Free Tools
Tools of the Bad Guys
Tools of Defense
Acronyms & Abbreviations
Misc.
100

A simulated phishing attack performed by KnowBe4 on email addresses an organization provides us.

What is Phishing Security Test (PST)

100

A weakness on a network, computer, or software which allows a bad guy to gain access.

What is Security Vulnerability

100

Any training that raises the awareness of a user to potential threats & how to avoid them.

What is Security Awareness Training

100

AD

What is Active Directory

100

Malicious code that loads into the early stages of a computer

What is rootkit

200

A tool that checks to see if an organization’s users are currently using passwords that are in publicly available breaches associated with the organization's domain.

What is Breached Password Test (BPT)

200

Software or code - usually malicious- that takes advantage of a flaw or vulnerability.

What is Exploit

200

A system for the administration, documentation, tracking, reporting & delivery of e-learning education courses or training programs.

What is Learning Management System

200

PCI DSS

What is Payment Card Industry Data Security Standard

200

Hardware or software designed to block unauthorized network access while permitting authorized communications.

What is firewall

300

A test that checks a domain name- for example KnowBe4.com - to see if it can be spoofed.

What is Domain Spoof Test (DST)

300

Also known as piggybacking- a method used by bad guys to gain access to a building or other protected area.

What is tailgating

300

A technical standard that governs how online learning content and Learning Management Systems communicate with each other.

What is Sharable Content Object Reference Model (SCORM)

300

HIPAA

What is Health Insurance Portability and Accountability Act

300

Like physical folders - something that organizes files or data on a hard drive or in a program.

What is Directory

400

Identifies the at-risk users in an organization by searching business social media information & hundreds of data breach databases.

What is Email Exposure Check Pro (EEC Pro)

400

Malware or hardware that observes what someone types on their keyboard, which is then sent back to the bad guys.

What is keylogger

400

Give 4 of the 7 reasons why an organization would outsource security awareness training (why they seek our product).

What is 

  1. Reduce costs

  2. Access to talent

  3. Geographic reach and scalability

  4. Compliance

  5. Mitigate risk

  6. Business focus 

  7. Leverage the cost of technology

400

SaaS

What is Software as a Service

400

 A list of trusted email address, domains and/or internet addresses that are permitted to pass through a system or filter.

What is Whitelist

500

An email plugin that gives users a safe way to handle actual or potential phishing emails.

What is Phish Alert Button (PAB)

500

A digital currency in which encryption techniques are used to regulate the generation of units of currency & verify the transfer of funds, operating independently of a central bank.

What is Bitcoin

500

The six steps to successful security awareness training 

(SAT)

What is

  1. Have a security policy and have everyone read and sign it 

  2. Have all employees take mandatory SAT ( online) with a clear deadline and reasons why they are taking the training 

  3. Make SAT part of the onboarding process (the process of integrating new hires in a company)

  4. Regularly test employees to reinforce the SAT its application 

  5. Have employees who fail phishing tests meet privately with a supervisor or HR; reward those who do well

  6. Send regular security hints and tips via email to all employees 

500

KCM

What is KnowBe4 Compliance Manager

500

The quantity of emails exposed on the internet.

What is Phishing Attack Surface