AP® Cybersecurity

Physical Vulnerabilities and Attacks | AP® Cybersecurity 2.2

Learn how physical vulnerabilities expose devices, networks, and data, recognize common attacks, apply layered defenses, and test your knowledge.

AP® Cybersecurity › Unit 2: Securing Spaces

Topic 2.2

Physical Vulnerabilities and Attacks

A physical vulnerability is a weakness in a building, room, device, process, or environmental safeguard. A physical attack deliberately exploits such a weakness to gain access, steal or alter equipment, expose information, disrupt service, or cause damage.

Why physical security matters to cybersecurity

Digital controls assume that devices, cables, storage media, screens, and network equipment remain in an environment where access is managed. Physical access can expose data or create opportunities that remote defenses were not designed to stop.

Vulnerability

The weakness

Examples include an unlocked window, propped door, unattended unlocked workstation, shared physical key, unmonitored storage room, missing visitor escort, or server room without environmental alerts.

Attack or incident

The harmful event

Examples include unauthorized entry, theft, tampering, impersonation, observing private information, connecting an unauthorized device, or intentionally damaging equipment.

Physical weaknessPossible consequenceDigital security impactBasic defensive approach
Unsecured door or windowUnauthorized access to a room or facilityAccess to devices, cables, documents, or logged-in systemsRepairable locks, alarms, inspections, controlled entry, and reporting
Unprotected server roomTheft, tampering, shutdown, or environmental damageLoss of confidentiality, integrity, and availabilityRestricted access, logs, monitoring, sensors, and resilient power and cooling
Unattended workstationScreen viewing or use of an active sessionUnauthorized data access or actions under another identityAutomatic and manual screen locks, positioning, and user awareness
Open storage areaLoss of documents, devices, keys, badges, or backup mediaCredential abuse, information disclosure, or loss of recovery dataInventory, secure cabinets, access records, and approved disposal
Exposed network equipmentCable changes, disconnection, or unauthorized peripheralsInterception, outage, or unapproved network accessLocked cabinets, tamper checks, port controls, and configuration monitoring

Physical access is not automatically total access

Encryption, MFA, secure boot, screen locks, least privilege, monitoring, segmentation, and backups can still reduce impact. Physical and digital controls should reinforce one another through defense in depth.

Unauthorized entry and human deception

Attackers may exploit helpfulness, distraction, authority, uniforms, busy entrances, or weak visitor procedures rather than damaging a lock.

Tailgating

Following without authorization

An unauthorized person enters behind an authorized person without independently presenting access credentials. The authorized person may not realize it happened.

Piggybacking

Entry with assistance

In a common distinction, the authorized person knowingly helps the other person enter, perhaps by holding a restricted door. Organizations may use the two terms differently, so follow local policy.

Impersonation

Using a believable identity

Someone may claim to be a technician, delivery worker, substitute, contractor, parent, or new employee. Clothing, tools, and confidence do not replace identity and authorization checks.

Badges

Stolen or copied credentials

A lost, borrowed, stolen, counterfeit, or cloned access card may be used to imitate an authorized holder. Badge use should be individual, logged, reviewable, and promptly disabled when lost.

Keys

Lost or uncontrolled keys

Shared keys, unlabeled key control, unreturned copies, and delayed reporting weaken physical access control. Key inventories and return procedures matter.

Visitors

Poor visitor management

Missing identity checks, generic badges, unrecorded visits, no host confirmation, broad access, and absent escorts make unauthorized movement difficult to detect.

Respond safely

Follow the organization’s reporting and visitor procedures. Do not physically confront a stranger or create personal danger. Contact an authorized staff member, security team, teacher, or supervisor and provide the location and observed behavior.

Shoulder surfing and visual data exposure

Shoulder surfing is observing sensitive information as someone types, reads, unlocks a device, uses a payment terminal, or handles documents. Observation may occur nearby or through cameras, reflections, windows, or unattended displays.

Information that may be exposed

  • Passwords, PINs, MFA codes, and recovery information
  • Student, employee, financial, medical, or customer records
  • Confidential messages, schedules, maps, and contact details
  • Door codes, badge numbers, keys, and restricted-area information
  • Information on whiteboards, sticky notes, printouts, and meeting screens

Practical prevention

  • Position screens away from public sight lines and windows.
  • Use privacy filters where the risk and device permit.
  • Cover keypads and avoid reading codes aloud.
  • Lock screens whenever a device is unattended.
  • Clear whiteboards and collect printed materials after use.
  • Avoid sensitive work in crowded public spaces when possible.

