Please enable JavaScript to use CodeHS

AP Cybersecurity

Securing Devices

Students learn how devices like computers, phones, and IoT devices store and process data, and how adversaries target them. They explore device vulnerabilities and types of malware, then study how authentication verifies user identity and how adversaries attempt to impersonate legitimate users. Students learn why hashing is used to store passwords and how to configure secure login settings. They also examine how anti-malware software, software updates, and host-based firewalls protect devices, and how to analyze log files for indicators of compromise.

Lessons

4.1 Everything is a Computer (Device Vulnerabilities and Attacks)

  • What Counts as a Computer?
  • IoT in the Wild
  • Reflection: IoT in the Wild
  • Connectivity Consequences
  • Computing Device Types

4.2 The Adversary's Toolkit (Device Vulnerabilities and Attacks)

  • The Malware Lineup
  • Which Malware Is It?
  • Know Your Malware
  • Malware That Hides
  • Name That Malware
  • +2 more

4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)

  • How Adversaries Get In
  • Vulnerability Scanner Explorer
  • Spot the Vulnerability
  • Open Doors
  • Port Scanner Explorer
  • +3 more

4.4 What's Worth Protecting? (Device Vulnerabilities and Attacks)

  • How Risky Is It?
  • Rate the Risk
  • Security Risk Report
  • Risk Assessment

4.5 Cracking the Hash (Authentication)

  • Guess the Hash
  • Guess the Hash Reflection
  • Hash Functions
  • Hash Algorithms in Action
  • Salting Your Hash
  • +5 more

4.6 Passwords Under Attack (Authentication)

  • You're the Attacker
  • The Offline Toolkit
  • Password Attacks
  • Now Defend It
  • Shattered Tables

4.7 Can You Prove It's You? (Authentication)

  • Morgan's Morning
  • Authentication Factors
  • Thinking Like an Attacker
  • Multifactor Authentication
  • Design an Authentication System
  • +3 more

4.8 Capstone: The Riverside High Security Breach (Authentication)

  • The Riverside High Security Breach
  • Part 1: The Stolen Database
  • Part 2: How They Got In
  • Part 3: Prove You’re You
  • Part 4: Locking It Down

4.9 Writing the Rules Devices Follow (Protecting Devices)

  • Introduction to Device Security Controls
  • Acceptable Use Policy
  • AUP Reflection
  • Password and Software Policies
  • Device Security Controls
  • +3 more

4.10 Defend the Device (Protecting Devices)

  • How Anti-Malware Works
  • Why Device Updates Matter
  • Anti-Malware and Patching
  • The Outdated Workstation
  • Lock County Lockdown

4.11 Host Firewalls (Protecting Devices)

  • Firewalls Within Firewalls
  • Host Firewall Decision-Making
  • Host-Based Firewalls
  • Scenario - Hardening a Developer's Laptop
  • Workstation Firewall Simulation
  • +1 more

4.12 Capstone: Device Defense-In-Depth (Protecting Devices)

  • Bringing the Controls Together
  • Securing Devices Cumulative Check
  • Device Security Audit
  • Incident Zero

4.13 Inside the Security Logs (Detecting Attacks on Devices)

  • What Do Logs Actually Capture?
  • Explore a Log
  • Host, File, and Behavior
  • Classify What You See
  • Reading Authentication Logs
  • +3 more

4.14 Smart Detection Choices (Detecting Attacks on Devices)

  • Choosing a Detection Method
  • Which Detection Approach Fits?
  • Detection Method Costs
  • Detection Method Tradeoffs
  • When Detection Gaps Have Consequences
  • +2 more

4.15 Detecting Password Attacks in the Wild (Detecting Attacks on Devices)

  • How Password Attacks Show Up in Logs
  • Guided Auth Log Analysis
  • The Suspicious Account
  • Identifying Password Attack Types
  • Credential Stuffing at Scale
  • +2 more

4.16 Capstone: Detection Across the Stack (Detecting Attacks on Devices)

  • Design a Detection Strategy
  • Detecting Attacks Against Devices
  • When Detection Succeeds: What Happens Next

4.17 Securing Devices Quiz

  • Securing Devices Quiz

Courses that include this module