Skip to main content

AP® Cybersecurity

Not weighted by unit

Unit 5: Securing Applications and Data

Stealing, changing or locking up data is often an attacker's real goal. This unit covers how apps get attacked through their input fields, how access controls and Linux permissions limit who can do what, and how symmetric and asymmetric encryption keep data secret. You'll also learn to check a file's hash and spot attacks in web server logs.

Study this unit

Flashcards (40)Practice questions (71)Cybersecurity must-know sheet

Free-response questions on this unit

Write your own answer, then score it with the rubric or with AI.

Big ideas

  • Apps that trust user input open the door to injection attacks
  • Give every user exactly the access they need and no more
  • Symmetric encryption shares one key, while asymmetric encryption uses a public and private key pair
  • Longer keys are stronger, but only compare key lengths within the same algorithm
  • A changed hash proves a file was altered, and log patterns reveal app attacks

Full unit reviews

Longer videos that cover the whole unit. Good for a first pass or a final review.

If files aren't encrypted, access controls are loose or regular users have admin rights, an attacker who gets in can read, steal or destroy data. Apps that don't validate input are open to injection attacks: SQL injection (sneaking database commands into an input field), cross-site scripting or XSS (planting code that runs in other people's browsers, reflected or stored), buffer overflows (sending more data than memory was set aside for) and directory traversal (using ../ in a URL to reach files outside the web folder).

Key terms

  • data validation
  • SQL injection
  • cross-site scripting (XSS)
  • buffer overflow
  • directory traversal
  • administrative privileges
  • SQL Injection - CompTIA Security+ SY0-701 - 2.3

    Professor MesserWatch on YouTube (opens in a new tab)

  • What Is SQL Injection?

    HacksplainingWatch on YouTube (opens in a new tab)

  • Cross-site Scripting - CompTIA Security+ SY0-701 - 2.3

    Professor MesserWatch on YouTube (opens in a new tab)

  • Cross-Site Scripting: A 25-Year Threat That Is Still Going Strong

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • From Missingno to Heartbleed: Buffer Exploits and Buffer Overflows

    Tom ScottWatch on YouTube (opens in a new tab)

  • What is directory traversal? (file path traversal) - Web Security Academy

    PortSwiggerWatch on YouTube (opens in a new tab)

Read the review notes: 5.1 Application and Data Vulnerabilities and Attacks

A few quick questions on this topic, with the answers explained.

Data can be at rest, in transit or in use. Sensitive kinds such as PII, PHI and payment card information (PCI) come with legal or industry rules, such as HIPAA for health data and the PCI DSS industry standard for card data. Access control models (role-based, rule-based, discretionary and mandatory, like Bell-LaPadula's "write up, read down") plus least privilege decide who can do what. On Linux you read permissions with ls -l and change them with chmod, in numbers (read 4, write 2, execute 1, as in chmod 640 file) or symbols (as in chmod g+r file).

Key terms

  • data at rest, in transit, in use
  • PII, PHI and PCI
  • role-based access control (RBAC)
  • mandatory access control (MAC)
  • least privilege
  • chmod
  • Access Controls - CompTIA Security+ SY0-701 - 4.6

    Professor MesserWatch on YouTube (opens in a new tab)

  • Linux File Permissions in 5 Minutes | MUST Know!

    Travis MediaWatch on YouTube (opens in a new tab)

  • States of Data - CompTIA Security+ SY0-701 - 3.3

    Professor MesserWatch on YouTube (opens in a new tab)

  • Linux Commands for Beginners 21 - Changing Permissions Numerically

    Learn Linux TVWatch on YouTube (opens in a new tab)

  • CertMike Explains The Bell LaPadula Model

    Mike ChappleWatch on YouTube (opens in a new tab)

  • Personally Identifiable Information (PII) | Internet safety | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

Read the review notes: 5.2 Protecting Applications and Data: Managerial Controls and Access Controls

A few quick questions on this topic, with the answers explained.

Encryption turns plaintext into ciphertext using a key, and a bigger keyspace means guessing the key takes longer. Symmetric algorithms use one key to encrypt and decrypt, while asymmetric ones use two; block ciphers work on fixed-size chunks, while stream ciphers work on a continuous flow. AES, the most common symmetric cipher, encrypts 128-bit blocks and can use keys of different lengths, and you can run it with tools like OpenSSL or AES Crypt.

