Phishing or Fishing?
Password Power
Cyber Policy & Compliance
Name That Breach
Cyber in the News
100

This type of phishing targets a specific person using personalized info

What is spear phishing?

100

Minimum character length required for DODEA accounts.

What is 15?

100

This DoD policy governs cyber workforce qualifications.

What is DoDI 8140?

100

This company’s 2013 breach exposed over 3 billion accounts.

What is Yahoo?

100

In 2025, this federal agency released updated AI cybersecurity guidance.

What is CISA?

200

A fake “urgent” email from your “boss” asking for gift cards is an example of this

What is business email compromise?

200

Using a phrase like “GoNavyBeatArmy2025!” is an example of this

What is a passphrase?

200

This DON Cyber Strategy Line of Effort emphasizes supporting the workforce.

What is Line of Effort 1: Improve and Support the Cyber Workforce?

200

This 2021 cyberattack shut down a major fuel pipeline on the East Coast.

What is the Colonial Pipeline attack?

200

In 2023, this major social media company (now called “X”) faced scrutiny after a breach exposed user data and raised concerns about platform security.

What is Twitter?

300

True or False: NAVAIR IT will never email you asking for your DODEA password.

True

300

This type of authentication requires two or more factors, like CAC + PIN.

What is multi-factor authentication?

300

NAVAIR uses this system to track and assign official taskers and correspondence

What is ETMS2?

300

In 2015, this  breach compromised millions of security clearance records.

What is the OPM data breach?

300

In 2023, the U.S. banned this app from government devices due to concerns it could expose data to foreign governments.

What is TikTok?

400

The most common type of malicious attachment in phishing emails.

What is a PDF or Word doc with macros?

400

You can reuse your DODEA password on your personal Netflix account.

False

400

RMF stands for this.

What is Risk Management Framework?

400

This 2017 ransomware attack disrupted hospitals worldwide.

What is WannaCry?

400

This popular video conferencing platform saw a huge surge during the pandemic and has also been a target for hackers trying to “bomb” meetings.

What is Zoom?

500

Clicking a link that takes you to a fake login site is known as this type of attack.

What is credential harvesting?

500

A password manager helps reduce this risk

What is password reuse?

500

In 2020, this supply chain attack infiltrated government and defense networks.

What is SolarWinds?

500

In 2022, Russia’s invasion of Ukraine included this type of cyberattack, which disrupts services by overwhelming systems with traffic.

What is a Distributed Denial of Service (DDoS) attack?