THE DEV BENCH
🎧

IT Help Desk — Tier 1 Support

Rung 1 of the Get Hired ladder: the highest volume of genuinely entry-level technical openings, the lowest bar of anything on this site, and properly remote. Track A is the knowledge the A+ examines. Track B is the job itself — triage, ticket writing, escalation, the call that is an attack, and the evidence pack you take to the interview. Track B is the half nobody teaches, and it is finished.

The job this is actually for

Being the one who fixes things for family and friendsIT help desk and tier-1 support

You are the first person anyone contacts when something at work stops working. A queue of tickets, a phone or a chat window, and a stream of problems that range from a forgotten password to a site outage. You resolve what you can, record all of it, and pass on what needs someone else. It is the trunk almost every infrastructure career on this site grows out of.

Search job boards for these titles

Help Desk Tier 1Remote Support TechnicianService Desk AnalystTechnical Support Specialist
Pay at entry
$48,154 average. Most roles $40,000 to $54,000, top decile $63,000. Remote-specific $25.03 an hour. That is about $18,000 a year more than fast-food work at $30,110.
What it costs to qualify
CompTIA A+, $530 for both exams. Public workforce funding may cover it, but the amount is set by your state and local workforce board rather than nationally — ask your local American Job Center whether the course is on your state's approved provider list. The study material itself is free.
Remote?
Remote-native. This is one of the few genuinely entry-level technical roles that is routinely advertised as fully remote.

Before you commit — the honest limit

🔴 There is no way to earn from this without being hired — nobody buys freelance tier-1 support, so unlike every other path here the job is the only route. ⚠️ And an entry-level posting is not an entry-level competition: 49% of applications from workers with ten or more years of experience went to entry-level roles, entry postings were down 7.5% year over year while senior rose 14.7%, and the hiring rate sat at 3.4%. This is still the highest-volume, lowest-bar door on the ladder. Expect the search to be slow anyway, and do not read that as a verdict on you.

See where this sits against every other entry path Pay and cert figures verified 2026-08-28
20 of 20 units built

All twenty units are written and every one has a drill attached. Track A links 62 specific videos from a free course, each with an instruction saying what to take from it and what to skip, and every duration is the video's real length rather than an estimate. Track B needs nothing installed and no account opened. Three decks, 119 cards, purpose-written for these units — and four units say honestly that their deck is only partial coverage rather than implying it is the unit. 🔴 What is still NOT here: no practice-exam pool and no hands-on lab. A deck is retrieval practice, not exam readiness, so do not read drilling as being ready to book. The A+ objectives are also broader than this path — A14 links the full indexes for the gaps we deliberately left, because this is ordered for the job and the exam is ordered for the exam.

Track A — What you need to know

Fourteen written units shaped by the CompTIA A+ objectives but ordered for the job rather than for the exam. It opens with what tier-1 work actually is — twenty-six minutes that will tell some people this is not for them, which is worth finding out before $530 of exam fees rather than after. The exam unit comes last, and tells you not to book it until you have done B6. Selected, not exhaustive: 62 videos of the 137 available, chosen for what reaches a help desk.

A1

What the job actually is, before you study for it

K ~26m

First, because almost nobody arriving here knows what a tier-1 support job involves, and several people will watch these three videos and decide it is not for them. That is a good outcome reached in twenty-six minutes rather than after $530 of exam fees. The work is a queue, a phone or chat window, and a stream of interruptions from people who are frustrated before you speak to them. It is not building or fixing computers for most of the day; it is identifying, recording, resolving or handing on.

After this you can

  • Describe what a tier-1 technician actually does across a shift
  • Explain what a ticket is for, beyond recording that something happened
  • Say what an SLA is and how it changes which work you do first
  • Decide whether you want this job, on evidence rather than on an idea of it

Do these in order

  1. 1 WatchTicketing Systems Professor Messer · ~14m

    Watch this one first, before any hardware content anywhere on this site. The ticket is the unit of work in this job and everything else is organised around it. Pay attention to the fields — category, severity, escalation — because those are the decisions you will be making dozens of times a day, and Track B is entirely about making them well.

  2. 2 WatchCommunication Professor Messer · ~7m

    Short, and more load-bearing than its length suggests. Notice how much of it is about setting expectations rather than about being pleasant. That distinction is the whole of B1's rubric.

  3. 3 WatchProfessionalism Professor Messer · ~5m

    Examined content, and it reads as obvious until you are tired at 16:50 on a Friday. Watch it now and again after B4, where you will meet a caller specifically engineered to make the professional response feel like the unkind one.

What to watch for

These three sit in Core 2, which almost every study plan puts second — so most people meet them after four hundred videos of hardware, if at all. They are here first deliberately. The single most common reason a new technician struggles is not that they do not know what RAM is; it is that nobody told them the job is a queue.

A2

How a computer is put together, and what each part failing looks like

K ~84m

The hardware half of Core 1, taught from the symptom backwards. Anyone can memorise that RAM is memory. The employable version is knowing what a failing stick of RAM does to a machine in front of a user, how that differs from a failing disk, and which of the two you can confirm without a screwdriver. Component knowledge is only useful here in the shape a caller presents it, which is why the two troubleshooting videos are the point of this unit and the component ones are the vocabulary for them.

After this you can

  • Name the likely failing component from a described symptom, and say what would confirm it
  • Distinguish a storage fault from a memory fault from a power fault by their symptoms
  • Explain why an intermittent fault is harder than a dead one, and what you do differently

Do these in order

  1. 1 WatchAn Overview of Memory Professor Messer · ~9m

    Vocabulary only at this stage. You need to recognise the terms when a tier-2 engineer uses them; you do not need to be able to specify memory for a build.

  2. 2 WatchStorage Devices Professor Messer · ~15m

    Focus on the mechanical-versus-solid-state distinction and what each sounds and behaves like when it is dying. That difference is the answer to the ticket you write in B2.

  3. 3 WatchComputer Power Professor Messer · ~16m

    Watch for the failure symptoms rather than the electrical theory. A failing power supply presents as random restarts and machines that will not wake, which users report as software problems every single time.

  4. 4 WatchTroubleshooting Hardware Professor Messer · ~26m

    The core of the unit. Watch it twice. On the second pass, write down the method being used underneath the specific examples — that method is what A10 is about, and this video demonstrates it without ever naming it.

  5. 5 WatchTroubleshooting Storage Devices Professor Messer · ~18m

    The other core one. Note every point at which the correct action is to stop and preserve data before continuing — those moments are the Risk content of A11 and they are where careers go wrong.

What to watch for

The trap is studying components as a catalogue. The exam will ask you to identify things, but the job asks you to explain a symptom, and the second skill does not follow automatically from the first. After each video, force yourself to answer one question: if this part were failing, what would the user say on the phone? They will never say 'my RAM is faulty'. They will say it has gone slow, or it keeps closing things, or it 'does the blue screen'.

A3

Networking, up to the point where you can say where it broke

K ~75m

🎯 Enough of the model to localise a fault, and deliberately no more. The single highest-value sentence a tier-1 can say is whether the problem is this machine, the local network, or the far end — because that sentence decides who fixes it, and getting it wrong sends a ticket to a team that will spend two hours proving it was never theirs. Addressing, DHCP and DNS are here because their failures are the ones that reach a help desk; routing protocols are not here because they are not.

After this you can

  • Read an IP configuration and say whether the machine got an address properly
  • Recognise a DHCP failure and a DNS failure by their distinct symptoms
  • State, for a reported fault, whether it is local to the machine, local to the site, or beyond it
  • Give the evidence for that statement rather than the impression

Do these in order

  1. 1 WatchIntroduction to IP Professor Messer · ~20m

    The foundation for the other four. If any of it does not land, come back to it rather than pressing on — the rest of this unit assumes it.

  2. 2 WatchAssigning IP Addresses Professor Messer · ~9m

    The one thing to take away and never forget: an address beginning 169.254 means the machine asked for an address and nothing answered. Recognising that on sight is worth more in a first week than any other single fact in this path.

  3. 3 WatchDHCP Professor Messer · ~11m

    Watch for what happens when a lease cannot be renewed, and what the user experiences at that moment — which is a machine that worked yesterday and does not today, with nothing changed.

  4. 4 WatchDNS Configuration Professor Messer · ~19m

    The highest-yield fifteen minutes in this unit for real support work. A DNS fault presents as 'the internet is down' while the connection is perfectly healthy, and being able to separate those two is a large part of why tier-1 exists.

  5. 5 WatchTroubleshooting Networks Professor Messer · ~16m

    Pulls the previous four into a method. Watch it after them, not before — it will feel like review, and that feeling is the unit working.

What to watch for

Two traps. The first is going deeper than this: subnetting arithmetic is examined but is not what a help desk does, and people lose weeks to it. The second is the phrase 'the internet is down', which is what users say for at least six unrelated faults. Never accept it as the problem statement — establish what specifically failed, on what device, and whether anything else on the same network is affected. That question alone resolves a surprising share of tickets before you have touched anything.

A4

Windows for the person who has to support it

K ~115m

The operating system you will support, aimed at the tasks a tier-1 actually performs rather than at a tour of the product. Profiles, settings, services, the tools that answer questions, and the command line — which is here because a remote session over a slow link is faster typed than clicked, and because the technician who can read a command output is the one tier 2 stops re-explaining things to.

After this you can

  • Find the setting, log or tool that answers a given question, without hunting
  • Read Task Manager well enough to say what a slow machine is waiting on
  • Run the network command-line tools and interpret what they return
  • Work through the standard Windows faults without a script

Do these in order

  1. 1 WatchAn Overview of Windows Professor Messer · ~10m

    Orientation. Skim if you already use Windows daily.

  2. 2 WatchWindows Settings Professor Messer · ~7m

    Know where things live. Most of a first month is knowing where to click, and there is no shortcut but familiarity.

  3. 3 WatchThe Windows Control Panel Professor Messer · ~24m

    Long, and worth it — a large amount of what you are asked to change still lives here rather than in Settings, and the exam tests it heavily.

  4. 4 WatchTask Manager Professor Messer · ~5m

    Five minutes, used every day. The specific skill: reading the disk column, not the CPU column, when a user says the machine is slow. That is the diagnosis behind the ticket in B2.

  5. 5 WatchWindows Command Line Tools Professor Messer · ~32m

    The longest video in this path. Do not try to memorise the list — work through it with a terminal open and run each one on your own machine as it appears. Reading about a command and running it are different activities and only one of them sticks.

  6. 6 WatchThe Windows Network Command Line Professor Messer · ~19m

    This is where A3 becomes usable. These are the commands that let you prove where a network fault is rather than assert it. Run every one of them while you watch.

  7. 7 WatchTroubleshooting Windows Professor Messer · ~18m

    Last in the unit. Notice how often the answer is to check something before changing anything — that ordering is the difference between a technician and someone rebooting hopefully.

What to watch for

Watching a command-line video without a terminal open feels productive and teaches almost nothing. Two hours of these videos with the commands typed alongside is worth considerably more than six hours of them watched. If you only do that for one unit on this whole path, do it for this one.

A5

macOS, Linux and mobile — enough not to be stranded

K ~88m

You will be handed devices you do not personally use, and the honest goal here is competence rather than depth: where the settings live, how software is installed, and what the equivalent of each Windows concept is called. Shallow deliberately — depth in a platform you rarely see is the wrong use of your hours. The exception is the Linux command line, which is genuinely worth the time because it is the same skill every rung above this one needs.

After this you can

  • Find settings, install software and join a network on macOS without guessing
  • Read and run the common Linux commands, and say what a given one will do before running it
  • Support a mobile device's mail, network and management basics

Do these in order

  1. 1 WatchmacOS Overview Professor Messer · ~12m

    Orientation only. You are learning names for things you already understand.

  2. 2 WatchmacOS Features Professor Messer · ~12m

    Focus on the tools that correspond to the Windows ones from A4 — the concepts transfer, only the names change.

  3. 3 WatchLinux Professor Messer · ~12m

    Context for the two command videos that follow.

  4. 4 WatchLinux Commands, Part 1 Professor Messer · ~36m

    🎯 The most valuable single video on this path for anything beyond tier-1. Every rung above this one — cloud support, sysadmin, platform — assumes it. Do it with a terminal open, as with A4, and do not skip it because you are aiming at a Windows help desk.

  5. 5 WatchConnecting Mobile Devices Professor Messer · ~7m

    The connectivity half of mobile support, which is most of what is asked.

  6. 6 WatchMobile Device Management Professor Messer · ~9m

    What an organisation can and cannot do to a phone it manages. Worth knowing precisely, because users ask and the honest answer matters to them.

What to watch for

The temptation is to skip this unit if your target employer is a Windows shop. Do not skip the Linux command video specifically. It is the single most portable thing in this track and it is the reason a tier-1 gets considered for the cloud support role two rungs up.

Then drill it — A+ Core 2 - Windows, Accounts, Security and Procedures - macos and linux cards

Partial, and deliberately so. The deck carries the Windows-to-macOS mapping, Linux permissions and the command list worth knowing - about six cards. This unit's 88 minutes of video go considerably deeper than that, and the Linux command video in particular is not something a card can replace. Drill it to keep the vocabulary; do not treat the deck as coverage.

A6

Accounts, passwords and access — the part you touch every single day

KR ~74m

🔴 Resets, lockouts, group membership and multi-factor enrolment are the highest-volume tickets in tier-1 and also the most dangerous thing you are trusted with on day one. The Risk elements are not ceremonial: the exact actions that help a locked-out colleague are the actions an attacker wants performed on their behalf, and the two situations are designed to be indistinguishable. The knowledge is here; the skill of holding a verification procedure under pressure is B4.

After this you can

  • Explain what a directory account is and what group membership actually grants
  • Describe each common authentication factor and what it does and does not protect against
  • State your organisation's verification requirement before performing a reset, every time
  • Name the specific harm each password attack causes, and the control that stops it

Do these in order

  1. 1 WatchAuthentication and Access Professor Messer · ~13m

    The model underneath every account ticket you will ever pick up.

  2. 2 WatchAuthentication Methods Professor Messer · ~8m

    Pay attention to what each factor protects against specifically. 'We have MFA' is not a security posture, and knowing why is what makes you useful in an incident.

  3. 3 WatchActive Directory Professor Messer · ~28m

    Long and worth it. This is the system most of your access tickets are actually about. Focus on groups and organisational units — most access requests resolve to group membership, and understanding that turns a confusing ticket into a one-line answer.

