AP CSP 5.6 Safe Computing | PII, Encryption, and Authentication

AP CSP Course Big Idea 5 5.6 Safe Computing
5.6
Big Idea 5 • Impact of Computing

Safe Computing

🕐 ~35 min FREE 📖 6 MCQ questions 🎮 Phishing Net game IOC-2.A / IOC-2.B / IOC-2.C

After this lesson, you will be able to:

  • Define personally identifiable information (PII) and explain the risks of sharing it online
  • Recognize the signs of a phishing message and describe how malware and social engineering attacks work
  • Explain how strong unique passwords and multifactor authentication protect an account
  • Describe what encryption does and distinguish symmetric encryption from public key encryption
  • Choose appropriate safe computing practices for a given scenario
📈 Big Idea 5 (Impact of Computing) is 21 to 26 percent of the AP CSP exam, and safe computing questions on PII, phishing, authentication, and encryption are dependable points. The vocabulary is precise and testable, so a little memorization here converts directly into correct answers.
💡 Think about this first

You get a text that looks like it is from your bank: it warns your account is locked and gives a link to 'verify your identity' by entering your password and Social Security number right now. The logo looks real and the message sounds urgent. Before you tap anything, what is the single biggest clue that this message might be a trap, and what should you do instead?

Personally Identifiable Information (PII)

Personally identifiable information (PII) is information that can be used to identify a specific individual, either on its own or combined with other data. Examples include your full name, home address, government identification number, phone number, email address, date of birth, biometric data such as a fingerprint or face scan, and your physical location.

The core risk is simple: once information is online, it is very hard to remove and easy to copy. PII that gets exposed can be exploited for identity theft, used to track your movements and habits, or combined with other leaked data to launch targeted attacks. Even seemingly harmless details can be pieced together. Sharing less PII, and thinking before you post, reduces how much of you is exposed.

🎯 What the exam rewards

When a question asks about the danger of sharing PII, the strongest answer names a concrete harm such as identity theft, tracking, or targeted attacks, and recognizes that information online is hard to remove and easy to copy. Answers about convenience or speed are distractors.

Threats: Phishing, Malware, and Social Engineering

Most attacks on ordinary users do not break encryption. They trick the user.

  • Phishing is a fraudulent message, often an email or text, designed to trick you into revealing credentials or PII, or into clicking a malicious link. Phishing usually creates urgency ("act now or lose access"), impersonates a trusted source, and sends you to a fake page that harvests what you type.
  • Malware is malicious software, such as a virus, that is installed without your informed consent to damage a system, steal data, or take control of a device.
  • Social engineering is the broad category of manipulating people into giving up information or access. Phishing is one kind of social engineering.

The common thread is that the human is the target. Signs of phishing include unexpected requests for a password or PII, links whose real address does not match the sender, pressure to act immediately, and small errors in the sender address or spelling.

Quick check
Which of these is the clearest sign that an email is a phishing attempt?

Protections: Passwords and Multifactor Authentication

Your first defense is a strong, unique password: long, hard to guess, and different for every account so that one breach does not unlock the rest. But passwords alone can be stolen or phished, which is why the strongest protection adds more factors.

Multifactor authentication (MFA) requires proof from two or more different kinds of factors before granting access. The three categories are:

Factor type Meaning Example
Something you know Information only you should have Password or PIN
Something you have A physical item or device Phone receiving a code, or a security key
Something you are A biometric trait Fingerprint or face scan

The power of MFA is that an attacker who phishes your password still cannot log in without the second factor, such as the code on your phone. Other everyday protections include being cautious with links and app permissions, and keeping software updated so known vulnerabilities are patched.

⚠ Common trap

Requiring two passwords, or a password plus a security question, is NOT multifactor authentication. Both are "something you know," so they are the same kind of factor. True multifactor combines different kinds of factors, such as a password (know) plus a code from your phone (have).

Encryption: Symmetric and Public Key

Encryption encodes data so that only authorized parties can read it. The scrambled data means nothing to an eavesdropper without the correct key. There are two schemes you must distinguish:

Symmetric encryption Public key (asymmetric) encryption
Keys used One shared key A pair: a public key and a private key
How it works The same key both encrypts and decrypts The public key encrypts; only the matching private key decrypts
Key sharing Both parties must already share the secret key The public key can be shared openly; no secret must be exchanged first

The key advantage of public key encryption is that two people who have never met can communicate securely. You publish your public key for anyone to use to encrypt a message to you, but you keep your private key secret, and only it can decrypt those messages. Symmetric encryption is fast but requires a way to share the one secret key safely in advance.

Quick check
A website publishes a key that anyone can use to encrypt a message to it, but only the website holds the separate key that can decrypt those messages. Which type of encryption is this?

How 5.6 Is Tested on the MCQ Exam

Safe computing appears on the multiple-choice section in a few predictable shapes. Expect a phishing scenario that describes a suspicious message and asks you to identify the warning sign or the safe response; the right answer names the mismatched link, the urgent request for credentials, or the choice to not click and to verify through a known channel. Expect a PII question that asks which item is personally identifiable or names the risk of sharing it, where the strong answer cites identity theft, tracking, or targeted attacks and the difficulty of removing information once it is online.

Expect a multifactor authentication item that tests whether you understand factors must be of different kinds (know, have, are), so two passwords do not count. And expect an encryption item that checks the difference between symmetric encryption (one shared key for both directions) and public key encryption (a public key encrypts, a private key decrypts, no shared secret needed first). Precise vocabulary is what earns these points, so learn the exact definitions rather than the general vibe.

