AP Cybersecurity Unit 2 Lesson 3 Exercise 1
Exercise 1 — Recommending Controls for Delmar
6 questions — Choose the managerial and physical controls that answer each walkthrough finding
You are on the physical security team at Xtensr Research Labs. Xtensr is acquiring Delmar Applied Optics, a smaller research company in the same town, and your walkthrough of the Delmar building is finished. The findings are on record: a finished-lens vault, an engineering file server on a shelf in an unlocked utility closet, a reception PC on the internal wireless network with exposed USB ports, a badge controller cabinet standing unlocked in the open lobby, a testing bay fed by a single power panel, and a ground-floor optics bay below street grade on a floodplain. Assessing the risk was the last exercise. This one is the recommendation: which control answers which finding, and what gets funded first.
(A) Incorrect — recognizing a social engineering attempt and reporting instead of replying is the phishing objective this module is built around.
(B) Incorrect — refusing to badge another person into a restricted area is the training objective that answers the tailgating finding at the engineering wing door.
(D) Incorrect — preventing device theft, including cabling a laptop and putting portable media away, is trained employee behavior.
I. Fit the reception PC with a privacy screen filter so a person standing at the counter cannot read the display.
II. Connect the engineering workstations to an uninterruptible power supply so an outage does not interrupt work in progress.
III. Install a turnstile at the engineering wing entrance so each person entering must authenticate individually.
Which measures belong in the workstation security policy itself?
(A) Incomplete — a workstation security policy also covers connecting the device to a surge protector or an uninterruptible power supply, which is measure II.
(C) Incorrect — the turnstile guards an entrance rather than a desk, and this option drops the privacy screen filter, which is a standard workstation measure.
(D) Incorrect — two of the three belong in the policy, but a turnstile at the wing entrance is a separate physical control on the building and is not a workstation measure.
(A) Incorrect — a camera records an entry after it has happened; it does not stop the server being reached. Swapping a preventative control for a detective one leaves the access itself unaddressed.
(B) Incorrect — an instruction to stay out of the closet asks for cooperation from precisely the person who would ignore it. A lock does not depend on the adversary agreeing to it.
(C) Incorrect — the conclusion is right and the justification is invented. No such success rate was measured here, and reaching a correct verdict from a number nobody produced is the habit these questions are written to break.
(B) Incorrect — authentication is what a card reader does. A bollard cannot tell one person from another; it obstructs everyone in exactly the same way.
(C) Incorrect — detection is what a camera, a motion sensor, or a guard does. A bollard raises no alert and produces no feed for anyone to monitor.
(D) Incorrect — the optics bay floods because it sits below street grade on a floodplain, and bollards are spaced posts rather than a barrier. That finding needs its own mitigation.
1. A stranger followed a technician through the engineering wing door → install an access control vestibule at that entrance
2. The reception PC has exposed USB ports in an area anyone may walk into → disable the USB ports on that PC
3. A Delmar badge was photographed on a lanyard in the open lobby, and the badge controller cabinet stands unlocked beside it → connect the badge controller to an uninterruptible power supply
4. The engineering file server sits in an unlocked utility closet → fit a keyed lock on the closet and a locking cabinet on the server
Which correction is BEST?
(A) Incorrect — training is worth adding, but a technician cannot watch a door he has already walked away from. A vestibule admits one authenticated person at a time whether or not anybody is paying attention, so row 1 was already sound.
(B) Incorrect — a cabinet lock protects the inside of the machine, while the exposed ports are on the outside and stay usable. Row 2’s port lockout already acts on the compromise.
(C) Incorrect — and this is the tempting one, because it is a genuine improvement to a row that was not broken: the keyed lock already prevents the access, and a card reader would add a record of it. The question asks which row recommends a control that does not act on its compromise, and row 4’s does.
W. Keyed lock and locking cabinet for the engineering file server — high severity, low cost
X. Access control vestibule at the engineering wing entrance — high severity, high cost
Y. Disabling the USB ports on the reception PC — moderate severity, negligible cost
Z. Bollards around the full building perimeter — low severity, high cost
Which pair should Xtensr fund first?
(A) Incorrect — funding from the top of the price list down retires the least risk per dollar. Cost is a reason to sequence a mitigation, never a reason to promote it.
(C) Incorrect — severity on its own would buy X ahead of Y, but the framework weighs severity against cost. Y costs almost nothing and its risk is real; deferring it to afford one expensive control is a poor trade.
(D) Incorrect — Y does belong in the funded pair, but on severity and cost rather than on position. Z is the lowest severity and the highest cost of the four, and “outer layers first” is not how mitigations are ranked.
AP® is a registered trademark of the College Board, which was not involved in the production of this content.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]