AP® Cybersecurity

Detecting Physical Attacks | AP® Cybersecurity Topic 2.4

Learn how to detect unauthorized access, equipment tampering, suspicious activity, and environmental threats, then test your skills with an interactive quiz.

AP® Cybersecurity · Unit 2: Securing Spaces · Topic 2.4

Detecting Physical Attacks

Physical attack detection is the process of noticing, confirming, recording, and reporting signs that someone or something may threaten a facility, device, system, or person. Strong detection combines alert people, dependable procedures, and monitored technology—then connects every credible signal to a safe response.

What physical attack detection means

A physical attack is an unauthorized or harmful action directed at people, spaces, equipment, utilities, or physical records. Detection looks for observable evidence of attempted entry, unauthorized presence, theft, tampering, visual information exposure, or an environmental condition that may disrupt operations.

A single clue is not always proof. An open door may have an innocent cause, while an access-card entry at an unusual time may be legitimate. Effective detection compares the signal with context: normal schedules, approved visitors, equipment inventories, camera views, access logs, sensor alerts, and reports from people nearby.

  1. ObserveNotice a person, condition, object, or record that seems abnormal.
  2. CompareCheck safe context such as policy, expected activity, or approved records.
  3. ProtectPrioritize people and avoid changing a potentially important scene.
  4. ReportUse the approved channel and describe facts without guessing motives.
  5. EscalateLet authorized responders assess urgency, preserve evidence, and act.

AP® connection: detection lowers impact only when response follows

Cameras, alarms, logs, and observations are detective controls. They provide value when alerts are reviewed and linked to a response plan. Detection can shorten the time between the start of an incident and protective action, limiting possible harm to confidentiality, integrity, and availability.

Detecting unauthorized access and suspicious behavior

Focus on behavior and authorization—not appearance, identity, disability, or assumptions about a person. A useful report describes what happened, where, when, and which policy or normal pattern made it unusual.

Access threat warning signs and safe responses
SituationPossible warning signsSafe detection or response
TailgatingOne person authenticates while another follows through without presenting a credential.Do not hold secure doors for unknown people; alert staff through the approved channel.
PiggybackingA person knowingly allows another person to enter using the first person’s authorization.Apply the rule that every entrant must authenticate or be processed as an approved visitor.
ImpersonationAn unexpected “technician,” courier, substitute, or contractor requests restricted access or urgent exceptions.Verify through an independent staff contact or work-order process, not contact details supplied by the visitor.
Badge misuseA badge photo or role does not match, a person conceals a badge, or one credential appears in conflicting places or times.Report the discrepancy; authorized staff can check badge status, identity, and access logs.
Unusual presenceRepeated waiting near secure doors, photographing restricted equipment, testing multiple entrances, or entering areas unrelated to a stated task.Move to a safe place and give a factual description to security or responsible staff.
Behavior-based observation

Specific facts beat vague labels

“At 3:15 p.m., a person without a visible visitor badge tried two locked doors beside Lab 4” is more useful than “someone looked suspicious.” The first report gives time, place, actions, and a policy-relevant detail.

Human verification

Urgency does not cancel procedure

Claims such as “the principal sent me” or “the server will fail unless I enter now” should be verified through known internal contacts. Verification should not require giving the requester sensitive information.

Signs of forced entry and altered access points

Doors and frames

Unexpected physical change

  • Splintering, bending, new gaps, or fresh scrape marks
  • A door that no longer closes or latches normally
  • An emergency exit or restricted door found open without an approved reason
Locks and seals

Damage or inconsistency

  • Broken, loose, missing, or visibly damaged locks
  • A numbered seal that is broken, replaced, or does not match the record
  • An access reader, keypad, hinge, or cover that appears shifted or damaged
Windows and barriers

Altered perimeter

  • Cracked glass, damaged screens, cut fencing, or moved barriers
  • Objects positioned to keep an entry point open
  • New blind spots caused by blocked lighting or camera views

Preserve the scene

Do not handle the damaged hardware, remove an unfamiliar object, close an altered door, or clean the area unless life safety requires action. Keep a safe distance and report the exact location. Authorized responders decide how to secure the area and document potential evidence.

