AP Cybersecurity 2.2 Quiz: Physical Vulnerabilities and Attacks
Lesson 2.2 Quiz: Physical Vulnerabilities and Attacks
5 questions — Identify common physical attacks, explain how threats exploit them, and assess the risk they create
You work on the physical security team at Xtensr Research Labs. Xtensr is acquiring a smaller research company in the same town, and you have been assigned the physical vulnerability assessment of the newly acquired lab: review the building plans and the controls already in place, identify physical vulnerabilities, and assess the likelihood and impact of each one.
(A) Incorrect — tailgating (EK 2.2.A.3) requires following close behind without the authorized person’s awareness or knowledge; this technician knowingly held the door.
(C) Incorrect — shoulder surfing (EK 2.2.A.4) is watching a user access sensitive information for later use; observing a badge tap yields nothing the courier could reuse.
(D) Incorrect — card cloning (EK 2.2.A.6) requires copying an authorized user’s access card; the courier presented no card at all.
I. A rack of servers holding participant medical records sits in an unlocked storage room reached through a hallway with no camera coverage.
II. The lobby receptionist’s workstation is joined to the internal wireless network and has enabled USB ports; visitors wait unescorted beside it.
III. Engineers in the badge-access design office leave non-sensitive loaner laptops uncabled on their desks during a weekly team lunch.
(B) Incorrect — the receptionist workstation is the moderate-risk case; it is a foothold toward other resources, not sensitive data or systems left directly exposed.
(C) Incorrect — neither finding II nor finding III exposes sensitive systems to uncontrolled access, so neither one reaches the high band.
(D) Incorrect — grading every finding as high destroys the prioritization that the assessment exists to produce, and it contradicts the low-risk definition in EK 2.2.C.4.
(A) Incorrect — this repeats the intern’s error. A compromise includes disruption of services and destruction of resources, not only disclosure of data (EK 2.2.B.2).
(B) Incorrect — patching and anti-malware settings are technical controls, and the miscategorization is not what makes the intern’s conclusion wrong.
(C) Incorrect — encryption at rest exists to protect stored data on powered-down or stolen media; the claim that it never secures data is simply false.
(A) Incorrect — unshredded experiment logs in an unlocked bin is dumpster diving, a direct route to copying sensitive information.
(B) Incorrect — unencrypted backup drives in an unlocked room can be carried out and copied wholesale, the highest-yield version of this exact risk.
(D) Incorrect — a screen facing a waiting area is a standing shoulder-surfing opportunity, and a seated visitor with a phone can record it for later analysis.
(A) Incorrect — limiting threats to deliberate human action is precisely the omission EK 2.2.B.1 rules out.
(C) Incorrect — the conclusion is right but the reason is an invented statistic; an assessment documents likelihood and impact for this site, not an unsourced national ranking.
(D) Incorrect — an assessment evaluates weaknesses that could be exploited, so waiting for an incident to occur defeats its purpose.
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]