The Door Is Part of the Network
The strongest firewall in the world can't stop someone who walks through an unlocked door. Physical security is the first practical layer — because a person standing at the server rack has already bypassed most of your software.
An adversary standing inside your server room doesn't need to defeat your encryption — they can unplug the drive, photograph a screen, or connect a device to an open port. This lesson teaches you to read a building for physical vulnerabilities, name the physical attack in play, and connect a specific weakness to a specific asset and impact so you can rate and document the risk.
Read the Building
Walk a floorplan and spot which spaces expose sensitive assets to physical attack.
Name the Attack
Tell piggybacking, tailgating, shoulder surfing, dumpster diving, and card cloning apart.
Document the Risk
Connect asset, vulnerability, threat, likelihood, and impact into a clean risk note.
Learning objectives
- Identify common physical attacks.
- Explain how threats exploit physical vulnerabilities to cause loss, damage, disruption, or destruction.
- Assess and document risks from physical vulnerabilities.
An adversary standing inside your server room doesn't need to defeat your encryption — they can unplug the drive, photograph a screen, or connect a device to an open port. That's why physical security is the first practical layer: physical access can quietly bypass many technical controls. Physical attacks usually pair with social engineering — holding a door, following a badge, looking helpful.
If they can touch it, they may not need to hack it.
Physical Attacks, Briefly
The common attacks, why physical access is so powerful, and how to rate the risk it creates.
The common attacks
Piggybacking manipulates an authorized person into granting access (carrying boxes so someone holds the door, claiming a forgotten badge, posing as maintenance). Tailgating is slipping in closely behind someone without their awareness. Shoulder surfing watches a user enter sensitive information for later use. Dumpster diving searches physical trash for useful information. Card cloning copies an authorized user's access card. Threats can also be natural disasters that damage devices or disrupt services.
Why physical access is so powerful
With physical access, an adversary may steal or copy sensitive data, disrupt services, modify data, or destroy resources. Open device ports let them connect unauthorized devices or media; power disruption makes systems unavailable; direct access can mean outright destruction — all potentially bypassing software controls.
Rating the risk
High risk: sensitive or critical assets exposed without sufficiently restricted, controlled access. Moderate risk: a noncritical area left open in a way that could become a foothold to reach other resources. Low risk: a low-value asset where exploitation is unlikely. Good documentation connects asset, vulnerability, threat, likelihood, impact, and the resulting risk rating.
Piggybacking vs. tailgating hinges on awareness: piggybacking manipulates a person into helping; tailgating sneaks in unnoticed.
The attack name is not the risk. "The risk is tailgating" loses points — the risk is the possible compromise of an asset that the tailgating enables.
High risk needs both a sensitive/critical asset and realistic exposure. A weak lock on an empty closet isn't high risk.
"Best documents the risk" wants the full chain — place, asset, vulnerability, likely attack, likelihood, and impact — not a single observation.
1 · Physical Attack Path
2 · Physical Risk Matrix
3 · Physical Access Bypasses Technical Controls
Threat-to-Impact Chain Builder
LAB · CHAINPick a starting threat. The chain assembles: threat → vulnerability → asset → compromise → impact.
The Language of Physical Risk
Name the attack precisely, and keep vulnerability, threat, and risk distinct.
Physical vulnerability
A tangible weakness (unlocked door, open port, unmonitored hallway) an attacker could exploit.
Piggybacking
Manipulating an authorized person into granting access — e.g., getting them to hold a door.
Tailgating
Slipping in closely behind someone without their awareness — stealth, not manipulation.
Shoulder surfing
Watching a user enter sensitive information (a PIN, a password) to reuse it later.
Dumpster diving
Searching physical trash for useful information, such as printed agendas or access lists.
Card cloning
Copying an authorized user's access card to reach whatever that user can access.
Natural disaster
A non-human environmental threat (flood, fire) that damages devices or disrupts services.
Device ports
Open physical ports that let an adversary connect unauthorized devices or media.
Unauthorized access
Reaching a restricted space or device without permission — often the threat in a physical risk.
Likelihood & impact
How probable exploitation is, and how severe the consequence — the two axes of a risk rating.
Risk rating (High / Mod / Low)
High = sensitive asset + realistic exposure; moderate = a foothold; low = low value or unlikely.
Risk documentation
A concise note connecting asset, vulnerability, threat, likelihood, impact, and the rating.
What AP Wants You to Document
This topic maps to AP Skill 1 (Analyze Risk), across MCQ and the Device Security Analysis FRQ.
"Best documents the risk" wants the full chain — place, asset, vulnerability, likely attack, likelihood, and impact — not a single observation. Don't confuse the attack name with the risk: the risk is the possible compromise of an asset that the attack enables. Use the builder below to assemble an AP-quality risk note before you face the FRQ.
Risk Documentation Builder
LAB · DOCUMENTBuild an analyst risk note from the server-room finding. Pick each field; the note assembles live.
