CASE FILE: WEEK 2 — CYBER FOUNDATIONS & SECURING SPACES AP Cybersecurity — Unit 1 Topic 1.5 & Unit 2 Topics 2.1–2.4
0 / 0 complete

Briefing: Week 2 Case File

Unit 1 Topic 1.5 & Unit 2 Topics 2.1–2.4

This week you'll work as a Security Analyst across five connected investigations: reviewing AI-generated security alerts, profiling adversaries and assessing risk for a small business, investigating physical security breaches, selecting the right controls to prevent them, and designing a monitoring plan to detect the next one. Each day builds on the last. By the end of the week, you'll pull everything together into one layered defense plan.

Day 1 · Tuesday, January 12, 2027

Topic 1.5 — Leveraging AI in Cyber Defense

Essential Question: How can artificial intelligence strengthen an organization's cybersecurity defenses?
Vocabulary
AI-Assisted Defense
Threat Detection
Detection Rule
False Positive
False Negative
Security Alert
Security Analyst
CASE 2027-1A
Flag: Review

The 3 A.M. Anomaly

Detection Rule Triggered: Impossible Travel — Login Velocity

At 8:02 AM, employee jdoe successfully logs into the company VPN from Fort Payne, Alabama. Forty-five minutes later, at 8:47 AM, the same account logs in again — this time from Kyiv, Ukraine. The AI-assisted defense platform's login-velocity rule calculates that no commercial flight could cover that distance in 45 minutes, and automatically generates a security alert.

Evidence: Authentication Log
TimestampUsernameSource IPGeolocationDeviceResultReview
08:02:14jdoe98.14.201.7Fort Payne, AL, USWindows-Laptop-JD11Success
08:47:52jdoe185.220.101.4Kyiv, UkraineUnknown / Linux CLISuccess
08:48:10jdoe185.220.101.4Kyiv, UkraineUnknown / Linux CLIAccessed Payroll Export Tool

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

CASE 2027-1B
Flag: Likely FP

The Cried-Wolf Update

Detection Rule Triggered: Behavioral Heuristic — System File Modification

The endpoint detection platform flags a new process, acrobat_update_service.exe, as malicious. Its behavior — writing files into System32 and modifying registry keys — matches patterns the AI associates with malware installation. A closer look at the process metadata tells a different story.

Evidence: Process & Signature Log
FieldValueReview
Process Nameacrobat_update_service.exe
Digital SignatureValid — signed by Adobe Inc., not expired
Deployment SourceCompany-managed patch management server
Hash ReputationMatches known-good hash in vendor database

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

DAY 1 EXIT TICKET
Reflection

Day 1 Exit Ticket

Topic 1.5 — Leveraging AI in Cyber Defense
Day 2 · Wednesday, January 13, 2027

Topic 2.1 — Cyber Foundations

Essential Question: How do organizations identify and manage cybersecurity risks?
Vocabulary
Script Kiddie
Hacktivist
Insider Threat
Cyberterrorist
Risk Assessment
Asset
Defense in Depth
CASE 2027-2A
Profile the Adversary

Who's Knocking?

Task: Match Each Incident to an Adversary Type

Four unrelated incidents landed on your desk this morning. For each one, use the dropdown to classify the adversary type based on their apparent skill level and motivation, then answer the questions below.

Evidence: Incident Summaries
IncidentClassify Adversary
A teenager downloads a free "DDoS booter" tool from a forum and takes a rival's game server offline for fun.
A group defaces a company's website with a political message after the company was accused of environmental damage.
A recently terminated employee, whose VPN access was never revoked, logs in and deletes shared project files out of anger.
A coordinated group attempts to knock a regional power grid's control system offline to cause widespread disruption.
CASE 2027-2B
Risk Assessment

Risk Assessment: Riverbend Bakery & Café

Task: Rate Likelihood, Impact, and Overall Risk

Riverbend Bakery & Café stores customer loyalty and payment data on an aging point-of-sale computer in an unlocked back office. Employees share one login, and the back door lock has been broken for weeks. Rate each risk below by selecting a Likelihood and Impact — the Risk Rating will calculate automatically.

Evidence: Asset / Threat / Vulnerability Register
AssetThreatVulnerabilityLikelihoodImpactRisk Rating
Customer payment dataExternal hackerOutdated POS software, no firewall Pending
Cash drawerBurglaryBack door lock is broken Pending
Employee login credentialsInsider misuseShared login, no accountability Pending
2.
DAY 2 EXIT TICKET
Reflection

Day 2 Exit Ticket

Topic 2.1 — Cyber Foundations
Day 3 · Thursday, January 14, 2027

Topic 2.2 — Physical Vulnerabilities and Attacks

Essential Question: Why is physical security a critical part of cybersecurity?
Vocabulary
Piggybacking
Tailgating
Shoulder Surfing
Dumpster Diving
Card Cloning
Physical Vulnerability
Risk
CASE 2027-3A
Flag: Review

The Held Door

Incident Type: Unauthorized Entry

Camera footage shows an employee badge in at the north entrance, then hold the door open while chatting with a coworker. A person in a delivery uniform, carrying no visible badge, walks in directly behind them without being challenged. Ten minutes later, the same "delivery" person is seen near the server room — nowhere close to the loading dock.

