AP Cybersecurity 2.2 Exercise 1: Physical Attacks and How Threats Exploit Them

Unit 2 • 2.2 • Exercise 1

Exercise 1 — Physical Attacks and How Threats Exploit Them

6 questions — Name the attack, separate the vulnerability from the threat, and trace the compromise

Score: 0 / 0 Predict the answer before selecting an option
Scenario Organization
Xtensr Research Labs — Scenario 2A

Xtensr Research Labs has acquired a smaller research company across town, and you are on the physical security team running the assessment of the new building. This exercise works through the walkthrough notes: name each physical attack correctly, separate the vulnerability from the threat, and state the compromise that would follow.

Q1 Spot the Error
A first-year analyst writes this finding for the assessment: “Employees at the new lab often chat with the front guard while badging in, so an adversary could stand behind them and enter unnoticed. This is card cloning, and the fix is to replace the badge readers with keypads.” Which statement identifies the errors in the finding?
Q2 Piggybacking Tactics
Three incidents are logged at the new lab’s rear entrance. Decide your own answer first: which incidents are examples of piggybacking?
I. A person balancing two boxes of copier paper waits by the door until an employee opens it and holds it for them.
II. A person in a utility uniform tells an employee they need to inspect the sprinkler riser and is walked inside without a work order.
III. A person moves quickly and silently through the door as it swings shut behind a departing employee who never looks back.
Q3 Attack Recognition
An adversary spends a week studying the new lab. Each observation below describes one of the physical attacks named in Topic 2.2 EXCEPT one. Which observation does not describe a Topic 2.2 physical attack?
Q4 Device Exploitation
The new lab’s conference room holds a wall-mounted PC that stays logged into a shared scheduling account, and its USB ports are enabled and within reach. Which statement BEST explains why the assessor rates this a serious vulnerability rather than a minor inconvenience?
Q5 Vulnerability vs Threat
The assessment has to separate the vulnerability from the threat in every finding. For the finding “the loading-dock door latch is broken and the door rests unlatched overnight,” which pairing is correct?
Q6 Availability Impact
The new lab’s electrical box sits in an unlocked exterior alcove, and the badge readers, cameras, and specimen freezers all draw from it with no backup power. Which consequence should the assessment document as the MOST direct result of an adversary opening that box and pulling the main breaker?
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 2 • 2.2 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
AP Cybersecurity · Unit 2 · Lesson 2.2 · Exercise 1
LessonExercise 1LabQuiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]