  4. 4 WatchWindows Security Settings Professor Messer · ~14m

    Where the local half of the previous video is configured and inspected.

  5. 5 WatchPassword Attacks Professor Messer · ~11m

    Watch this immediately after the others rather than as a separate security topic. It is the reason the verification procedure exists, and knowing the attack makes the procedure feel like protection rather than paperwork.

What to watch for

🔴 The dangerous belief in this unit is that verification is a formality that gets in the way of helping people. It is the opposite: it is the only thing standing between a helpful technician and being the route into their organisation. Every large breach that began with a phone call began with someone who wanted to help and did.

Write it · A6-R1

The reset you should not perform

A colleague you know by sight, but not by name, comes to your desk. They are locked out and visibly stressed. They say their manager is in a meeting and cannot approve it right now, and they need access for a client call in ten minutes. Your procedure requires manager approval or a callback to the number on record. Their phone, they say, is the problem — it is the one that broke and is why they cannot get the code.

Your task

Write down two things. First, the hazard here in one sentence — not 'they might be lying', but what specifically could go wrong. Second, the control that addresses it and why that control works even though this person is probably exactly who they say they are.

Score your own draft against these

  1. 1The hazard is stated as a consequence, not as a suspicion about the person
  2. 2You have identified that the broken-phone detail removes the one factor that would resolve this quickly, and that this is a pattern worth noticing rather than proof of anything
  3. 3The control you name is one your procedure actually specifies, not one you invented
  4. 4You explain why the control holds even in the overwhelmingly likely case that the request is genuine
  5. 5You have named a route that could still get them working, rather than stopping at refusal

A Risk element is closed by identifying the hazard AND stating its control. Both halves are needed: a technician who can name the danger but has no procedure freezes, and one who follows a procedure without understanding it abandons it the first time someone senior pushes.

Reveal a worked answer — only after you have written and scored yours

Hazard: if this is not who they say, I have just handed someone an account and every system it reaches, and because I performed the reset myself the audit trail will show it as a legitimate action by me. The damage is not the reset — it is that it will not look like an intrusion afterwards. Control: manager approval, or a callback to the number held on the record. It works because it moves the verification to a channel the requester does not control. That is the whole mechanism, and it is why 'I'll confirm on the number you're calling from' is not verification at all. Why it holds anyway: the control costs a genuine colleague a few minutes and costs an attacker the whole attempt. Those are not comparable losses, which is what makes the trade correct even though nearly everyone who triggers it is real. And the route forward is mine to take, not theirs — I can call the manager myself, or raise it to whoever holds out-of-hours authority, so the answer is 'not this way' rather than 'no'.

A7

Security, as it actually reaches a help desk

KR ~82m

Framed around what arrives in a ticket rather than around a taxonomy, because your job is to recognise a situation and route it correctly, not to classify it. Malware as the user experiences it, the email that got through, and the escalation rules for a suspected compromise. The most important thing in this unit is knowing the moment at which you stop trying to fix something and tell somebody.

After this you can

  • Recognise the reported symptoms that indicate malware rather than a fault
  • Follow a removal process in the correct order, including the steps before removal
  • Identify a business email compromise from what the user describes
  • State the point at which an incident stops being yours and say who it goes to

Do these in order

  1. 1 WatchMalware Professor Messer · ~18m

    Learn these by symptom, not by name. Nobody will ring to report a rootkit; they will report that the machine is slow and the browser has a new toolbar.

  2. 2 WatchAnti-Malware Tools Professor Messer · ~13m

    What the tools do and, more usefully, what they miss.

  3. 3 WatchRemoving Malware Professor Messer · ~12m

    🔴 The order is the content. Note specifically where disconnection and backup come in the sequence — doing those late, or not at all, is how a contained incident becomes a spread one.

  4. 4 WatchSocial Engineering Professor Messer · ~14m

    Watch this, then go and do B4 while it is fresh. This video tells you what the techniques are; B4 puts you in a conversation where all of them are used on you at once and none of them looks like a technique.

  5. 5 WatchBusiness Email Compromise Professor Messer · ~6m

    Short and specific. This is the attack most likely to reach your desk as a real ticket at a real employer.

  6. 6 WatchIncident Response Professor Messer · ~7m

    The one to remember under pressure. Your part is almost always the first two steps, and doing them properly is worth more than anything clever you could attempt instead.

  7. 7 WatchTroubleshooting Security Issues Professor Messer · ~11m

    Ties the unit together and shows the routing decisions in context.

What to watch for

The instinct when something looks compromised is to fix it quickly and quietly, partly because escalating feels like admitting you could not handle it. That instinct destroys evidence, and in a real incident the evidence is what determines whether anyone can tell what was taken. Preserving a situation you do not fully understand is a competent act, not a passive one.

Write it · A7-R1

The moment it stops being your ticket

A user reports that their machine is behaving oddly. While you are on the call you notice that a mail rule has been created on their account that forwards anything containing the word 'invoice' to an external address, and that it was created at 03:40 last Tuesday. The user has no idea what you are describing.

Your task

Write the hazard and its control, then the first three actions you take, in order, in the first five minutes. Under 200 words.

Score your own draft against these

  1. 1The hazard is stated as what may already have happened, not only as what might happen next
  2. 2You do not delete the rule as your first action, and you can say why
  3. 3Your first three actions include telling someone, and you name who
  4. 4You have said what you tell the user, and it neither alarms them unnecessarily nor misleads them
  5. 5Nothing in your actions depends on you diagnosing how the account was accessed

This is the highest-consequence judgement a tier-1 makes, and it is made in seconds. The correct instinct — preserve, report, contain, in that order — has to be rehearsed before the day it is needed, because on that day it will feel like doing nothing.

Reveal a worked answer — only after you have written and scored yours

Hazard: this is not a fault, it is an active compromise, and the 03:40 timestamp says it has been running for days. Anything invoice-related in that mailbox has already left the organisation, and the same credentials may reach other systems. The rule is evidence of the intrusion as well as part of it. Control: preserve, report, contain — and report before I am confident, not after. First three actions: 1. Screenshot or record the rule exactly as it stands, with its creation timestamp. I do not delete it yet, because it is the only record of when this started and deleting it also tips off whoever set it. 2. Raise it to the security contact immediately by whatever route is fastest, marked as a suspected account compromise rather than as a mail problem. This is not a queue item. 3. Follow their instruction on containment — typically session revocation and a password reset performed by them rather than by me. To the user: their account has a setting on it they did not create, I am getting the right team involved now, and they should not send or action anything about payments until we come back to them. That is true, actionable, and does not require me to explain something I do not yet understand.

A8

Printers, peripherals and the unglamorous majority

K ~65m

Named plainly because every honest account of this job includes it. Print queues, drivers, docks, displays and the physical connections behind them are low status and high volume, which makes them the fastest way to become visibly useful in a first job. The person who reliably fixes the printer is trusted with more within a month, and that is not a joke about the work — it is how competence is actually observed.

After this you can

  • Work a printer fault from the queue outward rather than from the hardware inward
  • Identify the common printer types by their failure modes and maintenance needs
  • Resolve display and peripheral connection problems without swapping parts blindly

Do these in order

  1. 1 WatchLaser Printer Maintenance Professor Messer · ~8m

    The printer type you will meet most in an office. Learn the consumables and the intervals.