📈
MCQ Practice
6 questions • Exam difficulty and above • Predict before you peek
Question 1 of 6Spot the phishing
Predict the single strongest warning sign before reading the options.

A student receives an email that appears to be from their school's login system. It says their account will be deleted in one hour unless they confirm their password by clicking a link, and the link's real address is a string of random characters unrelated to the school. Which feature most strongly indicates this is a phishing attempt?

Correct. Manufactured urgency plus a request for credentials at a mismatched link is the defining signature of phishing.
Incorrect. Attackers often personalize emails with a name to seem legitimate, so a first-name greeting is not the warning sign.
Incorrect. The time an email arrives is unrelated to whether it is fraudulent.
Incorrect. Naming a real service is exactly what attackers do to impersonate a trusted source; it is not itself a warning sign.
Question 2 of 6Encryption compare
State the key difference in your own words first.

Two people who have never communicated before want to exchange a secret message over the internet without first meeting to agree on a shared secret. Which approach makes this possible, and why?

Incorrect. Symmetric encryption needs both parties to already share one secret key, which is the very problem here.
Incorrect. Speed does not solve the problem; symmetric encryption still requires a pre-shared secret key.
Correct. Public key encryption lets the sender use the recipient's openly published public key, while only the recipient's private key can decrypt, so no prior shared secret is needed.
Incorrect. Public key encryption specifically removes the need to meet in advance to share a key.
Question 3 of 6I, II, III
Decide which items are truly PII before matching an option.

Consider the following pieces of information:

  • I. A person's government-issued identification number
  • II. A person's home address combined with their full name
  • III. The current outdoor temperature in a large city
Incorrect. Item II also identifies a specific individual, so I alone is incomplete.
Correct. A government ID number and a name plus home address both identify a specific individual, so they are PII. A city's temperature identifies no one.
Incorrect. Item III (a city temperature) identifies no individual and is not PII, and item I is PII, so this pairing fails.
Incorrect. Item III is not PII, so not all three can be correct.
Question 4 of 6Multifactor
Decide what makes authentication truly multifactor first.

A website wants to add multifactor authentication. Which change actually implements multifactor authentication?

Incorrect. Two passwords are both 'something you know,' the same kind of factor, so this is not multifactor.
Incorrect. A password and a security question are both 'something you know,' so they are the same factor type, not multiple factors.
Correct. A password ('something you know') plus a code on the user's phone ('something you have') combines two different kinds of factors, which is multifactor authentication.
Incorrect. Typing the same password twice is confirmation, not a second factor of any kind.
Question 5 of 6PII risk
Predict the real harm of the exposure before you look.

A user posts a photo online that automatically includes location data, along with their full name and daily schedule. Which outcome best describes the primary risk created by sharing this personally identifiable information?

Incorrect. Load speed is unrelated to the privacy risk of exposing PII.
Incorrect. Posting a photo does not consume storage in a way that matters here, and it is not the PII risk.
Incorrect. Viewing a photo does not degrade its quality, and this is not the privacy concern.
Correct. Location, name, and schedule together enable tracking and identity theft, and information posted online is difficult to remove or take back.
Question 6 of 6Best response
Predict the safest action before reading the choices.

An employee receives an unexpected message claiming to be from their company's help desk, asking them to reply with their username and password to 'complete a required security update.' What is the safest response?

Correct. Refusing to respond and confirming through an independent official channel defeats the phishing attempt without risking your credentials.
Incorrect. Legitimate help desks do not ask for your password; complying hands your credentials to an attacker.
Incorrect. Spreading the message endangers coworkers and does nothing to verify the request.
Incorrect. An attacker can easily fake a reply, and you should never send a password in a message regardless.
🎮 Lesson Game
Phishing Net
Spot phishing and weak security, then choose multifactor and encryption to lock the account down.

🐛 Phishing Net

Spot phishing and lock down accounts - AP CSP 5.6 Safe Computing.

How to play: Messages stream in. Tap PHISH or SAFE fast, then ace the Secure-the-Account bonus round.

Score0
Streak0
Round1

Frequently Asked Questions

PII is any information that can identify a specific individual, alone or combined with other data. Common examples are your full name, home address, government identification number, phone number, email address, date of birth, biometric data, and location. Even ordinary details can become identifying when combined.
Watch for an urgent demand to act immediately, an unexpected request for your password or PII, a link whose real address does not match the claimed sender, and small errors in the sender's address or spelling. When in doubt, do not click; verify through a known official channel instead.
Multifactor authentication requires two or more different kinds of factors, such as something you know (a password) plus something you have (a code on your phone). An attacker who steals or phishes your password still cannot log in without the second factor, so a single leaked password is no longer enough.
Symmetric encryption uses one shared key to both encrypt and decrypt, so both parties must already share that secret. Public key encryption uses a pair of keys: a public key that anyone can use to encrypt, and a private key that only the owner holds to decrypt. Public key encryption lets strangers communicate securely without sharing a secret in advance.
No. Two passwords, or a password plus a security question, are both 'something you know,' which is a single kind of factor. Multifactor authentication requires different kinds of factors, such as a password combined with a code from your phone or a fingerprint.
📦
AP CSP Teacher SuperpackSlides, lesson plans, unit tests for all 5 Big Ideas, $249
Get the Superpack →
🏫
For teachers

Safe computing lands best when students test it on themselves: have them audit their own accounts for reused passwords, turn on multifactor authentication somewhere real, and dissect an actual phishing email line by line. The Superpack includes a phishing-spotting worksheet, an encryption compare-and-contrast chart, and a PII scavenger hunt. View what's included →

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]