AP Cybersecurity Unit 2 Lesson 1 Quiz

Unit 2 • 2.1 • Quiz

Lesson 2.1 Quiz: Cyber Foundations

5 questions — Social engineering, adversaries, attack phases, risk, and controls

Score: 0 / 0 Answer each question, then check your score below
Before You Begin
Topic 2.1 — Cyber Foundations

These five questions span the whole of Topic 2.1: social engineering tactics (2.1.A), types of adversaries (2.1.B), the phases of a cyberattack (2.1.C), the risk assessment process (2.1.D), strategies for managing risk (2.1.E), and types of security controls (2.1.F). Read each stem twice and predict your answer before you look at the choices — every distractor here is written to be plausible. Watch for the bolded keyword in the stem; it changes what the question is asking.

Q1 Social Engineering Tactics
A student builds a quick-reference table of social engineering tactics for a study group. Exactly one row states its tactic incorrectly. Predict the mismatch before you read the choices. Which row is WRONG?
Q2 Phases of a Cyberattack
An incident report pairs three observed behaviors with the phase of the cyberattack it assigns them to.

I. Installing a remote access trojan that re-launches at boot and beacons to a command and control server — persistence.
II. Using a harvested service account to reach a domain controller the adversary could not previously access — lateral movement.
III. Clearing the security event log and deleting the dropped malware binaries — taking action.

Which pairings are correct?
Q3 Risk Assessment
A risk assessment team is estimating the likelihood that a specific vulnerability will be exploited. Which factor is LEAST relevant to that estimate?
Q4 Strategies for Managing Risk
A hospital finds that its patient-records vendor could be breached. Processing those records is central to the hospital’s mission, so the vendor relationship cannot be ended. The hospital buys a cyber-liability policy that would cover the notification and legal costs of such a breach. Which strategy did it use, and why was a different option unavailable?
Q5 Types of Security Controls
A district deploys four controls: a badge reader on the server-room door, full-disk encryption on staff laptops, an intrusion detection system on the network, and a written incident response plan. Each statement below classifies one of them correctly EXCEPT one. Which statement is incorrect?
Questions Correct
Course Hub →
AP Cybersecurity Unit 2 • 2.1 • Quiz | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]