  2. 2 WatchInkjet Printers Professor Messer · ~4m

    Brief. Enough to recognise the type and its characteristic faults.

  3. 3 WatchThermal Printers Professor Messer · ~4m

    Short but disproportionately useful in retail, logistics and warehousing — which is exactly where the entry-level roles are.

  4. 4 WatchMultifunction Devices Professor Messer · ~15m

    Covers the networked side, including scan-to-email — which fails constantly and is almost never a printer problem.

  5. 5 WatchTroubleshooting Printers Professor Messer · ~12m

    The core video. Note how much resolves in the queue and the driver rather than at the device — most 'printer is broken' tickets never require touching the printer.

  6. 6 WatchPeripheral Cables Professor Messer · ~9m

    Recognition. You need to name what you are looking at when a user describes it badly over the phone.

  7. 7 WatchDisplay Types Professor Messer · ~10m

    Enough vocabulary to handle docking and multi-monitor tickets, which are constant in hybrid offices.

What to watch for

There is a strong temptation to treat this unit as beneath the career you are aiming at. Resist it for one practical reason: these tickets are the ones you will be given first, they are how your competence gets observed, and being visibly reliable on them is what gets you handed the interesting work. Nobody is promoted out of a queue they were sloppy in.

Then drill it — A+ Core 1 - Hardware, Networking, Printers and Cloud - printer and peripheral cards

Partial. Five cards on print queues, printer types and peripherals against a unit of 65 minutes. Printer work is procedural and is learned at the device; the cards hold the diagnostic order, not the practice.

A9

Cloud and virtualisation, at the level tier-1 encounters them

K ~54m

What the terms mean, what changes about support when the application is not on the user's machine, and where your responsibility stops. This is also the bridge to rung 2: cloud support is the next rung up the ladder, pays materially more, and is the most common first promotion out of a help desk. This unit is where that door first becomes visible.

After this you can

  • Explain what changes about troubleshooting when the application is not local
  • Say where your organisation's responsibility ends and the provider's begins
  • Support the common cloud productivity and remote-access tools

Do these in order

  1. 1 WatchCloud Models Professor Messer · ~10m

    The vocabulary. Examined, and assumed by everyone above you.

  2. 2 WatchCloud Characteristics Professor Messer · ~7m

    Short. Focus on what changes operationally rather than on the definitions.

  3. 3 WatchVirtualization Concepts Professor Messer · ~6m

    Enough to follow a conversation about virtual machines without bluffing.

  4. 4 WatchVirtualization Services Professor Messer · ~12m

    Where virtual desktops come in, which many support roles now spend their whole day inside.

  5. 5 WatchCloud Productivity Tools Professor Messer · ~6m

    The tools your users actually live in, and therefore the tickets you actually get.

  6. 6 WatchRemote Access Professor Messer · ~13m

    Directly job-relevant: remote support is how most tier-1 work is delivered now. Note what you can and cannot see during a session, because that boundary is a privacy obligation as well as a technical limit — it comes back in A13.

What to watch for

The useful question to hold throughout: when something breaks, who is even able to fix it? A large part of cloud-era support is knowing that the answer is not you, and being able to say so with the evidence rather than after two hours of trying.

A10

A method for troubleshooting, and why yours is currently guessing

K ~45m

🔴 The unit that separates someone who fixes things from someone who tries things. A stated method — identify, theorise, test, plan, resolve, verify, document — is examined by CompTIA and is genuinely how competent people work. ⚠️ Note that the free video course has no standalone methodology video: the method is demonstrated inside the troubleshooting videos rather than taught as a topic. That is worth knowing rather than working around, so this unit is a re-watch with a different task attached.

After this you can

  • State the troubleshooting steps in order and say what each one is for
  • Name the step you personally skip under pressure, having observed yourself skip it
  • Explain why verifying and documenting are part of the method rather than admin after it

Do these in order

  1. You watched this in A2 for the content. Watch it again for the shape: pause at each transition and write down which step of the method just happened. You are extracting a method that is never named.

  2. Same task, different domain — which is the point. If the same sequence appears in both, you have found something general rather than something about networks.

What to watch for

🔴 The step almost everyone skips is the last one, and the second-most-skipped is the first. Under pressure people jump straight to a theory — usually the last thing that went wrong for anyone — and then stop the moment the symptom disappears, without confirming the cause or recording anything. The result is a fault that comes back in a fortnight with no record of what was tried. The Skill half of this unit is closed in Track B, where the method is applied to a real queue in B1 and written up in B2, because a method cannot be learned from a card.

A11

Backups, recovery and the data you are one click from destroying

KR ~23m

What is backed up, what is not, how restoration actually works, and the routine actions that quietly cause permanent loss — reimaging before checking, deleting a profile, resetting a device, wiping a disk you were about to redeploy. The failure mode here is unrecoverable and always looks like ordinary work at the moment you take the action, which is exactly why it needs to be rehearsed rather than read.

After this you can

  • Say what is and is not covered by a given backup before relying on it
  • Name the specific tier-1 actions that cause irreversible loss
  • State the check that must happen before any destructive step, every time

Do these in order

  1. 1 WatchManaging Backups Professor Messer · ~16m

    🔴 The critical idea is that a backup is not proven until it has been restored. Everything else in this video is secondary to that.

  2. 2 WatchData Destruction Professor Messer · ~7m

    The deliberate half of the same subject. Note the distinction between destruction that is a policy requirement and destruction that is an accident — the techniques overlap almost completely.

What to watch for

The dangerous moment is never labelled. It is a Tuesday afternoon, the user is waiting, and the fastest route to a working machine is a reimage. Nobody stops you. The only thing that reliably prevents this class of loss is a habit that runs before the destructive step rather than a rule you remember afterwards.

Write it · A11-R1

The reimage that would have been unrecoverable

A machine will not boot past the manufacturer logo. Your team's standard fix for this is a reimage, which takes forty minutes and always works. The user is waiting and has a deadline. They tell you, when asked, that everything is 'in the cloud, I think' — and that they have been keeping the last three weeks of a report on the desktop 'just while I'm working on it'.

Your task

Write the hazard and its control, then the exact check you perform before you start the reimage and what you do if it fails. Under 200 words.

Score your own draft against these

  1. 1The hazard is stated as permanent and specific, not as 'data might be lost'
  2. 2You identify that 'in the cloud, I think' is not evidence of anything
  3. 3Your check produces a verified copy rather than a belief that one exists
  4. 4You have said what you do when the check fails and the user is still waiting
  5. 5The control you describe would work on a day when you are rushed, not only on a calm one

This is the most common way a junior technician does real, uninsurable harm, and it happens while following the team's normal procedure. The control is not knowledge — everyone knows to check backups. It is having a habit that fires before the destructive action rather than a rule recalled afterwards.

Reveal a worked answer — only after you have written and scored yours

Hazard: three weeks of work exists in one place, on the desktop of a machine I am about to erase. Reimaging is irreversible — there is no undo, no recycle bin, and no version anywhere else. The loss would be total and it would be caused by me. Control: never run a destructive step until a copy exists that I have seen, on storage that is not the machine being wiped. The check: pull the disk or boot to recovery media, copy the user profile — desktop and documents at minimum — to network storage or an external disk, then open two or three of those files from the copy. Opening them is the part that matters; a folder that copied without error can still be a folder of nothing useful. If the check fails — the disk is unreadable — I stop and do not reimage. That machine now goes to whoever handles recovery, and the user gets a loan device so they can work while it happens. Forty minutes of my convenience is not worth three weeks of theirs, and the decision to give up on that data is not mine to make quietly.

