Working Through the Workbook 2 Assessment Defense Module
The Workbook 2 Defense Assessment section is part of the Sheep No More series that walks you through defending infrastructure in realistic scenarios. It's not a theoretical drill. The exercises assume you already know basic Linux command line, have some familiarity with network protocols, and can read logs without panicking. If you're starting from zero here, you're going to struggle and waste a lot of time. I spent about three weeks going through it properly. Not because it's difficult content, but because the interface quirks and a few ambiguous grading criteria slow you down if you don't know what to expect. The assessment portion specifically tests your ability to triage a compromised system, identify persistence mechanisms, and document your remediation steps in the format the workbook requires.
How to Approach the Sheep No More Workbook 2 Defense Assessment
Start by reading every scenario prompt twice. I made the mistake of rushing through the first scenario because it looked straightforward, missed that the question was asking about a second persistence vector, and got marked down for an incomplete answer. The workbook doesn't grade on partial credit the way most online platforms do. You either hit every required element or you don't get full marks for that section. The defense scenarios are scored against a rubric that's sometimes vague about edge cases. One thing that caught me off guard was how the grader handles timestamp discrepancies in log analysis questions. If your documented timeline is off by more than a few hours from the expected answer, it flags the whole section. This isn't a flaw in your understanding, it's just how the automated scoring works. I learned to include explicit timestamps in every log entry I reference, even when the question doesn't explicitly ask for them. That small habit kept me from losing points on things that were technically correct but formatted wrong. Here's the practical workflow I settled on:
Phase one — Recon. Before touching any tools, spend five to ten minutes mapping out what the scenario is actually asking. Note every deliverable mentioned. The prompt will list things like "identify the initial access vector," "list all persistence mechanisms," and "provide remediation steps." Write those down verbatim. Check them off as you go. Phase two — Evidence gathering. Run your standard triage toolkit. For the workbook environment, this usually means examining running processes, scheduled tasks, startup items, network connections, and recent file modifications. Use ps aux, crontab -l, checking /etc/rc.local, and lastlog. Don't skip the obvious stuff. I once spent forty minutes hunting for a rootkit when the actual persistence mechanism was a malformed systemd timer in /etc/systemd/system/. You'd be surprised how often the answer is in plain sight. Phase three — Documentation. This is where most people lose points. The workbook requires answers in a very specific format. Screenshots need to include the relevant command and its output. Text answers need to be concise but complete. Over-explaining doesn't help and can sometimes confuse the grader. Under-explaining gets you zero. Aim for one sentence per finding, then a separate sentence for your remediation action.
Get the Full Details

There are a few limitations you should be aware of. The automated scoring can be finicky about whitespace and formatting in text-based answers. If you copy-paste from a terminal window, make sure there are no extra line breaks. The environment sometimes resets between sessions, so save your notes externally rather than relying on the workbook's built-in text fields. I've had work disappear after a browser crash twice, and it took twenty minutes to reconstruct the answers from scratch both times. Another issue is that some of the later scenarios rely on knowledge from earlier modules. If you skipped around or didn't fully grasp the networking fundamentals from Workbook 1, the defense assessment will feel disproportionately hard. The scoring doesn't account for gaps in prerequisite knowledge. It just marks you wrong and moves on. If the workbook's approach doesn't fit your learning style, the hands-on labs at TryHackMe or HackTheBox offer similar defense-focused challenges with more detailed feedback on your methodology. They don't have the same structured curriculum, but the learning curve is gentler for beginners.
For the download link to the Sheep No More Workbook 2 Defense Assessment, head to the official Sheep No More website. The workbook is typically available as a PDF with accompanying lab environment instructions. Make sure you're getting it from the legitimate source, since third-party mirrors sometimes have outdated versions with broken lab configurations. The whole assessment section runs roughly four to six hours if you work through it methodically. Budget more if you're less comfortable with Linux or incident response procedures. The value is in the structured approach to defending a compromised system, not in memorizing commands. Once you understand the triage mindset the workbook builds, the specific tools matter less.