Exercise 1: What Changed Ticket 1 From a Report Into a Compromise — Possible Solution ==================================================================== THE ORIGINAL SHAPE OF THE TICKET ------------------------------ Up until one specific detail, Ticket 1 was a straightforward phishing report - a user forwarding a suspicious email and asking whether it's legitimate. Per Chapter 2's own reporting guidance, this is exactly the kind of report a support desk wants to receive and can typically resolve by confirming the email is malicious and thanking the user for reporting it. THE SPECIFIC DETAIL THAT CHANGED IT ------------------------------ Per this chapter, "near the end of the message, the user adds: 'Actually, I did click it before I got suspicious, and I think I entered my password.'" This single detail means the phishing attempt didn't just arrive and get caught - it may have already succeeded, at least partially. The email is no longer only evidence of an attempted attack; it's a potential entry point into the account. WHY THIS SPECIFIC DETAIL IS WHAT TRIGGERS THE SHIFT ------------------------------ A report of an email alone carries no confirmed harm - it can be handled by simply confirming it's phishing and moving on. A credential having actually been entered introduces the possibility that the account is already compromised, which is qualitatively different: the question is no longer just "was this a phishing attempt?" but "has someone else already gained access?" WHICH PROCEDURE TAKES OVER ------------------------------ Per this chapter, once that detail surfaces, "what looked like a simple report-and-close ticket is now a suspected active compromise" - Chapter 7's capture-then-mitigate-then-escalate procedure takes over: documenting the phishing email and the click before doing anything else, then performing a safe reset per Chapter 5, then escalating rather than closing the ticket once the reset is done. WHY THIS WORKS AS AN ANSWER ------------------------------ It identifies the exact detail (a clicked link plus an entered password) that shifted the ticket's category, explains why that specific detail - rather than the phishing email alone - is what triggers the shift, and names Chapter 7 as the procedure that takes over from that point.