AP CSP Topic 5.6 Guided Notes - Safe Computing
Big Idea 5: Impact of Computing · Topic 5.6 · Guided Notes (Student)
Safe Computing — Guided Notes
Fill these in during class or catch up here if you were absent. Print this page or work on paper — then check yourself with the CFUs on the Topic 5.6 page.
Print these notesTopic 5.6 lesson pageAll CSP topics
Day 1: The Trail You Can't See
Today’s objectives
- Define personally identifiable information (PII) and describe how searches, page visits, and locations are recorded and stored (LO IOC-2.A)
- Explain how disparate data can be aggregated into knowledge about a person — and why online information is hard to delete (LO IOC-2.A)
Bell ringer
A total stranger gets 10 minutes with ONLY your public profiles — the bios, posts, tags, and photos anyone on the internet can see.
List everything they could learn or DEDUCE: school, neighborhood, schedule, friends, habits. Star the deductions — things you never actually posted.
01. The Recorded Life
Key Vocabulary (LO IOC-2.A)
| Term | Definition (write it) |
|---|---|
| Personally identifiable information (PII) | |
| Aggregation |
Recorded While You Browse
- A search engine can turn your query history into .
- Location-aware programs can log not just where you went but .
- Websites can quietly build a record of .
The Double Life of PII
PII enhances
PII endangers
- Companies keep PII partly so that shopping feels .
- In criminal hands, the identical profile could support .
- A post meant for friends can still reach .
AP TIP: The exam pairs these — the storage that makes checkout instant is what identity thieves want. Judge the CONTEXT, not the data.
Stop and think
- Name three systems that recorded data about you before school today, and state exactly what each one stored.
- A friend says: 'I never post my address, so nobody online knows where I live.' Use location collection to challenge that.
- Give one way stored PII makes your life easier and one way the SAME data could harm you — same data, both directions.
Answer in complete sentences. Then check yourself with the matching CFUs on the Topic 5.6 page.
02. Aggregation and Permanence
Five Trails, One Dossier
Each trail looks harmless alone. Fill in what the pieces reveal once they are combined.
Complete the empty cells.
| Data trail | What gets collected | Aggregated, it reveals... |
|---|---|---|
| Search engine history | Every query you have typed | |
| Websites you visit | A log of who viewed which pages | Your reading habits, politics, and hobbies |
| Phone location services | Where you went, your route, how long you stayed | |
| Cookies + browsing history | Disparate records of activity across many sites | |
| Social media posts and tags | What you AND others post about you |
Watch out — “Deleted Means Gone”
Myth: If you delete an embarrassing post or photo, it is erased from the internet and can no longer hurt you.
Explain why this is wrong:
Deep Dive · Beyond the AP Exam
Deep Dive: The Data Broker Economy
- A data broker's actual product is .
- Aggregated broker scores can quietly shape .
Stop and think
- Using the worked table, explain how a stranger could find your school without you ever posting its name.
- Why does 'I deleted it' fail as a privacy strategy? Cite what happens to online information over time.
- An app's terms say it may share data with 'partners.' Predict one unintended use of that shared data and who might end up seeing it.
Answer in complete sentences. Then check yourself with the matching CFUs on the Topic 5.6 page.
Today in one box
- PII identifies, links, relates to, or describes you — SSN, age, race, phone, medical, financial, biometric
- Searches, page views, and locations are recorded and stored as you move through an ordinary day
- Aggregating disparate data creates knowledge — the dossier is the danger, not any single field
- The same PII that enhances experiences enables stalking and identity theft — and it is hard to delete
Before next class: The stranger who built your dossier now wants your password — using ONE email. Before tomorrow, think: what would that email need to say to fool you?
Day 2: Locks, Layers, and Lures
Today’s objectives
- Explain how computing resources are protected: authentication factors, encryption, certificates, scanning, updates, permissions (LO IOC-2.B)
- Explain how unauthorized access is gained: phishing, keylogging, rogue access points, malicious links and downloads (LO IOC-2.C)
Bell ringer
Yesterday's stranger has your dossier — and ONE email to trick you into handing over your password. Write that email: subject line plus two sentences.
Then switch sides: write the single rule that would have protected you from the exact email you just wrote.