Devices, hardware, peripherals, and discarded information

RiskDefensive explanationWarning signsPrevention and response
Device theftA laptop, phone, drive, backup, or network device may contain data or provide account access.Missing inventory, moved equipment, broken locks, or unexplained location changesInventory, secure storage, encryption, screen locks, MFA, prompt reporting, and managed recovery actions
Equipment tamperingHardware, cables, ports, settings, or protective features may be altered.Broken seals, loose panels, unfamiliar cables, unexplained restarts, or changed placementBaseline inspections, tamper evidence, access logs, monitoring, and authorized technical review
Hardware replacementAn approved component may be swapped for an unapproved or compromised one.Serial-number mismatch, packaging changes, undocumented maintenance, or unknown componentsAsset records, chain of custody, approved vendors, receiving checks, and configuration verification
Malicious USB or peripheralAn unfamiliar device may contain unsafe files, imitate another device type, or create an unauthorized connection.Found drives, unexpected adapters, unknown keyboards, storage devices, or network accessoriesDo not connect unknown devices; report them, use approved peripherals, and apply device-control policy
Dumpster divingDiscarded paper, labels, packaging, media, badges, or equipment may reveal useful information.Sensitive material in ordinary trash or unsecured recyclingClassification, locked disposal containers, approved destruction, and media sanitization

Found USB device? Do not test it yourself

Leave it disconnected and report it according to policy. Authorized staff can preserve evidence and decide whether specialized analysis is necessary. A label such as “photos,” “payroll,” or “exam answers” does not make a device trustworthy.

Documents and media need lifecycle protection

Sensitive information should be marked, stored, transported, shared, retained, sanitized, and disposed of according to its classification. Deleting a file or placing equipment in ordinary trash may not make stored data unrecoverable. Organizations should use an approved media-sanitization program appropriate to the information and media type.

Environmental hazards, insiders, and operational weaknesses

Not every physical incident is a deliberate attack. Accidents, natural hazards, equipment failure, and poor maintenance can damage availability and integrity just as seriously.

Fire

Heat, smoke, and suppression

Fire can injure people, destroy equipment, interrupt power, and damage storage media. Detection, safe suppression, evacuation procedures, and off-site recovery capability are separate layers.

Water

Leaks, floods, and plumbing

Water from pipes, roofs, sprinklers, or flooding can damage equipment and power systems. Placement, leak detection, isolation, and recovery plans reduce risk.

Heat

Cooling and airflow failure

Excess temperature or blocked airflow can shorten equipment life or cause shutdowns. Temperature monitoring, maintained cooling, and alerts support availability.

Dust

Contamination and maintenance

Dust can obstruct cooling and affect components. Controlled environments, filters, housekeeping, equipment enclosures, and maintenance help.

Power

Outage, surge, and instability

Power failure can interrupt services and corrupt data. Surge protection, uninterruptible power supplies, safe shutdown, backup power, and tested recovery serve different needs.

Dependency

Connected physical systems

Cooling, electricity, telecommunications, fire detection, doors, and monitoring may depend on one another. A single failure can affect several layers at once.

Insider threats

An insider is someone with legitimate knowledge or access, such as a student, employee, contractor, volunteer, or vendor. Harm may be malicious, accidental, or caused by negligence. Least privilege, separation of duties, access reviews, supervision, logging, clear procedures, and a supportive reporting culture reduce risk without assuming every insider is hostile.

Visitor controls protect visitors too

Verification, visible badges, host confirmation, escorts, restricted routes, sign-out, and prompt badge return make expectations clear and help prevent visitors from accidentally entering hazardous or sensitive areas.

Warning signs and layered prevention

Warning signs to report

  • Propped doors, damaged locks, open windows, or defeated alarms
  • Unbadged or unescorted people in restricted areas
  • A badge photo, name, role, or access pattern that appears inconsistent
  • Missing keys, badges, devices, documents, cables, or inventory labels
  • Unknown USB devices, adapters, peripherals, or network equipment
  • Broken seals, moved equipment, open panels, or unexplained wiring
  • Confidential material in ordinary trash or public view
  • Heat, smoke, water, unusual odors, dust buildup, or power alarms
  • Repeated visitor-policy exceptions or pressure to bypass normal checks

Layered prevention

  • Use risk-based zoning for public, staff-only, and highly restricted areas.
  • Issue individual credentials and review access regularly.
  • Combine locks and badges with logs, alarms, monitoring, and response.
  • Apply visitor verification, temporary badges, escorts, and sign-out.
  • Secure, encrypt, inventory, and promptly report missing devices.
  • Control approved peripherals and keep unknown devices disconnected.
  • Use clear-desk, screen-lock, storage, and media-disposal procedures.
  • Monitor temperature, water, smoke, power, and other relevant conditions.
  • Test backups, emergency communication, evacuation, and recovery plans.

If you notice possible tampering or unauthorized entry

  1. Protect people first Move to safety and use emergency procedures if there is fire, electrical, chemical, structural, or personal danger.
  2. Do not disturb evidence Avoid connecting, unplugging, moving, or testing suspicious equipment unless authorized safety procedures require action.
  3. Report promptly Contact the designated teacher, supervisor, facilities team, help desk, or security team through an approved method.
  4. Record observations Note the time, location, visible condition, people involved, and relevant alerts without guessing or making public accusations.

AP-style analysis

Identify the asset, physical vulnerability, threat event, effect on confidentiality, integrity, or availability, the most relevant preventive and detective controls, and the residual risk.

