AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/must-know)
Must-know sheet
AP® Cybersecurity must-know sheet
The vocabulary, attack signs, defenses, chmod math and log-reading patterns to know cold for the first AP Cybersecurity exam in May 2027, checked against the fall 2026 course framework. College Board doesn't list a reference sheet for this exam, so everything here is yours to remember.
Showing all 15 sections.
The exam at a glance
Units 1, 2, 3, 4, 5
- First exam: Wednesday, May 5, 2027, fully in Bluebook
- AP Cybersecurity is a new AP Career Kickstart course, so May 2027 is its first exam. It lasts 2 hours 10 minutes, and both sections are taken in the Bluebook app, which submits your answers automatically when time runs out.
- Section I: 60 multiple-choice questions, 80 minutes, 70%
- Questions come alone or in sets of 2 to 4 about one scenario, such as an email, a log or a firewall table. All five units are tested, and the section is weighted by skill rather than by unit: Analyze Risk, Mitigate Risk and Detect Attacks are each 25–40%.
- Section II: one Device Security Analysis question, 50 minutes, 30%
- You get several sources from one device: firewall rules, system and web logs, an
ls -lfile listing and a device policy. The sample question has parts A to E worth 14 points, and it tests Mitigate Risk and Detect Attacks. - The skills behind every question
- Analyze Risk: spot vulnerabilities, threats and attacks, and rate risk. Mitigate Risk: choose and set up controls, like a firewall rule or a
chmodcommand. Detect Attacks: choose detection tools and find attack evidence in logs. The fourth skill, Collaborate, is taught in class but not tested. - Free-response task verbs
- Identify: name it or point to the evidence. Describe: say what happens. Explain: give the reason and back it with specific evidence. Determine: reach a result from the sources. Write: give an exact command, such as a
chmodcommand, that does what's asked. - No reference sheet to lean on
- College Board doesn't list a reference sheet for this exam, so know the
chmodnumbers, the attack signs in logs and the detection trade-offs cold. Sources usually label each port with its service, but knowing the common ones (below) saves time.
Risk, the CIA triad and security controls
Unit 2
- Asset, vulnerability, threat, risk
- An asset is anything valuable: money, intellectual property, data, digital infrastructure, physical property or reputation. A vulnerability is a weakness that could let an asset be compromised, and a threat is a person or event (including a natural disaster) that could use it. Risk exists when a threat can exploit a vulnerability to compromise an asset.
- Risk depends on two factors: likelihood and severity
- Likelihood goes up when the target is valuable, the weakness takes little skill to exploit (well-documented exploits) and likely adversaries are motivated and capable. Severity is usually measured in money, including reputational and operational damage.
- Quantitative vs qualitative ratings
- Quantitative ratings use numbers, such as a 1–10 score or a dollar amount like a $10,000 annual risk. Qualitative ratings use words, such as low, medium, high and severe, or unlikely/likely paired with low/high impact.
- What a risk assessment write-up includes
- The vulnerable assets and their value, the likely threats, the specific vulnerabilities and how they'd be exploited, how bad the damage would be and how likely it is, and a final rating for each risk.
- High, moderate and low risk
- High: sensitive data or critical systems exposed with an easy, likely exploit (a customer-data server in an unlocked room). Moderate: something noncritical that could be a foothold to reach more (a lobby computer on the internal network with open USB ports). Low: a low-value asset that's unlikely to be attacked.
- Four ways to manage a risk: avoid, transfer, mitigate, accept
- Avoid: stop the risky activity (impossible if it's core to the mission). Transfer: shift the burden to someone else, such as an insurer. Mitigate: add controls to cut likelihood or impact. Accept: live with the residual risk that remains, because perfect security is impossible.
- Cost-effective controls win
- Organizations favor controls that are cheap and easy to install and maintain. A control is cost-effective when it costs less than the loss it's expected to prevent, and fixes are prioritized by how severe the risk is versus what the fix costs.
- CIA triad: confidentiality, integrity, availability
- Confidentiality: only authorized people, systems or processes can access data (lost through theft). Integrity: data stay accurate and trustworthy (lost through tampering). Availability: data and services work when authorized users need them (lost through downtime, DoS or ransomware). Every control protects at least one.
