Quick review

AP Cybersecurity Quick Review

High-impact topic boxes for a focused review session before you take the practice test.

1. Social Engineering Fundamentals

The big idea

Social engineering exploits human psychology and trust rather than technical flaws, which is why people, not code, are the most exploited attack surface.

Must know

Phishing (broad, deceptive email); spear phishing (targeted, personalized to one person/org using research); whaling (targets executives/high-value individuals); vishing (voice/phone-based); smishing (SMS/text-based); pretexting (fabricated scenario to build trust); OSINT (Open-Source Intelligence gathered from public sources to research a target).

Don't confuse

Phishing vs.\ spear phishing vs.\ whaling differ by targeting precision (mass vs.\ individual vs.\ executive), not by delivery channel; vishing vs.\ smishing differ by channel (voice vs.\ text), not precision.

Exam trap

A realistic-looking mass email is mislabeled ``spear phishing'' just because it looks convincing --- spear phishing requires evidence of specific research/personalization aimed at one target, not general realism.

5-second recall

Broad email $arrow$ phishing; personalized target $arrow$ spear phishing; executive $arrow$ whaling; voice $arrow$ vishing; text $arrow$ smishing.

2. Credential Attacks & Suspicious Logins

The big idea

Weak, reused, or exposed passwords let attackers log in as the legitimate user, bypassing every technical control that assumes the account holder is who they claim to be.

Must know

Brute force (systematically tries all password combinations against one account); dictionary attack (tries common words/leaked wordlists); password spraying (a few common passwords tried across many accounts to dodge lockout thresholds); credential stuffing (reuses username/password pairs leaked in a previous, unrelated breach); red flags of a suspicious login: unfamiliar device/location, impossible travel, off-hours access.

Don't confuse

Brute force guesses exhaustively against one account; password spraying tries few passwords against many accounts; credential stuffing uses previously breached, real credentials rather than guesses.

Exam trap

Credential stuffing is mistaken for brute force --- credential stuffing succeeds because of password reuse across sites after an unrelated breach, not because the password itself was weak or guessable.

5-second recall

Reused password + old breach $arrow$ credential stuffing; few passwords + many accounts $arrow$ spraying; all combos + one account $arrow$ brute force.

3. Public Wi-Fi & Safe Network Practices

The big idea

Unsecured or public networks let attackers intercept traffic between a user and the internet, so encrypting the connection end-to-end is the primary defense.

Must know

Evil twin (a rogue access point cloning a legitimate network's name/SSID); on-path (man-in-the-middle) interception on open Wi-Fi; packet sniffing of unencrypted traffic; a VPN encrypts traffic in transit across the network; HTTPS/TLS encrypts data between the browser and the site; never enter credentials or financial data over plain HTTP or an unknown network.

Don't confuse

A VPN protects data in transit across the network; it does not protect data already stored on the device or stop malware already installed there.

Exam trap

Assuming a network with the ``right'' name is automatically safe --- an evil twin is built specifically to clone the legitimate SSID, so the network name alone is not a reliable safety check.

5-second recall

Public Wi-Fi risk $arrow$ VPN + HTTPS; fake AP with the real name $arrow$ evil twin.

4. AI-Driven Cyberattacks

The big idea

Generative AI lowers the skill barrier for attackers, making social engineering more convincing (deepfakes, flawless phishing text) and automating reconnaissance and malicious code development.

Must know

AI-generated phishing with correct grammar and personalization; deepfake audio/video used in vishing or executive impersonation fraud; AI-assisted malware/exploit-code generation; AI used to automate large-scale OSINT gathering on targets.

Don't confuse

AI-driven attacks are not a brand-new attack category on the exam --- they are existing techniques (phishing, vishing, reconnaissance) accelerated and made more convincing by AI tools.

Exam trap

Relying on poor grammar/spelling as a phishing tell --- AI-generated phishing text is often grammatically flawless, so students must weight other indicators (sender address, urgency, mismatched links) more heavily.

5-second recall

AI $arrow$ same old attacks, but faster, more convincing, and more personalized.

5. AI in Cyber Defense

The big idea

The same AI capabilities that scale attacks can scale defense --- automating detection, pattern recognition, and alert triage across huge volumes of data.

Must know

AI/ML used for anomaly detection in logs and network traffic; automated threat-intelligence pattern matching; AI-assisted Security Operations Center (SOC) alert triage; key limitations: false positives, adversarial manipulation of models, and the continued need for human review.

Don't confuse

AI is framed in this course as a defensive tool that augments an analyst's judgment, not an autonomous decision-maker that replaces human verification.

Exam trap

Treating an AI tool's flagged alert as automatically confirmed --- the course's ``Collaborate'' skill expects a human to corroborate AI output with evidence before acting on it.

5-second recall

AI defense $arrow$ faster detection, but a human still verifies before acting.

6. The Risk Management Process

The big idea

Cybersecurity decisions are driven by evaluating risk --- what happens when a threat exploits a vulnerability affecting a valued asset --- not by chasing every possible flaw equally.

Must know

Asset (anything of value worth protecting); threat (a potential cause of harm, e.g., an attacker or event); vulnerability (a weakness that can be exploited); risk is a function of likelihood and impact given a threat/vulnerability pair; risk responses: avoid, mitigate/reduce, transfer (e.g., insurance), or accept.

Don't confuse

A vulnerability is a weakness (e.g., unpatched software); a threat is the actor or event that could exploit it (e.g., an attacker or malware) --- risk exists only where a threat can act on a vulnerability affecting an asset.

Exam trap

Labeling any discovered weakness ``high risk'' automatically --- real risk analysis weighs both likelihood and impact, not vulnerability presence alone.

5-second recall

Asset + threat + vulnerability $arrow$ risk; risk $arrow$ avoid / mitigate / transfer / accept.

7. Cyber Foundations & the CIA Triad

The big idea

Nearly every security control exists to protect one of three properties of information --- confidentiality, integrity, or availability, together called the CIA triad.

Must know

Confidentiality: only authorized parties can access data (protected by encryption, access controls); integrity: data is accurate and unaltered (protected by hashing, checksums, digital signatures); availability: data/services are accessible to authorized users when needed (protected by redundancy, backups, DDoS mitigation); non-repudiation: proof an action or message truly came from its claimed source.

Don't confuse

Integrity means data has not been tampered with; confidentiality means data has not been seen by unauthorized parties --- an attacker can violate integrity (e.g., defacing a public webpage) without ever violating confidentiality.

Exam trap

A denial-of-service attack is tested as an availability attack, not a confidentiality attack --- students wrongly assume every attack targets data secrecy.

5-second recall

Secrecy $arrow$ Confidentiality; accuracy $arrow$ Integrity; uptime $arrow$ Availability.

8. Physical Vulnerabilities & Attacks

The big idea

If an attacker gains physical access to a device or space, most software-based defenses can be bypassed entirely.

Must know

Tailgating/piggybacking (following an authorized person through a secured door); shoulder surfing; dumpster diving; unattended/unlocked workstations; unauthorized removable media (USB drop attacks); lack of visitor logging.

Don't confuse

Tailgating happens without the insider's awareness/consent; piggybacking happens with the insider knowingly holding the door --- both defeat badge access, but the exam distinguishes intent/awareness.

Exam trap

Assuming a badge/keycard system alone prevents physical intrusion --- tailgating defeats badge systems entirely because no credential is checked for the second person who slips through.

5-second recall

Physical access $arrow$ bypasses software controls; tailgating = unaware insider, piggybacking = aware insider.

9. Protecting Physical Spaces

The big idea

Physical security uses layered controls --- deterrent, preventive, and detective --- to govern who can reach sensitive spaces and devices.

Must know

Badge/keycard access control; mantraps (double-door airlocks that admit one person at a time, preventing tailgating); biometric locks; guards/reception; cable locks for devices; clean desk policy (no sensitive material left visible); asset tagging/inventory; visitor logs and escort policies.

Don't confuse

A mantrap physically prevents tailgating (only one authenticated person passes at a time); a badge reader alone only authenticates the first person and does nothing to stop a second person following behind.

Exam trap

Choosing ``add more badge readers'' as the fix for a tailgating vulnerability --- the correct control is a physical barrier (mantrap) or an enforced escort/visitor policy, not additional authentication points.

