AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/1/1-5)
Unit 1 · Topic 1.5
1.5 Leveraging AI in Cyber Defense
Networks produce far more activity than any team of people could read, and AI helps defenders find the few events that matter. This topic covers how AI tools sort events, raise alerts and take quick action, and why a knowledgeable human must always check AI recommendations before they're used.
Key terms
- threat detection
- triage
- alert
- automated response
- AI code review
- human review
Too much data for people alone
Every login, file download, web request and connection on a network creates a digital event, and a busy network logs millions of events every day. Hidden somewhere in that pile may be the handful that show an adversary at work. No team of humans can read every event carefully, so attacks can slip by unnoticed.
This is where AI helps. AI-powered tools can be trained on examples of normal and malicious activity, then quickly sort new events into likely malicious and likely harmless. Sorting events by how urgent they are is called triage, the same word hospitals use for deciding which patients to see first.
Alerts and automatic responses
Once an AI tool flags something as likely malicious, it can be set up to do one of two things:
- Alert a person. The tool notifies the security team, who investigate and decide what to do.
- Take corrective action on its own, based on the type of activity. For example, it might lock an account after a burst of suspicious logins, or cut a laptop off from the network if it starts behaving like ransomware.
Why speed matters
The faster defenders spot an attack, the less damage it can do. An attacker who goes unnoticed for weeks has time to steal data or spread to more devices. One caught in minutes may be stopped before they reach anything valuable. By shrinking the time between the attack and the response, AI tools help prevent loss, harm and destruction to systems and data.
AI as an assistant, with a human in charge
Defenders also use AI to improve their defenses before an attack happens:
- Checking how things are set up, such as firewall rules and who has access to what, and suggesting safer settings. Before any change goes in, a security technician who knows the system should look it over.
- Reading through an app's code to find weak spots and proposing fixes. A programmer who understands the code should approve each fix first.
- Drafting new rules for automated detection tools. A detection engineer should check each rule before it goes live.
Why the human check matters
AI can be wrong in confident-sounding ways. A suggested firewall rule might block a service the business depends on, or open a hole the AI didn't notice. A suggested code fix might break the program or add a new bug. A badly written detection rule might flood the team with false alarms. Human review catches these mistakes before they cause harm.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Reviewing an AI suggestion
Pinecrest Clinic's AI assistant reviews the firewall and recommends: "Rule 4 allows remote desktop from anywhere. Change it to allow remote desktop only from the IT office network." The IT manager wants to apply the change immediately to save time. What should happen first, and why?
Show the solutionHide the solution
- Step 1: Recognize the type of task: the AI reviewed a security configuration and made a recommendation.
- Step 2: Apply the rule from this topic: recommendations should be checked by a knowledgeable security technician before they're applied.
- Step 3: Explain what the technician checks: that the IT office network is described correctly, that no one else (like an outside support company) legitimately needs remote desktop, and that the new rule is in the right place in the rule order.
- Step 4: State the benefit: the change probably improves security, but a quick expert check prevents locking out needed users or making a mistake.
Answer: A knowledgeable security technician should review the recommendation before it's applied, to confirm it's correct and won't block legitimate users or create new problems.
Common mistakes
- Saying AI replaces the security team. In this course, AI sorts events and makes suggestions, but people investigate alerts and review recommendations.
- Applying AI-generated firewall rules, code fixes or detection rules without review. Each one should be checked by the matching expert: security technician, programmer or detection engineer.
- Thinking AI's only job is to raise alerts. It can also be set to take corrective action automatically, like locking an account.
On the exam
- Expect questions on why AI is needed (the volume of events is too large for people) and on what should happen to AI recommendations (expert human review before use).
- If asked how AI improves detection, mention both speed (catching attacks sooner) and sorting (separating likely malicious events from harmless ones).
Connected topics
Videos
Check yourself: 1.5 Leveraging AI in Cyber Defense
4 questions on 1.5 Leveraging AI in Cyber Defense. Pick an answer to see if you got it, and why.
The Cedar Valley School District's network records about 6 million events a day, such as logins, file downloads and connections to websites. Its security team has three analysts.
The district buys an AI-powered tool with three features:
Feature 1: It analyzes every event and sorts events that are likely malicious from those that are harmless.
Feature 2: When it finds likely malicious activity, it alerts the analysts. For a few attack types, it also disconnects the affected device from the network right away.
Feature 3: It reviews the district's firewall rules and recommends safer settings.
Invented scenario about an invented school district
Why does the district need Feature 1?
What is the main benefit of having the tool disconnect a device automatically for certain attacks?
Feature 3 recommends deleting two firewall rules and adding a new one. What should the district do next?
A programmer runs an AI-powered tool on a web application's code. The tool flags a possible vulnerability and suggests a code change to fix it. Which next step is best?
0 of 4 answered