Receptionist plugged in USB labeled 'Q2 Bonus' — EDR flagged PowerShell launch
A easy Cybersecurity scenario on Suspicious USB Device.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · usb-drop-lobby-bonus
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Removable-media awareness discipline
- Safe-handling response to unknown devices
- Replication Through Removable Media · Initial AccessT1091 · TA0001MappedHigh confidence
Trains triage of an unknown removable-media drop in a public area.
- Per-Host Application WhitelistingD3-PANMappedMedium confidence
Trains the host-control posture that limits unknown-binary execution.
- Access Control · ProtectPR.AC · PRMappedHigh confidence
Trains physical and endpoint-access posture for unsolicited media.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains initial response to a found-USB awareness report.
- Basic Cybersecurity Training2.FMappedHigh confidence
Trains the awareness baseline the scenario exercises.
- Security Awareness and Skills TrainingControl 14MappedHigh confidence
Trains the user-side awareness control.
- Malware DefensesControl 10MappedMedium confidence
Trains the endpoint-defense control invoked when the media is examined safely.