Hands-on·Scenario mode

Work a real incident
in four minutes.

Scenario cases hand you what a responder actually gets: the log, the config, the forwarded email. You make the calls one at a time, get told straight away whether you were right, and finish with a debrief on why it mattered.

Case 1 free · No card · 19 cases

logPostgreSQL connection and statement log
103:08:51 host=198.51.100.73 user=postgres db=reports auth=failed203:09:04 host=198.51.100.73 user=report_api db=reports auth=failed303:11:27 host=10.60.4.22 user=report_api db=reports auth=success403:12:10 host=10.60.4.22 user=report_api stmt=SELECT count(*) FROM daily_sales503:18:42 host=198.51.100.73 user=report_api db=reports auth=success603:19:06 host=198.51.100.73 user=report_api stmt=COPY customer_contacts TO STDOUT703:19:18 host=198.51.100.73 user=report_api disconnect bytes_out=48277120

Evidence from the case “Reporting database is published to the internet

Three tasks, three cases. Make the call.

Borrowed from three different cases, one per difficulty. Read the evidence, pick an answer, and see the same explanation the app would give you.

Task 1 of 3Hands-on·Easy

From the case “Failed sign-ins from a single address

The identity provider alerts on a burst of failed sign-ins from one external address this morning. MFA enrolment is still optional for older accounts.

tableIdentity provider sign-in log, 07:40 to 08:10
1TIME   USER                          SOURCE          MFA        RESULT207:41  m.okafor@northbay.example     203.0.113.58    -          Failure: invalid password307:42  r.lindqvist@northbay.example  203.0.113.58    -          Failure: invalid password407:43  s.ahmed@northbay.example      203.0.113.58    none set   Success507:44  t.byrne@northbay.example      203.0.113.58    -          Failure: invalid password607:45  j.moore@northbay.example      203.0.113.58    -          Failure: invalid password707:46  a.chen@northbay.example       203.0.113.58    -          Failure: invalid password807:47  d.walsh@northbay.example      203.0.113.58    -          Failure: invalid password907:48  p.novak@northbay.example      203.0.113.58    -          Failure: invalid password1007:52  j.moore@northbay.example      198.51.100.23   -          Failure: invalid password1107:52  j.moore@northbay.example      198.51.100.23   -          Failure: invalid password1207:53  j.moore@northbay.example      198.51.100.23   passed     Success1308:05  s.ahmed@northbay.example      203.0.113.58    none set   Success1408:06  a.chen@northbay.example       10.20.14.31     passed     Success

What is happening from 203.0.113.58?

Pick one, then check.

One situation. Several decisions.

A case is a session, not a question. The evidence stays on screen and the tasks change beneath it, in the order a real investigation runs.

Briefing

One situation, in plain words. Who you are, what has been reported, what you need to decide.

Evidence

One to three artifacts, exactly as the real tool shows them. Emails carry a raw-source view, because the headers are where the truth lives.

Decisions

Four or five linked tasks: identify, analyse, act. Each answer is revealed before the next task, so one wrong call never poisons the rest.

Debrief

What the pattern was, where you meet it at work, and one thing worth reading next.

No timer, no combo, no arcade chrome. You are meant to read the log.

The casebook

19 cases, easy to hard, each unlocked by finishing the one before. Replay any you have cleared. New cases land in batches as they pass review.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19

Easy5

  • 1Urgent supplier bank change
  • 2Fake employee benefits notice
  • 3A user forwards a suspicious email
  • 4Wireless profiles before office opening
  • 5Failed sign-ins from a single address

Medium7

  • 6Renewed portal serves an incomplete certificate chain
  • 7Customer exports exposed from cloud storage
  • 8Firewall review finds an open management path
  • 9Invoice worker has excessive cloud permissions
  • 10Contractors bypass the cloud MFA policy
  • 11SaaS tenant isolation design
  • 12A deployment key is found in a public repository

Hard7

  • 13Reporting database is published to the internet
  • 14Kerberos ticket harvesting and egress
  • 15Build runner can take control of the cluster
  • 16Suspicious lateral movement
  • 17Public web PKI design
  • 18Remote PowerShell and design archive
  • 19Customer data pulled through the orders API

Every task feeds your accuracy and coverage on the Progress page. Three badges track the ladder.

Built for the call, not the recall.

Studying for a cert

Security+, CySA+ and CISSP all lean on scenario questions, and the hard ones come with evidence attached. Practise reading it before the exam does it to you.

Working a queue

SOC analysts and on-call engineers. The cases are built from the sources you already have open: authentication events, flows, CloudTrail, process trees.

Building or reviewing systems

Half the cases are configuration reviews: a firewall rule base, an IAM policy, a Kubernetes runner. See the misconfiguration from the side that exploits it.

Plans

Free

Case 1, once, complete with its debrief. Plus one quiz a day across the free modes.

Pro · $8/mo or $80/yr

Every case, replays, new cases as they land, and all of Pro. Cancel any time.

See the full comparison

Questions people ask first

No. There is no terminal, no drag and drop, and no simulated command line. A case is a set of four or five linked select questions over real artifacts, closer to a CCNA testlet than a CompTIA performance-based question. The skill it trains is the same one a PBQ tests: reading evidence and making the call.

Work case 1. It is on us.

A real incident, the debrief, and your score. Free forever, no card.

Create free account