AP Cybersecurity 2.2 Exercise 1: Physical Attacks and How Threats Exploit Them
Exercise 1 — Physical Attacks and How Threats Exploit Them
6 questions — Name the attack, separate the vulnerability from the threat, and trace the compromise
Xtensr Research Labs has acquired a smaller research company across town, and you are on the physical security team running the assessment of the new building. This exercise works through the walkthrough notes: name each physical attack correctly, separate the vulnerability from the threat, and state the compromise that would follow.
(A) Incorrect — the attack is misnamed, and keypads do nothing about a second person walking in on someone else’s authorization.
(B) Incorrect — shoulder surfing (EK 2.2.A.4) is watching a user access sensitive information so it can be used later; nothing is observed and reused here.
(D) Incorrect — dumpster diving (EK 2.2.A.5) is searching a target’s physical trash; the finding involves no discarded material.
I. A person balancing two boxes of copier paper waits by the door until an employee opens it and holds it for them.
II. A person in a utility uniform tells an employee they need to inspect the sprinkler riser and is walked inside without a work order.
III. A person moves quickly and silently through the door as it swings shut behind a departing employee who never looks back.
(A) Incomplete — incident II is the maintenance-worker piggybacking tactic named in EK 2.2.A.2, so it belongs with incident I.
(C) Incorrect — incident III is tailgating rather than piggybacking, and incident I is a piggybacking tactic that this option leaves out.
(D) Incorrect — incident III involves no awareness or decision by the departing employee, which places it under tailgating.
(A) This is shoulder surfing — EK 2.2.A.4 explicitly includes recording the target with a camera for later analysis.
(B) This is dumpster diving — going through a target’s physical trash for information that advances the adversary’s goal.
(C) This is card cloning — producing a copy of an authorized user’s access card in order to use that user’s access.
(B) Incorrect — occupancy patterns are useful reconnaissance for an adversary, but they do not amount to device compromise.
(C) Incorrect — weak accountability is a real drawback of shared accounts, yet it does not explain the severity of reachable ports.
(D) Incorrect — license allocation is a cost question and does not belong in a vulnerability finding at all.
(A) Incorrect — this reverses the pair. Theft is the compromise that results, and the latch is the weakness rather than the actor.
(B) Incorrect — the hours and the location both affect likelihood, but neither is the flaw itself nor the party acting on it.
(C) Incorrect — asset value drives impact, and a missing camera is a second vulnerability, not the threat.
(A) Incorrect — cutting power does not make stored data readable; this confuses an availability compromise with a confidentiality one.
(B) Incorrect — modifying the reader database is an unauthorized-modification compromise and requires access to the system, not to the breaker.
(D) Incorrect — an outage stops new footage from being recorded; it does not hand the adversary the footage already stored.
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]