01
Overview

The Door Is Part of the Network

The strongest firewall in the world can't stop someone who walks through an unlocked door. Physical security is the first practical layer — because a person standing at the server rack has already bypassed most of your software.

An adversary standing inside your server room doesn't need to defeat your encryption — they can unplug the drive, photograph a screen, or connect a device to an open port. This lesson teaches you to read a building for physical vulnerabilities, name the physical attack in play, and connect a specific weakness to a specific asset and impact so you can rate and document the risk.

Read the Building

Walk a floorplan and spot which spaces expose sensitive assets to physical attack.

Name the Attack

Tell piggybacking, tailgating, shoulder surfing, dumpster diving, and card cloning apart.

Document the Risk

Connect asset, vulnerability, threat, likelihood, and impact into a clean risk note.

Learning objectives

  • Identify common physical attacks.
  • Explain how threats exploit physical vulnerabilities to cause loss, damage, disruption, or destruction.
  • Assess and document risks from physical vulnerabilities.

An adversary standing inside your server room doesn't need to defeat your encryption — they can unplug the drive, photograph a screen, or connect a device to an open port. That's why physical security is the first practical layer: physical access can quietly bypass many technical controls. Physical attacks usually pair with social engineering — holding a door, following a badge, looking helpful.

If they can touch it, they may not need to hack it.

02
Core Concept

Physical Attacks, Briefly

The common attacks, why physical access is so powerful, and how to rate the risk it creates.

The common attacks

Piggybacking manipulates an authorized person into granting access (carrying boxes so someone holds the door, claiming a forgotten badge, posing as maintenance). Tailgating is slipping in closely behind someone without their awareness. Shoulder surfing watches a user enter sensitive information for later use. Dumpster diving searches physical trash for useful information. Card cloning copies an authorized user's access card. Threats can also be natural disasters that damage devices or disrupt services.

Why physical access is so powerful

With physical access, an adversary may steal or copy sensitive data, disrupt services, modify data, or destroy resources. Open device ports let them connect unauthorized devices or media; power disruption makes systems unavailable; direct access can mean outright destruction — all potentially bypassing software controls.

Rating the risk

High risk: sensitive or critical assets exposed without sufficiently restricted, controlled access. Moderate risk: a noncritical area left open in a way that could become a foothold to reach other resources. Low risk: a low-value asset where exploitation is unlikely. Good documentation connects asset, vulnerability, threat, likelihood, impact, and the resulting risk rating.

🔍 Cyber Lens

Piggybacking vs. tailgating hinges on awareness: piggybacking manipulates a person into helping; tailgating sneaks in unnoticed.

⚠ AP Trap

The attack name is not the risk. "The risk is tailgating" loses points — the risk is the possible compromise of an asset that the tailgating enables.

🧠 Real Analyst Thinking

High risk needs both a sensitive/critical asset and realistic exposure. A weak lock on an empty closet isn't high risk.

📡 Exam Signal

"Best documents the risk" wants the full chain — place, asset, vulnerability, likely attack, likelihood, and impact — not a single observation.

1 · Physical Attack Path

Adversary Physicalvulnerability Restricted space/ device Assetexposure Possible impact Documented risk

2 · Physical Risk Matrix

Likelihood → Impact → High Mod Low Low Mod High Moderate High High Low Moderate High Low Low Moderate Read it as a sentence: High impact + real likelihood → High risk. Low value or unlikely → Low risk.

3 · Physical Access Bypasses Technical Controls

Physical access device ports · room access documents · power tangible weak points Possible bypass ofsoftware controls Confidentiality · Integrity · Availability one or more CIA principles impacted

Threat-to-Impact Chain Builder

LAB · CHAIN

Pick a starting threat. The chain assembles: threat → vulnerability → asset → compromise → impact.

Choose a scenario
Threat
Vulnerability
Asset
Compromise
Impact
03
Key Vocabulary

The Language of Physical Risk

Name the attack precisely, and keep vulnerability, threat, and risk distinct.

Physical vulnerability

A tangible weakness (unlocked door, open port, unmonitored hallway) an attacker could exploit.

