About this interactive
What you're doing: reading an incident review one stage at a time. Larkfield Logistics, a fictional freight company, lost $212,600 to a former contractor who was never meant to have access to anything. At each of eight stages you decide what failed and which control would have stopped or caught it, and every answer is revealed with the reason each of the other choices falls short. Why it matters: real breaches are rarely one dramatic failure. They are a chain of ordinary gaps, each of which somebody could have closed: an account not disabled, a network never divided, a default password never changed, a process one person could run alone, logs nobody read. Seeing the chain is what makes defense in depth concrete. Every control eventually fails, so the question is never whether you have a good control but whether the next layer holds when it does. How to use it: at each stage, ask two questions before you look at the options. What principle, lifecycle step or program function was supposed to cover this? And would the control that covers it have stopped the attack, caught it, or only helped clean up afterwards? The difference between preventative, detective, corrective and recovery controls decides several of the answers, so watch for options that name the right idea with the wrong type.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →