About this interactive
Awareness programs fail in a predictable way: an organization buys one generic course, assigns it to everyone once a year, and is surprised when the same incidents keep happening. The premise of this activity is the correction. A behavior that has already been observed is a diagnosis, and a diagnosis points at one intervention rather than all of them. Sorting these thirteen vignettes is practice at the question a program designer actually asks — not what went wrong, and not what the attacker did, but what this person did not know, because that is the only thing training can change. Phishing Awareness is the right module when the employee was deceived by an inbound message and acted on it. The IT-impersonation email that harvested credentials is the archetype: a message arrived, it looked authoritative, the employee entered their password into an attacker's form, and the account was compromised within minutes. The unknown-sender attachment opened because "it looked official" is the same failure with a different payload — the employee's trust decision was made on appearance rather than verification. The voicemail from "the bank" is the item most often filed somewhere else, and it is worth slowing down on. It is not email, so it is not phishing in the narrow sense; it is vishing, social engineering delivered by voice. But the training module that closes the gap is still Phishing Awareness, because in practice that module teaches the verification habit across every channel — stop, do not respond in the channel the request arrived in, contact the organization through a number you already had. Naming the module after its most common vector does not narrow its content. This is objective two in miniature: the technique and the intervention are two different questions, and only one of them is being asked here. Password Hygiene is the right module when the credential practice itself is the weakness, with no deception involved at all. Reusing one password across twelve accounts, corporate email among them, means a breach at any consumer site hands an attacker the corporate login — this is why credential-stuffing works, and why password reuse is the single habit worth naming in a program. The mention of personal social media in that vignette is a deliberate distractor; nothing was posted and no policy about posting was broken, so Social Media Policy is not the gap. The VPN password on a Post-it under the keyboard is the genuinely contentious item in this set, and it is better to know that before it is graded. It has an obvious physical dimension — a written secret in an unattended workspace is exactly what a clean-desk standard exists to prevent — and an instructor filing it under Physical Security is not making a mistake. This set files it under Password Hygiene on the reading that the Post-it is a symptom rather than the disease: the employee wrote the password down because they could not remember it, and the intervention that removes the behavior is a password manager, not a lecture about desks. Ask which training makes the note unnecessary. Physical Security is the right module when the failure is about access to space and equipment. Holding the lobby door for someone who did not badge in is tailgating, and the vignette captures why it is so hard to train away: the employee was being polite, and the assumption that the stranger was a new hire is exactly the reasoning an attacker relies on. Worth distinguishing from piggybacking, where the person being followed knowingly consents — here the employee did consent, believing the story, which is what makes the two terms blur in practice. The laptop left unlocked and unattended in a conference room is the same category from the other direction: no attacker is required, only opportunity, and the fix is a habit plus a short screen-lock timeout. Insider Threat is the right module when the risk originates with someone who already has legitimate access, and the three items here deliberately span its range. The developer copying proprietary repositories to a personal device to work over the weekend is the unintentional insider — the motive is diligence, the effect is that source code now lives on an unmanaged laptop outside every control the organization has. The employee sending customer PII to a personal Gmail account to keep work samples is a step further along the same road: still self-justified, but now regulated data has left the boundary, and this is data exfiltration whatever the intent behind it. The terminated contractor still using active VPN credentials is the item that deserves an honest caveat. Read strictly, the failure there is a process failure — offboarding did not revoke access — and no amount of training for that contractor would have helped, because the person who needed to act was whoever owned deprovisioning. It sits in Insider Threat because that is the module where offboarding, access review and the reporting of anomalous access by colleagues are taught, and because the awareness gap it exposes is organizational rather than individual. Use it as the reminder that awareness training is one control among several, and that some observed behaviors point at a broken process the training program should escalate rather than absorb. Social Media Policy is the right module when nothing was hacked and nothing was stolen, but information walked out through a public post. The three items are chosen so that no single post looks damaging on its own, which is the entire point. A photo of a planning board reveals product names and launch dates; a frustrated post about an outage names an internal tool and a vendor; a shared screenshot of a congratulatory Slack message names people who have not started yet. Each is trivial in isolation. Together they give an attacker a product roadmap, a technology stack with a supply-chain relationship attached, and a list of new hires who do not yet know who their colleagues are — which is the ideal target list for the impersonation email that arrives in week one. That aggregation effect is what a social media policy exists to explain, and it is why this module cannot be taught as a list of forbidden words. Two closing habits are worth carrying out of this set. First, read for the root cause rather than the surface noun: several vignettes mention a password, a device or a social platform without the gap being about any of those things. Second, notice that the attack technique and the training intervention are independent axes. Vishing is social engineering delivered by voice and still routes to Phishing Awareness; a Post-it is a physical artifact and still routes to Password Hygiene; a terminated contractor's live VPN account is an access-management defect and still routes to Insider Threat. In an exam, let the answer options tell you which axis is being asked about. In a real program, the label matters far less than whether the intervention you chose actually removes the behavior you observed.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →