4.3 Exercise 1: Harden the Field Device

🎯 How This Works

Each scenario describes a real device-security decision at Kestrel AgWorks. Before answering, type your prediction in the purple box — commit to a hypothesis first. Then answer the question and compare your reasoning to the feedback.

Why predict first? It keeps you from being swayed by a well-written distractor. AP MCQs are engineered so that the wrong choices sound plausible; knowing what you expect before you read the options is the most reliable defense.

✎ Guided Practice — 5 Scenarios
Scenario 4A — Kestrel AgWorks

You are a security engineer at Kestrel AgWorks, which manufactures internet-connected agricultural machinery: tractors, irrigation controllers and automated milking systems. Every machine carries an onboard computer that farmers operate remotely, and those onboard computers are updated only as needed. Field technicians carry company laptops onto customer farms and plug them into networks Kestrel does not own and cannot inspect. Renata Boyle leads IT; Dale Ferro manages field service and would rather technicians were not slowed down.

Scenario 1 of 5 — Which Managerial Control? A Kestrel field technician needed to open a customer’s equipment manual on his company diagnostic laptop. He searched the web for a free PDF converter and installed the first result; the installer also placed adware on the laptop. Renata asks which of Kestrel’s managerial controls, properly enforced, would most directly have prevented this.
Predict First Name the document that would have had to forbid this exact action, then look for it in the options.
Scenario 2 of 5 — Keeping Signatures Current Kestrel’s diagnostic laptops spend the season in the field and often go three or four weeks without reaching the company network. Anti-malware is installed on every one of them, but Renata finds signature databases on six laptops between two and five months old. Which change best fixes the underlying problem?
Predict First Signatures protect a device only while they are current. What has to change about WHEN they arrive?
Scenario 3 of 5 — Spot the Error in the Update Procedure Renata circulates the draft procedure below for firmware updates on Kestrel machines in the field. Exactly one numbered step is wrong for device security. Which correction fixes the step that is actually wrong?
DRAFT PROCEDURE: Onboard Controller Firmware (rev 2)
Owner: R. Boyle, IT Lead

1. Vendor firmware releases are reviewed within 5 business days.
2. Critical updates are tested on a bench machine before field rollout.
3. A machine is updated only when a technician is already on site for
   another reason, so no visit is scheduled just to apply an update.
4. Every applied update is recorded against the machine serial number.
5. A machine that misses two update cycles is flagged for follow-up.
Predict First Find the step that lets a known vulnerability stay open for an unpredictable length of time.
Scenario 4 of 5 — Multi-Select (Which statements are TRUE?) Kestrel enables the host-based firewall on every field laptop and on the irrigation-controller gateway. Consider what that does and does not buy them. Select ALL that are TRUE. No credit for selecting incorrect options.
Predict First For each statement decide what the firewall inspects and where. One of the four claims something a rule list cannot do.
Scenario 5 of 5 — Terminology Recall Fill in each blank with the correct term from Lesson 4.3.
Predict First Say the three terms aloud before typing. What do you expect to write?

1. An ordered list of allow and deny rules that a firewall evaluates from the top, where the first matching rule decides the outcome, is called an .

2. The published fingerprint of a known malware sample, which anti-malware software compares files against, is called a .

3. Applying a vendor’s update to close a known vulnerability in software or firmware is called .

0/5 Scenarios correct — review any missed answers, then move on to Exercise 2.
📚 Pattern to Remember

Every 4.3 item is asking one question in four costumes: is this the right control, at the right layer, kept current? (1) Match a managerial control to the ACTION in the stem — installing, browsing, signing in and patching are four different policies. (2) A control that is out of date is not the same as a control that is missing, and the fix differs. (3) An ordered rule list is read top to bottom, first match wins. (4) Filtering, detecting and removing are three different jobs. When two options are both real controls, the one that touches the action in the stem is the answer.

AP Cybersecurity · Unit 4 · Lesson 4.3 · Exercise 1
LessonExercise 1LabQuiz

Get in Touch

Whether you're a student, parent, or teacher — I'd love to hear from you.

Just want free AP CS resources?

Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.

Typically responds within 24 hours

Message Sent!

Thanks for reaching out. I'll get back to you within 24 hours.

🏫 Welcome, fellow educator!

I offer curriculum resources, practice materials, and study guides designed for AP CS teachers. Let me know what you're looking for — whether it's classroom materials, a guest speaker, or Teachers Pay Teachers resources.

Email

[email protected]

📚

Courses

AP CSA, CSP, & Cybersecurity

Response Time

Within 24 hours

Prefer email? Reach me directly at [email protected]