accreditation, licensure, or an external-standard requirement.

Version 1.0 · reviewed 2026-09-01 · owner: Foundry Academy curriculum owner

A future Wealth Synergy private professional-development certificate would be issued only after its assessment, capstone, identity, reviewer, retention, access, deletion, appeal, and issuance controls pass quality review. No credential is currently issued. Any future certificate would not be an accredited academic qualification, professional license, or government certification.