Hands-on labs aligned to CMMC Level 1 control families
The CRC Cyber Lab curriculum is organized by CMMC Level 1 control families. Students identify and remediate real security misconfigurations in a live Active Directory domain, a per-pod pfSense firewall, and file-based evidence artifacts.
All six families are live and seeded on all 20 pods. Students work them in this order:
AC → IA → SI → SC → MP → PE
Labs are:
New students should start with the Student Quick Start.
| # | Control Family | Labs | Status | Completion Guide | AWX Seed / Verify / Reset |
|---|---|---|---|---|---|
| 1 | Access Control (AC) | 12 | AC Guide | 12 / 13 / 14 | |
| 2 | Identification & Authentication (IA) | 12 | IA Guide | 15 / 16 / 17 | |
| 3 | System & Information Integrity (SI) | 12 | SI Guide | 18 / 19 / 20 | |
| 4 | System & Communications Protection (SC) | 12 | SC Guide | 21 / 22 / 23 | |
| 5 | Media Protection (MP) | 3 | MP Guide | 27 / 28 / 29 | |
| 6 | Physical Protection (PE) | 6 | PE Guide | 30 / 31 / 32 | |
| Total | 57 |
Status: Live — aligned to CMMC AC.L1-3.1.1 through AC.L1-3.1.22
| Module | Focus | Labs |
|---|---|---|
| M1: Account Management | Terminated users, unauthorized group access, privilege escalation | 3 |
| M2: Joiners, Movers, Leavers | New hire provisioning, role changes, offboarding | 3 |
| M3: Least Privilege | Group membership cleanup, delegation, separation of duties | 3 |
| M4: Audit & Accountability | Shared accounts, audit logging, group nesting | 3 |
Tools: Active Directory Users and Computers (ADUC)
All AC labs execute on the domain controller using ADUC exclusively — ideal for students new to Active Directory administration.
Status: Live — aligned to CMMC IA.L1-3.5.1 and IA.L1-3.5.2
| Module | Focus | Labs |
|---|---|---|
| M1: User Identification | Shared accounts, zombie accounts, generic accounts | 3 |
| M2: Non-Person Entity ID | Service accounts, rogue devices, account matrices | 3 |
| M3: Authentication Management | Password policies, credential resets, forced password changes | 3 |
| M4: Defaults & Process Auth | Default credentials, SNMP strings, hardcoded passwords | 3 |
Tools: ADUC, PowerShell, Task Scheduler, File Explorer
Instructor note: IA M3-L2 uses the Default Domain Password Policy, which is domain-wide in the shared
acs-p01.localdomain. The first pod to harden it satisfies M3-L2 for every pod, and re-seeding IA for one pod flips it back to FAIL for all. Converting this lab to a per-pod fine-grained password policy is a tracked backlog item.
Status: Live — aligned to CMMC SI.L1-3.14.1 through SI.L1-3.14.7
| Module | Focus | Labs |
|---|---|---|
| M1: Flaw Remediation | Patch management, vulnerability scanning, update deployment | 3 |
| M2: Malicious Code Protection | AV coverage, definition updates, exclusion review | 3 |
| M3: Security Alerts & Advisories | CISA advisory response, threat intelligence, alert triage | 3 |
| M4: System Monitoring | Defender configuration, endpoint audit, rogue process detection | 3 |
Tools: ADUC, PowerShell, Windows Defender, Event Viewer, File Explorer
Status: Live — aligned to CMMC SC.L1-3.13.1 and SC.L1-3.13.5
| Module | Focus | Labs |
|---|---|---|
| M1: Foundations of the Digital Perimeter | Trust boundaries, deny-by-default, monitor/control/protect | 3 |
| M2: External and Internal Boundaries | Boundary diagram, DMZ hardening, VLAN segmentation | 3 |
| M3: Firewall Rules | Rule audit, rule ordering, least-privilege access | 3 |
| M4: Monitoring and Validation | Firewall log investigation, compliance check, capstone | 3 |
Tools: per-pod pfSense web UI (pod gateway at 10.51.XX.1), plus worksheets on the DC
SC is the only family where students configure a network device rather than Active Directory. Each pod has its own pfSense gateway VM, so firewall changes are fully isolated per pod.
Status: Live — aligned to CMMC MP.L1-3.8.3
| Module | Focus | Labs |
|---|---|---|
| M1: Media Protection | Classify media, sanitize media for reuse, decide disposition | 3 |
Tools: File Explorer, Disk Management (mounted VHDX "removable media"), CSV worksheets
MP labs attach VHDX files as simulated removable media on the domain controller. Because drive-letter assignment is machine-global, MP seeding is always run as its own AWX job.
Status: Live — aligned to CMMC PE.L1-3.10.1 through PE.L1-3.10.5
| Module | Focus | Labs |
|---|---|---|
| M1: Physical Access Authorization | Physical access review, server room access decisions | 2 |
| M2: Visitor Escort & Temporary Badges | Unescorted visitor investigation, temporary badge lifecycle | 2 |
| M3: Audit Logs & Incident Response | Reconciling physical access logs, lost badge response | 2 |
Tools: CSV badge/visitor/access-log artifacts, ADUC for the associated accounts
Audit & Accountability (AU) and Configuration Management (CM) are candidate additions beyond CMMC Level 1. They are not built and not scheduled — nothing in the current environment references them.
Ansible playbooks configure each student pod with intentional misconfigurations. Every lab starts in a known FAIL state. All six families are seeded before class begins.
Students connect via Guacamole (browser-based RDP) and work the scenario with real enterprise tools. Each lab takes 15–30 minutes.
Verification runs automatically on a schedule (about every 30 minutes) — students see PASS/FAIL per objective on the Training Tracker. Instructors can also launch a verify job on demand.
When a family is fully passed, auto-advance marks it complete and unlocks the next family, and completion certificates are generated.
Use the reset templates (never the seed templates) to return a pod to its starting state. AC, IA, SI and SC seed jobs overwrite student work and must not be re-run once a class is in progress.
| Resource | Link |
|---|---|
| Student Quick Start | First-day instructions for students |
| Lab Guides | All six student completion guides |
| Training Tracker | Progress dashboard and API |
| AWX Automation | Seed, verify, reset, and auto-advance |
| Pod Infrastructure | Pod layout and per-pod networking |
TCecure CRC CyberLab — Building cybersecurity skills through hands-on practice