AP Cybersecurity 2.2 Exercise 2: Assessing and Documenting Physical Risk

Unit 2 • 2.2 • Exercise 2

Exercise 2 — Assessing and Documenting Physical Risk

3 parts, 24 points — Band, document and re-assess physical risk at Xtensr Research Labs

Score: 0 / 24Complete all 3 parts
Scenario 2A — Acquisition Site Assessment
Xtensr Research Labs — Delmar Applied Optics Site

You are on the physical security team at Xtensr Research Labs. Xtensr is acquiring Delmar Applied Optics, a smaller research company across town, and the Delmar building joins the Xtensr network in ninety days. You have the building plans, a list of the controls Delmar already has, and one walkthrough. Your job this week is not to fix anything — it is to assess and document what you found, so Xtensr’s leadership can decide what to fund first and so nothing gets bought on a hunch.

Part 1
Banding the Walkthrough Findings
Three findings from the Delmar walkthrough. (1) Server room, ground floor. Reached from an unmonitored back hallway; the door has a keyed lock, but staff wedge it open from 7 a.m. to 6 p.m. because the room runs hot. The rack holds the file server with Delmar’s client project data. (2) Reception check-in PC. Sits on Delmar’s internal wireless network with two USB ports exposed at the front of the desk; visitors stand alone at it for a minute or two while the receptionist walks back to the badge printer. (3) Second-floor project office. Behind a badge reader that logs every entry; six loaner laptops with no project data on them sit uncabled on the desks during the Friday all-hands lunch.
8 points
1a. Assign each finding a risk band of High, Moderate or Low. Justify each band with the characteristic that puts it there — what is exposed, how restricted and controlled the access to it is, and whether the finding is a foothold to other resources. Do not justify a band by how likely you personally feel an attack is.
Key terms: High, Moderate, low value, sensitive, restricted, uncontrolled, foothold, initial access, other resources, unlikely, badge, USB, wireless, unmonitored, propped open, loaner, exposed
Model Response: Finding 1 — High. A server holding client project data sits in a room whose access is not sufficiently restricted or controlled: the lock is defeated by the staff themselves for eleven hours a day, and the hallway that reaches it is unmonitored. Sensitive systems plus uncontrolled access is what the High band describes. Finding 2 — Moderate. The reception PC is noncritical and holds nothing sensitive, but it sits on the internal wireless network and its USB ports are exposed to unescorted visitors, so it is a foothold for initial access to other resources. Finding 3 — Low. The laptops are low-value assets with no project data, the office is behind a badge reader that logs entries, and an exploit is unlikely; the exposure is real but small. Notice that all three justifications name what is exposed and how controlled the access is. None of them guesses at attacker motivation — that guess is the most common way a walkthrough report loses its credibility with leadership.
Part 2
Documenting the Reception PC
Xtensr keeps a risk register with one row per finding: vulnerability, threat, likelihood with its reason, and impact named as a compromise type. The four compromise types Xtensr uses are unauthorized access to data or restricted space, disruption of services, theft or destruction of resources, and unauthorized modification of data. Delmar’s outgoing IT manager has already written his own note on the reception PC: “Low — there is nothing sensitive on that machine.”
8 points
2a. Write the risk-register row for the reception check-in PC. State the vulnerability, the threat that would exploit it, the likelihood and the reason for it, and the impact named as one of the four compromise types.
Key terms: vulnerability, threat, likelihood, impact, USB port, internal wireless, unattended, visitor, malware-loaded drive, keylogger, unauthorized access, moderate, repeats every visit
2b. The outgoing manager’s note bands this finding Low. Explain why that band is wrong, arguing from what the machine is a foothold to rather than from what is stored on it.
Key terms: foothold, initial access, other resources, noncritical, internal network, bypass technical controls, pivot, moderate, physical access, what it connects to
Model Response: Vulnerability — a networked workstation with physically exposed USB ports, left unattended beside unescorted visitors. Threat — a visitor, or somebody posing as one, who inserts a malware-loaded drive or a hardware keylogger into an open port. Likelihood — moderate to high, and the reason matters more than the word: the attack needs no tool, no skill and no credential, only the minute the receptionist spends at the badge printer, and that minute repeats on every visit. Impact — unauthorized access to data: the machine sits on Delmar’s internal wireless network, so anything running on it reaches resources that cannot be reached from outside the building.

Banding this Low because there is nothing sensitive on it tests the wrong thing. The Moderate band exists for exactly this case — a noncritical, nonsensitive component left unprotected in a way that gives an attacker a foothold for initial access to other resources. The value of this PC is not what it stores; it is what it connects to. Physical access to it also bypasses the technical controls that guard the network from the outside, so the layers Xtensr is counting on never get a turn.
Part 3
Re-Assessing as Information Arrives
A week after the walkthrough, four facts come back from Delmar’s IT records. (1) The file server in the server room holds only a nightly mirror of data that already lives in Xtensr’s hardened primary data center — but the same rack holds the controller for the building’s badge system. (2) The reception PC is confirmed to sit on the same wireless segment as the lab instrument controllers. (3) The loaner laptops are wiped nightly and hold nothing, but each one is still domain-joined with a cached credential. (4) The back hallway does have a camera, but its recorder has been full since March and is overwriting nothing.
8 points
3a. For each of the four facts, state whether that finding’s band should go up, down or stay the same, and name the characteristic that decides it — what is exposed, whether the access to it is controlled, whether it is a foothold, or whether a control that exists on paper actually does anything.
Key terms: stays High, badge controller, restricted space, raises the band, segment, instrument, cached credential, foothold, recorder, does not detect, mirror, domain-joined, low value, disruption of services, overstate
Model Response: (1) Stays High. The data justification weakens — a mirror of data that is already safe elsewhere is not the crown jewel — but the same rack holds the badge-system controller, so that room now governs access to every restricted space in the building. Sensitive system, uncontrolled access: still High, for a different reason than the one you wrote down first. (2) Raises the band. The foothold is no longer hypothetical. The segment reaches the lab instrument controllers, which adds disruption of services to the unauthorized-access impact already recorded. Moderate becomes High. (3) Raises the band. A wiped laptop is a low-value asset, but a domain-joined laptop carrying a cached credential is a foothold for initial access to other resources — the Moderate characteristic, not the Low one. The asset is worthless; the access sitting on it is not. (4) Raises the band, and at the very least cannot lower it. A camera whose recorder is full is a control on the plan and not a control in the building: it neither prevents nor detects, so it earns no credit. Writing it into the register as a control in place would overstate Delmar’s security to the people funding the fix. The pattern across all four: a band moves when what is exposed, how controlled the access is, or what the finding leads to changes — not when the story told about it changes.
Total Points
Lab 2.2 →Course Hub
AP Cybersecurity 2.2 Exercise 2 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
AP Cybersecurity · Unit 2 · Lesson 2.2 · Exercise 2
LessonExercise 1Exercise 2Quiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]