Phishing
Identity & MFA
Devices & Browsers
Data & Physical
Reporting
100

This emotional tactic pushes you to act without checking

What is Urgency

100

The only MFA prompt you should approve

What is an MFA prompt connected to a sign-in you personally initiated and recognized

100

The keyboard shortcut that can close a Windows browser window

What is Alt + f4

100

The keyboard habit used whenever you leave your desk

What is lock the screen

100

The best time to report a suspected mistake

What is immediately

200

The safest way to verify a link asking for a vendor login

What is navigate on your own to the official website through a trusted method

200

What to do with an unexpected MFA prompt

What is deny the prompt and report the attempt
200

A pop-up's loud alarm proves this about the computer

What is nothing by itself, a webpage can imitate a security warning without actually scanning the computer

200

The principle that limits access to what your job requires

What is need to know or least privilege

200

Four useful details to include in a report

What is, what happened, when it happened, the affected device, what actions were taken

300

A polished message from a real coworker's account can still be dangerous for this reason

What is the coworker's account being compromised

300

Why caller ID or a familiar voice is not enough

What is caller ID, voices, and accounts can be spoofed or compromised

300

After an unknown EXE runs, this immediate containment step is needed

What is disconnect the device from the network and contact security / IT

300

The safe response to an unknown person following you into a restricted area

What is keep the area secured and use the approved visitor or escort process

300

After entering a password on a suspicious page, this matters more than embarassment

What is report immediately and follow password-reset guidance using a known-good device
400

The information visible before the @ symbol does not prove this

What is the sender's true identity or legitimate domain
400

The verification method should not come from this source

What is the suspicious message, call, or request itself

400

The safest source for business software

What is an approved internal source or the publisher's known official website

400

Three checks before sending sensitive data

What is confirm the recipient, approved communication channel, and necessary content
400

Why you should not forward a suspicious email to everyone as a warning

What is forwarding it spreads dangerous content and gives more employees an opportunity to interact with it

500

After receiving a QR code for an unexpected secure document, this is the best next step.

What is do not scan the QR code; verify through a known channel and report if you are suspicious

500

A caller claiming to be IT asks for your one time code

What is refuse to share the code, end the call, contact IT

500

Why running random cleanup tools can hurt an investigation

What is cleanup tools can modify or damage evidence that could prevent future risk

500

A vendor asks for a complete customer export when a few records may work

What is minimize the information provided and obtain proper authorization or escalation

500

The response culture that improves containment

What is a no-blame culture that encourages good faith and early reporting