A12

Scripting and automation, just enough to be the person who saves time

K ~15m

Not a programming unit. Reading a script somebody else wrote well enough to know what it will do before you run it, and writing the small repetitive one yourself. This is disproportionately what gets a tier-1 noticed and promoted, and it is the honest first step toward every path further up this site. It is also the shortest unit here, which is a fair reflection of how little you need to start.

After this you can

  • Read an unfamiliar script and say what it will change before running it
  • Recognise the tasks in your own queue that are worth automating and the ones that are not
  • Name the risks of running a script you did not write

Do these in order

  1. 1 WatchScripting Languages Professor Messer · ~6m

    What you will meet and where each is normally used. Vocabulary, not syntax.

  2. 2 WatchScripting Use Cases Professor Messer · ~9m

    The more useful of the two. Note the cases where automation is the wrong answer — a script run against the wrong scope does damage at a speed no human error matches.

What to watch for

Fifteen minutes of video will not make you able to script, and it is not supposed to. What it gives you is the ability to recognise the opportunity and to refuse to run something you do not understand. Both are worth more in a first year than syntax is.

Then drill it — A+ Core 2 - Windows, Accounts, Security and Procedures - scripting cards

Partial by design - two cards, matching a 15-minute unit. This is the shortest unit on the path and the deck is sized to it rather than padded to look substantial.

A13

Operational procedures, change and the paper trail

KR ~58m

Ticketing conventions, asset records, change control, licensing, safe disposal, and the privacy rules governing what you may look at and what you must not. Dry, heavily examined, and the reason a competent technician is trusted with more. The Risk half is the privacy one: remote access and account administration give you routine sight of things you have no business reading, and the boundary is a professional obligation rather than a technical control.

After this you can

  • Follow a change process and say why each stage exists
  • Keep asset and licence records that survive an audit
  • State what you may access, what you may not, and what you do when you see something you should not have

Do these in order

  1. 1 WatchChange Management Professor Messer · ~22m

    Long and thoroughly examined. The useful framing: every stage of a change process exists because somebody once skipped it, and the rollback plan is the part people leave out.

  2. 2 WatchAsset Management Professor Messer · ~5m

    Short. Matters more than it seems when you are the person asked where a device went.

  3. 3 WatchDocument Types Professor Messer · ~8m

    Know what each document is for. You will be asked to follow several of them in week one.

  4. 4 WatchPrivacy, Licensing and Policies Professor Messer · ~11m

    🔴 The Risk content of this unit. Watch it properly rather than treating it as the compliance video — the obligations described here are the ones a support role actually puts you in reach of breaking.

  5. 5 WatchSafety Procedures Professor Messer · ~5m

    Physical safety. Brief, examined, and genuinely applicable if you handle hardware.

  6. 6 WatchManaging Electrostatic Discharge Professor Messer · ~6m

    The one hardware hazard that damages equipment invisibly and is trivially prevented.

What to watch for

This is the unit people skim, and it is the one that most reliably appears in interviews for the roles above tier-1 — because change control and record-keeping are what separates someone who can be given production access from someone who cannot.

Write it · A13-R1

What you saw during the remote session

You are in a remote session fixing a mail problem. While the user is talking you can see their screen, and an open document is plainly a grievance letter naming a colleague you know. The user has not mentioned it and does not appear to realise it is visible. You finish the fix in four minutes.

Your task

Write the hazard and its control, then what you do — during the session, immediately after, and if a colleague later asks you what the person is like. Under 200 words.

Score your own draft against these

  1. 1The hazard is stated as harm to the user and to trust in the service desk, not as a rule you might break
  2. 2You act during the session as well as after it
  3. 3Your action does not embarrass the user or draw attention to what you saw
  4. 4You are specific about what you do not record in the ticket, and why
  5. 5Your answer to the colleague is one you could give without lying and without disclosing anything

Nobody audits this and no control prevents it, which is exactly why it is a Risk element. A help desk that gossips is one people stop calling, and the tickets they stop raising are the security ones.

Reveal a worked answer — only after you have written and scored yours

Hazard: I have seen something private about a named third party that the user did not choose to show me. Repeating it harms two people directly, and the wider damage is that people who suspect the service desk reads their screens stop asking for help — including on the compromises we most need reported. Control: minimise the exposure while it is happening, and treat what I saw as though I had not. During: I keep my attention on the task and say something neutral that gets the document off screen without naming it — asking them to close other windows so I can see the mail client cleanly is true, ordinary, and does not signal that I noticed anything. After: the ticket records the mail fault and the fix. It does not record what was on screen, because a ticket is read by more people and kept far longer than anyone assumes, and a note about it would spread the disclosure rather than contain it. If asked: "I've only ever fixed their email." That is true, discloses nothing, and does not invite a follow-up.

A14

The A+ exam itself — what it is, what it costs, what it is worth

K ~44m

Last, and deliberately not first. Two exams, 220-1201 and 220-1202, at $530 for the pair. 🔴 That $530 is the single largest barrier on this path for exactly the person it was written for, so the funding resource below is not an afterthought — read it before you decide the path is unaffordable. ⚠️ The honest framing on the certificate itself: A+ gets a résumé read, and it is the one credential this ladder's employers genuinely recognise. It does not by itself get you hired, and the evidence pack you build in B6 is what carries the interview.

After this you can

  • Describe both exams, their format and what each covers
  • Decide when you are ready to book, on evidence rather than on feeling
  • State accurately what the certification does and does not do for an application

Do these in order

  1. 🔴 Read this FIRST, before the exam material and before you write off the $530. Public workforce funding can cover certification exam fees, and it is described as underused. ⚠️ Ignore any figure you have seen quoted as a national amount — there isn't one. Individual Training Account caps are set by your state and local workforce board, and the money is secondary to Pell, which almost no guide mentions. Two questions for your local American Job Center: which funding stream you qualify for, and whether the course you want is on your state's approved provider list. There is also a timing element on that page that genuinely matters.

  2. 2 WatchHow to Pass Your A+ Exams Professor Messer · ~16m

    ⚠️ Read the title carefully: this video is named for 220-1101 and 220-1102, the PREVIOUS version of the exams. The study advice, the format and the exam-day guidance all still apply; the objective numbers do not. Use it for how to prepare, and take the objectives themselves from the current 220-1201 and 220-1202 pages. We have left it in rather than quietly dropping it, because meeting one stale link inside a curated path is better practice than assuming everything you find will be current.

  3. 3 ReadCore 1 (220-1201) course index Professor Messer · ~10m

    The full 63-video index for Core 1. Use it to fill the gaps this path deliberately left — laptop hardware, cabling, RAID, display attributes — once the units above are done. This path is ordered for the job; the index is ordered for the exam, and you need both before you book.

  4. 4 ReadCore 2 (220-1202) course index Professor Messer · ~10m

    The full 74-video index for Core 2. Same instruction. The security domain in particular is broader than what A7 covers, because A7 selected for what reaches a help desk rather than for what is examined.

