Securing Physical Spaces
What this unit covers
The topics below follow the published Cybersecurity course framework for Unit 2. Cybersecurity publishes no per-unit weighting, so there is no percentage to chase here.
Lessons in this unit
- Securing Physical Spaces16 min · 3 objectivesIdentify physical vulnerabilities in a work space · Classify preventive, detective, and corrective controls · Explain how physical access can bypass digital security
- Layered Physical Controls18 min · 3 objectivesExplain defense in depth for facilities and equipment · Apply the idea to evidence from a realistic technology scenario · Justify a decision using security, reliability, cost, and user impact
- Asset Handling and Resilient Operations18 min · 3 objectivesExplain asset inventories, media handling, and continuity · Apply the idea to evidence from a realistic technology scenario · Justify a decision using security, reliability, cost, and user impact
Every term in Unit 2
All 36 terms we publish for Securing Physical Spaces, with definitions. Reading them through is the fastest way to find the ones you cannot define — then drill those in cram mode until you can produce them without the prompt.
- Why physical security is security
- An attacker with physical access can bypass most software controls — boot from external media, install a keylogger, or simply carry the machine out. Every logical control assumes the hardware is not in enemy hands.
- Physical access control
- Restricting who can enter a space: locks, badges, guards, biometrics. The first layer of defense in depth.
- Access control vestibule (mantrap)
- Two interlocking doors where only one opens at a time, so a person must be authorized alone. The direct countermeasure to tailgating.
- Badge and proximity card
- A credential carried and presented at a reader. Something-you-have, so it is cloneable and losable — which is why sensitive areas add a second factor.
- Security guard
- The control that can exercise judgment. Effective against social engineering in a way no reader is, and expensive, so it is reserved for high-value entry points.
- Visitor management
- Signing visitors in, issuing distinguishable badges and escorting them. Makes an unaccompanied stranger visibly wrong rather than merely unusual.
- Video surveillance (CCTV)
- Primarily detective and deterrent rather than preventive — it records what happened, it does not stop it. Retention period and camera coverage are the examinable design choices.
- Motion and door sensors
- Detect entry outside expected hours. Detective controls that feed an alarm or a log.
- Bollards and barriers
- Physical obstacles preventing vehicle approach to a building. A deterrent and preventive control against ramming and vehicle-borne attack.
- Fencing and lighting
- Delay and deter. Lighting also multiplies the value of surveillance, since a camera sees nothing in the dark.
- Signage
- Marking restricted areas. Legally useful and a deterrent — an intruder cannot claim they did not know.
- Deterrent, preventive, detective, corrective
- Four control types: discourage the attempt, stop it, notice it, and recover afterward. Most questions are asking you to place a given control in one of these.
- Compensating control
- An alternative measure used when the primary control is impractical. Not an excuse — it must reduce the same risk to a comparable level.
- Secure server room requirements
- Restricted access, no exterior windows, environmental monitoring, and separate power and cooling. Its contents are worth more than the room.
- Environmental controls (HVAC)
- Temperature and humidity management. Heat shortens hardware life and causes outages, so HVAC is an availability control, not a comfort feature.
- Fire suppression for equipment
- Clean-agent or gas systems rather than water, because sprinklers destroy the equipment they save the building from. Detection matters as much as suppression.
- Uninterruptible power supply (UPS)
- Battery power bridging a short outage and allowing a clean shutdown. An availability control against power loss.
- Generator
- Sustained backup power for long outages, unlike a UPS which buys minutes. Systems that must not stop have both.
- Faraday cage
- A shielded enclosure blocking electromagnetic signals in and out. Prevents wireless exfiltration and eavesdropping on emissions.
- Air gap
- Physically isolating a system from any network. The strongest network control there is, and defeated by removable media — which is exactly how baiting works.
- Cable lock
- Physically tethers a laptop to a fixed object. A low-cost deterrent against opportunistic theft, not against a determined attacker.
- Safe and secure cabinet
- Protects backup media, documentation and spare credentials. Physical confidentiality for things that are not on a network.
- Asset tracking and inventory
- Knowing what hardware exists and where it is. You cannot notice a missing device you never recorded owning.
- Clean desk policy
- Sensitive material is not left visible when unattended. Counters shoulder surfing and casual insider access.
- Screen locking
- Automatic lock after inactivity, plus locking on leaving. The most common physical exposure in an office, and the cheapest to fix.
- Media sanitization
- Removing data before disposal or reuse. Deleting a file does not remove it — overwriting, degaussing or physical destruction does.
- Degaussing
- Using a strong magnetic field to destroy data on magnetic media. Does nothing to solid-state drives, which is the trap in the question.
- Physical destruction of media
- Shredding, crushing or incinerating drives. The only method that is certainly effective on failed devices that cannot be overwritten.
- Chain of custody
- A documented record of who held evidence and when. Breaking it can make otherwise valid evidence useless.
- Breach detection in physical space
- Alarms, access log review, video review and periodic inventory. The examinable point is that a physical breach leaves records only if someone chose to create them.
- Access log review
- Comparing badge records against expected activity. Finds after-hours entries, shared credentials and doors held open — none of which the reader itself flags.
- Tamper-evident seal
- A seal that visibly breaks on opening, so interference is detectable even when it cannot be prevented.
- Two-person control
- Requiring two authorized people to be present for a sensitive action. The physical analogue of separation of duties.
- Site redundancy
- Hot, warm and cold sites offer decreasing readiness at decreasing cost. A hot site can take over almost immediately; a cold site is a building with power.
- Disaster recovery vs business continuity
- Disaster recovery restores IT systems; business continuity keeps the organization operating throughout. The second is broader and includes the first.
- RTO and RPO
- Recovery Time Objective is how long you can be down; Recovery Point Objective is how much data you can afford to lose. RPO drives backup frequency; RTO drives recovery design.
What examiners penalize here
- For a scenario about **defense in depth for facilities and equipment**, identify the decisive evidence before naming a response. A defensible conclusion here is: Add anti-tailgating and monitoring layers, then assign responsibility for reviewing alerts and logs.
- For a scenario about **asset inventories, media handling, and continuity**, identify the decisive evidence before naming a response. A defensible conclusion here is: Deletion alone is insufficient; sanitize the media and document chain of custody before release.
Practice Cybersecurity
Our practice bank is drawn from across the whole course rather than filtered to one unit, which is closer to how the exam asks anyway — it will not tell you which unit a question is testing.
Questions about this unit
How much of the AP Cybersecurity exam is Unit 2?
The Cybersecurity course framework does not publish a per-unit weighting, so there is no percentage to quote for Unit 2 and anyone who gives you one is guessing. Spread your time by where your own errors are instead.
What topics are covered in Cybersecurity Unit 2?
Securing Physical Spaces covers Physical vulnerabilities, Physical attacks, Protective controls and Breach detection. We publish 36 terms with definitions for this unit, all of them on this page.
How should I study Cybersecurity Unit 2?
Read the 3 lessons below first — about 50 minutes — then drill the 36 terms in cram mode until you can produce each definition from memory rather than just recognize it. Recognition is what makes a unit feel finished when it is not. Finish with practice questions and read the explanation for every one you get right by elimination as well as the ones you miss.
All 5 units of AP Cybersecurity
Unit names, topics and exam weights follow the published College Board course framework for AP Cybersecurity. AP® is a trademark registered by the College Board, which does not endorse this site.