Detecting theft, tampering, and unauthorized equipment

A physical change to a device can create a digital compromise. Inventory records, cable diagrams, tamper-evident seals, maintenance logs, and familiar workstation layouts help defenders notice what is missing, changed, or newly connected.

Device theft

Missing or unexpectedly moved assets

  • An empty docking station, cut cable lock, or missing school laptop
  • A device recorded in one room but discovered elsewhere
  • Missing storage media, backup drives, keys, badges, or printed records
  • An inventory label that is removed, changed, or inconsistent with records
Hardware tampering

Unexpected change to trusted equipment

  • Loose panels, broken seals, new marks, or unexplained repairs
  • A cable routed differently or a port used that is normally empty
  • A workstation, camera, access reader, or network cabinet behaving differently after an unexplained physical change
  • Serial numbers or components that no longer match the approved inventory

USB devices, cables, adapters, and peripherals

An unfamiliar object connected to a computer may be a forgotten accessory, but it may also create risk. Suspicious items can include unapproved USB storage, charging cables, keyboard-like devices, adapters, network equipment, hubs, cameras, or other peripherals that are not part of the expected setup.

STOP

Do not connect an unknown device to identify its contents or owner.

LEAVE

Do not unplug or move an already connected item unless an authorized responder or an immediate safety procedure directs you.

REPORT

Describe its location, appearance, and connection to the appropriate teacher, supervisor, IT team, or security contact.

Baseline thinking

Detection becomes easier when defenders know the approved baseline: which devices should be present, which ports should be used, who may service them, and when changes are scheduled. A difference from the baseline is a reason to verify—not automatic proof of an attack.

Cameras, sensors, alarms, and access-control logs

Automated systems extend human awareness, but they require correct placement, reliable timestamps, maintenance, protected records, trained reviewers, and a defined response. One alert should often be checked against another source.

Detection sourceWhat it can revealImportant limitation
Surveillance cameraMovement, entry sequence, object placement, direction of travel, or corroborating visual evidenceBlind spots, poor lighting, privacy rules, retention limits, or an obstructed view can reduce usefulness.
Motion or contact sensorMovement in a protected zone or a door/window changing stateAn alert does not identify intent; maintenance faults and normal activity can cause false alarms.
Intrusion or door-held-open alarmA barrier opened unexpectedly, forced, or left open beyond an allowed periodThe alert helps only if routed to someone who can assess and respond promptly.
Access-control logCredential, reader, time, success/failure, and sometimes door stateA valid badge event does not prove the badge holder was the person using it.
Visitor recordExpected visitor, host, arrival, purpose, badge, escort, and departureIncomplete sign-out or shared visitor badges weaken the record.
Inventory or maintenance logApproved device location, serial number, change, technician, and service timeOutdated records can make legitimate changes appear suspicious or conceal real changes.
Pattern monitoring

Examples of useful anomalies

  • Access outside a person’s normal approved hours
  • Repeated denied attempts at different restricted doors
  • Entry without a matching departure where one is expected
  • One credential appearing at distant locations too close together
  • Unusually long presence in a sensitive area
Corroboration

Combine independent evidence

A door alarm plus a camera view, a badge log plus a visitor record, or a missing asset plus an inventory discrepancy provides more context than one source alone. Authorized analysts should also consider clock accuracy, maintenance events, and approved exceptions.

Shoulder surfing and visual information exposure

Shoulder surfing occurs when someone observes confidential information such as a password, security code, document, screen, badge detail, or access procedure. The observer may stand nearby or use a camera or reflective surface. Detection should remain behavior-based and safety-focused.

Possible signs

  • Repeated positioning to view a screen or keypad
  • Unnecessary photography near credentials or sensitive displays
  • Close observation during password or code entry

Immediate protection

  • Pause entry and shield the screen or keypad
  • Lock the device if leaving it
  • Move sensitive work away from public view when possible

Report and recover

  • Report observed behavior through the proper channel
  • Change an exposed password or code using a trusted device
  • Review the account or access record for unexpected activity

Detecting environmental and utility threats

Fire, smoke, water, heat, humidity, dust, and power disruption can damage equipment or interrupt services. Physical attack detection therefore overlaps with safety, facilities management, and continuity planning.