01. Protecting Computing Resources
Key Vocabulary — Protection (LO IOC-2.B)
| Term | Definition (write it) |
|---|---|
| Multifactor authentication | |
| Encryption |
Three Kinds of Proof
- A fingerprint is a different factor from a password: it proves .
- Passwords built from a pet's name or a birthday are weak, since .
- A second factor matters even after a password is stolen: the thief still faces .
Watch out — “A Strong Password Is Enough”
Myth: If your password is long, random, and unique, your account is safe — extra login steps are just inconvenience theater.
Explain why this is wrong:
Two Ways to Lock Data
Symmetric key
Public key
- Symmetric encryption's classic weakness is .
- To send an encrypted message with public key encryption, you need .
- Only the intended receiver can read a public-key message, thanks to .
AP TIP: The math is officially EXCLUDED from the exam. Questions test who needs which key — not how the scrambling works.
The Rest of the Defense Kit
- You can trust a site's padlock ultimately since .
- Updates are a security tool: each patch .
- Before granting an app access, check .
Stop and think
- A bank login asks for a password, then a code texted to your phone. Name each factor's category and explain what the second step adds.
- Aisha wants to send Ben a message only Ben can read, using public key encryption. Whose key does she encrypt with, and why doesn't she need Ben's private key?
- Your laptop has nagged about a security update for two weeks. Explain what stays open until you click install.
Answer in complete sentences. Then check yourself with the matching CFUs on the Topic 5.6 page.
02. How Unauthorized Access Happens
Key Vocabulary — Attacks (LO IOC-2.C)
| Term | Definition (write it) |
|---|---|
| Phishing | |
| Keylogging |
Ways In Without a Password
- Traffic on an open network risks being .
- An attachment from a friend can still be dangerous when .
- 'Free' software carries a hidden price when shareware sites .
Attack Triage: Name It, Block It
Five incidents. Fill in the attack's CED name and the defense layer that blocks it (LO IOC-2.B, IOC-2.C).
Complete the empty cells.
| Incident | Attack (CED name) | Defense that blocks it |
|---|---|---|
| 'Account locked!' email links to a look-alike login page | Never log in from email links — go to the real site yourself | |
| After a free 'game booster' install, saved passwords leak one by one | Malware scanning software; download only from trusted sources | |
| A second 'Free_Cafe_WiFi' network appears; traffic is being read | No sensitive logins on public networks; encrypted connections only | |
| A teammate's hacked account emails you an 'invoice' attachment | Compromised known sender | |
| A stolen password still fails to open a student's email account | Attack stopped at the login |
Deep Dive · Beyond the AP Exam
Deep Dive: Inside the Padlock (HTTPS)
- HTTPS opens with public key encryption so both sides can .
- The browser believes a public key is genuine when .
Stop and think
- Write two tells that separate a phishing email from a real notice, and name the resource the attacker is actually after.
- At an airport you see 'Airport_WiFi' and 'Airport_WiFi_FREE.' Explain the risk of choosing wrong and what an attacker could do with your traffic.
- A pop-up on a free-downloads site says 'Update your video player now.' Predict what say happens next — and name two defenses from LO IOC-2.B that would stop it.
Answer in complete sentences. Then check yourself with the matching CFUs on the Topic 5.6 page.
Common AP Traps
Three ways Topic 5.6 loses points on the exam — one minute now, real points in May.
Two passwords ≠ multifactor — in your own words:
Whose key encrypts? — in your own words:
One field vs. the dossier — in your own words:
Safe Computing, in One Slide
- PII identifies, links, relates to, or describes you; searches, page views, and locations are recorded
- Aggregated disparate data becomes knowledge about you — and online information is hard to delete
- Protection layers: strong passwords + multifactor (two of knowledge / possession / inherence), encryption, certificates
- Maintenance is defense: scanning software, regular updates, permission reviews
- Attacks target people: phishing, keylogging, rogue access points, disguised links, risky downloads
Exit check — I can…
- ☐ define PII and describe how everyday activity is recorded and stored (LO IOC-2.A)
- ☐ explain how aggregation turns scattered data into privacy risk (LO IOC-2.A)
- ☐ match authentication factors and encryption approaches to what they protect (LO IOC-2.B)
- ☐ name the attack in a scenario and the defense that blocks it (LO IOC-2.C)
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]