# cardosec > Practise explaining cybersecurity out loud. Draw one of 182 cards across 10 domains, from SQL injection to Kerberoasting, answer against the clock with no notes, then see which key points you covered. Interview prep, incident drills and deep dives. Free during early access. cardosec (https://cardosec.com) is a web app for practising spoken explanations of cybersecurity topics. Each card has a question or scenario, a difficulty level (L1 Foundations to L5 Expert), and 3–5 key points that a strong answer covers. Users answer out loud against a timer, then check which key points they covered; AI feedback is optional and uses the user's own Anthropic or OpenAI key. Audio is never stored. Free during early access. ## Main pages - [Home](https://cardosec.com/): start practising, as a guest or with Google sign-in - [All cards](https://cardosec.com/cards): every card, by domain - [About](https://cardosec.com/about): how cardosec works, practice modes, where content comes from, FAQ - [Full card text](https://cardosec.com/llms-full.txt): every card's question, key points and follow-ups in one markdown file ## Domains - [Web AppSec](https://cardosec.com/cards/web): Web application security: injection, cross-site scripting, broken access control, SSRF, authentication and session flaws, and the OWASP Top 10. These are the questions AppSec, pentest and product-security interviews return to most. - [Network](https://cardosec.com/cards/network): Network security: TCP/IP and DNS attacks, firewalls and segmentation, TLS on the wire, lateral movement and network detection. Core ground for SOC, network and infrastructure roles. - [Identity & AD](https://cardosec.com/cards/identity): Identity and Active Directory: Kerberos and NTLM attacks such as Kerberoasting and pass-the-hash, OAuth and OIDC, SSO, MFA bypass and privilege escalation in AD. Identity is the new perimeter, and interviewers know it. - [Cloud](https://cardosec.com/cards/cloud): Cloud security: IAM misconfiguration, metadata service abuse, storage exposure, Kubernetes and container security, and detection in AWS, Azure and GCP. - [Cryptography](https://cardosec.com/cards/crypto): Applied cryptography: hashing versus encryption, TLS, PKI and certificates, key management, password storage and common implementation mistakes. Explain the maths simply and the failure modes precisely. - [Blue team / DFIR](https://cardosec.com/cards/dfir): Blue team, detection and incident response (DFIR): triage, log sources, SIEM detections, memory and disk forensics, and talking through an incident while it is happening. - [Malware & intel](https://cardosec.com/cards/malware): Malware and threat intelligence: ransomware, loaders and C2, persistence, MITRE ATT&CK techniques, and how analysts turn indicators into detections. - [Famous breaches](https://cardosec.com/cards/breaches): Famous breaches and incidents, from SolarWinds to Log4Shell: what happened, how the attackers got in, the impact, and the lessons defenders took away. Great material for interview stories. - [GRC](https://cardosec.com/cards/grc): Governance, risk and compliance (GRC): risk assessment, ISO 27001, SOC 2, NIST CSF, GDPR, policies, third-party risk and explaining security to the board. - [AI security](https://cardosec.com/cards/ai): AI security: prompt injection, jailbreaks, data poisoning, model and agent supply-chain risk, and securing LLM applications in production, including the OWASP Top 10 for LLMs. ## Practice modes - Explain it: One concept. No notes. Say what it is, how it breaks, how you stop it. - Incident drill: An alert just fired. Talk through triage like you are on call. - Deep dive: Research on a clock, then brief it like you are presenting to the team. - Interview: A real interview question. Answer, give an example, own the trade-offs. ## Optional - [Privacy Policy](https://cardosec.com/privacy) - [Terms of Use](https://cardosec.com/terms) - Contact: hello@cardosec.com