- Control types: physical, technical, managerial
- Physical controls work in the real world: locks, fences, bollards, cameras, guards. Technical controls work in the digital space: firewalls, anti-malware, encryption. Managerial controls are rules and plans: password policies, regular access reviews, incident response plans (IRPs).
- Control functions: preventive, detective, corrective
- Preventive controls stop an attack before it happens (locks, encryption). Detective controls spot an attack as it happens (IDS, cameras, SIEM). Corrective controls fix problems and restore systems (patching, repairing a broken card reader, and an IPS, which the course counts as corrective).
- Defense in depth (layered defense)
- Use several kinds of controls in layers (human, physical, network, device, application, data) so that when one is bypassed, another still blocks or limits the attack. It also lets you match each threat with the control best suited to it.
Social engineering and adversaries
Units 1, 2
- Social engineering
- Psychological tricks that get people to reveal information (elicitation), download a malicious file or click a malicious link. It can happen in person, but it usually comes by email, text or social media message.
- The seven tactics
- Pretexting: a believable made-up reason to contact you. Authority: posing as, or relaying orders from, someone with power over you. Intimidation: threatening bad consequences. Consensus: claiming everyone else has already done it. Scarcity: limited availability. Familiarity: posing as or knowing someone close to you. Urgency: a deadline to act fast.
- Urgency vs scarcity vs intimidation
- Urgency is about time ("by the end of the day"). Scarcity is about limited supply ("only 3 spots left"). Intimidation is about a threatened penalty ("or your payroll access is suspended"). One message often uses several, so match the exact phrase the question quotes.
- What victims lose
- Personal details (pets' names, birthdate, address) that answer security questions and enable impersonation; one-time passwords or login codes that let the attacker sign in as you; or malware that steals saved browser data or sends you to a fake login page.
- Adversary skill levels
- Low-skilled adversaries use tools made by others, often bought online, against known vulnerabilities. High-skilled adversaries build or adapt their own tools and can find zero-days: vulnerabilities nobody has documented yet.
- Five adversary types
- Script kiddies: low-skill, use others' tools without understanding them, want money or recognition. Hacktivists: driven by a social or political cause. Insiders: already have legitimate access, can be recruited by outsiders, often driven by greed or revenge. Cyberterrorists: driven by politics or beliefs, attack infrastructure like power grids to disrupt whole regions. Transnational criminal organizations: want money, mainly through ransomware and stealing intellectual property.
- Six phases of an attack
- 1. Reconnaissance: gather information, often open source intelligence (OSINT). 2. Initial access: get a foothold, often via social engineering or weak credentials. 3. Persistence: keep access, often with command and control (C2) through a RAT or rootkit. 4. Lateral movement: spread and escalate privileges. 5. Taking action: steal, exfiltrate, disrupt or destroy. 6. Evading detection: delete or edit logs and planted files. Not every attack uses every phase.
Everyday security: passwords, public Wi-Fi and AI
Unit 1
- Signs of an online password attack
- Many failed logins in a short time, login attempts at unusual times, and attempts from unknown devices.
- Weak password patterns attackers expect
- A word or two plus a two-digit year plus a symbol at the end, family or pet names, and meaningful dates. Attackers build custom guess lists from your personal details and feed them to automated tools.
- Stronger authentication
- Use long, random, unique passwords, or long passphrases, and let a password manager create and store them. Avoid names, dates and personal words, and turn on multifactor authentication (MFA) wherever it's offered.
- Evil twin
- A fake wireless access point with the same or a look-alike network name (SSID). Victims who join it send their traffic through the attacker, although traffic protected by encryption like HTTPS stays unreadable. Defense: check that the network name matches exactly.
- Jamming
- Flooding the area with a strong signal on the Wi-Fi frequencies so no one can connect. Any attack that blocks access to a resource is a denial of service (DoS).
- War driving
- Driving or walking around a target to pick up wireless beacons, learn what kind of network is in use and find where the signal leaks outside the building.
- VPNs on public Wi-Fi
- A VPN encrypts all your traffic to the VPN provider, so the local network and service provider can't read it, but the VPN provider can. Without one, think about how sensitive your data is (even DNS lookups can be exposed) before using an unencrypted network.
- How attackers use AI
- Cloning a voice or face for fake calls and video chats (worse as voice authentication spreads), writing fluent phishing in any language so bad grammar is no longer a reliable clue, coaxing sensitive data out of chatbots, planting false information that ends up in AI training data, automated reconnaissance of social media, and AI coding help to write malware or find vulnerabilities.
