AP® Cybersecurity › Unit 2: Securing Spaces
Topic 2.2
Physical Vulnerabilities and Attacks
A physical vulnerability is a weakness in a building, room, device, process, or environmental safeguard. A physical attack deliberately exploits such a weakness to gain access, steal or alter equipment, expose information, disrupt service, or cause damage.
Why physical security matters to cybersecurity
Digital controls assume that devices, cables, storage media, screens, and network equipment remain in an environment where access is managed. Physical access can expose data or create opportunities that remote defenses were not designed to stop.
The weakness
Examples include an unlocked window, propped door, unattended unlocked workstation, shared physical key, unmonitored storage room, missing visitor escort, or server room without environmental alerts.
The harmful event
Examples include unauthorized entry, theft, tampering, impersonation, observing private information, connecting an unauthorized device, or intentionally damaging equipment.
| Physical weakness | Possible consequence | Digital security impact | Basic defensive approach |
|---|---|---|---|
| Unsecured door or window | Unauthorized access to a room or facility | Access to devices, cables, documents, or logged-in systems | Repairable locks, alarms, inspections, controlled entry, and reporting |
| Unprotected server room | Theft, tampering, shutdown, or environmental damage | Loss of confidentiality, integrity, and availability | Restricted access, logs, monitoring, sensors, and resilient power and cooling |
| Unattended workstation | Screen viewing or use of an active session | Unauthorized data access or actions under another identity | Automatic and manual screen locks, positioning, and user awareness |
| Open storage area | Loss of documents, devices, keys, badges, or backup media | Credential abuse, information disclosure, or loss of recovery data | Inventory, secure cabinets, access records, and approved disposal |
| Exposed network equipment | Cable changes, disconnection, or unauthorized peripherals | Interception, outage, or unapproved network access | Locked cabinets, tamper checks, port controls, and configuration monitoring |
Physical access is not automatically total access
Encryption, MFA, secure boot, screen locks, least privilege, monitoring, segmentation, and backups can still reduce impact. Physical and digital controls should reinforce one another through defense in depth.
Unauthorized entry and human deception
Attackers may exploit helpfulness, distraction, authority, uniforms, busy entrances, or weak visitor procedures rather than damaging a lock.
Following without authorization
An unauthorized person enters behind an authorized person without independently presenting access credentials. The authorized person may not realize it happened.
Entry with assistance
In a common distinction, the authorized person knowingly helps the other person enter, perhaps by holding a restricted door. Organizations may use the two terms differently, so follow local policy.
Using a believable identity
Someone may claim to be a technician, delivery worker, substitute, contractor, parent, or new employee. Clothing, tools, and confidence do not replace identity and authorization checks.
Stolen or copied credentials
A lost, borrowed, stolen, counterfeit, or cloned access card may be used to imitate an authorized holder. Badge use should be individual, logged, reviewable, and promptly disabled when lost.
Lost or uncontrolled keys
Shared keys, unlabeled key control, unreturned copies, and delayed reporting weaken physical access control. Key inventories and return procedures matter.
Poor visitor management
Missing identity checks, generic badges, unrecorded visits, no host confirmation, broad access, and absent escorts make unauthorized movement difficult to detect.
Respond safely
Follow the organization’s reporting and visitor procedures. Do not physically confront a stranger or create personal danger. Contact an authorized staff member, security team, teacher, or supervisor and provide the location and observed behavior.
Shoulder surfing and visual data exposure
Shoulder surfing is observing sensitive information as someone types, reads, unlocks a device, uses a payment terminal, or handles documents. Observation may occur nearby or through cameras, reflections, windows, or unattended displays.
Information that may be exposed
- Passwords, PINs, MFA codes, and recovery information
- Student, employee, financial, medical, or customer records
- Confidential messages, schedules, maps, and contact details
- Door codes, badge numbers, keys, and restricted-area information
- Information on whiteboards, sticky notes, printouts, and meeting screens
Practical prevention
- Position screens away from public sight lines and windows.
- Use privacy filters where the risk and device permit.
- Cover keypads and avoid reading codes aloud.
- Lock screens whenever a device is unattended.
- Clear whiteboards and collect printed materials after use.
- Avoid sensitive work in crowded public spaces when possible.
