TechKnowSurge
NIST 800-53 PS-4 NIST 800-53 PS-5 NIST 800-53 AC-5 NIST CSF PR.AA-05 NIST CSF GV.RR-04 ISC2 CC 1.4 Cisco CCST Cybersecurity 1.1 CompTIA A+ Core 2 2.1 ISC2 CC 1.1 ISC2 CC 1.2 NIST 800-53 RA-7 NIST CSF GV.RM-04
InteractiveSecurityFree

Breach Post-Mortem

Walk through a fictional logistics firm's breach one stage at a time and name, at each step, the gap that let it through and the control that would have stopped it.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: reading an incident review one stage at a time. Larkfield Logistics, a fictional freight company, lost $212,600 to a former contractor who was never meant to have access to anything. At each of eight stages you decide what failed and which control would have stopped or caught it, and every answer is revealed with the reason each of the other choices falls short. Why it matters: real breaches are rarely one dramatic failure. They are a chain of ordinary gaps, each of which somebody could have closed: an account not disabled, a network never divided, a default password never changed, a process one person could run alone, logs nobody read. Seeing the chain is what makes defense in depth concrete. Every control eventually fails, so the question is never whether you have a good control but whether the next layer holds when it does. How to use it: at each stage, ask two questions before you look at the options. What principle, lifecycle step or program function was supposed to cover this? And would the control that covers it have stopped the attack, caught it, or only helped clean up afterwards? The difference between preventative, detective, corrective and recovery controls decides several of the answers, so watch for options that name the right idea with the wrong type.

What you'll learn

Aligned to

NIST 800-53
PS-4 Personnel Termination
PS-5 Personnel Transfer
AC-5 Separation of Duties
RA-7 Risk Response
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.
GV.RR-04 Cybersecurity is included in human resources practices.
GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated.
ISC2 CC
1.4 Understand cybersecurity controls
1.1 Understand cybersecurity concepts
1.2 Understand risk management concepts
Cisco CCST Cybersecurity
1.1 Define essential security principles
CompTIA A+ Core 2
2.1 Summarize various security measures and their purposes.

Key terms

Offboarding
The process of revoking a departing or transitioning employee's system access and decommissioning their accounts to prevent unauthorized access.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Hardening
The process of securing a system by reducing its attack surface — disabling unnecessary services, applying configuration best practices, removing default credentials, and keeping software patched. Hardened systems offer fewer opportunities for exploitation.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Log Management
The process of collecting, storing, analyzing, and monitoring log data generated by systems and applications.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Recovery Control
A security control designed to restore systems, data, and normal operations after a security incident has been identified and contained. Backup restoration, disaster recovery procedures, and system reimaging are examples of recovery controls.
Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Personnel Lifecycle
The full span of an employee's relationship with an organization, encompassing onboarding, role transitions, and offboarding, each of which carries distinct cybersecurity implications.
Onboarding
The process of integrating a new employee into an organization, including provisioning system access, assigning permissions, and providing security awareness training.
Cybersecurity Program
An ongoing organizational function that encompasses risk assessment, policy development, regulatory compliance, employee training, and accountability to protect the organization continuously.
Administrative Control
A cybersecurity control based on policies, procedures, and checklists that guide how an organization manages and implements its security practices.
Risk Reduction
A risk response strategy that takes steps to decrease the probability or impact of a risk.
Risk Transference
A risk response strategy that shifts the financial or operational burden of a risk to a third party, such as through insurance.
Risk Acceptance
A risk response strategy that acknowledges a risk and proceeds without additional mitigation because the benefits outweigh the potential harm.

Topics

Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →