AP Cybersecurity Unit 2 Lesson 1 Exercise 1

Unit 2 • 2.1 • Exercise 1

Exercise 1 — CIA Triad Incident Classification

6 questions — Map real-world incidents to Confidentiality, Integrity, or Availability

Score: 0 / 0 Predict which CIA property is violated before selecting
Client Organization
Ridgecrest Community Hospital

Ridgecrest Community Hospital is a 200-bed facility serving a rural community. The hospital stores electronic health records (EHR), processes insurance claims, operates networked medical devices (IV pumps, patient monitors), and maintains a patient-facing portal for appointment scheduling. Six security incidents were reported this quarter. Classify each using the CIA Triad.

Q1 Confidentiality
A hospital employee accesses the EHR system and views the medical records of a celebrity patient who is not under their care. The employee screenshots the records and shares them on social media. Which CIA property was PRIMARILY violated?
Q2 Integrity
A ransomware attack encrypts Ridgecrest’s billing database. Before encrypting the data, the malware alters 2,300 insurance claim amounts, changing them to random values. The hospital discovers the alterations only after submitting the corrupted claims to insurers. Which CIA property was PRIMARILY violated by the data alteration (not the encryption)?
Q3 Availability
A power surge damages Ridgecrest’s primary server room, taking the EHR system offline for 14 hours. During this period, doctors cannot access patient medication lists, allergy information, or lab results. Emergency patients are treated using paper-based protocols. Which CIA property was PRIMARILY violated?
Q4 Multi-Property
A phishing email tricks a nurse into entering her EHR credentials on a fake login page. The attacker uses the stolen credentials to: (1) download 500 patient records, (2) modify medication dosages in 12 patient charts, and (3) lock the nurse’s account, preventing her from accessing the system. Which CIA properties were violated?
Q5 Applied Classification
Ridgecrest’s patient portal allows patients to view their lab results online. A software bug causes the portal to display Patient A’s lab results when Patient B logs in. No data was modified, and the system remained operational. Which CIA property was violated?
Q6 Countermeasure Mapping
Ridgecrest implements daily encrypted backups stored at an offsite facility. Which CIA property does this countermeasure PRIMARILY protect?
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 2 • 2.1 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]