Piggybacking

Manipulating an authorized person into granting access — e.g., getting them to hold a door.

Tailgating

Slipping in closely behind someone without their awareness — stealth, not manipulation.

Shoulder surfing

Watching a user enter sensitive information (a PIN, a password) to reuse it later.

Dumpster diving

Searching physical trash for useful information, such as printed agendas or access lists.

Card cloning

Copying an authorized user's access card to reach whatever that user can access.

Natural disaster

A non-human environmental threat (flood, fire) that damages devices or disrupts services.

Device ports

Open physical ports that let an adversary connect unauthorized devices or media.

Unauthorized access

Reaching a restricted space or device without permission — often the threat in a physical risk.

Likelihood & impact

How probable exploitation is, and how severe the consequence — the two axes of a risk rating.

Risk rating (High / Mod / Low)

High = sensitive asset + realistic exposure; moderate = a foothold; low = low value or unlikely.

Risk documentation

A concise note connecting asset, vulnerability, threat, likelihood, impact, and the rating.

04
AP Exam Focus

What AP Wants You to Document

This topic maps to AP Skill 1 (Analyze Risk), across MCQ and the Device Security Analysis FRQ.

Piggybacking Tailgating Shoulder surfing Dumpster diving Card cloning Natural disasters Device ports Risk documentation
AP Skill 1 — Analyze Risk. Evaluate likelihood and impact of a physical vulnerability.
MCQ — high frequency. Attack identification and risk rating.
Device Security Analysis FRQ. Physical-assessment notes turned into a risk statement.

"Best documents the risk" wants the full chain — place, asset, vulnerability, likely attack, likelihood, and impact — not a single observation. Don't confuse the attack name with the risk: the risk is the possible compromise of an asset that the attack enables. Use the builder below to assemble an AP-quality risk note before you face the FRQ.

Risk Documentation Builder

LAB · DOCUMENT

Build an analyst risk note from the server-room finding. Pick each field; the note assembles live.

Asset
Vulnerability
Threat
Likelihood & Impact
Risk rating

Analyst Risk Note

Asset
— select —
Vulnerability
— select —
Threat
— select —
Lik/Impact
— select —
Risk
— select —
Choose specific options for every field to produce AP-quality documentation.
FRQ Connection

Device Security Analysis Connection

Expect physical assessment notes and a prompt to reason defensively: name a vulnerability and likely attack, the asset at risk, the impact, a risk rating, and one concise documentation statement.

--- Xtensr Physical Assessment Notes (fictional) ---
• Server room door has no automatic lock
• Hallway outside server room is not monitored by cameras
• Delivery staff pass this hallway daily
• Server stores prototype research files
• Visitor badges collected at reception, but delivery workers not always escorted
• Reception computer has exposed USB ports
• Trash bin contains printed meeting agendas with project names

Using the notes: (1) identify one physical vulnerability, (2) identify one likely physical attack, (3) identify the asset at risk, (4) explain possible impact, (5) assign a risk rating, and (6) write one concise risk documentation statement.

Reveal model reasoning
(1) Vulnerability: the server room door has no automatic lock and the hallway is unmonitored, while unescorted delivery staff pass daily.

(2) Likely attack: unauthorized physical access, plausibly enabled by piggybacking/pretexting as delivery staff (or simply walking through an unlocked door).

(3) Asset: the prototype research files on the server.

(4) Impact: theft, copying, modification, or destruction of valuable research data — primarily a confidentiality loss (with integrity/availability also at risk).

(5) Risk rating: High — a sensitive asset with realistic, recurring exposure (moderate-high likelihood × high impact).

(6) Documentation statement: "An unlocked, unmonitored server room (vulnerability) could allow an unauthorized person (threat) to physically access the prototype research files (asset); given daily unescorted hallway traffic (moderate-high likelihood) and the data's value (high impact), this is a high physical risk."
05
Worked Example

Audit the Building, Document the Risk

Walk the Xtensr floorplan zone by zone, then watch a complete risk statement assemble on an AP-style prompt.

XR

Securing Xtensr Research Labs · Physical Assessment. Xtensr is acquiring a smaller research facility. You're a junior member of the physical security assessment team. Review the building, identify physical vulnerabilities, and document the risks before any controls are recommended.

