All 5 Cybersecurity units
🔐
AP Cybersecurity · Unit 2 of 5

Securing Physical Spaces

3 lessons · 52 min36 terms

What this unit covers

The topics below follow the published Cybersecurity course framework for Unit 2. Cybersecurity publishes no per-unit weighting, so there is no percentage to chase here.

Physical vulnerabilitiesPhysical attacksProtective controlsBreach detection

Lessons in this unit

Every term in Unit 2

All 36 terms we publish for Securing Physical Spaces, with definitions. Reading them through is the fastest way to find the ones you cannot define — then drill those in cram mode until you can produce them without the prompt.

Why physical security is security
An attacker with physical access can bypass most software controls — boot from external media, install a keylogger, or simply carry the machine out. Every logical control assumes the hardware is not in enemy hands.
Physical access control
Restricting who can enter a space: locks, badges, guards, biometrics. The first layer of defense in depth.
Access control vestibule (mantrap)
Two interlocking doors where only one opens at a time, so a person must be authorized alone. The direct countermeasure to tailgating.
Badge and proximity card
A credential carried and presented at a reader. Something-you-have, so it is cloneable and losable — which is why sensitive areas add a second factor.
Security guard
The control that can exercise judgment. Effective against social engineering in a way no reader is, and expensive, so it is reserved for high-value entry points.
Visitor management
Signing visitors in, issuing distinguishable badges and escorting them. Makes an unaccompanied stranger visibly wrong rather than merely unusual.
Video surveillance (CCTV)
Primarily detective and deterrent rather than preventive — it records what happened, it does not stop it. Retention period and camera coverage are the examinable design choices.
Motion and door sensors
Detect entry outside expected hours. Detective controls that feed an alarm or a log.
Bollards and barriers
Physical obstacles preventing vehicle approach to a building. A deterrent and preventive control against ramming and vehicle-borne attack.
Fencing and lighting
Delay and deter. Lighting also multiplies the value of surveillance, since a camera sees nothing in the dark.
Signage
Marking restricted areas. Legally useful and a deterrent — an intruder cannot claim they did not know.
Deterrent, preventive, detective, corrective
Four control types: discourage the attempt, stop it, notice it, and recover afterward. Most questions are asking you to place a given control in one of these.
Compensating control
An alternative measure used when the primary control is impractical. Not an excuse — it must reduce the same risk to a comparable level.
Secure server room requirements
Restricted access, no exterior windows, environmental monitoring, and separate power and cooling. Its contents are worth more than the room.
Environmental controls (HVAC)
Temperature and humidity management. Heat shortens hardware life and causes outages, so HVAC is an availability control, not a comfort feature.
Fire suppression for equipment
Clean-agent or gas systems rather than water, because sprinklers destroy the equipment they save the building from. Detection matters as much as suppression.
Uninterruptible power supply (UPS)
Battery power bridging a short outage and allowing a clean shutdown. An availability control against power loss.
Generator
Sustained backup power for long outages, unlike a UPS which buys minutes. Systems that must not stop have both.
Faraday cage
A shielded enclosure blocking electromagnetic signals in and out. Prevents wireless exfiltration and eavesdropping on emissions.
Air gap
Physically isolating a system from any network. The strongest network control there is, and defeated by removable media — which is exactly how baiting works.
Cable lock
Physically tethers a laptop to a fixed object. A low-cost deterrent against opportunistic theft, not against a determined attacker.
Safe and secure cabinet
Protects backup media, documentation and spare credentials. Physical confidentiality for things that are not on a network.
Asset tracking and inventory
Knowing what hardware exists and where it is. You cannot notice a missing device you never recorded owning.
Clean desk policy
Sensitive material is not left visible when unattended. Counters shoulder surfing and casual insider access.
Screen locking
Automatic lock after inactivity, plus locking on leaving. The most common physical exposure in an office, and the cheapest to fix.
Media sanitization
Removing data before disposal or reuse. Deleting a file does not remove it — overwriting, degaussing or physical destruction does.
Degaussing
Using a strong magnetic field to destroy data on magnetic media. Does nothing to solid-state drives, which is the trap in the question.
Physical destruction of media
Shredding, crushing or incinerating drives. The only method that is certainly effective on failed devices that cannot be overwritten.
Chain of custody
A documented record of who held evidence and when. Breaking it can make otherwise valid evidence useless.
Breach detection in physical space
Alarms, access log review, video review and periodic inventory. The examinable point is that a physical breach leaves records only if someone chose to create them.
Access log review
Comparing badge records against expected activity. Finds after-hours entries, shared credentials and doors held open — none of which the reader itself flags.
Tamper-evident seal
A seal that visibly breaks on opening, so interference is detectable even when it cannot be prevented.
Two-person control
Requiring two authorized people to be present for a sensitive action. The physical analogue of separation of duties.
Site redundancy
Hot, warm and cold sites offer decreasing readiness at decreasing cost. A hot site can take over almost immediately; a cold site is a building with power.
Disaster recovery vs business continuity
Disaster recovery restores IT systems; business continuity keeps the organization operating throughout. The second is broader and includes the first.
RTO and RPO
Recovery Time Objective is how long you can be down; Recovery Point Objective is how much data you can afford to lose. RPO drives backup frequency; RTO drives recovery design.

What examiners penalize here

Practice Cybersecurity

Our practice bank is drawn from across the whole course rather than filtered to one unit, which is closer to how the exam asks anyway — it will not tell you which unit a question is testing.

Questions about this unit

How much of the AP Cybersecurity exam is Unit 2?

The Cybersecurity course framework does not publish a per-unit weighting, so there is no percentage to quote for Unit 2 and anyone who gives you one is guessing. Spread your time by where your own errors are instead.

What topics are covered in Cybersecurity Unit 2?

Securing Physical Spaces covers Physical vulnerabilities, Physical attacks, Protective controls and Breach detection. We publish 36 terms with definitions for this unit, all of them on this page.

How should I study Cybersecurity Unit 2?

Read the 3 lessons below first — about 50 minutes — then drill the 36 terms in cram mode until you can produce each definition from memory rather than just recognize it. Recognition is what makes a unit feel finished when it is not. Finish with practice questions and read the explanation for every one you get right by elimination as well as the ones you miss.

All 5 units of AP Cybersecurity

  1. Unit 1 · Introduction to Security
  2. Unit 2 · Securing Physical Spaces
  3. Unit 3 · Securing Networks
  4. Unit 4 · Securing Devices
  5. Unit 5 · Securing Applications and Data

Unit names, topics and exam weights follow the published College Board course framework for AP Cybersecurity. AP® is a trademark registered by the College Board, which does not endorse this site.