This is the last step. It checks that you can tell a genuine message from an attack when nothing is flagged for you in advance. Expect it to be tougher than the practice tasks, because several of the messages here are completely real.
Mail from your own company's domain is trustworthy by default, and treating normal internal work as suspicious is its own kind of mistake. The rare exception shows itself in the request rather than the sender: a payment outside the usual process, a code someone wants from you, a link that leads somewhere odd.
When something does look off, the right-sized check is one short message on a second channel, such as {{chat}}. Save the phone call for when that gets you nowhere.
Use the same address you used in the training. Your master code and your certificate are both calculated from it.