5-second recall

Stop tailgating $arrow$ mantrap or escort policy, not more badges.

10. Detecting Physical Attacks & Insider Threats

The big idea

Physical security requires ongoing monitoring --- cameras, logs, audits --- because preventive controls alone can be bypassed or subverted from the inside.

Must know

CCTV/video surveillance; motion sensors and alarms; access-log review/audit trails; insider-threat indicators (unusual access times, badge-use anomalies, disgruntled-employee behavior); environmental monitoring (fire, flood, temperature) as an availability concern.

Don't confuse

An insider threat is a trusted person misusing legitimate access; an external physical attacker must first defeat access controls to gain entry --- each requires different detection signals (log anomalies vs.\ forced/tailgated entry).

Exam trap

Dismissing environmental hazards (fire, water, power loss) as ``not cybersecurity'' --- the course treats environmental threats as availability risks that require monitoring and mitigation.

5-second recall

Prevention isn't enough $arrow$ log, watch, and audit for insiders too.

11. Network Vulnerabilities & Attacks

The big idea

Data moving across a network can be intercepted, altered, or disrupted at many points, so understanding how traffic flows reveals where attacks occur.

Must know

TCP/IP fundamentals (IP addressing, ports, packets); on-path (man-in-the-middle) attacks; DNS spoofing/poisoning (redirecting a domain lookup to a malicious IP); ARP spoofing; packet sniffing; denial-of-service (DoS) vs.\ distributed denial-of-service (DDoS).

Don't confuse

DoS comes from a single source overwhelming a target; DDoS comes from many distributed sources (often a botnet), which makes it much harder to block by simply blacklisting one IP.

Exam trap

Confusing DNS spoofing (corrupting the name-to-IP lookup before a connection is made) with an on-path attack (intercepting traffic on an already-established connection) --- they occur at different stages.

5-second recall

One source $arrow$ DoS; many sources/botnet $arrow$ DDoS; wrong IP returned $arrow$ DNS spoofing.

12. Managerial Controls & Wireless Security

The big idea

Strong network policy and secure wireless configuration shrink the attack surface before any technical device is even deployed.

Must know

Acceptable use policy (AUP); the policy/standard/procedure hierarchy; WPA3 as the current strongest Wi-Fi encryption standard (stronger than WPA2, and WEP is obsolete/insecure); disabling WPS; renaming default SSIDs; strong pre-shared keys; guest-network isolation from the internal network.

Don't confuse

A policy (managerial control, e.g., ``employees must use strong passwords'') is a rule; a technical control (e.g., WPA3 encryption) is the mechanism that enforces or supports it --- the exam tests which category a given control belongs to.

Exam trap

Treating WEP or plain WPA2 as still adequately secure --- the exam expects WPA3 (or at minimum WPA2 with AES) as best practice, with WEP flagged as clearly obsolete.

5-second recall

Rules $arrow$ managerial/policy controls; strongest Wi-Fi encryption $arrow$ WPA3 $>$ WPA2 $>$ WEP.

13. Network Segmentation & VLANs

The big idea

Dividing a network into smaller, isolated segments limits how far an attacker can move after breaching any one part of it.

Must know

VLAN (Virtual Local Area Network --- logically separates traffic on shared physical hardware); subnetting; DMZ (demilitarized zone --- isolates public-facing servers from the internal network); segmentation limits lateral movement; least privilege applied at the network level.

Don't confuse

Segmentation limits movement across zones after a breach; it does not prevent the initial breach itself --- it is a containment/mitigation control, not a control for the entry point.

Exam trap

Placing a public-facing web server on the same segment as internal databases --- the exam expects the public server isolated in a DMZ so its compromise doesn't directly expose internal assets.

5-second recall

Contain the breach $arrow$ segment / VLAN / DMZ.

14. Firewalls & Firewall Rules

The big idea

A firewall enforces network security policy by filtering traffic according to defined rules, acting as a chokepoint between trusted and untrusted zones.

Must know

Firewall rule fields: source, destination, port, protocol, action (allow/deny); default-deny (implicit deny) posture; stateful firewalls track connection context so replies are automatically allowed; stateless firewalls evaluate every packet independently; rule order matters, since most firewalls apply first-match logic; next-generation firewalls (NGFW) add application-layer inspection.