- Defending against AI-powered attacks
- Agree on a secret word or phrase with family to verify identity in a high-stakes call, turn on MFA so a cloned voice isn't enough, keep personal data out of chatbots (some train on your input), and check AI answers against reliable sources that aren't AI.
- How defenders use AI
- AI can sort millions of daily events into likely attacks vs harmless activity, alert people or take quick corrective action, review firewall rules and access controls, scan code for vulnerabilities and suggest detection rules. A knowledgeable person must always review its suggestions before they're used.
Physical security
Unit 2
- Piggybacking vs tailgating
- Piggybacking: the attacker manipulates an authorized person into letting them in, like carrying a big box so someone holds the door, or posing as a repair worker. Tailgating: the attacker slips in behind an authorized person who doesn't notice. The difference is whether the insider knowingly helps.
- Other physical attacks
- Shoulder surfing: watching (or filming) someone enter or view sensitive information. Dumpster diving: searching trash for useful information. Card cloning: copying an authorized person's access card to get all of their access.
- What physical access lets an attacker do
- Cut power (breakers, wiring, substations), steal or copy documents, plug in a keylogger or a malware-loaded drive, or destroy a device. Physical access can bypass many technical controls, which is why physical security is a first layer of defense.
- Managerial controls for physical spaces
- Security awareness training (spot phishing, don't badge others in, prevent device theft) and a workstation policy: lock your screen when you step away, keep a clean desk, use a privacy screen, and plug devices into surge protectors or an uninterruptible power supply (UPS).
- Controls for physical spaces and what each stops
- Fences, gates and bollards deter attackers from reaching the building. Locks on doors, server cabinets and computers prevent access and theft. Card readers log which badge opened which door and deny unauthorized badges. Access control vestibules and turnstiles stop piggybacking and tailgating. Disabled USB ports block malware-loaded drives. A UPS or generator keeps power on.
- Detection tools and where to put them
- Cameras: cover entrances and exits, mount them where they're hard to tamper with, and record and monitor the feed. Motion sensors: low-traffic areas like server rooms (in busy areas they cause false alarms). Stationary guards: where traffic funnels in, like lobbies and gates. Patrolling guards: perimeters, and they're hard to plan around. Employees are often the first to notice an intruder.
- Pairing detective controls
- Motion sensors work best with cameras, so an alert can be checked visually. Cameras with facial recognition can flag unauthorized people, and footage lets defenders trace an intruder's path after a breach.
- Badge logs reveal piggybacking and tailgating
- Electronic door sensors record how long a door stayed open after a badge was used. A door held open much longer than normal is a sign that someone else came in too.
Network attacks and how to spot them
Unit 3
- ARP poisoning (an on-path attack)
- The attacker sends fake ARP messages so the gateway's table links the victim's IP address to the attacker's MAC address (faking a MAC is MAC spoofing), and the victim's traffic flows to the attacker. Spot it: unusual ARP messages, especially one IP address suddenly paired with a different MAC address, or duplicates in the gateway's ARP table.
- On-path (man-in-the-middle) attack
- The attacker secretly sits between two parties, capturing and possibly changing their data before passing it on. Both sides think they're talking directly to each other.
- MAC flooding (eavesdropping)
- The attacker floods a switch with frames from many different MAC addresses until it starts broadcasting all traffic, which the attacker can then capture (eavesdropping, or sniffing). Spot it: a sudden surge of frames with different MAC addresses and an overloaded MAC table. Stop it: port security limits addresses per switch port.
- DNS poisoning (credential harvesting)
- The attacker poses as an authoritative name server and plants a fake DNS record, sending users to a look-alike login page that captures their credentials. It's hard to detect; an unexplained sudden drop in traffic to your website is a reason to check your DNS records.
- Smurf attack (DoS)
- The attacker sends many ICMP requests to the network's broadcast address with the victim's address as the sender, so every device replies to the victim at once. Spot it: a sudden jump in ICMP requests to the broadcast address. Many devices attacking one target at once is a distributed denial of service (DDoS).
- Spotting Wi-Fi attacks
- Evil twin: scan regularly for SSIDs that look like yours, and use signal triangulation to find and shut down the fake access point. Jamming: no device in an area can connect, and scans show electromagnetic noise in the Wi-Fi range.
