AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/4)
AP® Cybersecurity
Not weighted by unitUnit 4: Securing Devices
Phones, laptops, servers and even smart thermostats and farm machines all run software that attackers can target. In this unit you'll learn the main kinds of malware, how passwords are stored and attacked, how authentication factors work, and the settings and tools that harden a device. You'll finish by reading authentication logs to spot password attacks.
Study this unit
Flashcards (40)Practice questions (63)Cybersecurity must-know sheetFree-response questions on this unit
Write your own answer, then score it with the rubric or with AI.
- Device Security AnalysisBakery order server: guessed password and a database search box14 points · about 50 minutes
- Device Security AnalysisLibrary catalog server: sprayed staff logins and a poisoned book review14 points · about 50 minutes
- Device Security AnalysisClinic front-desk workstation: default-account guessing and an after-hours copy14 points · about 50 minutes
- Device Security AnalysisDorm heating controller: factory accounts and a scan of every port14 points · about 50 minutes
- Device Security AnalysisStore back-office server: a 3 a.m. login and an oversized gift card number14 points · about 50 minutes
- Device Security AnalysisWater plant operator workstation: a guessed remote login that stayed14 points · about 50 minutes
- Device Security AnalysisLaw firm file server: sprayed logins and files that suddenly locked14 points · about 50 minutes
- Device Security AnalysisResearch lab workstation: a scary email and a 2.3 GB upload14 points · about 50 minutes
- Device Security AnalysisHospital lobby kiosk: a held door and a drive plugged in after hours14 points · about 50 minutes
- Device Security AnalysisFood bank donation site: sprayed admin logins and a receipt download trick14 points · about 50 minutes
- Device Security AnalysisPayroll server: a convincing phone call and a login with no second factor14 points · about 50 minutes
- Device Security AnalysisOffice print server: admin guessing and a gateway with a new address14 points · about 50 minutes
- Device Security AnalysisEsports club game server: an officer password and a flood of replies14 points · about 50 minutes
- Device Security AnalysisWork laptop at a café: a look-alike network and a stolen mail login14 points · about 50 minutes
- Device Security AnalysisStore chatbot server: reused passwords and a chatbot talked into sharing14 points · about 50 minutes
- Device Security AnalysisSchool district DNS server: a contractor login and a changed record14 points · about 50 minutes
- Device Security AnalysisSoftware download server: a guessed upload account and a swapped installer14 points · about 50 minutes
- Device Security AnalysisWarehouse handheld scanner: a guessed PIN and a flashlight app that phones home14 points · about 50 minutes
Big ideas
- Unpatched software, weak logins and open ports are common device weak spots
- Systems store password hashes, and salt keeps identical passwords from matching
- A second authentication factor makes a stolen password far less useful
- Updates, anti-malware and host-based firewalls each stop a different kind of attack
- Authentication logs reveal online password attacks, but offline attacks leave no trace
Full unit reviews
Longer videos that cover the whole unit. Good for a first pass or a final review.
Topics
Devices include servers, personal computers, handheld devices and embedded computers built into machines (everyday ones are often called IoT devices). Malware comes in many forms: viruses, worms, trojans and remote access trojans (RATs), ransomware, spyware, keyloggers, logic bombs, rootkits and fileless malware. Attackers get in through unpatched software, weak passwords, a BIOS or UEFI with no password, autorun on external drives, open ports, and missing firewalls or anti-malware.
Key terms
- embedded computer (IoT)
- virus vs. worm
- trojan and remote access trojan (RAT)
- ransomware
- rootkit
- fileless malware
A few quick questions on this topic, with the answers explained.
Systems store a hash of your password, not the password itself. A good cryptographic hash is fixed-length and repeatable and hard to reverse or collide (MD5 and SHA-1 are no longer considered safe), and a unique salt makes identical passwords hash differently. Online attacks hit a login page (password spraying, or credential stuffing with stolen or default logins), while offline attacks guess against a stolen hash database (brute force, dictionary and rainbow tables). Systems fight back by combining authentication factors (something you know, have or are, or somewhere you are) and enforcing password complexity, length, history and lockout settings.
Key terms
- cryptographic hash
- salt
- password spraying
- credential stuffing
- rainbow table
- authentication factors
A few quick questions on this topic, with the answers explained.
Policies set the rules for devices: an acceptable use policy, a password policy and a software installation policy. Anti-malware software scans files against a database of malware signatures and quarantines matches, and updates and patches close known holes. A host-based firewall uses ordered rules to block ports and services the device doesn't need, including outbound traffic an attacker could use to sneak data out.
Key terms
- acceptable use policy
- software installation policy
- malware signature
- patch
- host-based firewall
- outbound rule
A few quick questions on this topic, with the answers explained.
Devices log logins, file activity, settings changes and running processes. Those logs hold indicators of compromise, such as many failed logins, logins at odd times or places, unexpected files or software, and files whose hashes match known malware. In an auth log, many wrong passwords for one user suggest an online password attack, many users tried from one IP address within seconds suggest password spraying, and a quick run of default username and password pairs suggests credential stuffing.
Key terms
- authentication (auth) log
- host-based IoC
- file-based IoC
- behavior-based IoC
- endpoint detection and response (EDR)
A few quick questions on this topic, with the answers explained.