Key terms

  • plaintext and ciphertext
  • keyspace
  • symmetric encryption
  • block vs. stream cipher
  • AES
  • OpenSSL
  • Cryptography: Crash Course Computer Science #33

    CrashCourseWatch on YouTube (opens in a new tab)

  • Encryption - Symmetric Encryption vs Asymmetric Encryption - Cryptography - Practical TLS

    Practical NetworkingWatch on YouTube (opens in a new tab)

  • Stream and Block Ciphers - SY0-601 CompTIA Security+ : 2.8

    Professor MesserWatch on YouTube (opens in a new tab)

  • AES Explained (Advanced Encryption Standard) - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Encrypting Data - CompTIA Security+ SY0-701 - 1.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • Symmetric Encryption With OpenSSL

    NeuralNineWatch on YouTube (opens in a new tab)

Read the review notes: 5.3 Protecting Stored Data with Cryptography

A few quick questions on this topic, with the answers explained.

With asymmetric encryption, each receiver makes a key pair: a public key they publish and a private key they guard. To send someone a secret, you encrypt with their public key, and only their private key can decrypt it. Each extra bit of key length doubles the number of possible keys, so longer keys are stronger but slower; recommended lengths rise as computers get faster, and you can only compare lengths within one algorithm, such as RSA or elliptic curve cryptography (ECC).

Key terms

  • public key
  • private key
  • key pair
  • key length
  • RSA
  • elliptic curve cryptography (ECC)
  • Encryption and public keys | Internet 101 | Computer Science | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

  • Asymmetric Encryption - Simply explained

    Simply ExplainedWatch on YouTube (opens in a new tab)

  • Public Key Cryptography - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Public Key Cryptography: RSA Encryption

    Art of the ProblemWatch on YouTube (opens in a new tab)

  • 128 Bit or 256 Bit Encryption? - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Elliptic Curve Cryptography in less than 5 minutes

    Practical NetworkingWatch on YouTube (opens in a new tab)

Read the review notes: 5.4 Asymmetric Cryptography

A few quick questions on this topic, with the answers explained.

Secure by design means building security in from the start: companies own their customers' security outcomes, are open about security problems and have leaders who put security first. Secure by default means security features come turned on out of the box. Programmers protect apps by sanitizing input, which means checking that it matches what's expected and removing or rejecting control characters like quotes and semicolons; this blocks many SQL injection, XSS and directory traversal attacks.

Key terms

  • secure by design
  • secure by default
  • input sanitization
  • control characters
  • data validation
  • Application Security - CompTIA Security+ SY0-701 - 4.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • 10 Principles for Secure by Design: Baking Security into Your Systems

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • SQL Injection Prevention: Security Simplified

    Vickie Li DevWatch on YouTube (opens in a new tab)

  • How To Prevent The Most Common Cross Site Scripting Attack

    Web Dev SimplifiedWatch on YouTube (opens in a new tab)

  • Application Security 101 - What you need to know in 8 minutes

    SnykWatch on YouTube (opens in a new tab)

Read the review notes: 5.5 Protecting Applications

A few quick questions on this topic, with the answers explained.

Accounting logs show who touched which data, so opening unusual files, activity outside a user's normal pattern, or attempts to copy or delete sensitive files are red flags. Honeypot files full of fake data raise an alert the moment someone opens them, data loss prevention (DLP) services watch how data is used and moved, and comparing a file's hash (with sha256sum or Get-FileHash) shows whether it changed. In web logs, quotes, OR 1=1, -- and SQL keywords suggest SQL injection, <script> tags suggest XSS, unusually long requests suggest a buffer overflow attempt, and ../ sequences suggest directory traversal.

Key terms

  • accounting
  • honeypot
  • file hash check
  • data loss prevention (DLP)
  • web log indicators
  • Deception and Disruption - CompTIA Security+SY0-701 - 1.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is a Honeypot?

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

  • Data Loss Prevention - SY0-601 CompTIA Security+ : 2.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • VERIFY MD5 / SHA256 Hash or Checksum on Linux - File Security (Ubuntu)

    SavvyNikWatch on YouTube (opens in a new tab)

  • How to Verify File Integrity with Checksum using PowerShell

    ACI LearningWatch on YouTube (opens in a new tab)

Read the review notes: 5.6 Detecting Attacks on Data and Applications

A few quick questions on this topic, with the answers explained.