- Network weak spots
- No firewall or a misconfigured one; open switch ports without port security; Wi-Fi signals and beacons that reach outside the building; networks that don't authenticate devices and users; rogue access points plugged into open ports (they bypass the firewall); and weak wireless encryption.
- Network risk levels
- High: an easy, big impact, like one flat unsegmented network reached through weakly encrypted Wi-Fi. Moderate: a weakness that leaks information about devices, like a firewall that doesn't block outside ICMP. Low: hard to exploit with little impact, like an access point broadcasting its beacon. Automated vulnerability scanners report known weaknesses, their severity and fixes.
- Network IoCs (indicators of compromise)
- Found in traffic captures by checking source and destination IPs, ports and protocols: connections to known-bad IP addresses, unauthorized scans, unusual spikes or slowdowns, and a port carrying the wrong kind of traffic.
Network defenses: policies, Wi-Fi, segmentation and firewalls
Unit 3
- Router and switch security policies
- Both ban local user accounts so every login goes through an approved authentication server. Router policies also turn off unneeded services like Telnet and require a firewall. Switch policies also require port security and MAC filtering.
- VPN and wireless security policies
- A VPN policy lists which roles may use the VPN, sets authentication requirements (such as keys or MFA) and bans split tunneling. A wireless policy requires users to sign in through EAP to an approved server, requires AES encryption with a minimum key length, and turns off beacon frames.
- Wireless settings to configure
- Turn off beacon broadcasting, aim and limit the signal so it stays inside the building, turn on MAC filtering, require users to sign in, and use strong encryption. WEP, WPS and the original WPA are insecure; the fall 2026 course framework names WPA3 as the strongest option.
- Segmentation
- Split the network into smaller isolated pieces so an attack on one can't easily spread, and give each piece its own security level. Methods: subnets (by IP address), VLANs (set up on switches) and a screened subnet.
- Screened subnet (DMZ)
- A lower-security zone between the internet and the private network that holds public-facing servers, like a web server. A second, stricter firewall separates it from the internal LAN.
- Stateless, stateful and next-generation firewalls
- Stateless: filters each packet on header details like IP addresses, ports and protocols. Stateful (dynamic packet filtering): also tracks connections and can filter by them. Next-generation (NGFW): does both, plus deep packet inspection, intrusion prevention and filtering by application.
- Access control list (ACL) rules
- Each rule gives a direction (inbound or outbound), what to match (IP address, port, service, protocol or application) and an action (allow or deny). Rules are checked from the top, and the first match wins; nothing below it is checked.
- Rule order changes everything
- If rule 1 allows inbound TCP port 443 from anywhere and rule 2 denies all other inbound TCP, HTTPS gets in and everything else is blocked. Put the deny first and HTTPS is blocked too, because the deny matches first. To let blocked traffic in, put or edit an allow rule above the deny rule that catches it, usually the final deny-all.
- Reading an address range
198.51.100.0/24means every address from 198.51.100.0 to 198.51.100.255 (the first three numbers are fixed). A rule for that range matches 198.51.100.77 but not 203.0.113.9. Rule tables may instead write the range as start - end, like 198.51.100.0 - 198.51.100.255.- Where firewalls go
- Put one on every network segment (each can have its own strictness) and at every point where the internal network meets the internet.
- Common ports you'll see in rule tables
- 21 FTP, 22 SSH, 23 Telnet, 25 SMTP (email), 53 DNS, 587 SMTP submission (sending email), 80 HTTP, 443 HTTPS, 445 SMB (file sharing), 3306 MySQL, 3389 RDP (remote desktop), 5900 VNC. FTP and Telnet send logins unencrypted, so policies often disable them.
Detection tools and their trade-offs
Units 2, 3, 4, 5
- NIDS vs NIPS
- A network intrusion detection system (NIDS) analyzes traffic and raises an alert. A network intrusion prevention system (NIPS) can also stop the attack by closing ports, blocking IP or MAC addresses, or rejecting protocols. If a tool only alerts and leaves the response to people, it's an IDS.
- SIEM
- A security information and event management system pulls logs from many sources (firewalls, IDS/IPS, devices, applications), finds patterns that suggest an attack and raises an alert. Analysts then check whether it's real and resolve or escalate it.
