Introduction
Workshop Overview
Dataparity Inc. is a fictional financial services firm assessing sensitive data across SaaS, endpoints, and AI tools. Alex explores existing findings and builds detection and enforcement policies, Kevin tests web, endpoint, and preconfigured browser controls, and Priya reviews existing incidents and response workflows. The company and personas connect these complementary exercises, not a single file or incident. Allow approximately four hours, including introductions, discussion, breaks, and setup.
Learning Path
Module Overview
Meet the Team
Dataparity's security admin. Alex reviews SaaS and endpoint findings in Module 1, then builds detection logic and web/endpoint policies in Labs 5–7. Browser policies in Lab 8 are preconfigured.
A busy employee testing convenient tools. Kevin tries a web upload, local file access and clipboard paste, then browser masking, sensitive-download blocking, and watermarking.
Dataparity's SOC analyst. Priya reviews a pre-populated incident queue, evidence, existing notifications and state changes, available actions, and workflow previews — without changing records.
Labs 6 and 7 reuse Dataparity_Q2_2025_Workforce_Financial_Summary.docx and the Lab 5 detection engine. Lab 8 uses supplied customer text, a sensitive sample PDF from DLP Test, and a browser-viewed document with preconfigured controls. Labs 3, 4, and 9 explore independent pre-populated records — not the student's file or incident.
Lab Tenants
Pre-populated with production-like data for read-only exploration. Sign in using CloudShare → Credentials → SDC Credentials for Modules 1 and 3. No configuration or incident-response actions are performed.
Use CloudShare → Credentials → Zscaler Tenant / Student Admin for Module 2. Build detection and web/endpoint policies in Labs 5–7; Lab 8 uses preconfigured browser controls and its separate extension login. Allow 15 minutes for Module 2 prerequisites, including VM/Client Connector setup and SSL inspection verification.