Physical Vulnerability Floorplan Inspector

LAB · AUDIT MAP

Click each zone on the Xtensr floorplan. The audit panel shows the vulnerability, possible attack, affected asset, likely impact, and risk level.

Zones inspected: 0 / 10

Select a zone on the floorplan to open its audit findings.
// FICTIONAL SCENARIO Xtensr Labs stores prototype research data on a server in a room connected to an unmonitored hallway. The server room door is sometimes left unlocked during deliveries. Delivery workers pass the hallway several times each day. The research data would be valuable to competitors.

Question: Which statement best documents the physical risk?

1
Asset: the prototype research data and the server holding it.
2
Vulnerability: the server room door is sometimes unlocked, off an unmonitored hallway.
3
Threat: an unauthorized person entering or accessing the server.
4
Likelihood: moderate to high — deliveries occur regularly and the hallway is unmonitored.
5
Impact: high — the prototype data is valuable to competitors.
6
Best statement: unauthorized physical access to an unlocked, unmonitored server room could lead to theft, copying, modification, or destruction of valuable research data — moderate-to-high likelihood, high impact → high risk.
✗ Common wrong (incomplete) answer

"The risk is that delivery workers are nearby." — That identifies a possible threat context, not the full risk. A complete risk statement must connect asset + vulnerability + threat + likelihood + impact.

06
Common Mistakes

Where Points Get Lost

Most missed marks come from naming the attack instead of the risk, or rating on feeling.

✗ "The attack name is the risk"

The risk is the possible compromise of an asset a threat causes by exploiting a vulnerability — not just "tailgating."

✗ Piggybacking = tailgating

It hinges on awareness: piggybacking manipulates a person into helping; tailgating sneaks in unnoticed.

✗ "Any weak lock = high risk"

High risk needs both a sensitive/critical asset and realistic exposure. An empty closet's weak latch isn't high.

✗ Spotting a stranger = attack

A person in a public lobby is a possible risk, not a confirmed attack. Separate observation from compromise.

07
Reference & Practice Bank

Classify Attacks, Rate the Risk, Sort the Tiers

An attack classifier, a likelihood×impact matrix, and a risk-tier sorter, then the analyst reference grid.

Physical Attack Classifier

LAB · CLASSIFY

Name the physical attack in each fictional micro-scenario — or flag when there isn't enough evidence.

SCENARIO AA person carrying a large box waits by the badge door until an employee holds it open for them "to be helpful."
Piggybacking. The authorized person is manipulated into granting access (holding the door).
SCENARIO BAn employee badges in; an unnoticed person slips through the closing door right behind them without being seen.
Tailgating. Following closely without the authorized person's awareness — no manipulation, just stealth.
SCENARIO CSomeone stands behind a worker at a kiosk and watches them type their PIN to use later.
Shoulder surfing. Watching a user access sensitive information so it can be reused.
SCENARIO DAn outsider sifts through the recycling bin behind the building, collecting printed memos with project names.
Dumpster diving. Searching physical trash for useful information.
SCENARIO EAn adversary makes a copy of an employee's access card to open the same doors the employee can.
Card cloning. Copying an authorized card to reach whatever that user can access.
SCENARIO FA flood damages on-site servers and knocks out network services for two days.
Natural disaster / environmental threat. A non-human threat causing physical damage and service disruption.
SCENARIO GA camera logs an unfamiliar person standing in the lobby for a few minutes, then leaving. Nothing else is recorded.
Not enough evidence. A person in a public lobby isn't a confirmed attack. Analysts separate possible risk from confirmed compromise.

Risk Rating Matrix

LAB · RATE

Set likelihood and impact for a physical-vulnerability scenario. The matrix returns low, moderate, or high.

Likelihood of exploitation
Impact if exploited
High risk needs both a sensitive/critical asset (high impact) and realistic exposure (meaningful likelihood). A low-value asset, or one unlikely to be reached, won't rate high no matter how it feels.
Imp Low
Imp Mod
Imp High
Lik High
Mod
High
High
Lik Mod
Low
Mod
High
Lik Low
Low
Low
Mod
Set both axes to rate the risk.