- Signature-based detection
- Compares data to a database of known indicators (signatures), which must be kept updated. Fastest, cheapest and almost no false positives, so it suits high-traffic networks and low-powered devices. But it can't catch brand-new attacks and is easier to bypass (more false negatives).
- Anomaly-based detection
- Compares activity to a baseline recorded on clean systems and alerts when things fall outside the normal range. It can catch new attacks and is harder to bypass, but it's slower, costs more, needs consistent traffic patterns, and gives more false positives.
- Hybrid detection
- Combines signature and anomaly detection. It's the most expensive and produces the most alerts, so it's used for the most sensitive or critical networks and devices. When new attacks are likely but hybrid costs too much, choose anomaly-based.
- AI alert thresholds
- AI detection reports a probability that something is malicious, and the organization picks the cutoff for an alert. Set it too high and real attacks slip through (false negatives); too low and the team drowns in false alarms.
- False positives and false negatives
- A false positive is an alert on harmless activity; too many waste time and cause alert fatigue, where responders start assuming alerts are fake. A false negative is an attack that slips past detection and can cause real harm.
- Picking detection for devices
- Detection tools use memory and processing power: signature-based suits weaker devices, and many embedded devices can't run any. Licenses cost money per device; an endpoint detection and response (EDR) service is expensive but monitors all devices from one place.
- Honeypot file
- A file that looks valuable (fake card numbers, PII or passwords) but holds fake data. No one has a legitimate reason to open it, so any access triggers an alert and is a sign of malicious activity.
- Picking detection for data and apps
- Honeypot files and hash checks are cheap. Data loss prevention (DLP) services watch how data is accessed, used and moved across the organization: strong but costly. Sensitive, critical or legally regulated data (health, financial, educational, private) needs closer monitoring.
- Real-time vs after the fact
- Honeypots, some DLP tools and real-time automated log analysis alert while an attack is happening, so you can stop it. Reviewing old logs and comparing hashes find attacks after they've happened.
- Blind spots
- A hash only shows that data changed, so an attacker who just reads or copies a file isn't caught. A honeypot only catches attackers who touch it. Log analysis needs automation to keep up.
Device threats and protections
Unit 4
- Four kinds of computers
- Servers provide services to other computers (DNS, DHCP, FTP). Personal computers are desktops and laptops for one user. Handheld computers run on batteries (phones, tablets, smartwatches). Embedded computers are built into machines, are slower and cheaper with little storage, and in everyday devices are called the Internet of Things (IoT).
- Malware by behavior
- Virus: runs only when a user opens or runs a file. Worm: spreads by itself with no human action. Trojan: hides inside software that seems harmless; a remote access trojan (RAT) gives the attacker remote control. Ransomware: encrypts files and demands payment for the key. Spyware: tracks and reports what you do. Keylogger: records keystrokes, often to capture passwords.
- More malware
- Logic bomb: waits for a trigger, like a date or a certain operating system. Rootkit: burrows into the operating system, controls almost everything and hides itself. Fileless malware: lives in RAM and abuses programs already installed instead of using its own files.
- How devices get compromised
- Unpatched software with known vulnerabilities, weak or guessable passwords, no BIOS/UEFI password (so attackers can boot their own operating system or recovery mode and reset passwords), autorun running malware from a plugged-in drive, open ports, and missing or misconfigured firewalls and anti-malware.
- Device risk levels
- High: sensitive data or critical operations exposed, like an email server missing a patch for a known critical flaw. Moderate: weak authentication or less likely exploits, like remotely managed water-plant pumps with passwords but no MFA. Low: little impact if exploited, like a laptop with Telnet port 23 open.
- Device policies
- Acceptable use policy: what users may, must and may not do (keep software updated, no social media sites, no external drives). Password policy: length, how long a password can be kept, no reuse, construction rules, use a password manager. Software installation policy: what users may install and how to request more.
- Anti-malware, patches and updates
- Anti-malware scans files against a database of malware signatures, then quarantines and removes matches. A patch is a small update that fixes a vulnerability, and staying current blocks attacks on known flaws.
- Host-based firewall
- Software on one device with its own ordered rule list (first match wins). It protects the device even on a compromised network, should block every port and service the device doesn't need, and can block outbound traffic, like outbound FTP, so an intruder can't send files out.
- Host, file and behavior IoCs
- An indicator of compromise (IoC) is evidence that an attacker has compromised a device or network. Host-based: unexpected files, processes, services, settings changes or software installs. File-based: files whose hash matches known malware, known malware file names, suspicious file paths. Behavior-based: repeated failed logins, odd login times or places, attempts to reach sensitive data or raise privileges.
