AP Cybersecurity Unit 3 Lesson 2 Exercise 1

Unit 3 • 3.2 • Exercise 1

Exercise 1 — Network Attack Classification

6 questions — Identify attack types from network incident descriptions

Score: 0 / 0 Predict the attack type before selecting an option
Client Organization
Harborview Regional Bank

Harborview Regional Bank operates 12 branches across the Pacific Northwest, serving 45,000 customers. The bank runs a centralized data center with customer-facing online banking, internal teller systems, and a SWIFT terminal for international transfers. The security operations center (SOC) has flagged six network anomalies in the past 48 hours.

Q1 DDoS Attack
Harborview’s online banking portal is receiving 4.2 million HTTP requests per second from 92,000 unique IP addresses spanning 40 countries. Legitimate customers cannot access their accounts. The traffic pattern shows randomized User-Agent strings and no repeated payloads. Which attack type is MOST likely occurring?
Q2 ARP Poisoning / MitM
A network analyst discovers that all traffic from teller workstations in Branch 7 is routing through an unknown device (MAC: DE:AD:BE:EF:00:01) before reaching the default gateway. The ARP tables on affected workstations show this MAC address mapped to the gateway’s IP. Which of the following BEST describes this attack?
Q3 DNS Spoofing
Customers report that typing harborviewbank.com in their browser takes them to a page that looks identical to the real site but has a slightly different URL in the address bar. The fake site has a valid TLS certificate. Which of the following statements about this attack are correct?

I. The attacker likely poisoned a DNS resolver’s cache to return a malicious IP for harborviewbank.com.
II. The presence of a valid TLS certificate (padlock icon) guarantees that the site is operated by Harborview Bank.
III. Customers who verify the URL in their address bar before entering credentials would avoid this attack.
Q4 Packet Sniffing
A security audit reveals that Harborview’s guest Wi-Fi segment and the internal teller network share the same physical switch without VLAN segmentation. An attacker on the guest network has placed their wireless adapter in promiscuous mode. Which type of data is the attacker LEAST likely to capture?
Q5 Session Hijacking
An employee logs into the bank’s HR portal over an unencrypted connection. An attacker on the same network segment captures the session cookie and uses it from a different device to access the employee’s HR account. This attack is BEST classified as:
Q6 SYN Flood / Reflection
Harborview’s web server begins sending SYN/ACK packets to thousands of IP addresses that never initiated a connection. External organizations are reporting Harborview’s IP as a source of unwanted traffic. The bank’s IP is being added to blocklists. Which of the following BEST explains what is happening?
Questions Correct
Exercise 2 → Course Hub
AP Cybersecurity Unit 3 • 3.2 • Exercise 1 | APCSExamPrep.com | Built by Tanner Crow, AP CS Teacher (11+ years)
AP® is a registered trademark of the College Board, which was not involved in the production of this content.

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]