The Bait 🎣
Lock It Down🔐
Cyber Fact🕵️
AI or A-Lie? 🤖
Trust No One 🎭
100

A fake email or message designed to trick you into clicking a link, sharing information, or taking another unsafe action.

Phishing

100

A secret combination of characters used to protect access to an account.

Password

100

Harmful software designed to damage, disrupt, spy on, or gain unauthorized access to a computer or device.

Malware

100

Before sensitive information like PII or PHI makes its way into an AI tool, this recently adopted security platform helps detect it.

STRAC

100

Someone you don’t recognize follows you toward a badge-only door and asks you to hold it open. What should you do?

Do NOT let them in

200

A message that appears to be from your boss urgently asks you to buy gift cards. What should your first step be?

Report the email by clicking the fishing hook in my email

200

This security feature requires more than just your password to prove that you are really you.

Multi Factor Authentication (MFA)

200

This type of malware locks or encrypts files and demands payment to get them back.

Ransomware

200

A message contains your name, job title, and details about your company. True or false: Those personal details prove the message came from someone you know.

False

200

An email appears to come from a coworker, but the request seems unusual. What should you do before acting?

Verify the coworker/email

300

This part of an email should be checked carefully because scammers may change just one letter to make an address look legitimate

Sender's Email Address

300

Instead of remembering dozens of unique passwords, this tool can securely create and store them for you.

Password Manager

300

A fake video or audio recording created with AI can make it appear that a real person said or did something they never did.

Deepfake

300

An employee pastes confidential company information into an unapproved public AI tool because they only want it to “summarize the text.” What's the security problem?

Exposing confidential Information

300

An attacker calls the pretending to be an employee and uses information from LinkedIn to answer questions convincingly. What are they trying to exploit?

Trust

400

This type of phishing attack is personalized for a specific person or group instead of being sent to thousands of random people.

Spear Phishing

400

You receive an MFA approval request on your phone, but you aren't trying to sign in. What should you do?

Deny/Report

400

An incident where sensitive or confidential information is accessed, stolen, or exposed without authorization.

Data Breach

400

When AI confidently produces information that sounds believable but is actually incorrect or made up, it's commonly called this.

AI Hallucination

400

Someone enters a secure area by following an authorized employee through the door without badging in. This is called what?

Tailgating

500

This phishing scam involves a criminal pretending to be a company executive, employee, or vendor to convince someone to send money or sensitive information.

Business Email Compromise (BEC)

500

Attackers repeatedly send login approval notifications to your phone, hoping you'll eventually get annoyed and press “Approve.”

MFA Fatigue

500

An attacker secretly watches communication between two parties and may intercept or alter the information being exchanged. This is known as this type of attack.

MITM (Man-In-the-Middle) attack

500

An employee removes customer names before entering data into an AI tool, but leaves email addresses and phone numbers. What type of information could still be exposed?

PII

500

Who is the one person in InfoSec you should never trust? (The biggest troll)

Andrew Gjovik

M
e
n
u