Human-observable clues

What people may notice

  • Smoke, burning smells, unusual heat, sparks, or repeated electrical trips
  • Water stains, dripping, condensation, standing water, or unusual humidity
  • Loud fans, equipment shutdowns, warning lights, or a room becoming unusually warm
  • Flickering lights, sudden power loss, or backup-power alarms
Automated detection

What systems may report

  • Smoke, heat, water, humidity, or temperature sensor alerts
  • Building-management or equipment-monitoring threshold alarms
  • UPS, generator, battery, or power-quality warnings
  • Repeated environmental anomalies in the same room or rack

Emergency conditions use emergency procedures

If there is smoke, fire, a dangerous electrical condition, significant water, or another immediate hazard, prioritize evacuation and the facility’s emergency plan. Do not enter a hazardous server room or attempt technical troubleshooting unless trained, authorized, and directed.

People and systems share detection responsibility

Employees and students

Notice and report

Follow badge and visitor rules, avoid admitting unknown people, protect screens and credentials, notice unexpected changes, and report facts quickly. They should not conduct a risky investigation.

Security, facilities, and IT

Assess and coordinate

Trained personnel review records, verify authorization, inspect safely, preserve evidence, isolate affected assets when appropriate, and coordinate incident response, safety, facilities, and law enforcement.

Automated monitoring

Record and alert

Sensors and systems continuously record selected events, compare activity with rules or baselines, and notify responders. They support—not replace— human judgment, maintenance, and accountability.

Documenting, reporting, and escalating safely

Reporting should be prompt, factual, and proportional to risk. Follow the organization’s policy and use emergency services for immediate threats to life or safety.

Before reporting

Protect people

  1. Move away from immediate danger.
  2. Do not confront or touch suspicious items.
  3. Use emergency procedures when conditions are urgent.
In the report

Record observable facts

  • Date and time
  • Exact location
  • What you directly saw, heard, or received
  • Direction of travel or affected asset, if safely known
  • People already notified
After reporting

Preserve and cooperate

  1. Do not post details publicly.
  2. Do not alter the scene or related records.
  3. Remain available for authorized follow-up.

A concise factual report

“At 10:20 a.m. today, I saw an unfamiliar USB device connected to the reception computer in Building B. The equipment label was not present. I did not touch it. I moved away and notified the IT help desk at 10:23 a.m.”

Real-world detection scenarios

School: an unexpected visitor near a records office

A student notices an adult without a visitor badge waiting beside a controlled door and following closely when a staff member enters. Best response: the student does not challenge the person, moves to a staffed area, and reports the location, time, and observed entry behavior to school staff.

Office: a changed workstation

An employee returns from lunch and sees an unfamiliar adapter between the keyboard cable and computer. Best response: the employee does not type credentials, move the adapter, or unplug it. They step away and notify the IT or security team, which can document and examine the setup safely.

Data center: access-log anomaly

Monitoring shows several denied door attempts followed by a successful entry outside the credential holder’s approved schedule. Best response: authorized personnel review the badge status, door state, camera record, work orders, and on-call schedule, then escalate according to the incident plan.

Public facility: water near an equipment room

A maintenance worker observes water moving toward a communications closet while a water sensor alarms. Best response: they follow the facility’s safety and emergency procedures, notify facilities and responsible technical personnel, and keep untrained people away from electrical hazards.

Watch: detecting physical attacks

While watching, list the human observations, automated signals, and records that could reveal an incident. Then decide who should receive each report.

Interactive knowledge check

Spot the Signal

Choose the safest and most defensible response. The quiz works entirely in your browser and does not collect personal information.

What the quiz covers

The ten questions test access warning signs, tailgating, equipment tampering, unknown peripherals, access-log anomalies, environmental alerts, shoulder surfing, evidence preservation, and safe escalation.