What to watch for

🔴 Do not book until you have done B6. The most common failure on this rung is not the exam — it is passing it, applying with a certificate and nothing else, and joining a queue of several hundred people holding the same certificate. The evidence pack is the part of your application that nobody else has.

Then drill it — The Help Desk Job Itself - career and exam cards

These cards are about what the certification does and does not do for an application. They are NOT exam practice - there is no practice-exam pool for this path yet, and a deck is not one. Do not treat drilling these as readiness to book.

Track B — The job, practised

🎯 Six units of real work against supplied situations. Help desk has a real exam, which makes it the easiest path on which to point at the A+ and call the job taught — so this track exists to stop that. Every brief here is a practice brief and is labelled as one everywhere it appears: the work is real, the client is not, and the difference matters the moment this goes on an application.

B1

The queue — deciding what to do first

S ~90m

Triage is the job. On any real service desk more work arrives than one person can do, and the difference between a good tier-1 and a struggling one is almost entirely the order they choose. Nobody teaches this because it looks like common sense until you are holding eight tickets, two of which are marked urgent by people who are not affected and one of which is quietly a site outage.

After this you can

  • Order a mixed queue by business impact rather than by how the request was worded
  • Separate the number of people affected from the volume of the person asking
  • Name, in one sentence, why each ticket sits where you put it
  • Spot the ticket in a queue that is a bigger problem wearing a small one

What to watch for

The trap is treating the requester's stated urgency as the input. Almost every queue you meet will contain a politely worded ticket that is genuinely blocking a department, and an angry one that affects one person who has a workaround. Impact times reach, then age. Read every ticket in the queue before you touch any of them — the ordering is only visible from the whole set.

Brief · B1-A1Practice brief — not client work

Order this morning's queue and defend it

It is 09:05 on a Tuesday. You are the only tier-1 on shift until 11:00. These eight tickets are open. Put them in the order you will work them and write one sentence for each saying why it sits where it does. 1. 08:12 — Finance: "URGENT!!! Need my Excel back, lost the file I was working on yesterday." 2. 08:31 — Reception: "Printer by the front desk is showing a paper jam, cleared it twice." 3. 08:44 — Warehouse supervisor: "None of the six scanners on the loading bay will connect this morning. Trucks are queued." 4. 08:47 — Sales: "Can someone install Spotify on my laptop?" 5. 08:51 — HR: "New starter today at 09:30, no account, no laptop." 6. 08:55 — Marketing: "Website is down." (Your company website loads fine from your machine.) 7. 09:00 — CFO: "My mouse is being slow." 8. 09:02 — Anonymous via the phishing button: "Reported an email asking me to confirm my password. I clicked the link and put my details in."

What you hand over

A numbered list of all eight tickets in your working order, each with a one-sentence reason. Roughly 250 words in total. Then two short paragraphs: which ticket you found hardest to place and why, and which one you would escalate immediately rather than work.

Done when — read this before you start

  • All eight tickets are placed and none is left out, including the ones you consider trivial
  • Every reason refers to impact, reach, or a deadline you can point to — not to the requester's tone or seniority
  • At least one ticket has been re-read as something larger than it first appears
  • You have named the ticket that leaves your hands immediately, and said who it goes to
  • Your reasoning would survive being read aloud to the person whose ticket you placed last
Write it · B1-R1

Explain your ordering to the person you put last

The CFO's slow mouse is eighth in your queue. At 09:40 they stop by your desk and ask, pleasantly but pointedly, why nobody has been to look at it yet.

Your task

Write what you would say. Four to six sentences, spoken aloud rather than written as an email. You are not permitted to blame a policy, a system, or a manager.

Score your own draft against these

  1. 1You answer the question honestly rather than deflecting to a process
  2. 2You say what is ahead of it in concrete terms, without naming individuals or leaking details of other people's tickets
  3. 3You give a time, or say plainly that you cannot give one yet
  4. 4You offer something now — a workaround, a spare, a specific next action
  5. 5You do not apologise more than once, and you never say the word 'just'
  6. 6Nothing in it would embarrass you if the warehouse supervisor also heard it

Being able to defend a queue to a senior person, without either caving or being defensive, is what makes triage stick. A technician who reorders the queue whenever an important person asks does not have a queue.

Reveal a worked answer — only after you have written and scored yours

"You're not being ignored — I've got you on the list for this morning. Right now the loading bay has six scanners down and trucks waiting, so that's taking me and my colleague until about half ten. After that I'm on a new starter who needs to be working by lunchtime, and then I'm with you. I can do one thing now if it helps: I've got a spare mouse at the desk, so if you want to swap it out while you wait, that'll tell us in thirty seconds whether it's the mouse or the machine. Either way I'll come and find you by eleven." Why this shape: it opens by answering the actual question, gives the real reason in terms of impact rather than hierarchy, names a time, and hands over something that both helps and diagnoses. It never says the mouse is unimportant, which would be both rude and untrue — it says what is ahead of it.

B2

Writing a ticket somebody else can pick up

S ~75m

🎯 The most under-taught skill in the whole job. Your notes are read by the next shift, by tier 2, by an auditor, and sometimes by you in six months with no memory of the call. Most tier-1 notes are useless — 'user had issue, resolved' — and the technician who writes usable ones is visible to their manager within a fortnight. This is also the skill that transfers to every rung above this one.

After this you can

  • Record a fault so a colleague can continue it without phoning the user again
  • Separate what the user reported from what you observed from what you concluded
  • Write a resolution that would let someone else fix the same fault next time
  • Leave out the things that must not be written down

What to watch for

Two failures, and they look opposite. The first is the empty note, which loses the work. The second is the wall of text nobody reads. The fix for both is the same: separate the sections. What was reported, what you found, what you did, what remains. And never paste a password, a full card number or a person's health or HR detail into a ticket, however convenient — the ticket system is read by more people than you think and is retained far longer than you expect.

Brief · B2-A1Practice brief — not client work

Turn a phone call into a ticket

This is what the user said, in the order they said it, on a call that lasted nine minutes: "Hi, yeah, my laptop's doing the thing again. It's really slow. Well, not slow exactly — it's fine and then it just stops for a bit. Started maybe Thursday? Could have been Wednesday. It's worse when I'm on the video calls, definitely worse then. Somebody in the office said it might be the update. Oh — and it did the blue screen thing once, last week I think, but only once and it came back fine. No, I don't remember what it said. I'm working from home today. Yes, it's plugged in. No, I haven't turned it off, I just close the lid at night." During the call you also established, by asking: the machine has not been restarted in 31 days, disk usage sits at 100% during the freezes, and the device is four years old with a mechanical hard disk.

What you hand over

One ticket, written the way you would leave it at the end of your shift. Include a one-line summary suitable for a queue list, then the body. Under 300 words.

Done when — read this before you start

  • Someone who was not on the call could continue the work without ringing the user back
  • What the user reported, what you established, and what you concluded are visibly separate — a reader can tell which is which
  • The vague details are recorded as vague rather than tidied into false precision — 'Thursday or Wednesday' does not become 'Thursday'
  • The one-line summary would let you find this ticket among two hundred others
  • The blue screen is in there. It is the detail most people drop, and it may be the whole answer
  • You have said what you have not yet checked
Write it · B2-R1

The resolution note

The laptop from B2-A1 turned out to have a failing mechanical disk. It was replaced with an SSD, the machine reimaged, and the user's files restored from the backup. The user has confirmed it is working. You are closing the ticket.

