AP Cybersecurity 2.2 Exercise 2: Assessing and Documenting Physical Risk
Exercise 2 — Assessing and Documenting Physical Risk
3 parts, 24 points — Band, document and re-assess physical risk at Xtensr Research Labs
You are on the physical security team at Xtensr Research Labs. Xtensr is acquiring Delmar Applied Optics, a smaller research company across town, and the Delmar building joins the Xtensr network in ninety days. You have the building plans, a list of the controls Delmar already has, and one walkthrough. Your job this week is not to fix anything — it is to assess and document what you found, so Xtensr’s leadership can decide what to fund first and so nothing gets bought on a hunch.
Banding this Low because there is nothing sensitive on it tests the wrong thing. The Moderate band exists for exactly this case — a noncritical, nonsensitive component left unprotected in a way that gives an attacker a foothold for initial access to other resources. The value of this PC is not what it stores; it is what it connects to. Physical access to it also bypasses the technical controls that guard the network from the outside, so the layers Xtensr is counting on never get a turn.
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]