Cards Collection

Browse all game cards by type

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

đŸ”Ĩ

Expert Phishing Detection

Special Challenge - Expert

Advanced phishing detection - analyze carefully!

Difficulty: Hard

From:

noreply-update@microsoft.com

Subject:

Mandatory update of terms of service

Real link:

https://account.microsoft.com.security-policy.net

❓ Is this legitimate or dangerous?

đŸ”Ĩ

Password Strength Expert

Special Challenge - Expert

Which password is truly the strongest?

Difficulty: Hard

Which is really the strongest password?

  • A. &T4p9Lm!2
  • B. GreenButterflyHitsAWallIn2025
  • C. N!k0lA5-R00
  • D. %zF3-@Lp
đŸ”Ĩ

Social Engineering Attack

Special Challenge - Expert

Real enterprise threat scenario

Difficulty: Hard

A "technician" calls you: "We need to reset your MFA due to an issue. I'll send you a code, read it to me to validate."

📋 The call seems internal (company number displayed)

❓ Is this legitimate?

đŸ”Ĩ

Mixed Content Security

Special Challenge - Expert

Technical web security analysis

Difficulty: Hard

A website uses HTTPS, but loads an external script via HTTP.

📋 Main page: https:// | External script: http://

❓ Is this secure?

đŸ”Ĩ

Evil Twin WiFi

Special Challenge - Expert

Network security threat detection

Difficulty: Hard

Employee connects to "Company-Secure" (WPA2, normally no captive portal).

📋 Phone suddenly opens a login page like a captive portal

❓ Bug or security risk?

đŸ”Ĩ

Modern Malware Behavior

Special Challenge - Expert

Identify advanced malware characteristics

Difficulty: Hard

Which behavior indicates modern stealthy malware?

  • A. PC overheating
  • B. Screen flickering
  • C. No visible symptoms
  • D. Pop-ups appearing
đŸ”Ĩ

Technical Email Phishing

Special Challenge - Expert

Very tricky phishing detection

Difficulty: Hard

From:

support@paypal.com

Subject:

Security verification required

Link displayed:

https://paypal.com/security

Real link:

https://paypal.com.security-check.info

❓ Is this legitimate?

đŸ”Ĩ

MFA Authentication Logic

Special Challenge - Expert

Advanced authentication reasoning

Difficulty: Hard

A company replaces passwords with a 6-digit PIN + MFA application.

📋 Old: Long password only | New: Short PIN + MFA app

❓ Does this reduce security?

đŸ”Ĩ

RDP Network Exposure

Special Challenge - Expert

Server security assessment

Difficulty: Hard

A Windows server exposes port 3389 (RDP) on the Internet.

📋 Security measures: Long password, MFA enabled, Active firewall

❓ Is this sufficient?

đŸ”Ĩ

SSL Certificate Trust

Special Challenge - Expert

Expert certificate analysis

Difficulty: Hard

Banking site in HTTPS with valid certificate.

📋 Padlock OK, Valid certificate, Issuer: Let's Encrypt, No browser alert

❓ Is this sufficient proof the site is authentic?

} else { answerDiv.classList.add('hidden'); button.textContent = 'Show Answer'; button.classList.remove('bg-gray-600', 'hover:bg-gray-700', 'dark:bg-gray-500', 'dark:hover:bg-gray-600'); button.classList.add('bg-blue-600', 'hover:bg-blue-700', 'dark:bg-blue-500', 'dark:hover:bg-blue-600'); } }