Your task

Write the resolution note. Six to ten lines. Assume it will be read by a colleague meeting the same symptoms on a different machine next month.

Score your own draft against these

  1. 1The root cause is stated as a cause, not as the action you took
  2. 2The evidence that identified it is included, so the next person can reproduce the diagnosis rather than repeat the guesswork
  3. 3The actions taken are listed in order and are specific enough to follow
  4. 4You have recorded what confirmed the fix — not just that the user said it was fine
  5. 5Anything relevant left outstanding is named, including anything the user should watch for
  6. 6No credentials, and nothing about the user as a person

A closed ticket is the only durable record of what happened. Written well it is an asset the whole team draws on; written badly the same fault is diagnosed from scratch every time it appears.

Reveal a worked answer — only after you have written and scored yours

Root cause: failing mechanical hard disk. SMART reported reallocated sectors; disk usage pinned at 100% with multi-second stalls under any sustained read, matching the reported freezes on video calls. The single blue screen the user mentioned a week earlier is consistent with this and was the earliest sign. Actions: 1. Confirmed with SMART and by observing disk queue length during a reproduced stall. 2. Backed up user profile, verified the backup opened before proceeding. 3. Replaced HDD with 500GB SSD. 4. Reimaged to the current standard build. 5. Restored user data, confirmed with the user that their working files were present. Verified: user opened three of their own recent files and completed a video call without a stall, observed on a remote session rather than reported. Outstanding: this is a four-year-old unit and three others from the same batch are still on mechanical disks — asset numbers in the linked ticket. Recommend they are looked at before they fail the same way. Why this shape: the cause is separated from the fix, the evidence is there so nobody has to re-derive it, the verification is something observed rather than something claimed, and the last line turns one repair into a prevented repeat.

B3

Escalating without losing the room

S ~60m

Knowing when to stop is a skill, and it is judged. Escalate everything and you are not doing the job; escalate nothing and you sit on a fault for three hours that tier 2 would have recognised in five minutes. New technicians almost always err toward holding on too long, because handing over feels like admitting failure. It is not — the failure is the three hours.

After this you can

  • State a time or evidence boundary at which you will hand a ticket on, before you start
  • Write a handover the receiving engineer does not have to re-investigate
  • Tell the user a ticket is moving on without it sounding like abandonment

What to watch for

A bad escalation is not one that happens too early. It is one that arrives with no information — 'user has network problem, please advise' — and forces the next person to start from nothing. Everything you already ruled out is the valuable part of the handover, and it is the part most often left out because it feels like a list of failures. It is not; it is the map.

Brief · B3-A1Practice brief — not client work

Hand over a fault you cannot finish

Six of the warehouse barcode scanners will not connect to the wireless network. You have spent forty minutes on it. You have established: the scanners power on and are charged; they see the network name but fail at authentication; a seventh scanner from the same batch, still in its box, behaves identically; a laptop connects to the same network in the same physical spot without difficulty; the scanners worked on Friday; nothing was changed over the weekend that anyone will admit to; and the certificate on the scanner profile shows an expiry date of yesterday. Trucks are waiting. Your shift ends in twenty minutes.

What you hand over

The escalation note you attach when you move this to the network team, plus the message you send the warehouse supervisor. Under 250 words for both.

Done when — read this before you start

  • The escalation names your best current theory and the evidence for it, rather than only listing symptoms
  • Everything you ruled out is included, with how you ruled it out
  • The business impact is stated in terms the receiving team will act on — trucks waiting, not 'urgent'
  • The supervisor's message says what is happening, who has it now, and when they will next hear something
  • Neither message blames anyone, including whoever let a certificate expire
  • You have said what you did NOT check, so nobody assumes you did
B4

The call that is an attack

RS ~75m

🔴 The help desk is the single most targeted point of entry in most organisations, because it exists to help people who cannot get in and it is staffed by the newest, most junior and most eager-to-please people in the building. Every large breach of the last few years that began with a phone call began at a desk like the one you are training for. This unit is a Risk element and a Skill element, and no card can test either: the hazard is identifiable only inside a conversation that is engineered to feel completely normal.

After this you can

  • Recognise the pressure patterns that distinguish a social-engineering call from an ordinary urgent one
  • Refuse an identity-verification bypass without accusing the caller of anything
  • Hold a verification procedure under manufactured time pressure and manufactured seniority
  • Report a suspected attempt in a way that is useful even if you turn out to be wrong

What to watch for

The tell is never the request on its own — every item a social engineer asks for is something you legitimately do all day. The tell is the combination: urgency, an authority you cannot verify, a reason why the normal check cannot be done this once, and a small emotional hook that makes refusing feel unkind. 🔴 And the correct response is never to catch them out. It is to follow the procedure exactly as written and let it fail closed, which works whether the caller is an attacker or a genuinely stressed director.

Brief · B4-A1Practice brief — not client work

The call you cannot verify

Transcript of an inbound call, 16:50 on a Friday. The caller ID shows a mobile number not in your directory. CALLER: "Hi — is that the service desk? Thank god. This is Dan Whelan, I'm covering for Priya in Finance, I've been seconded in this week. I'm so sorry, I know this is a nightmare on a Friday." YOU: [greeting] CALLER: "So I'm locked out of my account. I've got the payment run that has to go out tonight or about forty people don't get paid on Monday, and Priya's on annual leave and her phone's off. I've tried the self-service reset but it's sending the code to her old work mobile, which I obviously don't have." YOU: [ask for verification] CALLER: "Yeah, of course. Dan Whelan, W-H-E-L-A-N, employee number... hang on, it's on my badge, and my badge is in my other coat because I came straight from the client site. Look, I know how this sounds. Can you just reset it and send it to my mobile this once? I'll come down first thing Monday with the badge and you can do all the paperwork then. I really don't want to be the guy who broke payroll." Your organisation's procedure requires either a callback to the number held on the employee record, or verification by the employee's line manager.

What you hand over

Three things. First, what you say next, word for word. Second, a list of every pressure technique you can identify in the transcript, quoting the phrase that carries it. Third, the internal report you file afterwards, in under 100 words.

Done when — read this before you start

  • Your reply does not grant the request, and does not accuse the caller of anything either
  • Your reply offers a genuine route that satisfies the procedure — refusal alone is not the skill
  • You have identified at least five distinct pressure techniques and quoted the phrase for each
  • Your report is written so that it is still appropriate if Dan Whelan turns out to be entirely real
  • You have said who you would tell, and how quickly, rather than only what you would write
  • Nowhere do you rely on 'it felt suspicious' as the reason — the reason is that verification was not met
Write it · B4-R1

The reply that holds the line and keeps the person

The same call. You have decided you cannot reset the account. The caller has not become aggressive — they have gone quiet, then said, flatly: "Okay. So you're telling me forty people don't get paid because of a badge."

Your task

Write your response. Four to six sentences, spoken. It must not grant the reset, must not accuse, and must leave the caller with something to do next.

