Simulated workplaceCAQA Nova Digital Systems is a fictional business created by CAQA for training and assessment. It is not a real company and no person, client or record here is real.About this simulation
ICTCAQA NovaSimulated workplace
Simulated workplace
Scenario · Cyber Security Operations

Triage and contain two live security incidents

You are a security analyst.

Intermediate3 to 4 hours8 tasks
Home/Scenarios/Triage and contain two live security incidents
The situation

What has happened

Two incidents are open in the Security and Safety Incident Register. At Merriwa Medical Centre the practice manager received an email impersonating a pathology supplier asking for updated bank details, which she did not click. At Harbourline Accountants a partner's mailbox was signed into from overseas at 3:10 am and an inbox rule was created forwarding mail to an external address; the account has been contained but the exposure has not been assessed. Yasmin Haddad wants both worked through the Cyber Security Incident Response Procedure today, with evidence preserved, wider exposure checked, plain language client notifications drafted and an assessment of whether personal information was accessed at Harbourline.

Your brief. Confirm and classify both incidents, preserve evidence, complete or verify containment, check for wider exposure across the client, update the register, and prepare client notifications and a privacy assessment for the Business Services Manager.
Read the work request in your inbox
Tasks

Deliverables

  • Updated register entries with timelines and indicators
  • Emergency change record
  • Privacy breach assessment for the Business Services Manager
  • Two client notifications
  • Wider exposure check results
For trainers and assessors

Units of competency

Current on training.gov.au for the Information and Communications Technology as at 10 September 2026.

ICTCYS402Identify and confirm cyber security incidents
ICTCYS406Respond to cyber security incidents
ICTSAS440Monitor and administer security of ICT systems
ICTICT424Address cyber security requirements

Qualifications

ICT40120Certificate IV in Information Technology
ICT50220Diploma of Information Technology
Assessor notes

What to look for

Evidence guide

The student must show they preserved evidence before acting, followed the severity and timeframe rules, and checked for wider exposure rather than treating each incident as isolated. The privacy assessment must consider the type and volume of information and the likelihood of serious harm. Client notifications must be accurate, plain and free of blame.

The student's evidence summary lists every record they created or changed in the systems named above, their notes and the tasks they ticked. Verify it against the deliverables and your own assessment tool.