>_ The Cyber Casebook // AP CYBER · AP NETWORKING · AI
Home / All case studies / The Permission Puzzle

Key terms

AI agentPermissionOpt-inLeast privilege

AP Cybersecurity alignment

  • 1.4.B.3Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI- powered tools feed user input back into the model to provide continuous training. Adversaries could…Learning objective: Explain how to protect against some AI-augmented cyberattacks.
  • 5.2.C.1Access control enforces which users or applications (called subjects) can access, modify, add, or remove (called operations) which files or applications (called objects). Access control models describe how to determine which…Learning objective: Determine an appropriate access control model to protect applications and data.
  • 5.2.C.7The principle of least privilege is the idea that entities should be given exactly as much access as they need to perform their function and no more.Learning objective: Determine an appropriate access control model to protect applications and data.

AP Networking alignment

  • 1.4.B.6To protect devices and accounts from unauthorized access, users should configure strong security settings. Users should: • enable MFA • enable screen lock with a strong PIN, password, or biometric authentication • disable…Learning objective: Implement device- and account-level security practices to prevent phishing, credential compromise, and data loss.
  • 4.1.A.3When confidentiality is compromised, systems are vulnerable to having sensitive data exposed or stolen. A breach of confidentiality can be identified by: • unauthorized access • network traffic showing exfiltration of…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.
  • 4.5.B.4Security controls to limit the impact of unauthorized access include: • enforcing strong password policies and account lockout settings • applying the principle of least privilege • implementing segmentation to restrict access…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a managed network.

Related case studies