Technology Technology No wrong answersProfile result

Your Account May Be Hacked — What Do You Do First?

You spot a sign that an account or website might be compromised. This scenario-based choice test reveals which part of incident response you reach for first — containing it, investigating it, communicating it, or preventing the next one. There are no wrong answers; the four instincts are loosely organised around the stages that published incident-handling guidance describes — containment, analysis, communication, and preparing for next time. You'll get a response profile with strengths, blind spots, and a calm framework. This is general security education, not professional incident-response advice.

Questions
8
Time
6 min
Difficulty
Technology ·
Quick info

Before you start

Best for

Anyone curious how they'd react to a security incident

Format

8 self-reflection scenarios in about 6 minutes.

What you'll cover

A small map of the test

  1. 1You get an alert that an account had a suspicious login. First instinct?
  2. 2A website you run is behaving strangely. You first…
  3. 3What worries you most in the first ten minutes?
  4. 4You can only do one thing right now. You…
  5. 5A teammate asks 'should we tell users yet?' You…
  6. 6Which task feels most satisfying to complete?
Audience

Who this quiz is for

  • Anyone curious how they'd react to a security incident
  • Learners exploring incident-response instincts
Possible results

The 4 profiles you can land on

The Containment-First Responder

Your instinct is to stop the bleeding — change passwords, revoke sessions, cut off access — before anything else.

The Evidence Investigator

You want to understand what actually happened — check logs, sign-in history, and scope before reacting.

The Clear Communicator

Your first move is to tell the right people — your team, affected users, or a provider — honestly and quickly.

The Resilience Preventer

You jump to hardening — MFA, backups, patches — so this can't happen again, even mid-incident.

Scoring

How this test is scored

  1. Each of the 8 scenarios offers exactly one option per profile, so every one of the 4 profiles is equally reachable — no result is easier to land on than another.
  2. Your answers are counted up. The profile you chose most often is the one you are shown. There is no score, no percentage, and no pass mark.
  3. If two or more profiles finish level, the result says so and names them rather than quietly picking one. Roughly a quarter of all answer combinations end that way, so it is a normal outcome, not an error.
  4. Everything is worked out in your browser. Your answers are not sent to a server, and no account is created.

This is a self-reflection prompt, not a measurement. The profiles were written for this test — they are not a published or validated instrument, they have no reliability or norming data behind them, and they should not be used to assess anyone else or to make a decision about hiring, health, money, or study. Answer the same scenarios in a different mood and you may well land somewhere else, which is itself worth noticing.

After the quiz

Recommended next steps

  • Take the Cybersecurity Basics Quiz for the fundamentals behind staying safe
  • Try the Web Development Fundamentals Quiz to understand the systems involved
  • Read AWS Without the Panic for a calm introduction to cloud basics
References

Sources and further reading

  • NIST Special Publication 800-61, Computer Security Incident Handling Guide National Institute of Standards and Technology (NIST)
Important note

Educational disclaimer

This choice test is for general security awareness and self-reflection only. It is not professional incident-response, legal, or compliance advice. A real incident may carry reporting obligations — when in doubt, involve qualified security and legal help.

How it works

Instructions

  1. There are no right or wrong answers. Choose what you would realistically do.
  2. Answer all 8 short scenarios — it takes about 6 minutes.
  3. Your result shows the decision pattern your answers matched most, with strengths, watch-outs, and a better decision framework.
  4. This is for reflection and learning, not diagnosis or professional advice.
  5. No signup required. Your result stays on this device.
What the test asks

The questions in this test

There are no right or wrong answers here — each option maps to a different decision profile. These are the 8 scenarios you'll work through.

  1. You get an alert that an account had a suspicious login. First instinct?

    • Lock it down — change the password now
    • Check where and when the login came from
    • Flag it to my team or the provider
    • Turn on MFA so it can't happen again
  2. A website you run is behaving strangely. You first…

    • Take it offline or restrict access
    • Pull the logs to see what's happening
    • Warn users and stakeholders
    • Restore from a clean backup and patch
  3. What worries you most in the first ten minutes?

    • The damage spreading further
    • Not knowing what really happened
    • People being harmed without warning
    • That we'll just get hit again
  4. You can only do one thing right now. You…

    • Cut off the attacker's access
    • Confirm the scope of the breach
    • Alert the people who need to know
    • Close the hole that let them in
  5. A teammate asks 'should we tell users yet?' You…

    • Contain it first, then decide
    • Let's confirm what was exposed first
    • Yes — they deserve a heads-up now
    • Focus on making sure it's actually fixed
  6. Which task feels most satisfying to complete?

    • Slamming the door shut on the attacker
    • Reconstructing exactly what happened
    • A clear, honest update sent out
    • Defenses that make a repeat impossible
  7. After the dust settles, you most want to…

    • Confirm nothing's still active
    • Write up the full timeline
    • Do an honest post-incident update
    • Roll out hardening across the board
  8. Your friend's social account just got hacked. Your advice starts with…

    • Change the password and sign out everywhere
    • Check the login activity and recent changes
    • Warn their contacts about scam messages
    • Turn on two-factor for everything
Possible results

The profiles this test can return

Your answers are tallied across these profiles. Whichever you match most becomes your result — with the strengths, watch-outs, and a framework to work on.

The Containment-First Responder

Your instinct is to stop the bleeding — change passwords, revoke sessions, cut off access — before anything else.

Strengths

  • Limits damage fast
  • Acts decisively in a crisis
  • Buys time to think

Watch-outs

  • Hasty action can destroy evidence
  • May contain before scoping the breach
  • Can tip off or lock out the wrong party

Questions to take forward: Contain first, but capture before you clobber: note timestamps and take a quick snapshot/screenshot, then revoke access. Speed and a light evidence trail aren't mutually exclusive.

The Evidence Investigator

You want to understand what actually happened — check logs, sign-in history, and scope before reacting.

Strengths

  • Establishes the real scope
  • Preserves evidence
  • Avoids fixing the wrong thing

Watch-outs

  • Investigating while the door is open
  • Analysis can delay containment
  • Attacker may act during the delay

Questions to take forward: Investigate and contain in parallel, not in sequence: revoke obvious access right away, then dig into logs. Don't leave the door open while you study the lock.

The Clear Communicator

Your first move is to tell the right people — your team, affected users, or a provider — honestly and quickly.

Strengths

  • Builds trust through transparency
  • Gets help and resources fast
  • Reduces downstream harm to others

Watch-outs

  • Communicating before facts are clear
  • Can cause panic with partial info
  • May overshare sensitive detail

Questions to take forward: Communicate early but scoped: say what you know, what you're doing, and when you'll update — without speculating. Honest and measured beats fast and wrong.

The Resilience Preventer

You jump to hardening — MFA, backups, patches — so this can't happen again, even mid-incident.

Strengths

  • Turns incidents into lasting fixes
  • Thinks beyond the immediate fire
  • Reduces repeat risk

Watch-outs

  • Prevention won't stop an active breach
  • Can skip urgent containment
  • Future-focus delays the now

Questions to take forward: Sequence it: contain the active incident first, then harden so it can't recur. Prevention is the most valuable step — and the wrong first step during a live breach.