AP Cybersecurity 2.1 Lab: Phases of a Cyberattack

Unit 2 • 2.1 • Lab

Lab — Operation Nightjar: Tracing the Phases of a Cyberattack

6 steps, 30 points — Mixed formats: matching, fill-blank, select-all, MCQ, and written analysis

Score: 0 / 30 Each step uses a different assessment format
Incident Under Review
Northgate Regional Credit Union

Over eleven days an adversary moved from outside Northgate Regional Credit Union all the way to its domain controller. The incident response team has recovered a partial timeline: public-source research on staff, a spoofed invoice attachment opened by a finance clerk, a scheduled task that reloaded malware at every boot, a harvested service account used to reach the backup server and then the domain controller, 14 GB of member records compressed and uploaded to an external host, the payroll file share encrypted in place, and cleared security event logs. Your job is to place each observation in the phase of the cyberattack it belongs to, and to say where Northgate could have broken the chain.

Step 1Matching
Classify Each Attack Phase
Match each analyst note to the phase of the cyberattack it belongs to. Decide the phase in your head before you open the menu.
Scraped the public staff directory, conference talk pages, and job postings to build a list of names, roles, and the company email format
Used a harvested service account to authenticate to the backup server and then the domain controller, gaining permissions the clerk never had
Cleared the security event log entries for the compromised account and deleted the dropped malware binaries from disk
Note 1 = Reconnaissance — gathering freely available information about the target, which is open-source intelligence (EK 2.1.C.2). Note 2 = Lateral movement — reaching accounts and computers with elevated permissions the first foothold did not have (EK 2.1.C.5). Note 3 = Evading detection — removing or editing log files and erasing planted files (EK 2.1.C.7).
Exam Tip: Sort by what the adversary gains. Information about the target → reconnaissance. New permissions → lateral movement. Less evidence left behind → evading detection.
Step 2Fill in the Blank
Complete the Incident Timeline
Fill in each blank with the correct term from Topic 2.1.

Day 1: The adversary collected freely available information about Northgate from public sources — the staff directory, recorded conference talks, and job postings. Publicly available information used this way is called (acronym).

Day 3: A finance clerk opened a spoofed invoice attachment and the adversary gained its first foothold on the network. That phase is called initial .

Day 4: A scheduled task re-launched the malware at every boot and beaconed out for instructions to the adversary’s command and server.

Day 6: The adversary used a harvested service account to reach the domain controller. Moving to accounts and computers with elevated permissions is movement.

Day 9: 14 GB of member records were compressed and uploaded to an external host. Transferring data out of the organization without authorization is data .

Answers: (1) OSINT, open-source intelligence (2) initial access (3) command and control (4) lateral movement (5) data exfiltration
Exam Tip: The phase names are testable vocabulary. Reconnaissance uses OSINT; initial access is the first foothold; persistence keeps that foothold through a command and control channel; lateral movement escalates permissions; taking action collects, exfiltrates, disrupts, or destroys.
Step 3Select All That Apply
Identify Every Indicator of Persistence
Six findings appear in the forensic report. Select ALL of them that are evidence of the persistence phase — and only those. Wrong selections subtract.
Correct: the scheduled task, the dormant administrator account, the autostart registry entry, and the command and control beacons. All four let the adversary keep access without having to regain it (EK 2.1.C.4). The invoice attachment is initial access (2.1.C.3), and the cleared log entries are evading detection (2.1.C.7).
Exam Tip: Persistence answers one question: if the adversary were kicked off right now, what would let them back in automatically? Anything that only got them in once, or that only hides them, belongs to a different phase.
Step 4Multiple Choice
Audit the Analyst’s Phase Assignments
An analyst assigns three findings to phases. I. The harvested service account used to reach the domain controller is lateral movement. II. Deleting the dropped malware binaries is taking action, because it changes data on disk. III. Compressing and uploading 14 GB of member records is taking action. Which assignments are correct?
C. Statement I is correct (EK 2.1.C.5), and statement III is correct — collecting and exfiltrating targeted data is taking action (EK 2.1.C.6). Statement II is wrong: deleting the malware binaries is evading detection (EK 2.1.C.7). Taking action means acting on the adversary’s objective — collecting, exfiltrating, disrupting, or destroying — not cleaning up afterward.
Exam Tip: On a roman-numeral item, rule each statement true or false on its own before you read the combinations. One false statement eliminates every option containing it — here II is false, so B and D are gone immediately.
Step 5Analysis
Rule on a Junior Analyst’s Claim
Three weeks later Northgate logs a second, unrelated intrusion. Responders find reconnaissance against the member portal, initial access through a reused password, and one failed attempt to reach a file server. No elevated account was ever obtained and no data left the network.
5a. A junior analyst writes: “This one showed no lateral movement at all, so it should not be logged as a cyberattack.” Select the BEST correction:
5b. Name the phases this second intrusion did reach, and explain why a missing phase does not disqualify it as a cyberattack.
Key terms: reconnaissance, initial access, phases, not every attack, order, objective, skipped, foothold
B is correct. EK 2.1.C.1 states that adversaries work in phases which may not all be used in every attack, so a missing phase does not disqualify an intrusion. This second incident reached reconnaissance and initial access and then stalled — it is still a cyberattack and it is still reportable.
Exam Tip: The phase model describes how adversaries usually work; it is not a checklist an incident has to complete. Do not require every phase, and do not assume the phases always run in the printed order.
Step 6Written Response
Write the Countermeasure Recommendation
Northgate’s board wants one specific control for three phases — reconnaissance, initial access, and taking action. For each, name the control and say exactly what the adversary would have run into instead.
Key terms: OSINT, job posting, directory, awareness training, phishing, attachment, sandbox, email filter, least privilege, MFA, DLP, egress, monitor, detect, alert, log, block
Model: Reconnaissance — shrink the public footprint: review job postings and the staff directory so OSINT collection no longer yields the email format and role list (EK 2.1.C.2). Initial access — attachment sandboxing plus phishing awareness training, so the spoofed invoice is detonated and blocked before the clerk can open it (2.1.C.3). Taking action — data loss prevention with egress monitoring, alerting on a 14 GB outbound upload and blocking it mid-transfer (2.1.C.6).
Exam Tip: Every phase is a chance to break the chain. Name the control, name the phase, and say what the adversary loses — that three-part structure is what earns credit on a free-response.
Total Points
Quiz 2.1 → Course Hub
AP Cybersecurity 2.1 Lab | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board.
AP Cybersecurity · Unit 2 · Lesson 2.1 · Lab

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]