Skip to main content

AP® Cybersecurity

Not weighted by unit

Unit 4: Securing Devices

Phones, laptops, servers and even smart thermostats and farm machines all run software that attackers can target. In this unit you'll learn the main kinds of malware, how passwords are stored and attacked, how authentication factors work, and the settings and tools that harden a device. You'll finish by reading authentication logs to spot password attacks.

Study this unit

Flashcards (40)Practice questions (63)Cybersecurity must-know sheet

Free-response questions on this unit

Write your own answer, then score it with the rubric or with AI.

Big ideas

  • Unpatched software, weak logins and open ports are common device weak spots
  • Systems store password hashes, and salt keeps identical passwords from matching
  • A second authentication factor makes a stolen password far less useful
  • Updates, anti-malware and host-based firewalls each stop a different kind of attack
  • Authentication logs reveal online password attacks, but offline attacks leave no trace

Full unit reviews

Longer videos that cover the whole unit. Good for a first pass or a final review.

  • CS50 Cybersecurity - Lecture 0 - Securing Accounts

    CS50Watch on YouTube (opens in a new tab)

  • Cybersecurity Architecture: Endpoints Are the IT Front Door - Guard Them

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • Cybersecurity Architecture: Detection

    IBM TechnologyWatch on YouTube (opens in a new tab)

Devices include servers, personal computers, handheld devices and embedded computers built into machines (everyday ones are often called IoT devices). Malware comes in many forms: viruses, worms, trojans and remote access trojans (RATs), ransomware, spyware, keyloggers, logic bombs, rootkits and fileless malware. Attackers get in through unpatched software, weak passwords, a BIOS or UEFI with no password, autorun on external drives, open ports, and missing firewalls or anti-malware.

Key terms

  • embedded computer (IoT)
  • virus vs. worm
  • trojan and remote access trojan (RAT)
  • ransomware
  • rootkit
  • fileless malware
  • AP Cybersecurity Topic 4.1.b - Identify the type of malware - Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • An Overview of Malware - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is the Internet of Things (IoT) and how can we secure it?

    National Institute of Standards and TechnologyWatch on YouTube (opens in a new tab)

  • What is Ransomware?

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • Viruses and Worms - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • Other Malware Types - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

Read the review notes: 4.1 Device Vulnerabilities and Attacks

A few quick questions on this topic, with the answers explained.

Systems store a hash of your password, not the password itself. A good cryptographic hash is fixed-length and repeatable and hard to reverse or collide (MD5 and SHA-1 are no longer considered safe), and a unique salt makes identical passwords hash differently. Online attacks hit a login page (password spraying, or credential stuffing with stolen or default logins), while offline attacks guess against a stolen hash database (brute force, dictionary and rainbow tables). Systems fight back by combining authentication factors (something you know, have or are, or somewhere you are) and enforcing password complexity, length, history and lockout settings.

Key terms

  • cryptographic hash
  • salt
  • password spraying
  • credential stuffing
  • rainbow table
  • authentication factors
  • AP Cybersecurity Topic 4.2.a - Authentication Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • How NOT to Store Passwords! - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Multifactor Authentication - CompTIA Security+ SY0-701 - 4.6

    Professor MesserWatch on YouTube (opens in a new tab)

  • Passwords & hash functions (Simply Explained)

    Simply ExplainedWatch on YouTube (opens in a new tab)

  • How Hackers Steal Passwords: 5 Attack Methods Explained

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 4.2.d - Login settings - Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

Read the review notes: 4.2 Authentication

A few quick questions on this topic, with the answers explained.

Policies set the rules for devices: an acceptable use policy, a password policy and a software installation policy. Anti-malware software scans files against a database of malware signatures and quarantines matches, and updates and patches close known holes. A host-based firewall uses ordered rules to block ports and services the device doesn't need, including outbound traffic an attacker could use to sneak data out.

Key terms

  • acceptable use policy
  • software installation policy
  • malware signature
  • patch
  • host-based firewall
  • outbound rule
Read the review notes: 4.3 Protecting Devices

A few quick questions on this topic, with the answers explained.

Devices log logins, file activity, settings changes and running processes. Those logs hold indicators of compromise, such as many failed logins, logins at odd times or places, unexpected files or software, and files whose hashes match known malware. In an auth log, many wrong passwords for one user suggest an online password attack, many users tried from one IP address within seconds suggest password spraying, and a quick run of default username and password pairs suggests credential stuffing.

Key terms

  • authentication (auth) log
  • host-based IoC
  • file-based IoC
  • behavior-based IoC
  • endpoint detection and response (EDR)
  • Indicators of Compromise - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is Endpoint Detection and Response (EDR)?

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • how to CORRECTLY read logs as a Cybersecurity SOC Analyst

    Tech with JonoWatch on YouTube (opens in a new tab)

  • Log Data - CompTIA Security+ SY0-701 - 4.9

    Professor MesserWatch on YouTube (opens in a new tab)

  • Linux Logs Analysis Case Study | Detecting SSH Brute Force Attacks

    Motasem HamdanWatch on YouTube (opens in a new tab)

Read the review notes: 4.4 Detecting Attacks on Devices

A few quick questions on this topic, with the answers explained.