Passwords, hashes and authentication
Unit 4
- Cryptographic hash
- Turns input of any length into a fixed-length output (hash, digest or checksum). Properties: repeatable (same input, same hash), fixed length, pre-image resistant (can't work backward to the input) and collision resistant (hard to find two inputs with the same hash). Examples: MD5, SHA-1, SHA-256, SHA-512, NTHash, RIPEMD-160.
- Collisions are inevitable
- An n-bit hash has 2ⁿ possible outputs but infinitely many inputs, so collisions must exist. Once someone finds an efficient way to force them, the function is deprecated: MD5 and SHA-1 are no longer considered safe.
- Hash lengths in hex
- Each hex character is 4 bits: MD5 is 128 bits (32 hex characters), SHA-1 is 160 bits (40) and SHA-256 is 256 bits (64). Change even one character of the input and the whole hash changes.
- How passwords are stored
- Systems store a hash of each password, not the password. At login they hash what you typed and compare. A unique random salt is added to each password before hashing, so two users with the same password get different hashes and precomputed rainbow tables stop working.
- Online vs offline password attacks
- Online attacks try logins on a live login page, so lockouts can stop them and auth logs can show them. Offline attacks run against a stolen hash database on the attacker's own computer, so lockouts don't apply and nothing appears in your logs. If the hash database is stolen, make every user reset their password.
- Online attacks
- Trying leaked passwords from other breaches (people reuse passwords). Password spraying: one or a few common passwords tried against many accounts. Credential stuffing (as the course defines it): trying default logins, like a router's factory admin account, or stolen credentials.
- Offline attacks
- Brute force: hash every possible password. Dictionary: hash a list of common passwords. Rainbow table: look up the stolen hash in a precomputed table of passwords and their hashes, sorted by hash. Hashes can't be reversed; these attacks just find an input with the same hash.
- Four authentication factors
- Something you know (password, PIN, security question). Something you have (access card, phone, token). Something you are (fingerprint, face, iris or retina, voice). Somewhere you are (GPS, Wi-Fi, time zone or IP address). Biometrics are hard to copy because they're unique to each person.
- Multifactor authentication (MFA)
- Requires at least two different factors, so a stolen password alone isn't enough. Without MFA, an attacker with a stolen password gets all of that user's access. A password plus a PIN is still one factor (two things you know).
- Login settings to configure
- Complexity: at least one uppercase, lowercase, digit and special character. Minimum length: longer takes longer to crack. Password history: often the last 5–10 hashes, to block reuse. Lockout: often after 3–5 failed attempts. Maximum age: often 90 or 120 days, though NIST's current password guidance (SP 800-63B-4, 2025) says not to force scheduled changes, only a reset when a password may be compromised, because users fall into patterns like PasswordFall2028.
Application and data attacks
Unit 5
- Data weak spots
- Anyone with access to a drive can read files that aren't encrypted. Regular users with administrator rights hand an attacker those rights when their account is compromised. Loose access controls let too many people view or edit files.
- Data validation
- Checking that user input matches what's expected (like a number when asking for a quantity) and rejecting anything else. Apps that skip it are open to injection attacks.
- SQL injection
- SQL commands and control characters typed into an input field change the database query. This can expose more data than intended (confidentiality) or change and delete records (integrity).
- Cross-site scripting (XSS)
- Malicious script is injected into a website and runs in visitors' browsers, where it can reach saved logins and keys. Reflected (Type I): hidden in a link the victim clicks. Stored (Type II): saved on the site in a comment, forum post or visitor log, so it hits everyone who visits.
- Buffer overflow
- Input larger than the fixed-size memory buffer set aside for it spills into nearby memory. It can crash the system or let the attacker run actions outside the program's security rules.
- Directory traversal
- Changing a URL or GET request with
../sequences (each one moves up a folder) to reach files outside the web folder, like the system's list of user accounts. - Data risk levels
- High: highly sensitive or regulated data exposed to a likely exploit, like secret engine designs on an unencrypted drive. Moderate: sensitive data with weak encryption or loose access controls, like customer PII encrypted with a small key. Low: less sensitive data with weak protection, like unencrypted internal memos.
