AP Cybersecurity 4.1 Lab: Device Risk Triage Desk

🎯 Lab Scenario

You are on a SOC shift. Three device tickets are queued. For each, write your three answers in the boxes — CED risk level + justification, primary exploitation vector, and the matching CED defense — then click Reveal to compare against the expected analysis.

Case 1: The Exposed Server

Ticket #SOC-3101 — External Exposure

Reporter: Automated vulnerability scan

Description: A public-facing web server hosting the customer portal has not received OS or web-server patches in three months. A critical remote-code-execution advisory for its software version was published last week. The server holds session data for every logged-in customer.

Your Analysis (Case 1) Write all three answers before clicking Reveal.

1. CED risk level (High / Moderate / Low) and one-line justification:

2. Primary exploitation vector:

3. Recommended CED defense:

Case 2: The Quiet Controller

Ticket #SOC-3118 — Asset Review

Reporter: Network inventory audit

Description: An IoT building-automation controller still uses its factory-default credentials, cannot run anti-malware, and sits on the same flat network as HR and finance systems. It manages physical access doors.

Your Analysis (Case 2) Write all three answers before clicking Reveal.

1. CED risk level (High / Moderate / Low) and one-line justification:

2. Primary exploitation vector:

3. Recommended CED defense:

Case 3: The Shared Laptop

Ticket #SOC-3127 — Endpoint Concern

Reporter: Mei T., IT support

Description: A staff laptop used daily in a shared coworking space has autorun enabled for USB media and no BIOS/UEFI password. It stores cached credentials and customer spreadsheets. It is frequently left unattended at the desk.

Your Analysis (Case 3) Write all three answers before clicking Reveal.

1. CED risk level (High / Moderate / Low) and one-line justification:

2. Primary exploitation vector:

3. Recommended CED defense:

Exam Tip On the AP exam, “cannot be patched” is a cue to reach for compensating controls — segmentation and firewalls — not to mark a device Low risk.
AP Cybersecurity · Unit 4 · Lesson 4.1 · Lab

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]