AP® Cybersecurity · Unit 2: Securing Spaces · Topic 2.4
Detecting Physical Attacks
Physical attack detection is the process of noticing, confirming, recording, and reporting signs that someone or something may threaten a facility, device, system, or person. Strong detection combines alert people, dependable procedures, and monitored technology—then connects every credible signal to a safe response.
What physical attack detection means
A physical attack is an unauthorized or harmful action directed at people, spaces, equipment, utilities, or physical records. Detection looks for observable evidence of attempted entry, unauthorized presence, theft, tampering, visual information exposure, or an environmental condition that may disrupt operations.
A single clue is not always proof. An open door may have an innocent cause, while an access-card entry at an unusual time may be legitimate. Effective detection compares the signal with context: normal schedules, approved visitors, equipment inventories, camera views, access logs, sensor alerts, and reports from people nearby.
- ObserveNotice a person, condition, object, or record that seems abnormal.
- CompareCheck safe context such as policy, expected activity, or approved records.
- ProtectPrioritize people and avoid changing a potentially important scene.
- ReportUse the approved channel and describe facts without guessing motives.
- EscalateLet authorized responders assess urgency, preserve evidence, and act.
AP® connection: detection lowers impact only when response follows
Cameras, alarms, logs, and observations are detective controls. They provide value when alerts are reviewed and linked to a response plan. Detection can shorten the time between the start of an incident and protective action, limiting possible harm to confidentiality, integrity, and availability.
Detecting unauthorized access and suspicious behavior
Focus on behavior and authorization—not appearance, identity, disability, or assumptions about a person. A useful report describes what happened, where, when, and which policy or normal pattern made it unusual.
| Situation | Possible warning signs | Safe detection or response |
|---|---|---|
| Tailgating | One person authenticates while another follows through without presenting a credential. | Do not hold secure doors for unknown people; alert staff through the approved channel. |
| Piggybacking | A person knowingly allows another person to enter using the first person’s authorization. | Apply the rule that every entrant must authenticate or be processed as an approved visitor. |
| Impersonation | An unexpected “technician,” courier, substitute, or contractor requests restricted access or urgent exceptions. | Verify through an independent staff contact or work-order process, not contact details supplied by the visitor. |
| Badge misuse | A badge photo or role does not match, a person conceals a badge, or one credential appears in conflicting places or times. | Report the discrepancy; authorized staff can check badge status, identity, and access logs. |
| Unusual presence | Repeated waiting near secure doors, photographing restricted equipment, testing multiple entrances, or entering areas unrelated to a stated task. | Move to a safe place and give a factual description to security or responsible staff. |
Specific facts beat vague labels
“At 3:15 p.m., a person without a visible visitor badge tried two locked doors beside Lab 4” is more useful than “someone looked suspicious.” The first report gives time, place, actions, and a policy-relevant detail.
Urgency does not cancel procedure
Claims such as “the principal sent me” or “the server will fail unless I enter now” should be verified through known internal contacts. Verification should not require giving the requester sensitive information.
Signs of forced entry and altered access points
Unexpected physical change
- Splintering, bending, new gaps, or fresh scrape marks
- A door that no longer closes or latches normally
- An emergency exit or restricted door found open without an approved reason
Damage or inconsistency
- Broken, loose, missing, or visibly damaged locks
- A numbered seal that is broken, replaced, or does not match the record
- An access reader, keypad, hinge, or cover that appears shifted or damaged
Altered perimeter
- Cracked glass, damaged screens, cut fencing, or moved barriers
- Objects positioned to keep an entry point open
- New blind spots caused by blocked lighting or camera views
Preserve the scene
Do not handle the damaged hardware, remove an unfamiliar object, close an altered door, or clean the area unless life safety requires action. Keep a safe distance and report the exact location. Authorized responders decide how to secure the area and document potential evidence.
Detecting theft, tampering, and unauthorized equipment
A physical change to a device can create a digital compromise. Inventory records, cable diagrams, tamper-evident seals, maintenance logs, and familiar workstation layouts help defenders notice what is missing, changed, or newly connected.
Missing or unexpectedly moved assets
- An empty docking station, cut cable lock, or missing school laptop
- A device recorded in one room but discovered elsewhere
- Missing storage media, backup drives, keys, badges, or printed records
- An inventory label that is removed, changed, or inconsistent with records
Unexpected change to trusted equipment
- Loose panels, broken seals, new marks, or unexplained repairs
- A cable routed differently or a port used that is normally empty
- A workstation, camera, access reader, or network cabinet behaving differently after an unexplained physical change
- Serial numbers or components that no longer match the approved inventory
USB devices, cables, adapters, and peripherals
An unfamiliar object connected to a computer may be a forgotten accessory, but it may also create risk. Suspicious items can include unapproved USB storage, charging cables, keyboard-like devices, adapters, network equipment, hubs, cameras, or other peripherals that are not part of the expected setup.
Do not connect an unknown device to identify its contents or owner.
Do not unplug or move an already connected item unless an authorized responder or an immediate safety procedure directs you.