Evidence: Camera & Access Log
TimeLocationObservationReview
9:14 AMNorth EntranceEmployee badges in, holds door, chats with coworker
9:14 AMNorth EntranceUnbadged person in delivery uniform enters directly behind employee
9:24 AMServer Room CorridorSame person seen near server room, no delivery in hand

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

CASE 2027-3B
Flag: Multiple Findings

What the Trash Revealed

Incident Type: Information Exposure

A routine facility walkthrough turned up three separate findings in the same week. Each represents a different way physical exposure can compromise security — even when every digital password policy is followed perfectly.

Evidence: Facility Findings
FindingLocationReview
Sticky note with the office Wi-Fi password taped to a monitor, visible from the hallwayFront Office
Unshredded printout listing all employee ID numbers found in the recycling binLoading Dock Dumpster
Small skimmer device discovered attached to the badge readerLoading Dock Entrance

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

DAY 3 EXIT TICKET
Reflection

Day 3 Exit Ticket

Topic 2.2 — Physical Vulnerabilities and Attacks
Day 4 · Friday, January 15, 2027

Topic 2.3 — Protecting Physical Spaces

Essential Question: Which physical security controls are most effective at reducing organizational risk?
Vocabulary
Managerial Control
Physical Control
Preventative Control
Badge Reader
Turnstile
UPS
Clean Desk Policy
CASE 2027-4A
Pick the Control

Pick the Control

Task: Match Each Gap to the Best-Fit Control

A walkthrough of a mid-size office turned up five physical security gaps. Choose the best-fit control for each — the control type will tag automatically.

Evidence: Walkthrough Findings
GapSelect ControlControl Type
Server room door can be propped open and anyone can walk in.
Sensitive printed reports are left out on desks overnight.
A storm-related power outage risks corrupting financial transaction data.
Multiple people slip through the lobby behind a single badge scan.
New employees don't realize they shouldn't hold the door open for strangers.
CASE 2027-4B
Flag: Multi-Zone

Floor Plan Retrofit

Task: Recommend Improvements by Zone

Riverbend Bakery & Café is renovating and wants your recommendations for each zone of the building before they finalize construction.

Evidence: Zone Gaps
ZoneCurrent GapReview
Front LobbyNo barrier between public seating and staff-only hallway
Back OfficePOS server sits on an open desk with no locked cabinet
Loading DockDoor propped open during deliveries with no one monitoring it
Employee Break RoomShared computer stays logged in to the scheduling system all day

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

DAY 4 EXIT TICKET
Reflection

Day 4 Exit Ticket

Topic 2.3 — Protecting Physical Spaces
Day 5 · Tuesday, January 19, 2027

Topic 2.4 — Detecting Physical Attacks

Essential Question: How can organizations detect physical security breaches before significant damage occurs?
Vocabulary
CCTV
Motion Sensor
Security Guard
Alarm System
Access Log
Detection Control
Monitoring
CASE 2027-5A
Design the Plan

Design the Monitoring Plan

Task: Place Detection Controls on the Floor Plan

Click a zone on the floor plan below, then choose a detection control for it in the table. Assigned zones will highlight so you can see your full monitoring plan at a glance.

Evidence: Building Floor Plan
Front Lobby Server Room Exec. Office Loading Dock Parking Lot
Assign Detection Controls
ZoneAssigned Control
Front Lobby
Server Room
Executive Office
Loading Dock
Parking Lot

Clicking a zone on the floor plan jumps to and focuses its dropdown below.

CASE 2027-5B
Flag: Review

The 2 A.M. Badge Swipe

Incident Type: Detection Control Failure

An access log shows a badge used at the server room door at 2:14 AM by an employee who, according to the shift schedule, wasn't on shift that night. No alarm was triggered, because the motion sensor covering that hallway had been switched to "maintenance mode" two days earlier for a false-alarm issue — and no one ever turned it back on.

Evidence: Access Log
TimeEventDetailReview
2 days prior, 4:10 PMMotion sensor set to maintenance modeServer room corridor sensor, reason logged: "false alarms"
2:14 AMBadge swipe — server room doorEmployee not listed on tonight's shift schedule
2:14 AMNo alarm triggeredMotion sensor still in maintenance mode

Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.

DAY 5 EXIT TICKET
Reflection

Day 5 Exit Ticket

Topic 2.4 — Detecting Physical Attacks
CAPSTONE
Synthesis

Week 2 Synthesis: Building a Layered Defense Plan

Task: Bring Every Layer Together for Riverbend Bakery & Café

You've spent the week analyzing AI-generated alerts, assessing risk, investigating physical breaches, and choosing controls. Now assign a control type to each remaining gap at Riverbend Bakery, then answer the synthesis questions below.

Evidence: Remaining Gaps
Asset / AreaThreat / AdversarySelect Control Type
Customer payment data on POS systemExternal hacker
Back office serverInsider misuse
Loading dock entranceTailgating / unauthorized entry
Employee awareness of social engineeringPiggybacking / social engineering

Week 2 Case File — Cyber Foundations & Securing Spaces — Submission