Don't confuse

Stateful firewalls remember the context of an ongoing connection; stateless firewalls evaluate every packet independently with no memory of prior packets.

Exam trap

Reading firewall rules top-to-bottom but forgetting first-match logic --- a broad ``allow'' rule placed above a specific ``deny'' rule will override the intended block.

5-second recall

Firewall = rule chokepoint; default deny; first matching rule wins; stateful remembers, stateless doesn't.

15. Detecting Network Attacks

The big idea

Network-layer defense requires continuously monitoring traffic for anomalies and known attack signatures, not just blocking traffic at the perimeter.

Must know

IDS (Intrusion Detection System --- monitors and alerts, passive); IPS (Intrusion Prevention System --- monitors and actively blocks, in-line); signature-based detection (matches known attack patterns) vs.\ anomaly-based detection (flags deviation from a baseline); packet capture/analysis for MITM or exfiltration indicators; network logs (e.g., firewall logs, flow data) for forensic review.

Don't confuse

An IDS detects and alerts but does not block traffic; an IPS sits in-line and can actively block/drop malicious traffic in real time.

Exam trap

Choosing ``IDS'' when a scenario describes a system that automatically blocks an attack --- automatic blocking is the defining feature of an IPS, not an IDS.

5-second recall

Detect only $arrow$ IDS; detect + block $arrow$ IPS.

16. Device Vulnerabilities & Malware

The big idea

Endpoints (laptops, phones, IoT) are attacked through malicious software designed to exploit unpatched or misconfigured devices.

Must know

Virus (attaches to a host file, needs user action to spread); worm (self-replicates across a network with no user action); trojan (disguised as legitimate software); ransomware (encrypts data, demands payment); spyware (covertly collects data); rootkit (hides deep in the OS to maintain privileged access); keylogger; botnet (network of infected devices controlled remotely).

Don't confuse

A virus requires a host file and user action to spread; a worm self-propagates across a network independently --- a classic exam distinction.

Exam trap

Labeling any malicious program generically ``a virus'' --- the exam rewards precise identification (ransomware vs.\ spyware vs.\ rootkit) based on the behavior described, not a catch-all term.

5-second recall

Needs host + user action $arrow$ virus; spreads itself $arrow$ worm; encrypts + ransoms $arrow$ ransomware; hides with root access $arrow$ rootkit.

17. Authentication & Access Control

The big idea

Verifying identity (authentication) and then limiting what that identity can do (authorization) are the two gatekeeping steps protecting every device and account.

Must know

Authentication factor categories: something you know (password), something you have (token/phone), something you are (biometric); multi-factor authentication (MFA) combines two or more different factor categories; least privilege (grant only the access needed); role-based access control (RBAC); single sign-on (SSO).

Don't confuse

Authentication proves who you are; authorization defines what you're allowed to do --- a valid login (authentication) does not automatically grant full access (authorization).

Exam trap

Calling a password + PIN combination ``MFA'' --- both belong to the same factor category (something you know), so it is not true multi-factor authentication; a genuine second factor must come from a different category.

5-second recall

Two different categories $arrow$ true MFA; know + have + are.

18. Protecting Devices: Hardening & Patch Management

The big idea

Device hardening reduces the attack surface by removing unnecessary services, closing unused ports, and keeping software current.

Must know

Patch management (regularly applying vendor security updates); disabling unused services/ports; endpoint protection/antivirus and EDR (Endpoint Detection and Response); full-disk encryption; mobile device management (MDM) for centrally enforcing policy on phones/tablets; IoT-specific risks (default credentials, weak/absent update mechanisms).

Don't confuse

Patching fixes known vulnerabilities after disclosure; hardening more broadly reduces the attack surface (removing unneeded features/services) whether or not a specific vulnerability has been announced.

Exam trap

Assuming IoT devices are secure ``out of the box'' --- unchanged default credentials and poor patching make IoT one of the highest-risk device categories on the exam.

5-second recall

Reduce attack surface $arrow$ patch + disable unused + change defaults.

