AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/5)
AP® Cybersecurity
Not weighted by unitUnit 5: Securing Applications and Data
Stealing, changing or locking up data is often an attacker's real goal. This unit covers how apps get attacked through their input fields, how access controls and Linux permissions limit who can do what, and how symmetric and asymmetric encryption keep data secret. You'll also learn to check a file's hash and spot attacks in web server logs.
Study this unit
Flashcards (40)Practice questions (71)Cybersecurity must-know sheetFree-response questions on this unit
Write your own answer, then score it with the rubric or with AI.
- Device Security AnalysisBakery order server: guessed password and a database search box14 points · about 50 minutes
- Device Security AnalysisLibrary catalog server: sprayed staff logins and a poisoned book review14 points · about 50 minutes
- Device Security AnalysisClinic front-desk workstation: default-account guessing and an after-hours copy14 points · about 50 minutes
- Device Security AnalysisDorm heating controller: factory accounts and a scan of every port14 points · about 50 minutes
- Device Security AnalysisStore back-office server: a 3 a.m. login and an oversized gift card number14 points · about 50 minutes
- Device Security AnalysisWater plant operator workstation: a guessed remote login that stayed14 points · about 50 minutes
- Device Security AnalysisLaw firm file server: sprayed logins and files that suddenly locked14 points · about 50 minutes
- Device Security AnalysisResearch lab workstation: a scary email and a 2.3 GB upload14 points · about 50 minutes
- Device Security AnalysisHospital lobby kiosk: a held door and a drive plugged in after hours14 points · about 50 minutes
- Device Security AnalysisFood bank donation site: sprayed admin logins and a receipt download trick14 points · about 50 minutes
- Device Security AnalysisPayroll server: a convincing phone call and a login with no second factor14 points · about 50 minutes
- Device Security AnalysisOffice print server: admin guessing and a gateway with a new address14 points · about 50 minutes
- Device Security AnalysisEsports club game server: an officer password and a flood of replies14 points · about 50 minutes
- Device Security AnalysisWork laptop at a café: a look-alike network and a stolen mail login14 points · about 50 minutes
- Device Security AnalysisStore chatbot server: reused passwords and a chatbot talked into sharing14 points · about 50 minutes
- Device Security AnalysisSchool district DNS server: a contractor login and a changed record14 points · about 50 minutes
- Device Security AnalysisSoftware download server: a guessed upload account and a swapped installer14 points · about 50 minutes
- Device Security AnalysisWarehouse handheld scanner: a guessed PIN and a flashlight app that phones home14 points · about 50 minutes
Big ideas
- Apps that trust user input open the door to injection attacks
- Give every user exactly the access they need and no more
- Symmetric encryption shares one key, while asymmetric encryption uses a public and private key pair
- Longer keys are stronger, but only compare key lengths within the same algorithm
- A changed hash proves a file was altered, and log patterns reveal app attacks
Full unit reviews
Longer videos that cover the whole unit. Good for a first pass or a final review.
Topics
If files aren't encrypted, access controls are loose or regular users have admin rights, an attacker who gets in can read, steal or destroy data. Apps that don't validate input are open to injection attacks: SQL injection (sneaking database commands into an input field), cross-site scripting or XSS (planting code that runs in other people's browsers, reflected or stored), buffer overflows (sending more data than memory was set aside for) and directory traversal (using ../ in a URL to reach files outside the web folder).
Key terms
- data validation
- SQL injection
- cross-site scripting (XSS)
- buffer overflow
- directory traversal
- administrative privileges
A few quick questions on this topic, with the answers explained.
Data can be at rest, in transit or in use. Sensitive kinds such as PII, PHI and payment card information (PCI) come with legal or industry rules, such as HIPAA for health data and the PCI DSS industry standard for card data. Access control models (role-based, rule-based, discretionary and mandatory, like Bell-LaPadula's "write up, read down") plus least privilege decide who can do what. On Linux you read permissions with ls -l and change them with chmod, in numbers (read 4, write 2, execute 1, as in chmod 640 file) or symbols (as in chmod g+r file).
Key terms
- data at rest, in transit, in use
- PII, PHI and PCI
- role-based access control (RBAC)
- mandatory access control (MAC)
- least privilege
- chmod
A few quick questions on this topic, with the answers explained.
Encryption turns plaintext into ciphertext using a key, and a bigger keyspace means guessing the key takes longer. Symmetric algorithms use one key to encrypt and decrypt, while asymmetric ones use two; block ciphers work on fixed-size chunks, while stream ciphers work on a continuous flow. AES, the most common symmetric cipher, encrypts 128-bit blocks and can use keys of different lengths, and you can run it with tools like OpenSSL or AES Crypt.
Key terms
- plaintext and ciphertext
- keyspace
- symmetric encryption
- block vs. stream cipher
- AES
- OpenSSL
A few quick questions on this topic, with the answers explained.
With asymmetric encryption, each receiver makes a key pair: a public key they publish and a private key they guard. To send someone a secret, you encrypt with their public key, and only their private key can decrypt it. Each extra bit of key length doubles the number of possible keys, so longer keys are stronger but slower; recommended lengths rise as computers get faster, and you can only compare lengths within one algorithm, such as RSA or elliptic curve cryptography (ECC).
Key terms
- public key
- private key
- key pair
- key length
- RSA
- elliptic curve cryptography (ECC)
A few quick questions on this topic, with the answers explained.
Secure by design means building security in from the start: companies own their customers' security outcomes, are open about security problems and have leaders who put security first. Secure by default means security features come turned on out of the box. Programmers protect apps by sanitizing input, which means checking that it matches what's expected and removing or rejecting control characters like quotes and semicolons; this blocks many SQL injection, XSS and directory traversal attacks.
Key terms
- secure by design
- secure by default
- input sanitization
- control characters
- data validation
A few quick questions on this topic, with the answers explained.
Accounting logs show who touched which data, so opening unusual files, activity outside a user's normal pattern, or attempts to copy or delete sensitive files are red flags. Honeypot files full of fake data raise an alert the moment someone opens them, data loss prevention (DLP) services watch how data is used and moved, and comparing a file's hash (with sha256sum or Get-FileHash) shows whether it changed. In web logs, quotes, OR 1=1, -- and SQL keywords suggest SQL injection, <script> tags suggest XSS, unusually long requests suggest a buffer overflow attempt, and ../ sequences suggest directory traversal.
Key terms
- accounting
- honeypot
- file hash check
- data loss prevention (DLP)
- web log indicators
A few quick questions on this topic, with the answers explained.