- Secure by design and secure by default
- Secure by design, an initiative promoted by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), builds security into every phase of making a product, with three principles: own your customers' security outcomes, be radically transparent and accountable, and have leaders who put security first. Secure by default means security features come turned on out of the box.
- Input sanitization
- Check input against what's expected and remove, or reject, control characters like the single quote, double quote and semicolon. It protects against SQL injection, XSS and directory traversal. In the sample free response, it was the credited countermeasure that isn't a firewall, IDS, IPS or AI.
Data rules and access control
Unit 5
- Three data states
- At rest: stored on a drive; protect the drive and encrypt the data. In transit: moving between devices; protect the cables and encrypt the data. In use: being processed; it must be unencrypted to use, so access controls limit who can view or edit it.
- Regulated data and the rules that cover it
- PII (personally identifiable information, like name, address, SSN, birthdate, email, fingerprints): the Privacy Act of 1974 (records held by federal agencies) and COPPA, the Children's Online Privacy Protection Act of 1998 (children under 13). PHI (protected health information): HIPAA, 1996. PCI (payment card information, like card number, expiration date and CVV): the PCI DSS, an industry standard rather than a law.
- Data policies
- A cryptography policy lists approved algorithms, key lengths, and how keys are generated and stored. A web application security policy sets when apps get security assessments, how they're done and deadlines to fix flaws by risk level. Regulated data is labeled and handled by policy.
- Subjects, objects, operations
- Access control decides which subjects (users or applications) can perform which operations (access, modify, add, remove) on which objects (files or applications). Authorization is granting a subject a specific kind of access.
- Role-based access control (RBAC)
- Access comes from your role: only people in the "accountant" role can use the payroll software.
- Rule-based access control (RuBAC)
- Rules based on conditions, usually layered on another model: no database access outside business hours, or only from the company network, even for people who are otherwise allowed.
- Discretionary access control (DAC)
- The owner of an object decides who gets which access (Bob lets Alice edit his file and Frank only view it). Administrators can override owners.
- Mandatory access control (MAC)
- An outside administrator assigns levels to subjects and objects, and strict rules decide access by level. Bell-LaPadula, used by governments and the military: no reading above your level (simple security property) and no writing below it (star property), summed up as "write up, read down."
- Least privilege
- Give every user or program exactly the access it needs to do its job, and no more.
Linux permissions and chmod
Unit 5
- Reading
ls -l - In
-rw-r----- 1 avery staff 2048 Oct 2 09:15 report.txt, the owner is avery, the group is staff, and the first character is the type (-file,ddirectory). Then come three sets of rwx, always in the order owner, group, others.rread,wwrite,xexecute,-means that permission is off. A+at the end means extra permissions are set; view them withgetfacl. - Numeric values: read 4, write 2, execute 1
- Add them for each set: 7 = rwx, 6 = rw-, 5 = r-x, 4 = r--, 3 = -wx, 2 = -w-, 1 = --x, 0 = ---. The three digits are owner, group, others, in that order.
- Numeric examples
chmod 640 file→ rw-r----- (owner reads and writes, group reads, others nothing).chmod 750 file→ rwxr-x---.chmod 600 file→ rw------- (owner only).chmod 755 file→ rwxr-xr-x.chmod 777 filegives everyone everything, which is almost never right.- Symbolic method
chmod+ who ++or-+ what + file. Who: u (owner), g (group), o (others), a (all). What: r, w, x.chmod g-r report.txtremoves the group's read;chmod go-r report.txtremoves it from group and others;chmod ug+rx testadds read and execute for owner and group.- Working out a change
- Start from the current string and apply only what the command changes: rw-r--r-- (644) with
chmod go-rbecomes rw------- (600). Leadingsudois fine. Never paste anls -lstring into the command: the sample scoring guide markschmod -rw------- filewrong. - Free-response permission tips
- Name the file, then state the access for owner, group and others with the exact rwx set as evidence. When restricting access, take away permissions some users don't need; don't remove everything or lock out the owner. Make sure your command sets exactly what you described.
Cryptography
Unit 5
- Key vocabulary
- Plaintext is readable data, ciphertext is the encrypted output, and the key is the secret value combined with the data. The keyspace is the number of possible keys; a bigger keyspace takes longer to guess.
- Symmetric vs asymmetric
- Symmetric encryption uses the same key to encrypt and decrypt, so both sides must share it first. Asymmetric encryption uses a key pair, so people can communicate securely without sharing a secret in advance.