Devices, hardware, peripherals, and discarded information
| Risk | Defensive explanation | Warning signs | Prevention and response |
|---|---|---|---|
| Device theft | A laptop, phone, drive, backup, or network device may contain data or provide account access. | Missing inventory, moved equipment, broken locks, or unexplained location changes | Inventory, secure storage, encryption, screen locks, MFA, prompt reporting, and managed recovery actions |
| Equipment tampering | Hardware, cables, ports, settings, or protective features may be altered. | Broken seals, loose panels, unfamiliar cables, unexplained restarts, or changed placement | Baseline inspections, tamper evidence, access logs, monitoring, and authorized technical review |
| Hardware replacement | An approved component may be swapped for an unapproved or compromised one. | Serial-number mismatch, packaging changes, undocumented maintenance, or unknown components | Asset records, chain of custody, approved vendors, receiving checks, and configuration verification |
| Malicious USB or peripheral | An unfamiliar device may contain unsafe files, imitate another device type, or create an unauthorized connection. | Found drives, unexpected adapters, unknown keyboards, storage devices, or network accessories | Do not connect unknown devices; report them, use approved peripherals, and apply device-control policy |
| Dumpster diving | Discarded paper, labels, packaging, media, badges, or equipment may reveal useful information. | Sensitive material in ordinary trash or unsecured recycling | Classification, locked disposal containers, approved destruction, and media sanitization |
Found USB device? Do not test it yourself
Leave it disconnected and report it according to policy. Authorized staff can preserve evidence and decide whether specialized analysis is necessary. A label such as “photos,” “payroll,” or “exam answers” does not make a device trustworthy.
Documents and media need lifecycle protection
Sensitive information should be marked, stored, transported, shared, retained, sanitized, and disposed of according to its classification. Deleting a file or placing equipment in ordinary trash may not make stored data unrecoverable. Organizations should use an approved media-sanitization program appropriate to the information and media type.
Environmental hazards, insiders, and operational weaknesses
Not every physical incident is a deliberate attack. Accidents, natural hazards, equipment failure, and poor maintenance can damage availability and integrity just as seriously.
Heat, smoke, and suppression
Fire can injure people, destroy equipment, interrupt power, and damage storage media. Detection, safe suppression, evacuation procedures, and off-site recovery capability are separate layers.
Leaks, floods, and plumbing
Water from pipes, roofs, sprinklers, or flooding can damage equipment and power systems. Placement, leak detection, isolation, and recovery plans reduce risk.
Cooling and airflow failure
Excess temperature or blocked airflow can shorten equipment life or cause shutdowns. Temperature monitoring, maintained cooling, and alerts support availability.
Contamination and maintenance
Dust can obstruct cooling and affect components. Controlled environments, filters, housekeeping, equipment enclosures, and maintenance help.
Outage, surge, and instability
Power failure can interrupt services and corrupt data. Surge protection, uninterruptible power supplies, safe shutdown, backup power, and tested recovery serve different needs.
Connected physical systems
Cooling, electricity, telecommunications, fire detection, doors, and monitoring may depend on one another. A single failure can affect several layers at once.
Insider threats
An insider is someone with legitimate knowledge or access, such as a student, employee, contractor, volunteer, or vendor. Harm may be malicious, accidental, or caused by negligence. Least privilege, separation of duties, access reviews, supervision, logging, clear procedures, and a supportive reporting culture reduce risk without assuming every insider is hostile.
Visitor controls protect visitors too
Verification, visible badges, host confirmation, escorts, restricted routes, sign-out, and prompt badge return make expectations clear and help prevent visitors from accidentally entering hazardous or sensitive areas.
Warning signs and layered prevention
Warning signs to report
- Propped doors, damaged locks, open windows, or defeated alarms
- Unbadged or unescorted people in restricted areas
- A badge photo, name, role, or access pattern that appears inconsistent
- Missing keys, badges, devices, documents, cables, or inventory labels
- Unknown USB devices, adapters, peripherals, or network equipment
- Broken seals, moved equipment, open panels, or unexplained wiring
- Confidential material in ordinary trash or public view
- Heat, smoke, water, unusual odors, dust buildup, or power alarms
- Repeated visitor-policy exceptions or pressure to bypass normal checks
Layered prevention
- Use risk-based zoning for public, staff-only, and highly restricted areas.
- Issue individual credentials and review access regularly.
- Combine locks and badges with logs, alarms, monitoring, and response.
- Apply visitor verification, temporary badges, escorts, and sign-out.
- Secure, encrypt, inventory, and promptly report missing devices.
- Control approved peripherals and keep unknown devices disconnected.
- Use clear-desk, screen-lock, storage, and media-disposal procedures.
- Monitor temperature, water, smoke, power, and other relevant conditions.
- Test backups, emergency communication, evacuation, and recovery plans.
If you notice possible tampering or unauthorized entry
- Protect people first Move to safety and use emergency procedures if there is fire, electrical, chemical, structural, or personal danger.
- Do not disturb evidence Avoid connecting, unplugging, moving, or testing suspicious equipment unless authorized safety procedures require action.