19. Detecting Attacks on Devices

The big idea

Endpoint detection relies on monitoring device behavior and logs for indicators of compromise, since malware often evades static antivirus signatures.

Must know

Indicators of compromise (IoCs): unusual CPU/network spikes, unexpected new processes or startup programs, unauthorized account creation, disabled security software; EDR tools monitor endpoint behavior in real time; log review (event/system logs) for anomalies; sandboxing suspicious files before execution.

Don't confuse

Signature-based antivirus catches known malware matching a database; behavior/anomaly-based EDR can catch new or modified malware by watching for suspicious actions instead of matching a known file signature.

Exam trap

Assuming a clean antivirus scan proves a device isn't compromised --- signature-based tools miss novel or fileless malware, which is why behavioral monitoring/EDR is emphasized as a complementary layer.

5-second recall

Known malware $arrow$ signature match; unknown/new malware $arrow$ behavior-based EDR.

20. Application & Data Vulnerabilities

The big idea

Applications that fail to validate input or manage sessions/permissions correctly give attackers a direct path to the data behind them.

Must know

Injection attacks (e.g., SQL injection --- malicious input manipulates a database query); cross-site scripting (XSS --- injecting malicious script into a page viewed by other users); broken authentication/session management; insecure direct object references; buffer overflow (input exceeds allocated memory and can corrupt execution).

Don't confuse

SQL injection targets the backend database via malicious query input; cross-site scripting (XSS) targets other users' browsers by injecting malicious client-side script into a trusted page.

Exam trap

Assuming client-side (browser) input validation alone is sufficient --- the exam expects server-side validation too, since client-side checks can be bypassed by an attacker interacting with the server directly.

5-second recall

Bad input to a database $arrow$ SQL injection; bad input rendered to other users $arrow$ XSS.

21. Managerial Controls, Access Controls & Data Privacy Regulations

The big idea

Protecting data legally and ethically requires classifying it correctly and matching access/handling rules to that classification, not applying one policy to everything.

Must know

Data classification (public, internal, confidential/restricted); PII (Personally Identifiable Information); PHI (Protected Health Information); protections around student education records; payment card data governed by PCI DSS; least privilege applied to data access; data retention and secure-disposal policies.

Don't confuse

A law/regulation protecting categories like PHI or student records is government-mandated with legal penalties; PCI DSS is an industry standard enforced contractually by payment card networks, not a government law.

Exam trap

Treating all sensitive data the same way --- the correct control must match the data's classification (e.g., PHI demands stricter handling than general internal data), not a one-size-fits-all policy.

5-second recall

PII/PHI/education records $arrow$ classify first, then match access controls to sensitivity.

22. Symmetric Cryptography & Protecting Stored Data

The big idea

Encryption protects confidentiality by transforming plaintext into unreadable ciphertext using a key, and symmetric encryption uses the same key to encrypt and decrypt.

Must know

Symmetric encryption: one shared secret key (e.g., AES --- Advanced Encryption Standard), fast and efficient for large data volumes; the key-distribution problem (the shared key must be exchanged securely); encryption at rest (protecting stored data) vs.\ encryption in transit (protecting data moving across a network); hashing is a one-way function producing a fixed-size digest used to verify integrity, not confidentiality.

Don't confuse

Encryption is reversible with the correct key (protects confidentiality); hashing is a one-way function used to verify integrity --- a hash cannot be ``decrypted'' back into the original data.

Exam trap

Describing hashing as a way to keep data secret --- hashing verifies that data hasn't changed; it does not protect secrecy the way encryption does.

5-second recall

Same key both ways $arrow$ symmetric (AES); one-way, checks integrity $arrow$ hash.

23. Asymmetric Cryptography, PKI & Digital Signatures

The big idea

Asymmetric cryptography solves the key-distribution problem with a mathematically linked key pair --- a public key anyone can use, and a private key only the owner holds.

Must know

Asymmetric/public-key cryptography (e.g., RSA); public key encrypts / private key decrypts (for confidentiality); private key signs / public key verifies (for digital signatures and non-repudiation); PKI (Public Key Infrastructure) and certificate authorities (CAs) issue and validate certificates binding identities to public keys; HTTPS uses asymmetric cryptography (via TLS) to establish a secure session, then typically switches to symmetric encryption for speed.

