AP Cybersecurity Unit 2 Lesson 3 Exercise 2

Unit 2 • 2.3 • Exercise 2

Exercise 2 — Designing Delmar’s Physical Security Program

3 parts, 24 points — Managerial controls and a capital plan for Delmar Applied Optics

Score: 0 / 24Complete all 3 parts
Client Organization
Xtensr Research Labs · Delmar Applied Optics acquisition

Your Unit 2.2 walkthrough of Delmar Applied Optics documented the vulnerabilities and banded the risk. The acquisition closes in nine weeks, and the Xtensr security director now wants the program: the managerial controls that govern how people behave in the building, and a capital plan that spends a fixed budget where it buys the most risk reduction. For every control you recommend, name the control and say whether it prevents, detects, or corrects the attack — that is the question EK 2.3.B.1 tells you to ask.

Part 1
Scenario: The Reception Workstation Policy
Delmar’s reception PC sits in the open lobby, joined to the internal wireless network, with two exposed USB ports on the front of the tower. Waiting visitors stand within reach of it and within reading distance of the screen. Nothing is plugged into a surge protector. Delmar’s office manager, Priya Raman, rejects your first draft of the workstation security policy: “Reception doesn’t need a policy. There is nothing sensitive on that machine, and it is staffed every minute we are open.”
8 points
1a. Priya is wrong on both counts. Rebut each claim — that the machine holds nothing sensitive, and that being staffed makes a policy unnecessary — by describing what an adversary could actually do from that workstation.
Key terms: internal wireless, foothold, USB port, external drive, shoulder surf, privacy screen, unattended, line of sight, open lobby, within reach, moderate, other resources, not the data
1b. Write the reception tier of Delmar’s workstation security policy: four requirements, each labelled prevent, detect, or correct. At least one requirement must address power.
Key terms: clean desk, privacy screen, lock the screen, disable the USB, port blocker, surge protector, uninterruptible, prevent, detect, correct, tier, sensitive documents
Model Response: Claim 1. The policy tier is not set by the value of the data on the machine — it is set by what the machine reaches. The reception PC is joined to the internal wireless network, so it is a foothold: an adversary who loads malware from an external drive through one of those open USB ports is inside Delmar’s network, and the engineering file server is on the other end of it. That is exactly the CED’s moderate-risk pattern — a nonsensitive asset used to get at other resources — not a reason to skip the policy. Claim 2. Being staffed is not access control. The receptionist looks away, steps to the copier, or is talking to the visitor who is standing within reach of the tower; and a screen in the open lobby is in a stranger’s line of sight all day, which is shoulder surfing with no effort required.

Reception tier of the workstation policy. (1) The workstation locks automatically after two minutes and the user locks the screen before leaving it unattendedprevent. (2) A privacy screen filter is fitted, and no sensitive documents are left on the desk surface (clean desk) — prevent. (3) The USB ports are disabled in firmware and fitted with port blockers; any external drive must be handed to IT — prevent. (4) The workstation is connected to a surge protector on an uninterruptible power supply (UPS), so a power event does not corrupt the visitor log — correct. A reasonable fifth: badge-log review of lobby entries, which detects what the first three only prevent.
Part 2
Scenario: The Hardware Worked and the People Did Not
Xtensr funds an access control vestibule at the entrance to Delmar’s finished-lens corridor. In its first week: engineers wedge the inner door open because it slows equipment carts; a senior optician badges a delivery driver through so the driver can hand a package to the lab manager; and on one morning the badge log records nine entries when eleven people were in the corridor. Priya’s conclusion: “The vestibule is faulty. Rip it out and put a card reader on a single door.”
8 points
2a. Explain what actually failed here, and name the CED awareness-training objective that addresses it. Your answer must distinguish the delivery-driver incident from the wedged-door incident.
Key terms: piggyback, tailgat, badge other people, awareness training, not faulty, one badge per, consent, restricted area, missing entries, defeat, with their knowledge, human behavior
2b. Priya’s fix would replace a stronger control with a weaker one. Recommend what Delmar should do instead — the training plus one physical or technical backstop — and label each as prevent, detect, or correct.
Key terms: security awareness training, turnstile, door contact, held open, anti-passback, recorded and monitored, camera, prevent, detect, correct, weaker control, one person at a time
Model Response: The vestibule is not faulty — it did what a vestibule does, and the control that failed was human behavior, which is why EK 2.3.A.1 makes employee security awareness training a managerial control in its own right. Its second objective is precisely this: employees must be taught not to badge other people into restricted areas.

The two incidents are different failures. Badging the delivery driver through is piggybacking: the authorized person granted the access, with their knowledge and consent, so no hardware was beaten — the optician chose to override it. The wedged door is worse than either, because it converts the vestibule into an open corridor and lets an adversary tailgate in with nobody aware of it. The two missing entries on the badge log are the evidence: the log records one badge per entry, so nine badges and eleven bodies means two people came through on somebody else’s credential.

