TechKnowSurge
CompTIA Security+ 4.6 CompTIA Security+ 2.2 NIST 800-53 IA-2 NIST CSF PR.AA-03 CompTIA Tech+ 6.4 ISC2 CC 1.1
InteractiveSecurityFree

Phishing-Proof Ladder

Rank TechKnowDJ’s sign-in options from most phishing-proof to least, and name what beats each one.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

More like this

About this interactive

What you’re seeing: the sign-in options a company can choose from, shuffled, and a ladder to put them on, from the most phishing-proof at the top to the least at the bottom. The setting is TechKnowDJ, a music-tech company that just watched a phishing kit take over a rival’s accounts and wants a second sign-in step that would have stopped it. Why it matters: turning on multi-factor authentication is one of the biggest single improvements an organization can make, but not every kind of MFA holds up the same way. A fake login page can ask for a texted code and pass it straight to the real site. An attacker with a stolen password can send push prompts until someone taps Approve just to make them stop. A hardware security key or a passkey is different: it is tied to the real website’s address, so a lookalike site gets nothing at all. How to use it: rank each round by one question, how hard would a phishing attack find this, then read every explanation afterwards, right or wrong. Each one names the attack that beats that method, or the reason it resists.

What you'll learn

Aligned to

CompTIA Security+
4.6 Given a scenario, implement and maintain identity and access management.
2.2 Explain common threat vectors and attack surfaces.
NIST 800-53
IA-2 Identification and Authentication (Organizational Users)
NIST CSF
PR.AA-03 Users, services, and hardware are authenticated.
CompTIA Tech+
6.4 Compare and contrast authentication, authorization, accounting, and non-repudiation concepts.
ISC2 CC
1.1 Understand cybersecurity concepts

Key terms

Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
MFA Fatigue
An attack technique where an adversary overwhelms a user with repeated MFA push notifications, manipulating them into approving an unauthorized access request out of frustration.
Man-in-the-Middle Attack
MitM
An attack where an adversary secretly intercepts and potentially alters communications between two parties.
Authentication Factor
A category of evidence a user presents to prove identity: something you know, something you have, something you are, or somewhere you are. Multi-factor authentication is only strong when its factors come from different categories, because two proofs of the same kind fall to the same attack — the category is what counts, not the number of prompts.
Something You Know
The authentication factor category for evidence recalled from memory, such as a password, a passphrase, a PIN, a security question answer, or a pattern unlock. The device the secret is entered on is only the reader, not the factor — what is proven is that the user remembers the secret.
Time-based One-time Password
TOTP
Time-based One-time Password generates short-lived authentication codes using HMAC and the current Unix time, widely used in authenticator apps as a second factor.
Single-Factor Authentication
An authentication method that requires only one form of verification, such as a password, to grant access.
Open-Source Intelligence
OSINT
Open-Source Intelligence is the collection and analysis of publicly available information from sources such as websites, social media, and public records to support cybersecurity investigations, threat intelligence, and penetration testing reconnaissance.

Topics

Interactive Rank Multi Factor Authentication Phishing Authentication Mfa Fatigue

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →