AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/2)
AP® Cybersecurity
Not weighted by unitUnit 2: Securing Spaces
Here you learn the core ideas of cybersecurity, such as risk, threats, vulnerabilities and security controls, and apply them to physical places like offices and labs. If an attacker can walk up to a device, they can skip many digital protections, so locks, badges, cameras and good habits are the first layer of defense. You'll practice finding weak spots in a building, rating the risk, and choosing and placing controls.
Study this unit
Flashcards (40)Practice questions (61)Cybersecurity must-know sheetFree-response questions on this unit
Write your own answer, then score it with the rubric or with AI.
- Device Security AnalysisClinic front-desk workstation: default-account guessing and an after-hours copy14 points · about 50 minutes
- Device Security AnalysisDorm heating controller: factory accounts and a scan of every port14 points · about 50 minutes
- Device Security AnalysisWater plant operator workstation: a guessed remote login that stayed14 points · about 50 minutes
- Device Security AnalysisHospital lobby kiosk: a held door and a drive plugged in after hours14 points · about 50 minutes
- Device Security AnalysisPayroll server: a convincing phone call and a login with no second factor14 points · about 50 minutes
Big ideas
- Risk depends on how likely an attack is and how much damage it would do
- You can avoid, transfer, mitigate or accept a risk
- Controls protect confidentiality, integrity or availability
- Layered defenses (defense in depth) mean one failure doesn't expose everything
- Physical access lets an attacker bypass many technical controls
Full unit reviews
Longer videos that cover the whole unit. Good for a first pass or a final review.
Topics
This topic is the course's core toolkit. It covers social engineering tactics (pretexting, authority, intimidation, consensus, scarcity, familiarity, urgency), adversary types such as script kiddies, hacktivists, insiders and cyberterrorists, and the six phases of an attack, from reconnaissance to evading detection. Risk is a threat exploiting a vulnerability to harm an asset (anything valuable); you rate it by likelihood and severity, then avoid, transfer, mitigate or accept it. Controls are physical, technical or managerial, and they prevent, detect or correct attacks; layering them is called defense in depth.
Key terms
- risk assessment
- avoid, transfer, mitigate, accept
- CIA triad
- physical, technical and managerial controls
- preventive, detective and corrective controls
- defense in depth
A few quick questions on this topic, with the answers explained.
Physical attacks often use social engineering. In piggybacking, the attacker talks an authorized person into letting them in; in tailgating, they slip in behind someone who doesn't notice. Shoulder surfing, dumpster diving and card cloning are physical attacks too. Once inside, an attacker can cut power, steal or copy documents, or plug a keylogger or malware-loaded drive into a device, and natural disasters are physical threats as well.
Key terms
- piggybacking
- tailgating
- shoulder surfing
- dumpster diving
- card cloning
- keylogger
A few quick questions on this topic, with the answers explained.
Managerial controls include security awareness training and a workstation policy: lock your screen, keep a clean desk, use a privacy screen, and plug devices into surge protectors or an uninterruptible power supply (UPS). Other controls deter or block attackers, such as fences, bollards, locks, card readers, access control vestibules and disabled USB ports. Organizations choose among them by weighing how serious each risk is against what the fix costs.
Key terms
- security awareness training
- clean desk policy
- privacy screen
- uninterruptible power supply (UPS)
- access control vestibule
- bollard
A few quick questions on this topic, with the answers explained.
Cameras, guards, motion sensors and alert employees detect physical intrusions, and placement matters. Put cameras on entrances and exits where they're hard to tamper with, and motion sensors in low-traffic spots like server rooms so they don't set off false alarms. Stationary guards work best where traffic funnels in, and patrolling guards on the perimeter. Badge logs help too: a door held open longer than normal can point to tailgating or piggybacking.
Key terms
- security camera
- motion sensor
- false alarm
- stationary vs. patrolling guard
- badge entry log
- detective control
A few quick questions on this topic, with the answers explained.