About this interactive
What you’re seeing: the sign-in options a company can choose from, shuffled, and a ladder to put them on, from the most phishing-proof at the top to the least at the bottom. The setting is TechKnowDJ, a music-tech company that just watched a phishing kit take over a rival’s accounts and wants a second sign-in step that would have stopped it. Why it matters: turning on multi-factor authentication is one of the biggest single improvements an organization can make, but not every kind of MFA holds up the same way. A fake login page can ask for a texted code and pass it straight to the real site. An attacker with a stolen password can send push prompts until someone taps Approve just to make them stop. A hardware security key or a passkey is different: it is tied to the real website’s address, so a lookalike site gets nothing at all. How to use it: rank each round by one question, how hard would a phishing attack find this, then read every explanation afterwards, right or wrong. Each one names the attack that beats that method, or the reason it resists.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →