AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/2/2-1)
Unit 2 · Topic 2.1
2.1 Cyber Foundations
This topic is the vocabulary the whole course runs on: the tactics social engineers use, the kinds of adversaries, the phases of an attack, how to assess and manage risk, and how security controls are sorted. Almost every later question asks you to apply one of these ideas, so learn them precisely.
Key terms
- risk assessment
- avoid, transfer, mitigate, accept
- CIA triad
- physical, technical and managerial controls
- preventive, detective and corrective controls
- defense in depth
Seven social engineering tactics
Social engineers use psychology to get a target to act. The course names seven tactics, and one message often uses several:
| Tactic | What the attacker does | Sounds like |
|---|---|---|
| Pretexting | Invents a believable reason to make contact | Hi, I'm from the IT help desk doing a mailbox upgrade |
| Authority | Poses as someone with power over you, or relays orders from them | The principal needs this done before the board meeting |
| Intimidation | States bad consequences if you don't comply | Ignore this and your account will be closed |
| Consensus | Claims everyone else is already doing it | 90% of your team has already confirmed |
| Scarcity | Says something is in short supply | Only 5 free upgrades left |
| Familiarity | Pretends to be, or to know, someone close to you | Your cousin Dana gave me your number |
| Urgency | Sets a deadline to avoid a bad outcome | Respond within one hour |
Adversary types and attack phases
Attacks unfold in phases, though not every attack uses all six: (1) reconnaissance, gathering information, often from open source intelligence (OSINT), meaning freely available information; (2) initial access, getting a foothold, often through social engineering or weak or stolen credentials; (3) persistence, keeping access, often with malware like a remote access trojan (RAT) or rootkit that talks to the attacker over a command and control (C2) channel; (4) lateral movement, reaching other computers and accounts to gain higher privileges; (5) taking action, collecting data, sending it out (exfiltration), disrupting services or destroying data; (6) evading detection, deleting or editing logs and erasing planted files.
- Script kiddies: low-skilled adversaries who use tools made by others without understanding them, often for money or bragging rights.
- Hacktivists: attack to support a social, political or personal cause, believing the cause justifies breaking the law.
- Insiders: people with legitimate credentials and access, like employees, which makes them especially dangerous. Greed or revenge can motivate them, and outsiders may recruit them.
- Cyberterrorists: driven by politics or beliefs, they try to disrupt whole communities or nations, for example by attacking a power grid or water plant. They may act alone or for governments or criminal groups.
- Transnational criminal organizations: profit-driven groups that mainly deploy ransomware and steal intellectual property to sell.
Assessing risk
You have a risk whenever some threat could use a vulnerability (a weakness) to harm an asset (anything valuable: money, intellectual property, data, digital infrastructure, physical property or reputation).
A risk assessment weighs two factors. Likelihood depends on how valuable the target looks to adversaries, how much skill the exploit takes (well-documented exploits are easier, so more people can use them) and how motivated and capable the likely adversaries are. Severity is the projected damage, usually measured in money, including reputational and operational harm.
Ratings can be quantitative (a number, like 7 on a 1–10 scale or a $25,000-a-year risk) or qualitative (a label, like low, medium, high or severe, or likely-high-impact). Good documentation lists each vulnerable asset and its value, the likely threats, the specific vulnerability and how it could be exploited, the severity and likelihood, and a final rating.
Managing risk
Organizations favor controls that are cost-effective (cheaper to install and maintain than the loss they're expected to prevent) and easy to run.
- Avoid: stop the activity that creates the risk. Impossible if the activity is central to the organization's mission.
- Transfer: shift the burden to someone else, like an insurance company, a government or consumers.
- Mitigate: add security controls that lower the likelihood or the impact.
- Accept: live with the residual risk, the risk left after avoiding, transferring and mitigating. Perfect security doesn't exist, so some risk is always accepted.
Security controls and defense in depth
Every control protects at least one part of the CIA triad: confidentiality (only authorized people can access data), integrity (data stays accurate and unaltered) or availability (data and services work when authorized people need them).
By type, controls are physical (locks, fences, cameras, bollards, guards), technical (firewalls, anti-malware, encryption) or managerial (policies and procedures, like password policies, access reviews and incident response plans). By function, they are preventive (stop an attack, like locks and encryption), detective (spot an attack, like cameras, an intrusion detection system or a SIEM) or corrective (fix the problem and restore service, like patching, repairing a broken card reader or an intrusion prevention system that stops an attack in progress).
Defense in depth means layering different controls across human, physical, network, device, application and data layers. Each threat meets the control best suited to it, and if an adversary gets past one layer, the next can still stop them or limit the damage.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Naming the tactics in a message
An email says: "This is Dean Patel's office. The dean needs every club advisor to confirm their login on the new portal today. Most advisors already have. Accounts not confirmed by 5 p.m. will be deactivated." Identify four social engineering tactics and the phrase that shows each.
Show the solutionHide the solution
- Step 1: Authority: the message claims to come from the dean, someone with power over the advisors ("Dean Patel's office").
- Step 2: Consensus: "Most advisors already have" creates social pressure.
- Step 3: Urgency: "by 5 p.m." and "today" set a deadline.
- Step 4: Intimidation: "will be deactivated" states a negative consequence.
- Step 5: Pretexting also fits: the "new portal" is an invented reason for the contact. Any four correct tactics with matching evidence would answer the question.
Answer: Authority ("Dean Patel's office"), consensus ("Most advisors already have"), urgency ("by 5 p.m." today) and intimidation ("will be deactivated"); pretexting (the new portal story) also fits.
- Example 2
Choosing a risk strategy
Harbor Bike Rentals keeps customers' scanned driver's licenses on an old laptop. The licenses aren't needed after a bike is returned. For each option, name the risk strategy: (a) delete the scans after each return and stop scanning; (b) buy cyber insurance; (c) encrypt the laptop's drive and lock it in a cabinet; (d) after doing (c), decide the remaining risk is acceptable.
Show the solutionHide the solution
- Step 1: (a) Stopping the activity that creates the risk is avoidance. It works here because keeping scans isn't essential to renting bikes.
- Step 2: (b) Insurance shifts the financial burden to another company, which is transference.
- Step 3: (c) Adding controls (encryption and a lock) lowers the likelihood and impact, which is mitigation.
- Step 4: (d) Living with what's left after mitigation is acceptance of the residual risk.
Answer: (a) avoid, (b) transfer, (c) mitigate, (d) accept the residual risk.
- Example 3
Classifying controls
Classify each control by type (physical, technical or managerial) and by function (preventive, detective or corrective): a door lock on the server room; a password policy requiring 15-character passwords; an intrusion detection system; installing a security patch.
Show the solutionHide the solution
- Step 1: Door lock: it exists in physical space, so physical. It stops entry, so preventive.
- Step 2: Password policy: a written rule people follow, so managerial. Long passwords make guessing fail before anyone gets in, so preventive.
- Step 3: Intrusion detection system: software in the digital space, so technical. It spots attacks and alerts, so detective.
- Step 4: Security patch: applied to software, so technical. It fixes a known flaw, which the course classifies as corrective.
Answer: Lock: physical, preventive. Password policy: managerial, preventive. IDS: technical, detective. Patch: technical, corrective.
Common mistakes
- Mixing up consensus and scarcity. Consensus is "everyone else is doing it"; scarcity is "there isn't much left."
- Calling buying insurance mitigation. Insurance doesn't make an attack less likely or less damaging; it transfers who pays, so it's transference.
- Confusing a control's type with its function. "Physical, technical, managerial" is what it is; "preventive, detective, corrective" is what it does. A camera is physical and detective.
- Treating risk as just likelihood. Risk combines likelihood and severity, so an unlikely attack on a very valuable asset can still be a high risk.
On the exam
- Many questions give a short scenario and ask you to name a tactic, adversary type, attack phase, risk strategy or control category. Quote or point to the exact detail that proves your answer.
- When asked why defense in depth is needed, say both parts: different threats need different controls, and if one control is bypassed, another can still stop or limit the attack.
Connected topics
Videos
Check yourself: 2.1 Cyber Foundations
4 questions on 2.1 Cyber Foundations. Pick an answer to see if you got it, and why.
From: Marcus Webb, Office of the CEO <m.webb@pinecrest-benefits.example.net>
To: All Pinecrest Credit Union Staff
Subject: Quick benefits survey
Hi team, the CEO asked me to make sure everyone fills out this year's benefits survey.
Only the first 20 employees to finish will receive a $50 gift card, and most of the people in your branch have already completed it.
Just sign in at the link below with your work email and password. Thanks!
A message reported to the security team at Pinecrest Credit Union, an invented organization
Which sentence uses the tactic of scarcity?
A coworker reads the message and says, "If most of our branch already did it, it must be legit." Which tactic in the message worked on this coworker?
The message says the CEO asked Marcus to collect the surveys. Which tactic is this?
A caller says he works for the company that inspects the office building's elevators and needs to confirm which days the security desk is unstaffed so he can schedule a visit. Which social engineering tactic is he mainly using?
0 of 4 answered