Analyst Risk Note
Device Security Analysis Connection
Expect physical assessment notes and a prompt to reason defensively: name a vulnerability and likely attack, the asset at risk, the impact, a risk rating, and one concise documentation statement.
• Server room door has no automatic lock
• Hallway outside server room is not monitored by cameras
• Delivery staff pass this hallway daily
• Server stores prototype research files
• Visitor badges collected at reception, but delivery workers not always escorted
• Reception computer has exposed USB ports
• Trash bin contains printed meeting agendas with project names
Using the notes: (1) identify one physical vulnerability, (2) identify one likely physical attack, (3) identify the asset at risk, (4) explain possible impact, (5) assign a risk rating, and (6) write one concise risk documentation statement.
Reveal model reasoning
(2) Likely attack: unauthorized physical access, plausibly enabled by piggybacking/pretexting as delivery staff (or simply walking through an unlocked door).
(3) Asset: the prototype research files on the server.
(4) Impact: theft, copying, modification, or destruction of valuable research data — primarily a confidentiality loss (with integrity/availability also at risk).
(5) Risk rating: High — a sensitive asset with realistic, recurring exposure (moderate-high likelihood × high impact).
(6) Documentation statement: "An unlocked, unmonitored server room (vulnerability) could allow an unauthorized person (threat) to physically access the prototype research files (asset); given daily unescorted hallway traffic (moderate-high likelihood) and the data's value (high impact), this is a high physical risk."
Audit the Building, Document the Risk
Walk the Xtensr floorplan zone by zone, then watch a complete risk statement assemble on an AP-style prompt.
Securing Xtensr Research Labs · Physical Assessment. Xtensr is acquiring a smaller research facility. You're a junior member of the physical security assessment team. Review the building, identify physical vulnerabilities, and document the risks before any controls are recommended.
Physical Vulnerability Floorplan Inspector
LAB · AUDIT MAPClick each zone on the Xtensr floorplan. The audit panel shows the vulnerability, possible attack, affected asset, likely impact, and risk level.
Zones inspected: 0 / 10
Question: Which statement best documents the physical risk?
✗ Common wrong (incomplete) answer
"The risk is that delivery workers are nearby." — That identifies a possible threat context, not the full risk. A complete risk statement must connect asset + vulnerability + threat + likelihood + impact.
Where Points Get Lost
Most missed marks come from naming the attack instead of the risk, or rating on feeling.
✗ "The attack name is the risk"
The risk is the possible compromise of an asset a threat causes by exploiting a vulnerability — not just "tailgating."
✗ Piggybacking = tailgating
It hinges on awareness: piggybacking manipulates a person into helping; tailgating sneaks in unnoticed.
✗ "Any weak lock = high risk"
High risk needs both a sensitive/critical asset and realistic exposure. An empty closet's weak latch isn't high.
✗ Spotting a stranger = attack
A person in a public lobby is a possible risk, not a confirmed attack. Separate observation from compromise.
Classify Attacks, Rate the Risk, Sort the Tiers
An attack classifier, a likelihood×impact matrix, and a risk-tier sorter, then the analyst reference grid.
Physical Attack Classifier
LAB · CLASSIFYName the physical attack in each fictional micro-scenario — or flag when there isn't enough evidence.
Risk Rating Matrix
LAB · RATESet likelihood and impact for a physical-vulnerability scenario. The matrix returns low, moderate, or high.
High / Moderate / Low Risk Sorter
LAB · SORTSort each finding into a risk tier. Drag a card into a bucket, or tap a card then a bucket.
High
Moderate
Low
Document, don't just alarm
- Avoid "this is dangerous" — record evidence
- Connect the weakness to a specific asset and impact
Risk vs. confirmed compromise
- A vulnerability is possible risk, not proof of an attack
- Ask whether the asset is sensitive or critical
Rate, then recommend
- Assess both likelihood and severity
- Recommend later controls based on the documented risk
Prove It, Then Lock It In
Six checks across attack ID, the piggybacking/tailgating split, why physical matters, documentation, CIA impact, and risk level — then the exam-day essentials.
Five takeaways
Physical security is the first practical layer — physical access can bypass many technical controls.
Key attacks: piggybacking (manipulated help), tailgating (unnoticed follow), shoulder surfing, dumpster diving, card cloning — plus natural disasters.
Physical compromise can mean unauthorized access, service disruption, theft/destruction, or unauthorized data modification.
High risk = sensitive/critical asset + realistic exposure; moderate = a foothold to other resources; low = low-value & unlikely.
Documentation connects asset, vulnerability, threat, likelihood, impact, and risk rating.
✓ AP Exam Tip
For physical risk questions, connect the place, asset, vulnerability, likely attack, and impact — never stop at one observation.
✗ Common Mistake
Don't confuse the attack name with the risk. The risk is the possible compromise of an asset caused by a threat exploiting a vulnerability.
Practice — attempt these now.
AP-style assessments aligned to this lesson. Time them.