AP Networking 1.3: Identifying the Security Needs of My Device
AP Networking 1.3: Identifying the Security Needs of My Device
Security is a two-column habit: name the threat, then match a control. This guide covers the digital and physical attacks that target a personal device, the real damage when they succeed, and the layered controls that limit that damage.
Your device holds accounts, messages, photos, and payment details, which makes it a target, even if you are "just a student." Attackers want unauthorized access to your accounts, your data, or the device itself. Once they have it, the harm ranges from drained accounts and stolen identity to a device quietly taken over by malware. The good news is that a small set of well-chosen controls, used in layers, blocks the most common attacks.
- What attackers are after
- The four impacts of a successful attack
- Threats and the controls that limit them
- Weak logins: strong passwords, MFA, biometrics
- Phishing: filtering and a skeptical eye
- Shoulder surfing: privacy screens and positioning
- Malware: antivirus and patching
- Why layers beat any single control
- Key terms
- Frequently asked questions
What attackers are after
Digital and physical attacks share one goal: unauthorized access to accounts, data, or a device. Digital attacks come through software and networks, such as malware or a phishing message. Physical attacks use physical presence, such as watching your screen or grabbing an unlocked laptop. Either way, the prize is the same, and once an attacker has access, the sensitive information exposed can include financial records, health data, and personally identifiable information (PII). That data may then be leaked publicly or sold.
The four impacts of a successful attack
Understanding the impact is what makes a control worth using. There are four impacts to know.
| Impact | What it looks like |
|---|---|
| Exposed personal data | Financial, health, and identifying information is revealed, then leaked or sold. |
| Fraud and identity theft | Stolen credentials are used to make purchases, apply for loans, and misuse your identity, causing credit damage and debt. |
| Business disruption | For an organization, leaked client data, unprofessional communication, or downtime erodes trust and costs customers. |
| Malware takeover | Malware slows, crashes, or disables a device, lets attackers read files or watch activity, and can spread to other systems. |
Threats and the controls that limit them
A security control is a measure you put in place to mitigate a vulnerability. Choosing the right one starts with understanding the specific threat and its impact, then matching a control to it. Here is the map for a personal device.
| Threat | Controls that limit the impact |
|---|---|
| Weak or stolen logins | Strong passwords, multifactor authentication (MFA), biometric verification |
| Phishing | Email filtering, and training yourself to detect and report deceptive messages |
| Shoulder surfing | Privacy screens, and positioning your screen away from others |
| Malware | Updated antivirus/antimalware software, and patching the OS and apps |
Weak logins: strong passwords, MFA, biometrics
The most common way in is a weak or reused password. Three controls harden your logins. A strong password is long and hard to guess. Multifactor authentication (MFA) requires a second factor, such as a code or a tap on your phone, so a stolen password alone is not enough. Biometric verification, like a fingerprint or face scan, authenticates you by a physical characteristic that is hard to copy. Used together, these mean one leaked password does not hand over your account.
Phishing: filtering and a skeptical eye
Phishing is deceptive communication, spoofed emails, fake websites, or urgent messages, designed to trick you into revealing credentials or downloading malware. It targets the person, not the software, which is why antivirus alone does not stop it. Two controls help: email filtering blocks many malicious messages before you see them, and training yourself to detect and report phishing catches the rest. The habit to build: verify the sender, hover over links before clicking, and when in doubt, go to the site directly instead of using the link in the message.
Shoulder surfing: privacy screens and positioning
Shoulder surfing is a physical attack: an unauthorized person observes or records your screen or keyboard to gather information, such as a password or a message. It is easy to forget in a crowded cafe, library, or bus. The controls are simple and physical: a privacy screen narrows the viewing angle so only someone directly in front can read the display, and positioning your screen away from high-traffic areas reduces who can see it at all.
Malware: antivirus and patching
Malware is software that harms or hijacks a device. It can make a device behave abnormally, slow it down, crash it, or let an attacker read files, watch activity, or take remote control, and an infected device can spread malware to others. Two controls limit the risk: install and regularly update antivirus and antimalware software, and keep your operating system and applications updated so known vulnerabilities are patched before an attacker can use them. Updates are not just new features; they are security fixes.
Why layers beat any single control
No single control makes a device safe. A strong password does nothing against a screen-watcher; antivirus does nothing against a convincing phishing email; a privacy screen does nothing against malware. Real security stacks controls so that when one fails, another still stands. This layered thinking, called defense in depth, is the habit this course builds from here forward.
Practice: Threat Match
Read the scenario, name the threat, then pick the control that best limits its impact. Scenarios and choices shuffle each time.
AP Networking - Unit 1 - Topic 1.3
Threat Match
Read the scenario, name the threat, then pick the control that best limits its impact.
Scenario 1
Step 1. What is the threat?
Step 2. Which control best limits it?
AP is a trademark of the College Board, which was not involved in the production of, and does not endorse, this resource.
Key terms
- PII (personally identifiable information)
- Data that can identify you, such as your name, address, or financial and health records.
- Security control
- A measure put in place to mitigate a vulnerability and limit an attack's impact.
- MFA (multifactor authentication)
- Requiring more than a password to sign in, such as a code or a fingerprint.
- Phishing
- Deceptive messages that trick you into revealing credentials or installing malware.
- Malware
- Harmful software that can damage, spy on, or take control of a device.
- Shoulder surfing
- Watching or recording someone's screen or keyboard to steal information.
Full quiz, saved progress, and the practice bank
Unlock the full 8-question Topic 1.3 quiz, every Threat Match scenario, and saved progress that reports to your class gradebook. Ad-free.
Get AP Networking premiumFrequently asked questions
What can hackers do with my password?
A stolen password can be tried on your other accounts to make purchases, apply for loans, or misuse your identity, which can damage your credit and finances. Unique passwords and MFA limit the damage.
Am I really a target if I am just a student?
Yes. Individuals are targeted constantly. A single reused password or one careless click can unlock accounts and data worth money to an attacker.
What is phishing?
Phishing is a deceptive message, such as a spoofed email, fake website, or urgent alert, designed to trick you into revealing credentials or downloading malware.
Is antivirus enough to stay safe?
No. Antivirus helps against malware but must be kept updated, and it does not stop phishing, which targets you rather than your software. Use layered controls.
What is multifactor authentication (MFA)?
MFA requires a second factor beyond your password, like a code or fingerprint, so a stolen password alone cannot get into your account.
What is shoulder surfing?
Shoulder surfing is when someone watches or records your screen or keyboard to steal information. Privacy screens and screen positioning limit it.
Why do software updates matter for security?
Updates patch known vulnerabilities that attackers exploit. Keeping the OS and apps current, and enabling automatic updates, closes those holes.
What is malware and how does it get on a device?
Malware is harmful software that can spy on or control a device. It often arrives through phishing links, malicious downloads, or unpatched vulnerabilities.
What is PII?
Personally identifiable information is data that can identify you, such as your name, address, and financial or health records. Attackers value it because it enables fraud.
Why is one strong password not enough?
Security controls are layered. A password does nothing against a screen-watcher or a phishing email, so combine it with MFA, updates, and good habits.
AP is a trademark of the College Board, which was not involved in the production of, and does not endorse, this resource.
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]