4.2 Lab: Credential Incident Desk

🎯 Lab Scenario

You are a tier-1 analyst on the overnight security operations centre shift at Aceshack. Three tickets against the sign-in system have landed within the hour. For each case you review the evidence, write your analysis, and submit it for scoring — the expected analysis appears only after you submit, so write first.

Your task per case: (1) name the attack and the nearest attack it is not, (2) cite the evidence in the record that proves it, (3) recommend one control that would have stopped it and one that would not have. Each of the nine boxes is worth 2 points: 2 for a response that makes both required claims, 1 for a response that makes one. 18 points total.

Case 1: The One-Try Wave

Ticket #SOC-3118 — Sign-in Portal Anomaly

Reporter: Portal monitoring (automated escalation)

Description: Between 01:05 and 01:22 the public sign-in portal recorded 5,600 failed sign-ins. Nine sign-ins succeeded. Account lockout is configured at five failed attempts and no account locked. Aceshack requires a 14-character minimum and 3-of-4 complexity, and all nine of the passwords that worked met both rules. All nine account owners, when asked, confirmed they had used the same password on a retail site that disclosed a data leak last year.

Portal telemetry:

signin.log — aggregated 01:05–01:22
  distinct usernames attempted:   5,412
  attempts per username:          1   (maximum observed: 2)
  distinct source addresses:      1,840   (residential ranges)
  successful sign-ins:            9
  accounts locked out:            0
  passwords per username:         1   — each already present in a public leak corpus

No account received a second guess. The nine that opened, opened on the first try.

Your Analysis (Case 1) Write all three answers, then submit. Each box is worth 2 points.

1. Name the attack — and name the nearest attack this is not:

2. Cite the evidence in the log that proves it:

3. One control that stops it — and one that would not have:

Case 2: The Decommissioned Backup

Ticket #SOC-3126 — Credential Store Exposure

Reporter: Threat intelligence vendor (external notification)

Description: A backup image taken from an Aceshack server that was decommissioned in 2019 has been found for sale on a criminal forum. The image contains the credential store. Two tables are inside it — a retired table that was never migrated, and a copy of the table the current portal uses. Sample rows:

legacy_users   (retired 2019, 3,540 rows, never migrated)
  a.okafor     5f4dcc3b5aa765d61d8327deb882cf99
  j.mensah     5f4dcc3b5aa765d61d8327deb882cf99
  t.ruiz       e10adc3949ba59abbe56e057f20f883e
  m.iqbal      5f4dcc3b5aa765d61d8327deb882cf99

portal_users   (current, 4,102 rows)
  a.okafor     $2b$12$Kx9pQ7rT…   salt: 9f3c1e04b7
  j.mensah     $2b$12$Wq2mLd8Z…   salt: 41b8da62c5
  t.ruiz       $2b$12$Hn5vXe1R…   salt: c07e93f1a8

Thirty-six hours after the image was posted, a researcher monitoring the forum reported that 3,100 of the 3,540 legacy passwords had been recovered. Not one portal_users password has been recovered. Aceshack sign-in logs for the same 36 hours show no unusual activity at all.

Your Analysis (Case 2) Write all three answers, then submit. Each box is worth 2 points.

1. Name the attack — and name the nearest attack this is not:

2. Cite the evidence that explains why one table fell and the other did not:

3. One control that stops it — and one that would not have:

Case 3: The 2 A.M. Approvals

Ticket #SOC-3131 — Account Takeover

Reporter: Nadia Osei, accounts payable

Description: “At 02:14 someone signed in as me and changed a supplier’s payment details. I was asleep. My phone had been buzzing — there is a wall of sign-in approval requests on it from just after two. I tapped Approve on one of them so it would stop, and went back to sleep. I never entered my password anywhere.”

Authentication log and helpdesk record for the account:

auth.log — user n.osei
02:03:11   approval challenge sent -> registered phone      denied
02:03:44   approval challenge sent -> registered phone      denied
           ... 24 further challenges, all denied ...
02:12:06   approval challenge sent -> registered phone      APPROVED
02:14:52   session established -> supplier payment record modified

helpdesk.log — previous day
15:40:22   inbound call, caller states she is locked out
15:44:07   technician verified caller: employee ID number + mother’s maiden name
15:45:19   password reset issued verbally over the phone
Your Analysis (Case 3) Write all three answers, then submit. Each box is worth 2 points.

1. Name both failures in the chain — the two are different attacks:

2. Cite the evidence for each, including what the technician actually checked:

3. One control that stops it — and one that would not have:

📚 How This Prepares You for the AP Exam

The Device Security Analysis free-response task asks you to do on paper what this lab just asked on screen: read a record, name the mechanism, and justify a control with the evidence in front of you. Notice what carried across all three cases — the control that is correct depends entirely on where the guessing happens. Account lockout is the right answer against an online attack and worthless against an offline one; a longer password helps against cracking and does nothing against reuse or against a user who approves a prompt. Never recommend a control without naming the attack it is answering.

0/18 Credential Incident Desk — all three cases submitted
AP Cybersecurity · Unit 4 · Lesson 4.2 · Lab

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]