>_ The Cyber Casebook // AP CYBER · AP NETWORKING · AI
Home / All case studies / One Missed Patch

Key terms

PatchThird partyWAFData breach

AP Cybersecurity alignment

  • 2.1.G.3A defense-in-depth strategy allows for resilience in data protection so when one security control is bypassed by an adversary, another security control may still prevent access to the data or system or limit the damage done to…Learning objective: Explain why a defense-in- depth security strategy is necessary to optimally protect an organization.
  • 4.3.C.2Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.Learning objective: Explain why keeping a device’s operating system and software updated makes it more secure.
  • 5.1.C.2High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.Learning objective: Assess and document risks from application and data vulnerabilities.

AP Networking alignment

  • 4.1.A.3When confidentiality is compromised, systems are vulnerable to having sensitive data exposed or stolen. A breach of confidentiality can be identified by: • unauthorized access • network traffic showing exfiltration of…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.
  • 4.5.B.1Organizations apply a combination of security controls to reduce the impact of different types of vulnerabilities. To determine appropriate security controls, administrators evaluate the likelihood and impact of specific…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a managed network.
  • 4.6.B.4Applying and documenting software updates and patches reduces the risk of failure and reduces recovery time if an outage occurs.Learning objective: Identify ways to improve the reliability and availability of networked systems.

Related case studies