Don't confuse

Encrypting with the recipient's public key protects confidentiality (only their private key can decrypt); signing with your own private key proves authenticity/non-repudiation (anyone with your public key can verify it) --- two different uses of the same key pair.

Exam trap

Reversing which key does what --- students often mix up ``public key encrypts'' and ``private key signs'' under time pressure.

5-second recall

Confidentiality $arrow$ encrypt with the recipient's PUBLIC key; proof of origin $arrow$ sign with YOUR OWN private key.

24. Protecting Applications

The big idea

Secure applications are built by validating all input, limiting privileges, and following secure development practices rather than bolting on security afterward.

Must know

Input validation and sanitization (defense against injection/XSS); parameterized queries/prepared statements (the primary defense against SQL injection); secure session management (timeouts, secure cookies); least privilege for application service accounts; regular security testing (code review, vulnerability scanning, penetration testing); keeping frameworks/libraries patched.

Don't confuse

Input sanitization (cleaning/escaping dangerous characters) is a general practice; parameterized queries are the specific, most reliable defense against SQL injection because they separate code from data entirely.

Exam trap

Relying on a web application firewall (WAF) alone as ``the fix'' for an injection vulnerability --- a WAF adds a helpful layer, but the exam expects secure coding (parameterized queries/input validation) as the root-cause fix.

5-second recall

Fix the root cause $arrow$ parameterized queries + input validation, not just a filter in front.

25. Detecting Attacks on Data & Applications

The big idea

Detecting compromise at the application/data layer relies on logging, monitoring access patterns, and continuously verifying data integrity.

Must know

Application/web server logs (failed logins, unusual query patterns); file integrity monitoring (detects unauthorized changes to critical files, often via hash comparison); data loss prevention (DLP) tools flag/block unauthorized data exfiltration; anomalous access-pattern detection (mass downloads, off-hours access); audit trails for compliance and forensic investigation.

Don't confuse

File integrity monitoring detects changes to files/data (an integrity concern); DLP tools detect and block unauthorized data leaving the organization (a confidentiality/exfiltration concern) --- different CIA-triad targets.

Exam trap

Assuming a large, sudden data transfer at 3 a.m.\ is normal because the credentials used were valid --- valid credentials do not rule out compromise; anomalous access patterns are themselves a detection signal.

5-second recall

Files changed $arrow$ integrity monitoring; data leaving $arrow$ DLP; odd timing/volume $arrow$ investigate regardless of valid login.

POWER BOX 1 --- Key Numbers & Core Facts

5-second recall

3 pillars, 2+ factors, 6 layers, 130 minutes total.

POWER BOX 2 --- Terms Students Always Confuse

5-second recall

When two terms look alike, ask: reversible or one-way? passive or active? targeted or mass?

POWER BOX 3 --- Malware Taxonomy: What Does What

5-second recall

Match the behavior described, not just ``it's malware'' --- precision earns credit.

POWER BOX 4 --- Frameworks, Standards & Regulations Reference List

5-second recall

Classify the data first (PII/PHI/records/payment data), then apply the matching standard.

POWER BOX 5 --- How to Analyze a Cybersecurity Scenario (FRQ Method)

5-second recall

Read literally $arrow$ compare to policy $arrow$ name the gap $arrow$ recommend a matched control $arrow$ cite the evidence.

POWER BOX 6 --- Exam Format & Question-Type Playbook

5-second recall

60 MCQ/80 min (70%) + 1 FRQ/50 min (30%) = 130 minutes, all digital.

POWER BOX 7 --- Process Box: The Defense-in-Depth Pathway

5-second recall

No single layer is enough --- a breach of one layer should be caught or contained by the next.

POWER BOX 8 --- Reading Firewall Rules & Logs (Emergency Guide)

5-second recall

Order matters, default is deny, and every anomaly gets checked against policy before you call it a violation.

POWER BOX 9 --- AP Cybersecurity Trap Statements

POWER BOX 10 --- Final 15-Minute Review

5-second recall

Triad, risk, MFA, social-engineering ladder, encryption vs.\ hashing, IDS vs.\ IPS, defense-in-depth --- know all seven cold.