AP Cybersecurity Unit 2 Lesson 5 Exercise 1

Unit 2 • 2.5 • Exercise 1

Exercise 1 — Access Control Models

6 questions — Evaluate access control strategies and identify misconfigurations

Score: 0 / 0 Predict the answer before selecting an option
Client Organization
Ridgecrest Community Hospital

Ridgecrest Community Hospital is overhauling its access control system after an audit found that 40% of employees have excessive permissions. Nurses can access billing data, billing clerks can view clinical records, and three former employees still have active accounts. You are reviewing six access control decisions.

Q1 Least Privilege
A nurse at Ridgecrest has access to the billing system, the pharmacy inventory, the HR payroll portal, and all patient records across every department. The nurse’s actual job requires only patient records for patients in her department. Which principle is violated, and what is the specific risk?
Q2 RBAC
The IT team proposes Role-Based Access Control (RBAC) with these roles: Nurse (patient records, medication administration), Physician (patient records, ordering, lab results), Billing (claims, payment, insurance), Admin (all systems). A new nurse is hired. Under RBAC, how should her access be configured?
Q3 Account Management
Three former Ridgecrest employees who left over 6 months ago still have active accounts in the EHR system. One account shows login activity from last week. This finding indicates a failure in:
Q4 MFA
Ridgecrest implements MFA for EHR access. A physician logs in with her password (something she knows) and then confirms on her phone app (something she has). An attacker who steals her password through phishing would STILL need to:
Q5 Separation of Duties
Ridgecrest’s pharmacy system allows the same pharmacist to both order medications from suppliers AND approve the purchase order. A pharmacist orders $50,000 of controlled substances and approves the order herself, diverting the drugs for personal sale. Which access control principle would have prevented this?
Q6 Privilege Escalation
A billing clerk discovers she can access the EHR admin panel by modifying the URL from /ehr/billing to /ehr/admin. The admin panel gives her full control over user accounts, including the ability to create new admin accounts. This vulnerability is called:
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 2 • 2.5 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]