How scoring works

Answer every question, select Check my answers, and receive a score plus an explanation for each answer. Use Restart quiz to practice again.

Choose the strongest answer

0 of 10 answered

1. What best describes physical attack detection?
2. Which event is the clearest example of tailgating?
3. You find an unfamiliar adapter connected to a shared computer. What should you do?
4. Which method best assesses an unusual after-hours badge event?
5. Which observation most strongly suggests an access point needs immediate review?
6. Which statement about surveillance cameras is most accurate?
7. You smell smoke near a locked equipment room. What is the safest first action?
8. Which report is the most useful to responders?
9. What is an appropriate response to suspected shoulder surfing?
10. Which approach best demonstrates layered physical attack detection?

AP® Cybersecurity study support

Anomaly

An event or condition that differs from an expected baseline and deserves verification.

Corroboration

Checking one signal against independent evidence to improve context and confidence.

Detective control

A safeguard designed to discover, record, or alert on an event that may require response.

False positive

An alert that appears suspicious but is explained by legitimate activity or error.

Physical access log

A record of credential use, door or reader, time, result, and related access events.

Tamper evidence

An observable change that may indicate equipment, packaging, a seal, or a barrier was altered.

Exam reasoning pattern

For scenario questions, identify the asset, observable signal, possible consequence, safest immediate action, reporting path, and evidence that could corroborate the event. Prefer answers that protect people and preserve facts.

Continue studying

Strengthen your wider computing vocabulary with RevisionTown computer science resources, or use the AP® self-study guide to plan retrieval practice and spaced review.

Frequently asked questions

1. What is physical attack detection?

It is the use of observations, records, sensors, monitoring, and reporting procedures to identify possible unauthorized access, theft, tampering, damage, visual exposure, or environmental danger so trained responders can assess and act.

2. Are suspicious behavior and suspicious appearance the same?

No. Reports should focus on specific actions, access authorization, location, time, and policy—not clothing, identity, disability, ethnicity, or vague feelings about appearance.

3. What is the difference between tailgating and piggybacking?

Both involve entry using another person’s access. Tailgating often describes following through without the authorized person deliberately granting entry; piggybacking commonly describes knowingly allowing the second person through. In practice, policies may use the terms differently.

4. Does a valid badge event prove the correct person entered?

No. A badge can be lost, shared, stolen, or misused. Logs should be checked against context such as schedules, door states, visitor records, camera evidence, and reports.

5. What should I do if I find an unknown USB device?

Do not connect it to any system. Leave it undisturbed when safe, prevent accidental use without handling it, and report its exact location and appearance through the approved IT or security channel.

6. Why should suspected tampering be left untouched?

Touching, moving, disconnecting, cleaning, or testing an item can increase risk, change system state, or destroy evidence. Authorized responders should decide how to isolate and examine it safely.

7. Can cameras detect every physical attack?

No. Cameras have blind spots and depend on lighting, maintenance, retention, privacy rules, accurate time, monitoring, and response. They work best as one layer alongside access controls, sensors, logs, and trained people.

8. What access-log patterns may deserve review?

Examples include repeated denied entries, access outside approved hours, unusual sequences, unexpectedly long visits, one credential appearing at distant locations too quickly, or access unrelated to a person’s role. Each signal still needs context.

9. How should an environmental threat be reported?

Follow the site’s emergency plan. For immediate danger such as smoke, fire, electrical hazards, or significant water near equipment, move to safety and use emergency reporting channels. Provide the location and observable condition without entering a hazardous area.

10. What details belong in a physical security incident report?

Include date, time, exact location, direct observations, affected assets, relevant direction of travel if safely known, actions taken, and people notified. Separate facts from assumptions and avoid posting incident details publicly.

Trusted references

These primary sources support the lesson’s treatment of physical-access monitoring, log review, alarms, surveillance, suspicious-activity reporting, and emergency procedures:

AP® is a trademark registered by the College Board, which is not affiliated with and does not endorse this page. This lesson provides general defensive cybersecurity education; always follow the safety, reporting, privacy, and emergency procedures of the relevant school, workplace, or facility.

Shares: