AP Cybersecurity Unit 2 Lesson 1 Exercise 2
Exercise 2 — Risk Assessment, Risk Strategy & Defense in Depth
3 parts, 24 points — Apply CED Topic 2.1 (EK 2.1.D, 2.1.E, 2.1.F, 2.1.G) to a live risk review at Riverbend Community Credit Union
Riverbend Community Credit Union serves 41,000 members from four branches and one operations center. It holds a member database (names, Social Security numbers, account balances, loan files), runs a member-facing mobile app, and outsources core account processing to a third-party vendor. Riverbend’s board has ordered a full risk review. Each part below hands you one stage of that review — assess the risk, decide how to manage it, then defend the control set. Draft your own answer before you read the model response.
A complete member-database entry would state the asset and its value to Riverbend and to an adversary; the specific vulnerabilities (for example, database credentials stored in an application config file, and no alerting on bulk export queries); how each would be exploited; the likelihood, argued from adversary motivation and capability and from how much skill the exploit requires (2.1.D.4); the severity, argued from restoration cost, regulatory penalties, and member harm (2.1.D.5); and only then the rating.
A bare rating cannot guide spending because two assets rated “high” can need completely different controls. Without the vulnerability and the exploitation path, leadership cannot tell whether the money should buy segmentation, monitoring, staff training, or a vendor change — so the rating tells them to act but not what to buy.
The strategies are not interchangeable. Avoidance was available for Finding A only because guest Wi-Fi is not critical to the mission; EK 2.1.E.2 states that avoidance is impossible when the activity is a critical part of the organization’s mission, which is exactly the case for core account processing. Running the argument the other way, transference would have been a poor answer for Finding A: paying an insurer to absorb a loss Riverbend could remove for free, by turning off a courtesy service, spends money to keep a risk it never had to hold.
Residual risk is what is left after the chosen strategy is applied. Insurance reimburses notification and legal costs; it does not stop the breach, restore member trust, or recover the exposed data, so Riverbend still carries the operational and reputational loss. Even after avoidance, members now use cellular data in the lobby and staff may be tempted to re-enable a hotspot. Acceptance means leadership has looked at that remaining exposure, judged it tolerable against the cost of reducing it further, and recorded that judgment with a date and an owner (2.1.E.4). Doing nothing is not acceptance — it is an undocumented risk that nobody has agreed to carry and nobody is monitoring.
The consultant is wrong. Encryption is a single technical control protecting one property of one asset — the confidentiality of stored data. It does nothing about a staff member who hands over credentials to a caller, a stranger walking into an unlocked server room, an adversary pivoting from the mobile app servers onto teller workstations, or the first confused hour after an alert fires. Defense in depth means placing controls in layers so that each layer mitigates the threat it is best suited to, and so that if one control is bypassed or fails, another still limits the damage (2.1.G.2, 2.1.G.3).
Mapped to the layers named in 2.1.G.4: training defends the human layer, the badge reader the physical layer, segmentation the network layer, encryption the data layer, and the incident response plan governs the response across all of them. Those are five different threats, not one threat paid for five times — which is what redundant spending would actually look like.
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]