TechKnowSurge
CompTIA Security+ 4.5 NIST 800-53 AC-4 NIST 800-53 MP-7 CompTIA Security+ 3.3 ISC2 CC 5.1 NIST 800-53 SI-4 NIST 800-53 AC-17 NIST 800-53 SC-41
InteractiveSecurityFree

Friday at TechKnowDJ

Read one employee's Friday-afternoon activity log at TechKnowDJ and flag every event where confidential data left the company.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Most data does not leave a company in a dramatic break-in. It walks out on an ordinary afternoon, one sensible-looking action at a time — a file copied to a thumb drive to finish at home, an attachment sent to a personal inbox, a contract printed to read on the train. Data loss prevention, or DLP, is the set of tools, technologies and strategies a company uses to catch those moments, and this activity puts you in the seat of the person reading its log. TechKnowDJ, a music distribution company, has just switched its DLP software on in monitor mode: it records every save, email, print, upload and remote session on a company laptop and blocks nothing yet. You get one employee's Friday afternoon and click every event where confidential data left the company. Six are planted, and together they cover every channel the lesson names. Two are removable media — a USB thumb drive and a burned DVD — the storage people forget is still plugged into every desk. One is a printer, because paper leaves the building in a bag and ends up in a recycling bin unshredded. One is remote desktop, which opens a path from the company network to a computer the company does not manage. One is email to an address outside the company. And one is the reason DLP does not rely on labels alone: a file with no label at all that turns out to hold dozens of social security numbers, which DLP software recognizes by their shape. What makes the activity work is the ten events that are fine and look almost the same. The artist roster that leaks at 13:40 was saved to the company share at 13:05, and that was exactly right. The royalty rates that went to a personal address also went to three coworkers, who were allowed to see them. A public press release sent to a reporter, a public flyer printed, a USB headset that cannot store a byte, a logo downloaded into the company rather than out of it — none of these is a leak, and a DLP policy that blocked them would stop the work without protecting anything. The difference, every time, is two questions: how sensitive is this data, and where is it going? Classification labels answer the first, which is why DLP depends on them. Submit and every leak is explained along with the control that closes it: removable media blocking, print blocking, blocking remote desktop, and scanning outbound email by label and by content.

What you'll learn

Aligned to

CompTIA Security+
4.5 Given a scenario, modify enterprise capabilities to enhance security.
3.3 Compare and contrast concepts and strategies to protect data.
NIST 800-53
AC-4 Information Flow Enforcement
MP-7 Media Use
SI-4 System Monitoring
AC-17 Remote Access
SC-41 Port and I/O Device Access
ISC2 CC
5.1 Understand data security

Key terms

Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Data Classification
The process of organizing and labeling data based on its sensitivity or confidentiality level to inform access and handling policies.
Removable Media Blocking
A DLP control that prevents the use of external storage devices to stop sensitive data from being copied or transported outside the organization.
Print Blocking
A DLP control that restricts users from printing sensitive documents to prevent physical data leakage.
Remote Desktop Protocol
RDP
Remote Desktop Protocol is a Microsoft protocol that enables remote graphical access to Windows systems; it is a frequent attack target commonly exploited via credential brute-forcing, session hijacking, and unpatched vulnerabilities such as BlueKeep.
Sensitive Data
Information that must be protected from unauthorized access due to its private, confidential, or regulated nature, such as customer records or proprietary business plans.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Endpoint
Any device that connects to a network, including computers, smartphones, tablets, and IoT devices.

Topics

Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →