CASE FILE: WEEK 2 — CYBER FOUNDATIONS & SECURING SPACESAP Cybersecurity — Unit 1 Topic 1.5 & Unit 2 Topics 2.1–2.4
0 / 0 complete
Briefing: Week 2 Case File
Unit 1 Topic 1.5 & Unit 2 Topics 2.1–2.4
This week you'll work as a Security Analyst across five connected investigations: reviewing AI-generated security alerts, profiling adversaries and assessing risk for a small business, investigating physical security breaches, selecting the right controls to prevent them, and designing a monitoring plan to detect the next one. Each day builds on the last. By the end of the week, you'll pull everything together into one layered defense plan.
Day 1 · Tuesday, January 12, 2027
Topic 1.5 — Leveraging AI in Cyber Defense
Essential Question: How can artificial intelligence strengthen an organization's cybersecurity defenses?
At 8:02 AM, employee jdoe successfully logs into the company VPN from Fort Payne, Alabama. Forty-five minutes later, at 8:47 AM, the same account logs in again — this time from Kyiv, Ukraine. The AI-assisted defense platform's login-velocity rule calculates that no commercial flight could cover that distance in 45 minutes, and automatically generates a security alert.
Evidence: Authentication Log
Timestamp
Username
Source IP
Geolocation
Device
Result
Review
08:02:14
jdoe
98.14.201.7
Fort Payne, AL, US
Windows-Laptop-JD11
Success
08:47:52
jdoe
185.220.101.4
Kyiv, Ukraine
Unknown / Linux CLI
Success
08:48:10
jdoe
185.220.101.4
Kyiv, Ukraine
Unknown / Linux CLI
Accessed Payroll Export Tool
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
CASE 2027-1B
Flag: Likely FP
The Cried-Wolf Update
Detection Rule Triggered: Behavioral Heuristic — System File Modification
The endpoint detection platform flags a new process, acrobat_update_service.exe, as malicious. Its behavior — writing files into System32 and modifying registry keys — matches patterns the AI associates with malware installation. A closer look at the process metadata tells a different story.
Evidence: Process & Signature Log
Field
Value
Review
Process Name
acrobat_update_service.exe
Digital Signature
Valid — signed by Adobe Inc., not expired
Deployment Source
Company-managed patch management server
Hash Reputation
Matches known-good hash in vendor database
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
DAY 1 EXIT TICKET
Reflection
Day 1 Exit Ticket
Topic 1.5 — Leveraging AI in Cyber Defense
Day 2 · Wednesday, January 13, 2027
Topic 2.1 — Cyber Foundations
Essential Question: How do organizations identify and manage cybersecurity risks?
Vocabulary
Script Kiddie
Hacktivist
Insider Threat
Cyberterrorist
Risk Assessment
Asset
Defense in Depth
CASE 2027-2A
Profile the Adversary
Who's Knocking?
Task: Match Each Incident to an Adversary Type
Four unrelated incidents landed on your desk this morning. For each one, use the dropdown to classify the adversary type based on their apparent skill level and motivation, then answer the questions below.
Evidence: Incident Summaries
Incident
Classify Adversary
A teenager downloads a free "DDoS booter" tool from a forum and takes a rival's game server offline for fun.
A group defaces a company's website with a political message after the company was accused of environmental damage.
A recently terminated employee, whose VPN access was never revoked, logs in and deletes shared project files out of anger.
A coordinated group attempts to knock a regional power grid's control system offline to cause widespread disruption.
CASE 2027-2B
Risk Assessment
Risk Assessment: Riverbend Bakery & Café
Task: Rate Likelihood, Impact, and Overall Risk
Riverbend Bakery & Café stores customer loyalty and payment data on an aging point-of-sale computer in an unlocked back office. Employees share one login, and the back door lock has been broken for weeks. Rate each risk below by selecting a Likelihood and Impact — the Risk Rating will calculate automatically.
Evidence: Asset / Threat / Vulnerability Register
Asset
Threat
Vulnerability
Likelihood
Impact
Risk Rating
Customer payment data
External hacker
Outdated POS software, no firewall
Pending
Cash drawer
Burglary
Back door lock is broken
Pending
Employee login credentials
Insider misuse
Shared login, no accountability
Pending
2.
DAY 2 EXIT TICKET
Reflection
Day 2 Exit Ticket
Topic 2.1 — Cyber Foundations
Day 3 · Thursday, January 14, 2027
Topic 2.2 — Physical Vulnerabilities and Attacks
Essential Question: Why is physical security a critical part of cybersecurity?
Vocabulary
Piggybacking
Tailgating
Shoulder Surfing
Dumpster Diving
Card Cloning
Physical Vulnerability
Risk
CASE 2027-3A
Flag: Review
The Held Door
Incident Type: Unauthorized Entry
Camera footage shows an employee badge in at the north entrance, then hold the door open while chatting with a coworker. A person in a delivery uniform, carrying no visible badge, walks in directly behind them without being challenged. Ten minutes later, the same "delivery" person is seen near the server room — nowhere close to the loading dock.
