Free practice · The second step
A password is one proof. A second step asks for a second one: a code from an app on your phone, a tap on a prompt, or a small key you plug in. With it on, a password that has leaked is no longer enough on its own — and passwords leak.
Start with the e-mail account. Then anything that holds money, then anything that holds your messages.
The second step has exactly one way of being used against you: you are asked to approve, or to read out, a step you did not start. A prompt appears when you are not signing in. A call asks you to "read back the code we just sent to confirm it's you". In both cases someone already has your password and needs you to open the second door for them.
New sign-in request from a device in another city. Tap Approve to continue.
[ Deny ] [ Approve ]
The answer is Deny — not because of the city, but because you did not just try to sign in. That is the whole test. Then change the password, because somebody has it.
The same rule spoken aloud: a code is never read out to anyone who calls. No support desk, no bank, no delivery service ever needs it. The only person who should ever see your code is the screen you are typing it into.
When you turn the second step on, the service offers a short list of one-time backup codes for the day your phone is lost. Save them: in your password manager, or printed and kept with your passport. Without them, losing the phone can lock you out of your own account for weeks.
A sign-in prompt lab that shows the notification exactly as it appears and asks the one question that matters; the call transcript round where the code is asked for politely; and review that returns to the trap until denying it is a reflex. Four languages, offline once signed in, $6 for the first year until 1 December.
Three free questions, drawn from the drills. One of them may be a prompt you did not start.