Suggested use: individual play, pairs, cybersecurity/CTE stations, career exploration, advisory, or a whole-class discussion where students explain each decision before clicking. Typical play time: about 15 minutes for 12 alerts, leaving time in a 40-minute lesson for introduction and discussion.
Learning objectives
- Distinguish normal activity from suspicious activity.
- Use multiple pieces of evidence before reaching a conclusion.
- Recognize when an event should be escalated or contained.
- Understand why false positives matter in security operations.
- Connect practical defensive tasks with cybersecurity careers.
Career / NICE connection
The primary career connection is SOC Analyst, mapped on GetIntoCyberJobs.com to NICE PD-WRL-001 — Defensive Cybersecurity.
Related roles include Cybersecurity Analyst, Incident Responder, Threat Hunter, Detection Engineer, Incident Forensics Analyst, and Systems Security Analyst.
Suggested discussion questions
- Which alert was hardest to decide?
- What evidence made you change your mind?
- Why can immediately isolating every device be a bad strategy?
- Why does a SOC care about false positives?
- Which related career sounded most interesting?
Safety and scope
All names, users, systems, addresses, and incidents are fictional. The game focuses on defensive interpretation and decision-making. It does not teach students how to compromise real systems.
Privacy: the game does not use cookies, localStorage, sessionStorage, analytics, accounts, or browser persistence. Progress exists only in memory while the page is open.
Teacher snapshot
At the end of a shift, the game can show that student's current-run accuracy, hints used, and missed scenarios for discussion. It is not stored. Class-wide median accuracy, most-missed items across students, and first-versus-second-attempt comparisons would require an explicit teacher collection process or backend and are not collected by this version.