AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/1)
AP® Cybersecurity
Not weighted by unitUnit 1: Introduction to Security
This unit starts with the security you use every day: spotting scam messages, keeping your accounts safe, using public Wi-Fi wisely and seeing through new AI tricks. You'll learn how attackers manipulate people and guess passwords, and the simple habits that stop most of these attacks. You'll also see how defenders now use AI to catch attacks faster.
Study this unit
Flashcards (35)Practice questions (52)Cybersecurity must-know sheetFree-response questions on this unit
Write your own answer, then score it with the rubric or with AI.
- Device Security AnalysisLibrary catalog server: sprayed staff logins and a poisoned book review14 points · about 50 minutes
- Device Security AnalysisStore back-office server: a 3 a.m. login and an oversized gift card number14 points · about 50 minutes
- Device Security AnalysisResearch lab workstation: a scary email and a 2.3 GB upload14 points · about 50 minutes
- Device Security AnalysisFood bank donation site: sprayed admin logins and a receipt download trick14 points · about 50 minutes
- Device Security AnalysisPayroll server: a convincing phone call and a login with no second factor14 points · about 50 minutes
- Device Security AnalysisWork laptop at a café: a look-alike network and a stolen mail login14 points · about 50 minutes
- Device Security AnalysisStore chatbot server: reused passwords and a chatbot talked into sharing14 points · about 50 minutes
Big ideas
- Many attacks start by tricking a person, not by breaking into a computer
- Urgency and intimidation in a message are warning signs
- Long, unique passwords plus multifactor authentication make account takeovers much harder
- On public Wi-Fi, check the network name and rely on encryption like HTTPS or a VPN
- AI makes attacks more convincing, but it also helps defenders sort through huge amounts of data
Full unit reviews
Longer videos that cover the whole unit. Good for a first pass or a final review.
Topics
Social engineering means tricking people into giving away information, opening a harmful file or clicking a bad link. It often arrives by email, text or social media. Watch for intimidation (threats if you don't obey) and urgency (pressure to act right now). Falling for it can hand an attacker your personal details, a one-time login code, or malware that steals data saved in your browser.
Key terms
- social engineering
- phishing
- elicitation
- intimidation
- urgency
- one-time password (OTP)
A few quick questions on this topic, with the answers explained.
In an online password attack, someone tries common, patterned or stolen passwords on a real login page. Warning signs are many failed logins in a short time, logins at odd hours and logins from unknown devices. Attackers build guess lists from personal details like pets' names and birthdays, so use long, random, unique passwords or passphrases (a password manager helps) and turn on multifactor authentication (MFA).
Key terms
- online password attack
- password patterns
- password manager
- passphrase
- multifactor authentication (MFA)
A few quick questions on this topic, with the answers explained.
Low-skilled attackers use tools bought online, while high-skilled ones build their own tools and find unknown flaws called zero-days. On Wi-Fi, an attacker may set up an evil twin (a fake network with a look-alike name), jam the signal so no one can connect (a denial of service), or go war driving to find networks that reach outside a building. Protect yourself by checking the network name exactly and relying on encryption like HTTPS. A VPN hides your traffic from the local network, but the VPN provider can still see it.
Key terms
- low-skilled vs. high-skilled adversary
- zero-day
- evil twin
- jamming
- war driving
- virtual private network (VPN)
A few quick questions on this topic, with the answers explained.
Attackers use AI to clone a person's voice or face for fake calls and video chats, and to write polished phishing in any language. They also coax sensitive data out of chatbots, plant false information that ends up in AI training data, and use AI to speed up research and malware writing. You can fight back with a secret word or phrase shared with family, MFA, keeping personal data out of AI tools, and checking AI answers against reliable non-AI sources.
Key terms
- deepfake
- voice cloning
- large language model (LLM)
- AI-written phishing
- poisoned training data
- shared secret
A few quick questions on this topic, with the answers explained.
Networks log millions of events a day, far more than people can read. Defenders train AI tools to sort likely attacks from harmless activity, alert the security team and even take quick corrective action. AI can also review firewall rules, scan code for vulnerabilities and suggest detection rules, but a knowledgeable person should always check its suggestions before they're used.
Key terms
- threat detection
- triage
- alert
- automated response
- AI code review
- human review
A few quick questions on this topic, with the answers explained.