Simulation 1: Network Scan Walkthrough

You're auditing a fictional department's public-facing web server. Type the commands yourself — this is the same toolkit covered in Part 4.2, so the syntax should look familiar. Stuck? A hint appears after two attempts, and you can always reveal the exact command.

Simulation 2: Vulnerability Triage Decision Tree

You've finished scanning three systems and have limited time before the exit conference. Decide what to prioritise.

Simulation 3: Phishing Red-Flag Spotter

Click every element of this email you'd flag as a phishing red flag during a security awareness review. There are 5 to find.

From: IT-Support@fictionaldept-helpdesk.in
Subject: URGENT: Your mailbox will be suspended in 2 hours!!

Dear Employee,

Our system detected unusual activity. You must verify your credentials immediately or your account will be permanently locked. Click below to confirm your identity:

http://fictionaldept-secure-verify.com/login

Please use your full username and password to avoid disruption.

Regards,
IT Helpdesk Team

Simulation 4: OT Incident Response Tabletop

You're observing as an auditor while the OT team responds to a developing situation at a water treatment facility.

Simulation 5: Evidence Sufficiency Game

For each piece of evidence, decide: is this enough to support the finding as written, or does it need more work first?

Capstone: Mock Audit of a Fictional Department

A condensed end-to-end audit of the (fictional) Department of Urban Water Supply. Your choices at each phase shape the outcome — there's no single "correct" path, but some choices are clearly stronger than others.