Evidence: Camera & Access Log
Time
Location
Observation
Review
9:14 AM
North Entrance
Employee badges in, holds door, chats with coworker
9:14 AM
North Entrance
Unbadged person in delivery uniform enters directly behind employee
9:24 AM
Server Room Corridor
Same person seen near server room, no delivery in hand
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
CASE 2027-3B
Flag: Multiple Findings
What the Trash Revealed
Incident Type: Information Exposure
A routine facility walkthrough turned up three separate findings in the same week. Each represents a different way physical exposure can compromise security — even when every digital password policy is followed perfectly.
Evidence: Facility Findings
Finding
Location
Review
Sticky note with the office Wi-Fi password taped to a monitor, visible from the hallway
Front Office
Unshredded printout listing all employee ID numbers found in the recycling bin
Loading Dock Dumpster
Small skimmer device discovered attached to the badge reader
Loading Dock Entrance
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
DAY 3 EXIT TICKET
Reflection
Day 3 Exit Ticket
Topic 2.2 — Physical Vulnerabilities and Attacks
Day 4 · Friday, January 15, 2027
Topic 2.3 — Protecting Physical Spaces
Essential Question: Which physical security controls are most effective at reducing organizational risk?
Vocabulary
Managerial Control
Physical Control
Preventative Control
Badge Reader
Turnstile
UPS
Clean Desk Policy
CASE 2027-4A
Pick the Control
Pick the Control
Task: Match Each Gap to the Best-Fit Control
A walkthrough of a mid-size office turned up five physical security gaps. Choose the best-fit control for each — the control type will tag automatically.
Evidence: Walkthrough Findings
Gap
Select Control
Control Type
Server room door can be propped open and anyone can walk in.
—
Sensitive printed reports are left out on desks overnight.
—
A storm-related power outage risks corrupting financial transaction data.
—
Multiple people slip through the lobby behind a single badge scan.
—
New employees don't realize they shouldn't hold the door open for strangers.
—
CASE 2027-4B
Flag: Multi-Zone
Floor Plan Retrofit
Task: Recommend Improvements by Zone
Riverbend Bakery & Café is renovating and wants your recommendations for each zone of the building before they finalize construction.
Evidence: Zone Gaps
Zone
Current Gap
Review
Front Lobby
No barrier between public seating and staff-only hallway
Back Office
POS server sits on an open desk with no locked cabinet
Loading Dock
Door propped open during deliveries with no one monitoring it
Employee Break Room
Shared computer stays logged in to the scheduling system all day
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
DAY 4 EXIT TICKET
Reflection
Day 4 Exit Ticket
Topic 2.3 — Protecting Physical Spaces
Day 5 · Tuesday, January 19, 2027
Topic 2.4 — Detecting Physical Attacks
Essential Question: How can organizations detect physical security breaches before significant damage occurs?
Vocabulary
CCTV
Motion Sensor
Security Guard
Alarm System
Access Log
Detection Control
Monitoring
CASE 2027-5A
Design the Plan
Design the Monitoring Plan
Task: Place Detection Controls on the Floor Plan
Click a zone on the floor plan below, then choose a detection control for it in the table. Assigned zones will highlight so you can see your full monitoring plan at a glance.
Evidence: Building Floor Plan
Assign Detection Controls
Zone
Assigned Control
Front Lobby
Server Room
Executive Office
Loading Dock
Parking Lot
Clicking a zone on the floor plan jumps to and focuses its dropdown below.
CASE 2027-5B
Flag: Review
The 2 A.M. Badge Swipe
Incident Type: Detection Control Failure
An access log shows a badge used at the server room door at 2:14 AM by an employee who, according to the shift schedule, wasn't on shift that night. No alarm was triggered, because the motion sensor covering that hallway had been switched to "maintenance mode" two days earlier for a false-alarm issue — and no one ever turned it back on.
Evidence: Access Log
Time
Event
Detail
Review
2 days prior, 4:10 PM
Motion sensor set to maintenance mode
Server room corridor sensor, reason logged: "false alarms"
2:14 AM
Badge swipe — server room door
Employee not listed on tonight's shift schedule
2:14 AM
No alarm triggered
Motion sensor still in maintenance mode
Click "Unreviewed" on each row to cycle through Suspicious → Confirmed Malicious → Cleared.
DAY 5 EXIT TICKET
Reflection
Day 5 Exit Ticket
Topic 2.4 — Detecting Physical Attacks
CAPSTONE
Synthesis
Week 2 Synthesis: Building a Layered Defense Plan
Task: Bring Every Layer Together for Riverbend Bakery & Café
You've spent the week analyzing AI-generated alerts, assessing risk, investigating physical breaches, and choosing controls. Now assign a control type to each remaining gap at Riverbend Bakery, then answer the synthesis questions below.