What to do instead. Training — mandatory awareness training on restricted-area access at onboarding and annually, with the rule stated as one badge per person and no exceptions for couriers or colleagues (prevent); deliveries are received at the lobby counter so no one has a reason to badge a stranger through. Backstop — a door contact with a held-open alarm on the inner door, so a wedge raises an alert within seconds (detect); a turnstile or anti-passback reader that admits one person at a time is the stronger physical option (prevent), and a camera on the vestibule that is recorded and monitored gives the investigation afterwards (detect). Replacing the vestibule with a single card reader trades a control that stops piggybacking for one that only records badges — a weaker control against the attack Delmar has actually seen.
Part 3
Scenario: Spending $150,000 Where It Buys the Most
Xtensr gives you a one-time $150,000 capital budget for Delmar. Your 2.2 walkthrough produced six findings, priced:
1. Finished-lens vault — keyed lock only, no reader, no record of who entered. HIGH. Card reader + door contact + vestibule at the corridor: $96,000
2. Engineering file server on an open shelf in an unlocked utility closet. HIGH. Lockable cabinet + relocation into the controlled server room: $14,000
3. Badge controller cabinet unlocked in the open lobby. HIGH. Locking enclosure + tamper switch: $6,000
4. Reception PC — exposed USB ports, internal wireless. MODERATE. Port blockers + privacy screen: $3,500
5. Testing bay on a single power panel. MODERATE. UPS on the two instruments that must ride through an outage: $11,000 (a building generator would be $180,000)
6. Ground-floor optics bay below street grade on a floodplain. MODERATE. Flood barriers + racking the stored optics above grade: $38,000

Delmar’s operations director, Curtis Okafor, wants the whole budget on Finding 1: “The vault is the highest risk in the building. Fund the highest risk first and stop there.”
8 points
3a. Choose which findings you fund with the $150,000 and justify the set — on severity and on cost, as EK 2.3.B.8 requires. Name at least one finding you deliberately leave unfunded and say what Delmar does about it in the meantime.
Key terms: severity and cost, badge controller, file server, port blocker, above grade, leave unfunded, phase, interim, defeats every, lowest cost, remaining risk, compensating
3b. Curtis’s rule — fund the highest risk first and stop there — is not what EK 2.3.B.8 says. Explain what is wrong with it, and explain why ranking by severity alone and ranking by cost alone are both wrong.
Key terms: severity and cost, highest severity, ignores cost, ignores severity, cheapest first, risk reduction per, leaves the other, still exposed, unmitigated, low-value, stop there, trade
Model Response: A defensible plan. Fund Findings 3 ($6,000), 2 ($14,000), 4 ($3,500), 5 ($11,000) and 6 ($38,000) — $72,500 — and put the remaining $77,500 toward Finding 1 as the first phase of the vault project. Finding 3 goes first regardless of its price: an unlocked badge controller cabinet in a public lobby defeats every reader in the building, so $6,000 buys back the whole access-control system. Finding 2 is the other high-severity item and it is cheap, because the file server problem is a missing cabinet and a wrong room, not a construction job. Findings 4, 5 and 6 are moderate, but at the lowest cost per unit of risk removed: $3,500 of port blocker closes the foothold into the internal network, $11,000 of UPS protects availability in the testing bay where the $180,000 generator cannot be justified, and $38,000 racks the stored optics above grade before the next storm.

Left unfunded. The vault reader and vestibule. The interim measure: the vault keeps its keyed lock, the key count drops to two named holders, a paper sign-in sheet is countersigned by the lab manager at each entry, and a monitored camera covers the vault door — compensating controls that detect what the reader would have prevented, and that leave documented remaining risk for the phase-two request.

Why Curtis is wrong. EK 2.3.B.8 says organizations prioritize by the severity and cost of the mitigation — two variables, not one. Spending all $150,000 on the highest severity finding buys one control and leaves the other five findings unmitigated, including two more HIGH ones that together cost $20,000; the building is measurably less safe after his plan than after this one. His rule ignores cost, so it cannot see that trade. But ranking cheapest first is the mirror-image error: it ignores severity, so it would buy a pile of low-value fixes while the vault stays open. The question is neither “what is worst” nor “what is cheap” but risk reduction per dollar, checked against the constraint that no HIGH finding is left still exposed with nothing at all in front of it — which is why the vault gets compensating controls rather than a note saying wait.
Total Points
Lab 2.3 →Course Hub
AP Cybersecurity 2.3 Exercise 2 | APCSExamPrep.com
AP® is a registered trademark of the College Board.
AP Cybersecurity · Unit 2 · Lesson 2.3 · Exercise 2
LessonExercise 1Exercise 2Quiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]