Score your own draft against these

  1. 1You do not accept the framing that you are the cause of the consequence
  2. 2You do not defend yourself by citing 'policy' as though it were external to you
  3. 3You name at least one concrete route that could still solve it tonight
  4. 4You take an action yourself rather than leaving it entirely with the caller
  5. 5The tone would be appropriate if this is a real, exhausted colleague
  6. 6You do not reveal what verification data you hold, or what specifically failed

Refusing is the easy half. A desk where refusing means being unhelpful is a desk where people stop refusing, so the skill is holding the check while genuinely trying to solve the person's problem by a route that satisfies it.

Reveal a worked answer — only after you have written and scored yours

"I'm not going to leave you stuck — but I can't send a reset to a number I can't match to the record, and that's true for everyone, including me if I locked myself out. Here's what I can do right now. If you give me your line manager's name, I'll call them myself — you don't have to chase them, I'll do it. If they confirm it, I can reset it in two minutes. If you'd rather not, the other route is the on-call Finance lead, and I can raise that as a P1 so it goes to someone with authority tonight rather than sitting in a queue. Either way I'm staying on this until it's resolved. Which of those two do you want me to start?" Why this shape: it declines without ever suggesting the caller is lying, it removes the effort from them by taking the call itself, it offers two real routes with a time attached, and it ends with a question that hands them a choice rather than a wall. If the caller is Dan, he is helped. If he is not, every route offered goes through someone who can actually verify — so it fails closed either way.

B5

Explaining a fix to someone who is not technical

S ~60m

You will spend more of this job talking than typing, and most of the talking is to people who do not have the words for what is happening to them. The technician who can walk a frightened user through a fix over the phone, without making them feel stupid, is the one who gets kept. It is also the skill that survives every technology change in your career.

After this you can

  • Give spoken instructions that can be followed without seeing the screen
  • Check understanding without asking 'does that make sense?'
  • Explain what went wrong at the level the listener actually wants

What to watch for

The two habits that ruin this are jargon and speed, and speed is the worse of the two. Silence while someone finds a menu is not dead air to be filled. And 'just' is the most damaging word in support — 'just click the thing at the bottom' tells a struggling person that what they cannot do is trivial.

Brief · B5-A1Practice brief — not client work

The phone walkthrough, written as a script

A user working from home cannot get onto the company system. You have established it is the VPN client, which has lost its saved configuration and needs to be re-added. The user described their own computer skills, unprompted, as "honestly, terrible — my daughter usually does this." They are on a mobile phone, so they cannot use the computer's screen and talk to you at the same time without putting you on speaker, which they do not know how to do. You cannot take remote control, because remote control requires the connection that is broken.

What you hand over

The call, written as a script: everything you say, with a note in brackets where you are waiting and what you are waiting for. Assume roughly ten steps. Under 500 words.

Done when — read this before you start

  • Every instruction names what the thing looks like and where it is, not only what it is called
  • You confirm each step by asking the user to tell you what they can see, not whether they have done it
  • The word 'just' does not appear once
  • You have planned for at least one step going wrong, and written what you say when it does
  • There is a point where you deliberately say nothing, and it is marked
  • You tell them at the start roughly how long this will take and how many steps there are
  • Nothing you say would embarrass the user if a colleague overheard their half of it
B6

The evidence pack — what you take to the interview

S ~120m

🔴 This is the unit that makes the rest of the path worth walking. An A+ certificate proves you passed an exam that thousands of other applicants also passed. Nothing else on your application shows how you think, and the entry market is not short of applicants — 49% of applications from people with ten or more years of experience go to entry-level roles, so you are not only competing with beginners. Everything you produced in B1 through B5 is real work about real situations, and assembled deliberately it is the only thing in your application that is yours.

After this you can

  • Assemble the Track B work into something a hiring manager will read in three minutes
  • Describe practice work accurately, without ever letting it read as employment
  • Answer 'you have no experience' with something specific instead of enthusiasm

What to watch for

🔴 The honesty rule is absolute and it is in your interest as well as ours. These are practice briefs against simulated situations — the work is real, the client is not. Presented as workplace experience, they are a lie that collapses in the first interview question and takes the rest of your credibility with it. Presented accurately, they are unusual and strong: almost no other entry candidate brings written evidence of how they triage or how they refuse a social-engineering call.

Brief · B6-A1Practice brief — not client work

Assemble and label the pack

Collect your work from B1 through B5 into one document you could attach to an application or hand across a table. For each piece, add two or three sentences saying what the exercise was, what you decided, and what you would do differently now. Then write a short opening page: who you are, what this is, and what it demonstrates.

What you hand over

One PDF, no more than six pages. An opening page, then five labelled pieces of work with your commentary on each.

Done when — read this before you start

  • The opening page states plainly that these are training exercises, not client or employer work
  • Each piece is labelled with what it was practising, so a reader knows what they are looking at
  • Your commentary shows a decision and a reason, not a description of the task
  • At least one piece includes something you got wrong on the first attempt and what changed
  • A hiring manager could read the opening page and one piece in three minutes and know something real about how you work
  • Nothing in it could be mistaken for paid work by a reader who is skimming — that is the test, not whether it is technically accurate
Write it · B6-R1

"You don't have any experience, though."

Second interview for a tier-1 role. The hiring manager has your pack in front of them and says, not unkindly: "This is more than most people send. But it's all made up, isn't it? You haven't actually done any of this."

Your task

Write your answer. Five to eight sentences, spoken. You may not overclaim, and you may not apologise for the pack.

Score your own draft against these

  1. 1You agree with the accurate part of what they said, immediately and without defensiveness
  2. 2You draw the distinction that matters — the situations were supplied, the thinking was not
  3. 3You point at one specific decision in the pack rather than describing it in general
  4. 4You acknowledge what practice cannot give you, and name it accurately
  5. 5You do not disparage candidates who have real experience, or imply the pack substitutes for it
  6. 6You end somewhere useful rather than trailing off into willingness to learn

This question is coming, and the answer is genuinely good if you do not flinch. Candidates lose here by either overclaiming — which ends the interview — or by apologising until the pack looks worthless. Both are avoidable.

Reveal a worked answer — only after you have written and scored yours

"That's right — the situations were given to me, and I've labelled them that way because I'd rather you heard it from me than found it out. What isn't made up is the reasoning. Nobody told me what order to put that queue in. The one I'd point you at is the warehouse scanners. My first version of that escalation was a list of symptoms, and it was useless — I'd left out everything I'd ruled out, which was the only part that would have saved the next person any time. Rewriting it is what taught me what an escalation is for. What I haven't had is a real queue on a bad day with somebody standing at my desk, and I'm not going to pretend the practice is the same thing. What I'd say is that I've thought about the job rather than just about the exam, and I'd rather show you that than tell you I'm a fast learner." Why this shape: it concedes the true thing first, which removes the trap. It then draws the only distinction that survives scrutiny — supplied situation, own judgement — and evidences it with one specific decision including a mistake, which is far more convincing than a success. It names the real gap honestly, and closes on the difference between preparing for a job and preparing for an exam.

This is rung 1 of the Get Hired ladder, which ranks the entry paths by how likely each one is to actually land a first job — and is honest about what each one does not do.

All twenty units are written, and every one has a drill attached — three decks, 119 cards, written for these units rather than borrowed from elsewhere. Track A costs nothing but time: every video it links is free and the durations shown are the real ones. Track B needs nothing installed at all. What is still missing is a practice-exam pool, so drilling the cards is retrieval practice and not evidence you are ready to book. See the full list of learning paths for the ones with practice exams and labs already built.