- Block vs stream ciphers
- Block ciphers encrypt fixed-size chunks (blocks), one output block per input block. Stream ciphers encrypt a continuous flow, one element at a time.
- AES
- The Advanced Encryption Standard is the most common symmetric algorithm: a block cipher using 128-bit (16-byte) blocks with keys of 128, 192 or 256 bits. It protects Wi-Fi, web browsing, disk encryption and processor-level encryption. Longer keys are more secure but slower. Tools: OpenSSL on the command line (
openssl enc -aes-128-cbc -e ..., with-dto decrypt), AES Crypt, or web tools. - Public and private keys
- The receiver makes a key pair: publish the public key, guard the private key. What one key encrypts, only the other can decrypt. If the private key is ever exposed or lost, delete the pair and make a new one.
- Which key do you use?
- To send someone a secret, encrypt with the receiver's public key; only the receiver's private key can decrypt it. Common trap: picking any other key. The sender never has the receiver's private key.
- Key length math
- An n-bit key has 2ⁿ possible keys, and random guessing finds it in 2ⁿ⁻¹ guesses on average (half the keyspace). Each extra bit doubles the keyspace: a 4-bit key has 16 keys and needs 8 guesses on average.
- Compare key lengths only within one algorithm
- AES-256 beats AES-128 and RSA-4096 beats RSA-2048, but you can't compare an RSA key length with an AES one. Recommended lengths keep rising as computers get faster.
- RSA and ECC
- The common asymmetric algorithms are RSA and elliptic curve cryptography (ECC). They're also used for digital signatures and certificates. OpenSSL can make an RSA key pair (
openssl genrsa -out rsa.pem 2048), pull out the public key, and encrypt or decrypt withopenssl pkeyutl.
Reading logs: what each attack looks like
Units 3, 4, 5
- Online password guessing (auth log)
- One account with many failed passwords in a short time, often from one IP address. Cite the line numbers, timestamps and that IP address.
- Password spraying (auth log)
- Logins for many different usernames, seconds apart, coming from a single IP address or from IP addresses you don't normally see.
- Credential stuffing (auth log)
- A quick run of default username and password pairs (admin, root, guest and similar) tried on a device, often from the same IP address.
- Compromised password (auth log)
- A successful login for a real user from an unexpected place, IP address or time of day.
- SQL injection (web log)
- Input containing quote characters, always-true conditions like
OR 1=1, the SQL comment marker--, or capitalized SQL words such as WHERE, IN and FROM. - XSS (web log)
- Input containing HTML tags, especially
<script>and</script>. - Buffer overflow (web log)
- An unusually long URL, cookie, query string or total request.
- Directory traversal (web log)
- GET requests with repeated
../sequences reaching for system files outside the web folder. In the CED's sample free response, full-credit answers named the attack, quoted those exact lines, and offered input sanitization (stripping../) as the fix that isn't a firewall, IDS, IPS or AI. - Firewall blocks (system log)
- Lines like
[UFW BLOCK] IN=eth0 SRC=203.0.113.25 DST=192.0.2.10 PROTO=TCP DPT=25show a blocked connection: SRC is who tried, DPT the port they tried. The sample exam writes the port asPORT=25, so formats vary. Match the port to the rule table: if no allow rule covers it, the final deny-all rule blocked it. - Data theft signs (accounting log)
- Accounting is recording and monitoring what users do with data. Warning signs: a user opening files they never usually touch, activity at odd times or places or from an odd device, attempts to copy or delete sensitive files, any access to a honeypot file, or a file whose new hash doesn't match its recorded hash.
- Checking a file's hash
- Record the hash, re-hash later, compare. Windows PowerShell:
Get-FileHash testfile -Algorithm SHA256. Linux (bash):sha256sum testfile. Mac (zsh):shasum -a 256 testfile. Identical files match under every hash function; two files that match under one function but differ under another have a collision, so they aren't copies. - Free-response evidence habits
- Quote specific evidence: line or rule numbers, IP addresses, ports, file names and the exact suspicious text. When asked for the adversary's IP, give exactly one. When asked to change a firewall rule, modify one existing rule (don't add another deny, change an unrelated rule or turn the firewall off), then describe a side effect beyond the connection you just allowed, like newly exposed services.