Describe its location, appearance, and connection to the appropriate teacher, supervisor, IT team, or security contact.
Baseline thinking
Detection becomes easier when defenders know the approved baseline: which devices should be present, which ports should be used, who may service them, and when changes are scheduled. A difference from the baseline is a reason to verify—not automatic proof of an attack.
Cameras, sensors, alarms, and access-control logs
Automated systems extend human awareness, but they require correct placement, reliable timestamps, maintenance, protected records, trained reviewers, and a defined response. One alert should often be checked against another source.
| Detection source | What it can reveal | Important limitation |
|---|---|---|
| Surveillance camera | Movement, entry sequence, object placement, direction of travel, or corroborating visual evidence | Blind spots, poor lighting, privacy rules, retention limits, or an obstructed view can reduce usefulness. |
| Motion or contact sensor | Movement in a protected zone or a door/window changing state | An alert does not identify intent; maintenance faults and normal activity can cause false alarms. |
| Intrusion or door-held-open alarm | A barrier opened unexpectedly, forced, or left open beyond an allowed period | The alert helps only if routed to someone who can assess and respond promptly. |
| Access-control log | Credential, reader, time, success/failure, and sometimes door state | A valid badge event does not prove the badge holder was the person using it. |
| Visitor record | Expected visitor, host, arrival, purpose, badge, escort, and departure | Incomplete sign-out or shared visitor badges weaken the record. |
| Inventory or maintenance log | Approved device location, serial number, change, technician, and service time | Outdated records can make legitimate changes appear suspicious or conceal real changes. |
Examples of useful anomalies
- Access outside a person’s normal approved hours
- Repeated denied attempts at different restricted doors
- Entry without a matching departure where one is expected
- One credential appearing at distant locations too close together
- Unusually long presence in a sensitive area
Combine independent evidence
A door alarm plus a camera view, a badge log plus a visitor record, or a missing asset plus an inventory discrepancy provides more context than one source alone. Authorized analysts should also consider clock accuracy, maintenance events, and approved exceptions.
Shoulder surfing and visual information exposure
Shoulder surfing occurs when someone observes confidential information such as a password, security code, document, screen, badge detail, or access procedure. The observer may stand nearby or use a camera or reflective surface. Detection should remain behavior-based and safety-focused.
Possible signs
- Repeated positioning to view a screen or keypad
- Unnecessary photography near credentials or sensitive displays
- Close observation during password or code entry
Immediate protection
- Pause entry and shield the screen or keypad
- Lock the device if leaving it
- Move sensitive work away from public view when possible
Report and recover
- Report observed behavior through the proper channel
- Change an exposed password or code using a trusted device
- Review the account or access record for unexpected activity
Detecting environmental and utility threats
Fire, smoke, water, heat, humidity, dust, and power disruption can damage equipment or interrupt services. Physical attack detection therefore overlaps with safety, facilities management, and continuity planning.
What people may notice
- Smoke, burning smells, unusual heat, sparks, or repeated electrical trips
- Water stains, dripping, condensation, standing water, or unusual humidity
- Loud fans, equipment shutdowns, warning lights, or a room becoming unusually warm
- Flickering lights, sudden power loss, or backup-power alarms
What systems may report
- Smoke, heat, water, humidity, or temperature sensor alerts
- Building-management or equipment-monitoring threshold alarms
- UPS, generator, battery, or power-quality warnings
- Repeated environmental anomalies in the same room or rack
Emergency conditions use emergency procedures
If there is smoke, fire, a dangerous electrical condition, significant water, or another immediate hazard, prioritize evacuation and the facility’s emergency plan. Do not enter a hazardous server room or attempt technical troubleshooting unless trained, authorized, and directed.
People and systems share detection responsibility
Notice and report
Follow badge and visitor rules, avoid admitting unknown people, protect screens and credentials, notice unexpected changes, and report facts quickly. They should not conduct a risky investigation.
Assess and coordinate
Trained personnel review records, verify authorization, inspect safely, preserve evidence, isolate affected assets when appropriate, and coordinate incident response, safety, facilities, and law enforcement.
Record and alert
Sensors and systems continuously record selected events, compare activity with rules or baselines, and notify responders. They support—not replace— human judgment, maintenance, and accountability.
Documenting, reporting, and escalating safely
Reporting should be prompt, factual, and proportional to risk. Follow the organization’s policy and use emergency services for immediate threats to life or safety.
Protect people
- Move away from immediate danger.
- Do not confront or touch suspicious items.
- Use emergency procedures when conditions are urgent.
Record observable facts
- Date and time
- Exact location
- What you directly saw, heard, or received
- Direction of travel or affected asset, if safely known
- People already notified
Preserve and cooperate
- Do not post details publicly.
- Do not alter the scene or related records.
- Remain available for authorized follow-up.
A concise factual report
“At 10:20 a.m. today, I saw an unfamiliar USB device connected to the reception computer in Building B. The equipment label was not present. I did not touch it. I moved away and notified the IT help desk at 10:23 a.m.”
