Make My Jeopardy

Cybersecurity Awareness Jeopardy

Phishing red flags, password hygiene, and social engineering, packaged as a game show. Copy the board for free and run it with everyone buzzing in on their phones.

6 categories · 30 clues · Final Jeopardy · everyone buzzes in from their phone

Copies all 30 clues into an editor of your own. Free, no account needed.

Every clue on this board

This page is public, so anyone can read the answers — copy the board and swap a few clues before game day.

Phishing Red Flags

  1. $200

    This urgent tone, pressuring a reader to act immediately or face a consequence, is a common tactic in fraudulent emails meant to short-circuit careful thinking.

    What is a sense of urgency?

  2. $400

    This mismatch, where the visible text of a link differs from the web address it actually points to, is a classic sign of a fraudulent email.

    What is a mismatched link?

  3. $600

    This deceptive technique disguises a sender's email address to look like it comes from a trusted source, such as a coworker or a bank.

    What is email spoofing?

  4. $800

    This narrowly targeted form of phishing is customized with personal details about a specific victim, such as their name, employer, or job title.

    What is spear phishing?

  5. $1,000

    This form of phishing targets senior executives specifically, often impersonating a CEO to pressure staff into a wire transfer or a data release.

    What is whaling?

Password Hygiene

  1. $200

    This practice, using a different password for every account, limits the damage if just one of those accounts is ever compromised.

    What is a unique password?

  2. $400

    This security add-on requires a second proof of identity, such as a code sent to a phone, in addition to a password.

    What is multi-factor authentication?

  3. $600

    This software tool securely stores and automatically fills in unique, complex passwords so a user does not have to memorize each one.

    What is a password manager?

  4. $800

    This type of attack systematically tries enormous numbers of character combinations until it guesses the correct password.

    What is a brute-force attack?

  5. $1,000

    This passwordless authentication method uses a device-stored cryptographic key pair, unlocked by a fingerprint or device PIN, to verify identity.

    What is a passkey?

Malware and Ransomware

  1. $200

    This umbrella term covers any software intentionally designed to damage, disrupt, or gain unauthorized access to a computer system.

    What is malware?

  2. $400

    This type of malicious program encrypts a victim's files and demands payment in exchange for the key needed to unlock them.

    What is ransomware?

  3. $600

    This self-replicating type of malware spreads across networks and systems on its own, without needing a host file or user action to propagate.

    What is a worm?

  4. $800

    This type of malware disguises itself as legitimate or desirable software to trick a user into installing it, named for a wooden gift from Greek mythology.

    What is a Trojan horse?

  5. $1,000

    This type of malware secretly records a victim's keystrokes to capture sensitive information like passwords and card numbers.

    What is a keylogger?

Safe Browsing and Wi-Fi

  1. $200

    This padlock icon, displayed in a browser's address bar, indicates that the connection to a website is encrypted.

    What is the padlock icon?

  2. $400

    This protocol, seen at the start of a web address in place of plain HTTP, indicates that traffic between a browser and a site is encrypted.

    What is HTTPS?

  3. $600

    This type of Wi-Fi network, common in cafes and airports and often requiring no password, is especially risky for accessing sensitive accounts.

    What is public Wi-Fi?

  4. $800

    This encrypted tunnel routes a device's internet traffic through a remote server, shielding it from snooping on an untrusted network.

    What is a VPN?

  5. $1,000

    This attack secretly intercepts communication between two parties on a network, letting an attacker eavesdrop on or alter the data exchanged.

    What is a man-in-the-middle attack?

Social Engineering

  1. $200

    This umbrella term describes manipulating people, rather than exploiting software, into giving up confidential information or access.

    What is social engineering?

  2. $400

    This tactic involves an unauthorized person slipping through a secured door right behind an employee who badges in, without badging in themselves.

    What is tailgating?

  3. $600

    This tactic uses a fabricated scenario or false identity, such as posing as IT support, to persuade a target to hand over information.

    What is pretexting?

  4. $800

    This phishing variant is carried out over the phone rather than by email, often impersonating a bank or a government agency.

    What is vishing?

  5. $1,000

    This phishing variant is carried out by text message, often containing a malicious link disguised as a delivery or account alert.

    What is smishing?

Reporting an Incident

  1. $200

    This department is typically an employee's first point of contact for reporting a suspicious email or a suspected security problem.

    What is the IT help desk?

  2. $400

    This built-in email client feature lets an employee flag a suspicious message directly to security teams with a single click.

    What is a report phishing button?

  3. $600

    This formal record documents what happened, when, and how during a security incident, and supports later analysis.

    What is an incident report?

  4. $800

    This team, often on call around the clock, is responsible for containing and remediating a confirmed security breach.

    What is an incident response team?

  5. $1,000

    This step, taken immediately after a device is suspected of being compromised, cuts it off from the network to stop malware from spreading further.

    What is isolating the device from the network?

Final Jeopardy — Cyber Threats

Taking its name from a fishing homophone, this attack uses fraudulent messages posing as trusted senders to trick recipients into revealing credentials.

What is phishing?

How to run this board

Most breaches start with a person, not a firewall, which is why this board drills the human side: spotting phishing, building strong passwords, recognizing social engineering, browsing safely on public Wi-Fi, and knowing exactly who to tell when something looks wrong.

IT and security teams can run it during security awareness month or right after a phishing simulation, when the topic is already on everyone's mind. Department-versus-department scoring adds useful peer pressure.

Swap in your own reporting address and help-desk details so the right answers match your real process.

More from the library

Spotted a clue that's wrong or out of date? Tell us and we'll fix the board. Or start from a blank board and write your own.