AP Cybersecurity Unit 2 Lesson 4 Exercise 1

Unit 2 • 2.4 • Exercise 1

Exercise 1 — Risk Assessment Analysis

6 questions — Evaluate threats, vulnerabilities, and risk mitigation strategies

Score: 0 / 0 Predict the answer before selecting an option
Client Organization
Catalyst Biotech Labs

Catalyst Biotech Labs is conducting an annual risk assessment. The security team must identify threats, evaluate vulnerabilities, estimate potential impact, and recommend risk treatments for six scenarios. Your job is to apply risk assessment methodology to each finding.

Q1 Risk Formula
Catalyst’s risk assessment uses the formula: Risk = Threat × Vulnerability × Impact. A scenario has high threat (nation-state actors targeting pharma IP), low vulnerability (strong encryption and access controls), and catastrophic impact ($400M research loss). How should this risk be rated?
Q2 Threat vs Vulnerability
Which of the following correctly distinguishes a threat from a vulnerability?
Q3 Risk Treatment
Catalyst identifies that its research servers are vulnerable to ransomware. The security team presents four options to the board. Which option represents risk TRANSFER?
Q4 Quantitative Risk
Catalyst estimates: a data breach would cost $15 million (Single Loss Expectancy). The probability of a breach occurring in any given year is 8% (Annual Rate of Occurrence). What is the Annual Loss Expectancy (ALE)?
Q5 Risk Matrix
Catalyst uses a 5×5 risk matrix (Likelihood: 1-5, Impact: 1-5). An unpatched vulnerability in the lab’s HVAC system is rated Likelihood 2 (Low) and Impact 4 (High — could destroy temperature-sensitive research samples worth $50M). Where does this fall on the matrix, and what action is appropriate?
Q6 Residual Risk
After implementing EDR, network segmentation, and MFA, Catalyst’s risk assessment shows the research server breach risk dropped from “Critical” to “Medium.” The remaining “Medium” risk is called:
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 2 • 2.4 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]