Real-world detection scenarios
School: an unexpected visitor near a records office
A student notices an adult without a visitor badge waiting beside a controlled door and following closely when a staff member enters. Best response: the student does not challenge the person, moves to a staffed area, and reports the location, time, and observed entry behavior to school staff.
Office: a changed workstation
An employee returns from lunch and sees an unfamiliar adapter between the keyboard cable and computer. Best response: the employee does not type credentials, move the adapter, or unplug it. They step away and notify the IT or security team, which can document and examine the setup safely.
Data center: access-log anomaly
Monitoring shows several denied door attempts followed by a successful entry outside the credential holder’s approved schedule. Best response: authorized personnel review the badge status, door state, camera record, work orders, and on-call schedule, then escalate according to the incident plan.
Public facility: water near an equipment room
A maintenance worker observes water moving toward a communications closet while a water sensor alarms. Best response: they follow the facility’s safety and emergency procedures, notify facilities and responsible technical personnel, and keep untrained people away from electrical hazards.
Watch: detecting physical attacks
While watching, list the human observations, automated signals, and records that could reveal an incident. Then decide who should receive each report.
Interactive knowledge check
Spot the Signal
Choose the safest and most defensible response. The quiz works entirely in your browser and does not collect personal information.
What the quiz covers
The ten questions test access warning signs, tailgating, equipment tampering, unknown peripherals, access-log anomalies, environmental alerts, shoulder surfing, evidence preservation, and safe escalation.
How scoring works
Answer every question, select Check my answers, and receive a score plus an explanation for each answer. Use Restart quiz to practice again.
AP® Cybersecurity study support
Anomaly
An event or condition that differs from an expected baseline and deserves verification.
Corroboration
Checking one signal against independent evidence to improve context and confidence.
Detective control
A safeguard designed to discover, record, or alert on an event that may require response.
False positive
An alert that appears suspicious but is explained by legitimate activity or error.
Physical access log
A record of credential use, door or reader, time, result, and related access events.
Tamper evidence
An observable change that may indicate equipment, packaging, a seal, or a barrier was altered.
Exam reasoning pattern
For scenario questions, identify the asset, observable signal, possible consequence, safest immediate action, reporting path, and evidence that could corroborate the event. Prefer answers that protect people and preserve facts.
Continue studying
Strengthen your wider computing vocabulary with RevisionTown computer science resources, or use the AP® self-study guide to plan retrieval practice and spaced review.
Frequently asked questions
1. What is physical attack detection?
It is the use of observations, records, sensors, monitoring, and reporting procedures to identify possible unauthorized access, theft, tampering, damage, visual exposure, or environmental danger so trained responders can assess and act.
2. Are suspicious behavior and suspicious appearance the same?
No. Reports should focus on specific actions, access authorization, location, time, and policy—not clothing, identity, disability, ethnicity, or vague feelings about appearance.
3. What is the difference between tailgating and piggybacking?
Both involve entry using another person’s access. Tailgating often describes following through without the authorized person deliberately granting entry; piggybacking commonly describes knowingly allowing the second person through. In practice, policies may use the terms differently.
4. Does a valid badge event prove the correct person entered?
No. A badge can be lost, shared, stolen, or misused. Logs should be checked against context such as schedules, door states, visitor records, camera evidence, and reports.
5. What should I do if I find an unknown USB device?
Do not connect it to any system. Leave it undisturbed when safe, prevent accidental use without handling it, and report its exact location and appearance through the approved IT or security channel.
6. Why should suspected tampering be left untouched?
Touching, moving, disconnecting, cleaning, or testing an item can increase risk, change system state, or destroy evidence. Authorized responders should decide how to isolate and examine it safely.
7. Can cameras detect every physical attack?
No. Cameras have blind spots and depend on lighting, maintenance, retention, privacy rules, accurate time, monitoring, and response. They work best as one layer alongside access controls, sensors, logs, and trained people.
8. What access-log patterns may deserve review?
Examples include repeated denied entries, access outside approved hours, unusual sequences, unexpectedly long visits, one credential appearing at distant locations too quickly, or access unrelated to a person’s role. Each signal still needs context.
9. How should an environmental threat be reported?
Follow the site’s emergency plan. For immediate danger such as smoke, fire, electrical hazards, or significant water near equipment, move to safety and use emergency reporting channels. Provide the location and observable condition without entering a hazardous area.
10. What details belong in a physical security incident report?
Include date, time, exact location, direct observations, affected assets, relevant direction of travel if safely known, actions taken, and people notified. Separate facts from assumptions and avoid posting incident details publicly.
Trusted references
These primary sources support the lesson’s treatment of physical-access monitoring, log review, alarms, surveillance, suspicious-activity reporting, and emergency procedures:
AP® is a trademark registered by the College Board, which is not affiliated with and does not endorse this page. This lesson provides general defensive cybersecurity education; always follow the safety, reporting, privacy, and emergency procedures of the relevant school, workplace, or facility.





