TechKnowSurge
CompTIA Security+ 5.6 CompTIA Security+ 2.1 CompTIA Security+ 1.2 ISC2 CC 2.3 CompTIA Security+ 2.2 CompTIA Security+ 4.6 CompTIA Security+ 5.1
InteractiveSecurityFree

Security Awareness Training Scenario Selector

Match employee behavior vignettes to the training module they most urgently need: Phishing Awareness, Password Hygiene, Physical Security, Insider Threat, or Social Media Policy.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Awareness programs fail in a predictable way: an organization buys one generic course, assigns it to everyone once a year, and is surprised when the same incidents keep happening. The premise of this activity is the correction. A behavior that has already been observed is a diagnosis, and a diagnosis points at one intervention rather than all of them. Sorting these thirteen vignettes is practice at the question a program designer actually asks — not what went wrong, and not what the attacker did, but what this person did not know, because that is the only thing training can change. Phishing Awareness is the right module when the employee was deceived by an inbound message and acted on it. The IT-impersonation email that harvested credentials is the archetype: a message arrived, it looked authoritative, the employee entered their password into an attacker's form, and the account was compromised within minutes. The unknown-sender attachment opened because "it looked official" is the same failure with a different payload — the employee's trust decision was made on appearance rather than verification. The voicemail from "the bank" is the item most often filed somewhere else, and it is worth slowing down on. It is not email, so it is not phishing in the narrow sense; it is vishing, social engineering delivered by voice. But the training module that closes the gap is still Phishing Awareness, because in practice that module teaches the verification habit across every channel — stop, do not respond in the channel the request arrived in, contact the organization through a number you already had. Naming the module after its most common vector does not narrow its content. This is objective two in miniature: the technique and the intervention are two different questions, and only one of them is being asked here. Password Hygiene is the right module when the credential practice itself is the weakness, with no deception involved at all. Reusing one password across twelve accounts, corporate email among them, means a breach at any consumer site hands an attacker the corporate login — this is why credential-stuffing works, and why password reuse is the single habit worth naming in a program. The mention of personal social media in that vignette is a deliberate distractor; nothing was posted and no policy about posting was broken, so Social Media Policy is not the gap. The VPN password on a Post-it under the keyboard is the genuinely contentious item in this set, and it is better to know that before it is graded. It has an obvious physical dimension — a written secret in an unattended workspace is exactly what a clean-desk standard exists to prevent — and an instructor filing it under Physical Security is not making a mistake. This set files it under Password Hygiene on the reading that the Post-it is a symptom rather than the disease: the employee wrote the password down because they could not remember it, and the intervention that removes the behavior is a password manager, not a lecture about desks. Ask which training makes the note unnecessary. Physical Security is the right module when the failure is about access to space and equipment. Holding the lobby door for someone who did not badge in is tailgating, and the vignette captures why it is so hard to train away: the employee was being polite, and the assumption that the stranger was a new hire is exactly the reasoning an attacker relies on. Worth distinguishing from piggybacking, where the person being followed knowingly consents — here the employee did consent, believing the story, which is what makes the two terms blur in practice. The laptop left unlocked and unattended in a conference room is the same category from the other direction: no attacker is required, only opportunity, and the fix is a habit plus a short screen-lock timeout. Insider Threat is the right module when the risk originates with someone who already has legitimate access, and the three items here deliberately span its range. The developer copying proprietary repositories to a personal device to work over the weekend is the unintentional insider — the motive is diligence, the effect is that source code now lives on an unmanaged laptop outside every control the organization has. The employee sending customer PII to a personal Gmail account to keep work samples is a step further along the same road: still self-justified, but now regulated data has left the boundary, and this is data exfiltration whatever the intent behind it. The terminated contractor still using active VPN credentials is the item that deserves an honest caveat. Read strictly, the failure there is a process failure — offboarding did not revoke access — and no amount of training for that contractor would have helped, because the person who needed to act was whoever owned deprovisioning. It sits in Insider Threat because that is the module where offboarding, access review and the reporting of anomalous access by colleagues are taught, and because the awareness gap it exposes is organizational rather than individual. Use it as the reminder that awareness training is one control among several, and that some observed behaviors point at a broken process the training program should escalate rather than absorb. Social Media Policy is the right module when nothing was hacked and nothing was stolen, but information walked out through a public post. The three items are chosen so that no single post looks damaging on its own, which is the entire point. A photo of a planning board reveals product names and launch dates; a frustrated post about an outage names an internal tool and a vendor; a shared screenshot of a congratulatory Slack message names people who have not started yet. Each is trivial in isolation. Together they give an attacker a product roadmap, a technology stack with a supply-chain relationship attached, and a list of new hires who do not yet know who their colleagues are — which is the ideal target list for the impersonation email that arrives in week one. That aggregation effect is what a social media policy exists to explain, and it is why this module cannot be taught as a list of forbidden words. Two closing habits are worth carrying out of this set. First, read for the root cause rather than the surface noun: several vignettes mention a password, a device or a social platform without the gap being about any of those things. Second, notice that the attack technique and the training intervention are independent axes. Vishing is social engineering delivered by voice and still routes to Phishing Awareness; a Post-it is a physical artifact and still routes to Password Hygiene; a terminated contractor's live VPN account is an access-management defect and still routes to Insider Threat. In an exam, let the answer options tell you which axis is being asked about. In a real program, the label matters far less than whether the intervention you chose actually removes the behavior you observed.

What you'll learn

Aligned to

CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
2.1 Compare and contrast common threat actors and motivations.
1.2 Summarize fundamental security concepts.
2.2 Explain common threat vectors and attack surfaces.
4.6 Given a scenario, implement and maintain identity and access management.
5.1 Summarize elements of effective security governance.
ISC2 CC
2.3 Understand security awareness

Key terms

Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Credential Harvesting
A technique used by attackers to capture usernames and passwords by impersonating a trusted application or login interface.
Password Reuse
The poor security practice of using the same password across multiple accounts, increasing exposure if one account is compromised.
Password Manager
A secure application that stores and manages a user's passwords in an encrypted vault, requiring only one master credential for access. Password managers enable users to maintain strong, unique passwords for every account without memorizing them.
Physical Security
The use of tangible controls — such as locks, barriers, surveillance cameras, and access badges — to protect facilities, hardware, and infrastructure from unauthorized physical access, theft, or damage.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Piggybacking
A physical security attack where an unauthorized person follows an authorized person through a secured entry point with the authorized person's consent, typically by deceiving them.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Offboarding
The process of revoking a departing or transitioning employee's system access and decommissioning their accounts to prevent unauthorized access.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →