AP Cybersecurity Unit 2 Lesson 2 Lab

Unit 2 • 2.2 • Lab

Lab — The Delmar Walkthrough: Assessing Physical Risk at an Acquisition Site

6 steps, 30 points — Mixed formats: matching, fill-blank, select-all, MCQ, and written risk analysis

Score: 0 / 30Each step uses a different assessment format
Site Assessment — Scenario 2A
Delmar Applied Optics (acquisition of Xtensr Research Labs)

You are on the physical security team at Xtensr Research Labs. Xtensr is buying Delmar Applied Optics, a smaller research company across town, and you have two days on site with the building plans. Nothing has been attacked yet — your job is to name what an adversary could do and band each finding, so Xtensr knows what to fix before the two networks are joined. Every judgement must rest on the CED’s characteristics, not on how likely an attack feels.

Step 1Matching
Name the Attack Each Finding Enables
Three findings from the Delmar walkthrough. For each, choose the named threat or physical attack it most directly enables.
Think first: two of these options differ only by consent — one authorized person grants access, the other never knows anyone is there. Decide which finding is which before you open the menus.
A contractor photographs both faces of an employee’s proximity badge while it hangs on a lanyard at the coffee shop across the street.
A stranger slips through the loading-dock door a half-second behind a technician who is pushing a cart, facing forward, and never learns anyone came in behind her.
The ground-floor optics bay sits below street grade on a mapped floodplain, and its sump pump shares one breaker with the polishing benches.
Badge photographed → card cloning (A.6): the copy inherits the authorized user’s access. Entry behind an unaware technician → tailgating (A.3): following close behind an authorized individual without that individual’s awareness or knowledge. Had she turned, believed a story about a forgotten token and held the door, it would be piggybacking (A.2). Flood-prone bay → natural disaster (B.1): threats are adversaries and natural events, and both damage devices and disrupt services.
Exam Tip: Piggybacking and tailgating describe the same doorway and differ on one word — consent. Granted access is piggybacking; unaware is tailgating. And “threat” is not only people — the CED names natural disasters in the same sentence as adversaries.
Step 2Fill in the Blank
Complete the Assessment Write-Up
Complete the paragraph you will hand to Xtensr. Each blank takes one term from the CED vocabulary for Topic 2.2.
Think first: blanks 2 and 3 are the consent pair from Step 1, and blanks 4 and 5 are the words the CED uses to separate a Moderate finding from a High one.

The photographed badge was reproduced on a blank fob that inherits the original’s permissions. Copying an authorized user’s access card this way is card .

The stranger who followed the technician through the loading-dock door while she faced forward committed , because the authorized individual was never aware of him.

Had she turned, accepted his story about a forgotten access token and held the door open, the same entry would instead be , because access was granted to him.

Delmar’s reception PC stores nothing sensitive, but it sits on the internal wireless network with open USB ports, so it is a for initial access to other resources — which is why it bands Moderate rather than Low.

The finished-lens vault holds customer prototypes and its door is propped during production shifts, so its access is not sufficiently , and the finding bands High.