High / Moderate / Low Risk Sorter

LAB · SORT

Sort each finding into a risk tier. Drag a card into a bucket, or tap a card then a bucket.

High
Moderate
Low
Unlocked server room with customer data
Receptionist computer with exposed USB ports
Unsecured employee laptops with no sensitive data
Trash bin with a printed access list
Utility room with an unlocked power panel
Visitor area separated from restricted office by badge access

How Cyber Analysts Think

Document, don't just alarm

  • Avoid "this is dangerous" — record evidence
  • Connect the weakness to a specific asset and impact

Risk vs. confirmed compromise

  • A vulnerability is possible risk, not proof of an attack
  • Ask whether the asset is sensitive or critical

Rate, then recommend

  • Assess both likelihood and severity
  • Recommend later controls based on the documented risk
08
Checkpoint & Takeaways

Prove It, Then Lock It In

Six checks across attack ID, the piggybacking/tailgating split, why physical matters, documentation, CIA impact, and risk level — then the exam-day essentials.

QUESTION 1 · SELECT ALL
Which of the following are physical attacks? Select all
Piggybacking
Shoulder surfing
Dumpster diving
Card cloning
QUESTION 2 · PIGGYBACKING vs TAILGATING
What best distinguishes piggybacking from tailgating?
They are identical terms
Piggybacking is sneaking in unnoticed; tailgating is being let in
Piggybacking manipulates an authorized person into granting access; tailgating follows in without their awareness
Only tailgating is a physical attack
QUESTION 3 · WHY PHYSICAL MATTERS
Why can physical access bypass many technical controls?
Technical controls stop being active during the day
An adversary at the device can use ports, steal/destroy hardware, or read screens — actions software controls may not prevent
Firewalls block physical doors
Physical access is never a real risk
QUESTION 4 · RISK DOCUMENTATION
Which is the most complete physical risk statement?
"The server room is unsafe."
"The risk is the unlocked door."
"An unlocked, unmonitored server room (vulnerability) could let an unauthorized person (threat) access prototype data (asset) — moderate-high likelihood, high impact = high risk."
"Deliveries happen daily."
QUESTION 5 · CIA IMPACT
An unlocked utility room lets someone cut power to the lab's network devices. Which CIA principle is most directly impacted?
Confidentiality
Availability
Integrity
None of the above
QUESTION 6 · RISK LEVEL
Which scenario is the clearest high risk?
Unsecured laptops that hold no sensitive data
A visitor area separated from restricted offices by badge access
An unlocked server room holding customer data on an unmonitored hallway
An empty closet with a weak latch

Five takeaways

Physical security is the first practical layer — physical access can bypass many technical controls.

Key attacks: piggybacking (manipulated help), tailgating (unnoticed follow), shoulder surfing, dumpster diving, card cloning — plus natural disasters.

Physical compromise can mean unauthorized access, service disruption, theft/destruction, or unauthorized data modification.

High risk = sensitive/critical asset + realistic exposure; moderate = a foothold to other resources; low = low-value & unlikely.

Documentation connects asset, vulnerability, threat, likelihood, impact, and risk rating.

Physical vulnerabilityPhysical attackPiggybackingTailgatingShoulder surfingDumpster divingCard cloningNatural disasterUnauthorized accessService disruptionTheftDestructionSensitive dataPhysical accessDevice portsLikelihoodImpactHigh riskModerate riskLow riskRisk documentation
✓ AP Exam Tip

For physical risk questions, connect the place, asset, vulnerability, likely attack, and impact — never stop at one observation.

✗ Common Mistake

Don't confuse the attack name with the risk. The risk is the possible compromise of an asset caused by a threat exploiting a vulnerability.

09
Section · 09

Practice — attempt these now.

AP-style assessments aligned to this lesson. Time them.

Topic Quiz 40 min 30 marks Pending

Ap Cyber U2 T2 Sec1 Topic

AP-style topic practice assessment

Start
FRQ Practice 17 min 8 marks Pending

Ap Cyber U2 T2 Sec2 Topic Frq

AP-style topic practice assessment

Start