Know Your Enemy
Phish Food
Password Problems
Cyber Speak
What would you do?
100

This broad term describes malicious software designed to damage, disrupt, spy on, or gain unauthorized access to a system.

What is Malware?

100

A fraudulent message designed to trick someone into revealing information, clicking a malicious link, or opening an attachment.

What is phishing?

100

This security control requires something beyond your password—such as an authenticator app, security key, or biometric—to sign in.

What is multi-factor authentication (MFA)?

100

This technology creates an encrypted connection between your device and another network and is commonly used for secure remote access. 

What is a VPN?

100

You accidentally click on a suspicious link but nothing appears to happen. This should be your next move.

What is report it to DivTech/Service Desk?

200

This type of malware encrypts or locks access to data and demands payment to restore it.

What is ransomware?

200

Phishing delivered specifically through text messages has this name.

What is smishing?

200

Instead of a short, complicated password, security guidance often recommends using a longer sequence of memorable words known as this.

What is a passphrase?

200

This process transforms readable information so that someone without the appropriate key cannot understand it.

What is encryption?

200

You receive an unexpected email from someone you know asking you to open a document. The messages feels unusual. Before opening it, you should do this.

What is verify the request through a trusted/separate method?

300

An attacker manipulates a person rather than exploiting technology to convince them to reveal information or perform an action.

What is social engineering?

300

Instead of sending an email or text, this phsihing technique uses a phone call or voice message.

What is vishing?

300

This tool securely stores credentials and can generate unique passwords so you don't have to remember every one.

What is a password manager?

300

This principle says that users should receive only the access necessary to perform their job—and nothing more.

What is least privilege?

300

Your authenticator suddenly asks you to approve a login you didn't initiate. You should deny it and do this immediately afterward.

What is report the unexpected authentication attempt? (and change your password)

400

This security risk comes from someone who already has legitimate access to an organization's systems or information.

What is an insider threat?

400

Unlike mass phishing, this attack is carefully crafted for a particular person or organization.

What is spear phishing?

400

Your password is long, complex, and impossible to guess—but you use the same one for your work account, email, and several websites. This practice is still your biggest password-related risk.

What is password reuse?

400

Rather than relying on one security control, this strategy uses multiple overlapping safeguards so another control can still protect the organization if one fails.

What is defense in depth?

400

You realize your agency laptop or phone is missing. Even if you think you know where you left it, you should do this promptly.

What is report the lost device?

500

Attackers compromise a trusted vendor, product, or service as a way to reach it's customers.

What is a supply-chain attack?

500

You spotted the phish! Deleting it protects your inbox, but using this outlook feature helps the Cyber Security team identify and respond to the threat.

What is the Phish Alert Button?

500

Instead of trying thousands of passwords against one account, attackers try a small number of common passwords against many accounts to avoid lockouts.

What is password spraying?

500

An website asks for your username. An attacker gives it database commands instead, hoping the application will execute them. This classic web attack is known as this.

What is SQL injection?

500

While working, your computer suddenly begins displaying security alerts, behaving strangely, or showing signs that it may be compromised. Rather than investigating it yourself, your priority should be this.

What is stop using it and contact the DivTech/Service Desk?

M
e
n
u