Fiveable
🔒AP Cybersecurity
​

🔒AP Cybersecurity

Device Security Analysis
​
Unit 1: Introduction to Security
​
FRQ Types & Units

Each FRQ type tests specific skills taught in particular units. Here's why certain units appear for each question type:

This mapping reflects College Board's exam structure - each FRQ type tests specific skills that are taught in particular units.

Practice FRQ 1 of 11/1

1. UNIT PRACTICE ADAPTATION: Device Security Analysis. You are a cybersecurity analyst reviewing evidence from a student's laptop and accounts to investigate potential security incidents. Use the provided sources to analyze the security posture, identify attacks, and recommend defenses. All sources are simulated for this practice question.

Supplied evidence:

</>TEXT
Source 1: Student Device Security Policy (Excerpt)  
Rule 1: Passwords must be at least 8 characters long.  
Rule 2: Students must connect to the "School_Guest" Wi-Fi network when on campus which school IT operates and monitors for known threats.  
Rule 3: Multifactor Authentication (MFA) is recommended, but not required, for student email accounts.

Source 2: Authentication Logs (Student Email Portal)  
Timestamp | IP Address | Event | Status  
08:01:12 | 198.51.100.50 | Login Attempt | Success  
09:15:00 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:02 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:05 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:07 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
10:30:00 | 192.0.2.15 | Login Attempt | Success

Source 3: Suspicious Text Message (Received at 09:10)  
"URGENT: Your student account will be locked in 15 minutes due to suspicious activity. Click here [http://school-portal-update.example/login] immediately to verify your password and prevent account deletion. - IT Dept"

Source 4: Network Context & Authorized Behavior  
Device Owner: Alex (Student)  
Authorized Home Network IP: 198.51.100.50  
Public Wi-Fi Used Today: "CoffeeShop_Free" (IP: 192.0.2.15)  
The school’s verified sign-in domain is school.example. The public-facing IP addresses shown identify connection sources; they do not identify individual people.  

A.
i.

Explain how the policy provision in Rule 2 protects the student's device.

ii.

Describe how Rule 3 could be modified to improve the security of student email accounts.

B.
i.

Describe the evidence of a password attack by citing specific log entries from Source 2.

ii.

Identify the source IP address associated with the suspected password-guessing attempts.

C.
i.

Identify one psychological tactic used by the adversary in the suspicious text message (Source 3).

ii.

Explain how the tactic identified in Part C(i) influences the victim to perform the desired action.

iii.

Describe one possible impact for the victim if they click the link in Source 3 and enter their credentials.

D.
i.

Identify the type of wireless cyberattack where an adversary sets up their own access point with a name similar or identical to a target network like "CoffeeShop_Free".

ii.

Explain one risk to unencrypted information sent over an untrusted public Wi-Fi network.

iii.

Describe one action that can protect traffic between the student’s device and a trusted VPN service while using public Wi-Fi. Explain the protection, without claiming it makes every website trustworthy.

E.
i.

Explain how adversaries take advantage of weak authentication using automated tools.

ii.

Explain how enabling Multifactor Authentication (MFA) protects an account even if an adversary successfully obtains the user's password.

iii.

Explain how adversaries can use generative AI tools, like large language models (LLMs), to augment phishing attacks like the one seen in Source 3.

iv.

Explain how cyber defenders can leverage AI-powered tools to enable faster and more accurate threat detection of events like those shown in Source 2.

Timed

00:00

Response auto-saves






Pep

essential ap study content awaits..

Features
Testimonials
Testimonials
start studying →
FRQ Directions
Free Response Question Practice

This practice environment simulates the AP AP Cybersecurity Free Response Questions section. Here are some guidelines:

  • Read each question carefully before responding. Pay attention to command verbs like "identify," "explain," "analyze," or "evaluate."
  • Use the timer to practice time management. You can pause, restart, or hide the timer as needed.
  • Mark for Review if you want to come back to a question later.
  • Your responses are saved automatically as you type. You can also use the drawing tool for questions that require diagrams or graphs.
  • Use the toolbar for formatting options like bold, italic, subscript, and superscript.
  • Navigate between questions using the Previous and Next buttons at the bottom of the screen.

Tip: Answer all parts of each question. Partial credit is often available, so even if you are unsure, provide what you know.

Source 1: Student Device Security Policy (Excerpt)  
Rule 1: Passwords must be at least 8 characters long.  
Rule 2: Students must connect to the "School_Guest" Wi-Fi network when on campus which school IT operates and monitors for known threats.  
Rule 3: Multifactor Authentication (MFA) is recommended, but not required, for student email accounts.

Source 2: Authentication Logs (Student Email Portal)  
Timestamp | IP Address | Event | Status  
08:01:12 | 198.51.100.50 | Login Attempt | Success  
09:15:00 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:02 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:05 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
09:15:07 | 203.0.113.45 | Login Attempt | Failed (Invalid Password)  
10:30:00 | 192.0.2.15 | Login Attempt | Success

Source 3: Suspicious Text Message (Received at 09:10)  
"URGENT: Your student account will be locked in 15 minutes due to suspicious activity. Click here [http://school-portal-update.example/login] immediately to verify your password and prevent account deletion. - IT Dept"

Source 4: Network Context & Authorized Behavior  
Device Owner: Alex (Student)  
Authorized Home Network IP: 198.51.100.50  
Public Wi-Fi Used Today: "CoffeeShop_Free" (IP: 192.0.2.15)  
The school’s verified sign-in domain is school.example. The public-facing IP addresses shown identify connection sources; they do not identify individual people.