(1) cloning — A.6. (2) tailgating — A.3, no awareness. (3) piggybacking — A.2, access granted. (4) foothold — C.3: a nonsensitive part left unprotected that enables initial access to other resources. (5) restricted (or controlled) — C.2: sensitive systems exposed without sufficiently restricted, controlled access.
Exam Tip: Learn C.2 and C.3 as sentences, not adjectives. High is sensitive asset + access not sufficiently restricted; Moderate is nonsensitive asset that is a foothold to something else. Neither one means “bad” or “medium-bad”.
Step 3Select All That Apply
Band the Walkthrough Findings
Select ALL findings that band as HIGH under EK 2.2.C.2 — sensitive information or systems exposed without sufficiently restricted, controlled access.
Think first: two of these six are deliberately not High. Decide which two, and name the characteristic that caps each of them, before you tick anything.
High (4): lens vault, engineering file server, badge controller cabinet, testing bay workstation — each pairs a sensitive asset or security system with access that is not sufficiently restricted (C.2). The badge cabinet qualifies although it stores no data: the access system is the sensitive system. Not High (2): the reception PC is Moderate — nonsensitive, but a foothold for initial access to other resources (C.3); the laptops are Low — low-value assets inside controlled space (C.4).
Exam Tip: The trap is banding on how alarming a sentence sounds — “unlocked” and “no camera” appear in the Moderate example too. Ask two questions in order: is the exposed thing sensitive, and is the access sufficiently restricted? Only “yes, no” is High.
Step 4Multiple Choice
Correct the Draft Risk-Register Row
A junior assessor drafted this register row: “Vulnerability: the reception PC’s USB ports are exposed and it is joined to the internal wireless network. Threat: an adversary posing as a delivery courier. Likelihood: Moderate — reception is unattended about forty minutes at lunch. Impact: unauthorized access to data. Risk band: LOW, because the PC stores nothing sensitive.” Which single correction is the BEST one?
Predict first: read the row against C.2, C.3 and C.4 and decide which one field is wrong before you look at the options. Exactly one field is.
B is correct. Every other field is defensible; only the band is wrong. C.3 bands a nonsensitive, unprotected component Moderate when it is a foothold for initial access to other resources — and the CED’s own example is a reception-area PC on the internal wireless network with exposed USB ports. (A) swaps the compromise type: unauthorized access to data is the right one of B.2’s four, and a slower front desk is not the harm being tracked. (C) overreaches — C.2 requires that the exposed thing be sensitive, and this PC holds nothing. (D) is wrong about the site: reception is the public side of the door.
Exam Tip: On a spot-the-error item, find the error before you rank the fixes. Three options here sound like assessment language but change a field that was already right — which is how a BEST-correction stem punishes reading the options first.
Step 5Analysis
The Shared Contractor Badge
Delmar keeps one badge labelled CONTRACTOR. Whoever is on site that day carries it; overnight it hangs on a hook behind reception. The facilities lead calls this “efficient” and notes that it opens only corridor doors, not the vault.
5a. Select the security-assessment failure this arrangement creates:
5b. Recommend how Xtensr should re-issue credentials at Delmar before day one, and state what each change prevents.
Use these terms: one badge per person / individually issued · revoke or deactivate the shared badge · an audit trail attributable to a named holder · an expiration date · collected at exit or in a locked cabinet · visitors escorted · cards that resist cloning.
B is correct. The failure is not which doors the badge opens — the credential is not attributable to a person, so the log cannot answer “who entered,” and the card hangs unattended overnight where it can be pocketed or copied (A.6). Recommended: one badge per named individual with an expiration date; revoke the shared CONTRACTOR credential on day one; collect badges at exit or keep them in a locked cabinet; escort visitors; move to cards that resist cloning — restoring attribution, revocability, custody and supervision.
Exam Tip: A control can exist, be worn every day, and still fail — a control that cannot say who gives no accountability. When a stem describes a shared or borrowed credential, the finding is about the audit trail, not the door.
Step 6Written Response
Rebut the Operations Director
Xtensr’s operations director writes: “Delmar’s optics bay is our lowest concern — windowless room, and nobody has ever broken into it.” Write the assessment paragraph that (1) explains why “nobody has ever” is not a risk band, (2) bands the bay and names the characteristic you applied, and (3) names one natural-disaster threat to that room and which of the four compromises it causes.
Make each claim in these words: an attack history is not a characteristic · band it high because access is not sufficiently restricted around a sensitive prototype asset · name the natural disaster (below grade, floodplain, sump pump) · end with disruption of services or destruction of resources.
Model: (1) An attack history is not a characteristic. Risk is banded on what is exposed and how controlled the access to it is — not on whether anyone has tried yet, so “nobody has ever broken in” describes the past, not the exposure. (2) The bay bands High: prototype optics and master calibration standards are sensitive, and access is not sufficiently restricted — a motion-release door onto the public showroom corridor (C.2). Windowless closes one route and does nothing about the one people use. (3) The bay is below street grade on a floodplain and its sump pump shares a breaker, so a flood (B.1) damages the devices and leaves the bay unavailable — disruption of services, and where benches and standards are ruined, destruction of resources (B.2).
Exam Tip: Two habits lose points here: arguing likelihood from history rather than from the missing control, and forgetting that a threat can be weather. B.1 puts natural disasters beside human adversaries, and B.2’s four compromises apply to both.
Total Points
Quiz 2.2 →Course Hub
AP Cybersecurity 2.2 Lab | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board.
AP Cybersecurity · Unit 2 · Lesson 2.2 · Lab

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]