Realistic spaces and decisions

School

After-class computer lab

A workstation remains unlocked and student records are visible. The user should lock the screen, protect the display, and report any unauthorized access rather than assuming the room itself provides privacy.

Office

Unexpected technician

A person with tools requests access to a network closet. Staff should use the normal work-order, identity, host-confirmation, and escort process rather than relying on clothing or confidence.

Data center

Temperature alarm

A rising-temperature alert can become an availability incident. Staff follow the approved facilities and incident procedures, protect people, and avoid improvised equipment changes.

Public space

Crowded transport hub

A traveler opens confidential documents on a visible screen. Better choices include postponing the work, repositioning the screen, using a privacy filter, and locking the device when distracted.

Storage

Discarded equipment

Old drives are placed near ordinary waste. They should remain under controlled custody and enter the organization’s approved sanitization and disposal process.

Restricted area

Door held open

A person asks to follow someone into an exam-storage area. The authorized user should follow policy and direct the person to the normal access or visitor-verification point.

Watch: physical attacks and defensive awareness

As you watch, identify the weakness, possible physical action, digital impact, warning sign, and safest defensive response.

Interactive knowledge check

Spot the Physical Risk

Complete all ten questions, check your score, and review the explanation for every answer. The quiz runs in your browser and does not collect personal information.

What the quiz covers

  • Physical vulnerabilities, unauthorized entry, and visitor risks
  • Tailgating, visual exposure, theft, tampering, badges, keys, and USB devices
  • Dumpster diving, media disposal, insiders, and environmental hazards
  • Warning signs, digital consequences, reporting, and layered prevention

Choose the safest answer

0 of 10 answered

1. A restricted door is propped open for convenience. What does this represent?
2. An unauthorized person quietly follows an employee through a badge-controlled door. What is this?
3. Someone watches a user enter a PIN in a crowded public area. Which risk is this?
4. You find an unfamiliar USB drive labeled “Exam Files.” What should you do?
5. What is the best response to a lost access badge?
6. Printed student records are found in an ordinary recycling bin. What is the main concern?
7. A server room’s cooling fails and temperature rises. Which security objective is most immediately at risk?
8. Which statement about insider threats is most accurate?
9. Which visitor-management process is strongest?
10. You notice an unfamiliar adapter connected behind an office workstation. What is the safest response?

AP® Cybersecurity study support

Chain of custody

A documented record of who controlled an item or evidence and when.

Environmental control

A safeguard for conditions such as temperature, humidity, water, smoke, or power.

Media sanitization

A process that makes access to target data on media infeasible for a defined level of effort.

Physical access control

A measure that manages entry to a facility, room, cabinet, or other space.

Shoulder surfing

Observing sensitive information from a screen, document, keypad, or user action.

Tamper evidence

A feature or record that helps reveal whether equipment or packaging was altered.

Continue your study

Device theft and physical access make strong encryption and secure computing fundamentals especially important. Review how cryptography protects digital information, explore broader computer science study materials, or organize your revision using the guide to self-studying for an AP exam.

Trusted defensive references

Frequently asked questions

1. What is a physical vulnerability in cybersecurity?

It is a weakness in a facility, room, device, storage location, environmental safeguard, or physical process that could expose people, systems, equipment, or information to harm.

2. How can a physical attack compromise digital security?

Physical access may expose screens, logged-in sessions, devices, storage media, cables, network equipment, credentials, or recovery systems, affecting confidentiality, integrity, and availability.

3. What is the difference between tailgating and piggybacking?

A common distinction is that tailgating happens without the authorized person knowingly assisting, while piggybacking involves knowing assistance. Organizations may use the terms differently, so follow local definitions and access policy.

4. What is shoulder surfing?

Shoulder surfing is observing sensitive information as someone uses a screen, keypad, document, or device. It can occur nearby or through reflections, windows, or cameras.

5. What should I do with an unknown USB device?

Do not connect or test it. Keep it disconnected and report it through the approved process so authorized staff can preserve and assess it safely.

6. What should happen when a badge or physical key is lost?

The loss should be reported immediately. Electronic credentials can be disabled, affected access can be reviewed, and physical keys can be handled according to the organization’s key-control procedure.

7. Why is ordinary trash unsafe for confidential documents and storage media?

Discarded materials may still reveal readable or recoverable information. Sensitive documents and media need approved storage, sanitization, and disposal methods based on their classification.

8. Which environmental risks affect cybersecurity?

Fire, smoke, water, heat, humidity, dust, power loss, surges, cooling failure, and related dependencies can damage systems or interrupt access to essential services.

9. What makes visitor management effective?

Effective visitor management verifies identity and host, records visits, issues visible time-limited credentials, limits access, provides escorts where required, and records departure and badge return.

10. What should I do if I notice possible equipment tampering?

Avoid disturbing or testing the equipment, protect personal safety, report the observation promptly, and record the time, location, and visible condition without making unsupported accusations.

Shares: