About
About cardosec
Practise explaining cybersecurity out loud. Draw one of 182 cards across 10 domains, from SQL injection to Kerberoasting, answer against the clock with no notes, then see which key points you covered. Interview prep, incident drills and deep dives. Free during early access.
How it works
- Draw a card. cardosec picks a security topic for your goal, level and domains, or you choose one.
- Talk it through. Explain it out loud against the clock, with no notes. A live transcript follows along.
- Debrief. Tick the key points you hit, see what you missed, and optionally get AI feedback on your own API key. Weak spots come back as retention quizzes.
Four ways to practise
- Explain it. One concept. No notes. Say what it is, how it breaks, how you stop it.
- Incident drill. An alert just fired. Talk through triage like you are on call.
- Deep dive. Research on a clock, then brief it like you are presenting to the team.
- Interview. A real interview question. Answer, give an example, own the trade-offs.
Where the content comes from
Every card is written to a fixed format: a title, a level from L1 Foundations to L5 Expert, the question or alert, three to five technically precise key points, harder follow-ups, and references to stable primary sources such as MITRE ATT&CK, OWASP, NIST, CISA and RFCs. Cards are reviewed against real drill results: when people consistently miss a point, the card is reworded. Content last reviewed 2026-10-09.
Questions
What is cardosec?
cardosec is a speaking-practice app for cybersecurity. It draws a card (one of 182 security topics), gives you a timer, and you explain the topic out loud with no notes. Then you see which key points you covered and which you missed.
Who is cardosec for?
Anyone who has to explain security out loud: people preparing for security interviews (SOC analyst, pentester, AppSec, cloud security, GRC), students and career switchers, and working professionals who brief teams, executives or customers.
How do I practise for a cybersecurity interview with cardosec?
Pick Interview mode and your domains. Each card is a real interview question. Answer it out loud against the clock, giving an example and the trade-offs, then compare your answer with the key points and the likely follow-up questions.
What topics does cardosec cover?
182 cards across 10 domains: Web AppSec, Network, Identity & AD, Cloud, Cryptography, Blue team / DFIR, Malware & intel, Famous breaches, GRC, AI security. Cards range from L1 Foundations to L5 Expert, and come in four modes: Explain it, Incident drill, Deep dive and Interview.
Is cardosec free?
Yes. cardosec is free during early access, with no card details needed. You can try it as a guest or sign in with Google to keep your progress across devices.
Does cardosec give AI feedback on my answers?
Yes, optionally. Connect your own Anthropic or OpenAI API key and cardosec grades your transcript against the card: what you covered, what you missed and how to say it better. The key is encrypted, and requests run on your own provider account.
Does cardosec record or store my voice?
No. Your answer is transcribed so you can review it, and the audio is discarded straight away. cardosec never stores recordings.
Why practise explaining security out loud?
Knowing a topic and explaining it clearly under pressure are different skills. Saying an answer out loud, then checking it against key points, is a form of active recall: it shows the gaps that re-reading notes hides, and builds the fluency interviews and incident calls need.
Contact
Feedback, corrections and card suggestions: hello@cardosec.com.