TechKnowSurge
CompTIA Security+ 5.6 NIST 800-53 AT-2 NIST 800-53 AT-3 ISC2 CC 2.3 NIST NICE K0638 CompTIA A+ Core 2 2.4 Cisco CCST IT 5.2 NIST NICE K1087
InteractiveSecurityFree

Security Awareness Life Cycle Walkthrough

Run a security awareness program for a fictional clinic group through all four life cycle stages, deciding at each step what to teach, how to deliver it, how to test it, and what the results mean.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

More like this

About this interactive

What you're doing: running a security awareness program rather than sitting through one. Harbor Ridge Medical Group is a fictional clinic group with 420 staff, 240 of whom have no work email, and an awareness program that until now was a single annual slide deck with a 96% completion rate and nothing to show for it. You take it over and walk it through all four stages of the training life cycle — Develop, Deliver, Test, Monitor — making eight decisions along the way, each revealed with the reasoning and with the reason the other three options fall short. Why it matters: almost everything that makes an awareness program work or fail is a program-design decision rather than a fact about phishing. A policy that was published but never communicated will not be followed. A perfectly delivered email reaches the half of this workforce that has email. A simulation nobody can fail measures nothing, and a 96% completion rate is not awareness. The stage most programs never reach is the last one, and it is the one that closes the loop: monitoring exists to change what you develop next. How to use it: at each stage, ask who the decision is actually about before you look at the options — the whole organization, or one person. Several items turn on that difference, and several wrong answers are the right idea aimed at the wrong population. Watch for the options that are genuinely half right: threat intelligence really is an input, credential theft really is the most severe outcome, and a wave of pretext phone calls really is an incident. Each of those is true, and none of them is the answer.

What you'll learn

Aligned to

CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
NIST 800-53
AT-2 Literacy Training and Awareness
AT-3 Role-Based Training
ISC2 CC
2.3 Understand security awareness
NIST NICE
K0638 Knowledge of security awareness programs
K1087 Knowledge of social engineering tools and techniques
CompTIA A+ Core 2
2.4 Explain common social-engineering attacks, threats, and vulnerabilities
Cisco CCST IT
5.2 Recognize how to avoid becoming a victim of social engineering attacks

Key terms

Security Awareness
The ongoing effort to ensure employees understand security policies, recognize threats, and apply safe behaviors through multiple communication methods beyond formal training alone.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Simulated Phishing Campaign
A controlled test in which an organization sends fake phishing emails to employees to assess and reinforce their ability to recognize and report phishing attempts.
Anomalous Behavior
Activity that deviates from normal or expected patterns and may indicate a social engineering attempt or security threat.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.

Topics

Interactive Predict Security Awareness Training Training Life Cycle Social Engineering Phishing Simulation Administrative Controls

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →