Unit 1 · Case Files
0 / 14 answered
Briefing — read before you begin

Unit 1 Case Files: Introduction to Security

You've been handed five open cases from the incident log. Each one describes something that actually happens to real people online — a suspicious email, a hijacked account, a rigged Wi-Fi network, a cloned voice, a vulnerable app. Read the case narrative, examine the evidence, and answer the investigator's questions in your own words. There's no single "correct" paragraph — your reasoning is what's being evaluated.

Estimated time35–45 minutes
Cases5 open, 14 questions total
AutosaveOn this device, as you type
SubmittingUse "Export my case file" when done
CASE 2026-1A

Detecting Phishing Messages

UNVERIFIED SENDER

You're sitting next to your teacher at their desk, working on a problem, when they receive an email. Your teacher wants to click the link inside it — but something about it makes you want to look twice first.

To: ljones@school.edu
From: do-not-reply@g00gle.com
Subject: [Urgent!] Access Requested

"One of your students has requested access to make a copy of a document. Click this link to authorize your student to copy your document. If you don't click the link, your student won't be able to copy the document and complete their assignment. Research shows that the faster teachers respond to students' document-sharing requests, the more likely students are to submit assignments on time. — The Google Drive Team"

Investigator's questions
saved
saved
saved
CASE 2026-1B

Detecting Unauthorized Logins

ACCOUNT ACTIVITY FLAGGED

You play an online game that lets users build and manage virtual teams. One day you notice some of your past choices were changed without your input. You normally only log in on weekends and evenings — you're in school on weekdays. Pull up the account activity log below.

Website logins — click a row to flag it as suspicious
#Entry date / timeDevice IP address
1Saturday, April 18 · 10:43208.104.29.211
2Sunday, April 19 · 20:51208.104.29.211
3Tuesday, April 21 · 18:34208.104.29.211
4Wednesday, April 22 · 11:13142.54.195.17
5Saturday, April 25 · 13:21208.104.29.211
6Sunday, April 26 · 21:18208.104.29.211
7Monday, April 27 · 10:07142.54.195.17
8Wednesday, April 29 · 19:12208.104.29.211
0 rows flagged
Investigator's questions
saved
saved
saved
CASE 2026-1C

Verifying Network Authenticity

ROGUE ACCESS POINT

At your neighborhood coffee shop, you try to connect to the Wi-Fi and land on a captive portal that offers to log you in with an existing account from a popular platform. You use it, get online, and start studying while your music streams in the background — until it suddenly stops. You've been logged out, and your password is now "invalid."

A sign on the wall reads "Login to our free Wi-Fi network: Sunshine Coffee Wi-Fi" — but you actually joined a network called "Guest Wi-Fi." That network, and its captive portal, were set up by an adversary. When you entered your credentials, the adversary captured them and used them to log in to every other service linked to that same account, including your music service, then changed the password to lock you out.

Investigator's questions
saved
saved
CASE 2026-1D

AI-Powered Cyberattacks

SYNTHETIC VOICE

A relative calls you, frantic: "Are you okay? Did you get the money I sent? How did you end up in so much trouble?" Once you calm them down, they explain — they got a call from "you" claiming to have been arrested and needing bail money, and they wired it immediately. It sounded exactly like you. You were never arrested and never made that call.

What really happened: two weeks earlier you accepted a friend request from someone with a name similar to a classmate's. It wasn't them — it was an adversary who scraped voice samples from your public short-form videos, fed them into a voice-cloning tool, found your relative through social media, and called them pretending to be you in a fabricated emergency.

Investigator's questions
saved
saved
saved
CASE 2026-1E

AI-Powered Cyber Defense

CODE REVIEW — PRE-LAUNCH

Your company is building a web app that lets customers place orders. It pulls live inventory from the warehouse database and updates it whenever an order is placed. Before launch, you ask an AI-powered tool to review the code for security issues.

The tool flags several places where user input is fed directly into database requests — a weakness an adversary could use to learn about warehouse contents or alter the database in unintended ways. It recommends validating and sanitizing input before it ever reaches the database. The development team reviews those recommendations, updates the code, and pushes it to a testing environment before deployment.

Investigator's questions
saved
saved
saved