- Report promptly Contact the designated teacher, supervisor, facilities team, help desk, or security team through an approved method.
- Record observations Note the time, location, visible condition, people involved, and relevant alerts without guessing or making public accusations.
AP-style analysis
Identify the asset, physical vulnerability, threat event, effect on confidentiality, integrity, or availability, the most relevant preventive and detective controls, and the residual risk.
Realistic spaces and decisions
After-class computer lab
A workstation remains unlocked and student records are visible. The user should lock the screen, protect the display, and report any unauthorized access rather than assuming the room itself provides privacy.
Unexpected technician
A person with tools requests access to a network closet. Staff should use the normal work-order, identity, host-confirmation, and escort process rather than relying on clothing or confidence.
Temperature alarm
A rising-temperature alert can become an availability incident. Staff follow the approved facilities and incident procedures, protect people, and avoid improvised equipment changes.
Crowded transport hub
A traveler opens confidential documents on a visible screen. Better choices include postponing the work, repositioning the screen, using a privacy filter, and locking the device when distracted.
Discarded equipment
Old drives are placed near ordinary waste. They should remain under controlled custody and enter the organization’s approved sanitization and disposal process.
Door held open
A person asks to follow someone into an exam-storage area. The authorized user should follow policy and direct the person to the normal access or visitor-verification point.
Watch: physical attacks and defensive awareness
As you watch, identify the weakness, possible physical action, digital impact, warning sign, and safest defensive response.
Interactive knowledge check
Spot the Physical Risk
Complete all ten questions, check your score, and review the explanation for every answer. The quiz runs in your browser and does not collect personal information.
What the quiz covers
- Physical vulnerabilities, unauthorized entry, and visitor risks
- Tailgating, visual exposure, theft, tampering, badges, keys, and USB devices
- Dumpster diving, media disposal, insiders, and environmental hazards
- Warning signs, digital consequences, reporting, and layered prevention
AP® Cybersecurity study support
Chain of custody
A documented record of who controlled an item or evidence and when.
Environmental control
A safeguard for conditions such as temperature, humidity, water, smoke, or power.
Media sanitization
A process that makes access to target data on media infeasible for a defined level of effort.
Physical access control
A measure that manages entry to a facility, room, cabinet, or other space.
Shoulder surfing
Observing sensitive information from a screen, document, keypad, or user action.
Tamper evidence
A feature or record that helps reveal whether equipment or packaging was altered.
Continue your study
Device theft and physical access make strong encryption and secure computing fundamentals especially important. Review how cryptography protects digital information, explore broader computer science study materials, or organize your revision using the guide to self-studying for an AP exam.
Trusted defensive references
Frequently asked questions
1. What is a physical vulnerability in cybersecurity?
It is a weakness in a facility, room, device, storage location, environmental safeguard, or physical process that could expose people, systems, equipment, or information to harm.
2. How can a physical attack compromise digital security?
Physical access may expose screens, logged-in sessions, devices, storage media, cables, network equipment, credentials, or recovery systems, affecting confidentiality, integrity, and availability.
3. What is the difference between tailgating and piggybacking?
A common distinction is that tailgating happens without the authorized person knowingly assisting, while piggybacking involves knowing assistance. Organizations may use the terms differently, so follow local definitions and access policy.
4. What is shoulder surfing?
Shoulder surfing is observing sensitive information as someone uses a screen, keypad, document, or device. It can occur nearby or through reflections, windows, or cameras.
5. What should I do with an unknown USB device?
Do not connect or test it. Keep it disconnected and report it through the approved process so authorized staff can preserve and assess it safely.
6. What should happen when a badge or physical key is lost?
The loss should be reported immediately. Electronic credentials can be disabled, affected access can be reviewed, and physical keys can be handled according to the organization’s key-control procedure.
7. Why is ordinary trash unsafe for confidential documents and storage media?
Discarded materials may still reveal readable or recoverable information. Sensitive documents and media need approved storage, sanitization, and disposal methods based on their classification.
8. Which environmental risks affect cybersecurity?
Fire, smoke, water, heat, humidity, dust, power loss, surges, cooling failure, and related dependencies can damage systems or interrupt access to essential services.
9. What makes visitor management effective?
Effective visitor management verifies identity and host, records visits, issues visible time-limited credentials, limits access, provides escorts where required, and records departure and badge return.
10. What should I do if I notice possible equipment tampering?
Avoid disturbing or testing the equipment, protect personal safety, report the observation promptly, and record the time, location, and visible condition without making unsupported accusations.
AP® is a registered trademark of the College Board, which is not affiliated with and does not endorse this independent educational resource.





