All posts by mistermarmolejo

CYBER.ORG: AP Cybersecurity – Lesson 11 – Topic 4.6.2 – Multifactor Authentication (MFA) & Case Study – Biometrics

Objective:

  • Students will investigate common methods to manage access.

Standards:

  • CompTIA Security+ SYO-701 Objective:
  • 4.6 – Given a scenario, implement and maintain identity and access management
  • Multifactor authentication
    • Implementations
      • Biometrics
      • Hard/soft authentication tokens
      • Security keys
    • Factors
      • Something you know
      • Something you have
      • Something you are
      • Somewhere you are

Guiding Question:

  • What are some common implementations of multifactor authentication?

Resources:

  • Lesson Slides Lesson 4.6.2 – Multifactor Authenticaion (MFA).pptx and Case Study – Biometrics.pdf available on Google Classroom

Assignment:

  1. Follow along with the Lesson 4.6.2 – Multifactor Authentication (MFA).pptx presentation in today’s class.
  2. Complete the Case Study – Biometrics.pdf Activity using the Case Study 4.6.2 – Biometrics Question Responses document available in the Google Classroom.

Posted: September 29th, 2026
Teacher Pacing Due Date: September 30th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 10 – Topic 3.3.2 – Technical Controls and Attacks 2 & Brute Forcing with Metasploit Lab

Objective:

  • Students will:
    • Define and categorize technical controls and how they relate to other control types.
    • Examine ways to implement technical controls that prevent and deter attacks.
    • Recognize common attacks and how technical controls mitigate them.

Standards:

  • CompTIA Security+ Compatibility Standard(s)
    • 1.1 Compare and contrast various types of security controls.
      • Technical

Guiding Question:

  • What are technical security controls and how do they relate and work in tandem with the other types of security controls to create a strong security posture for an organization?

Resources:

Assignment:

  1. Read the Lesson Slides Cyber2 3.3.2.pptx presentation in today’s class.
  2. Complete the Lab PPT Cyber2 3.3.2.pptx Activity in class. Use the PPT and the Lab Worksheet 3.3.2 – Brute Forcing with Metasploit Google Doc provided in today’s Google Classroom Assignment Post to complete the Brute Forcing with Metasploit Lab, and answer the “Putting it all Together” questions at the bottom of the Worksheet to demonstrate completion of the lab by the end of the day on Friday, September 24th.

Posted: September 23rd, 2026
Teacher Pacing Due Date: September 24th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 9 – Topic 3.3.1 – Technical Controls and Attacks 1

Objective:

  • Students will:
    • Define and categorize technical controls and how they relate to other control types.
    • Examine ways to implement technical controls that prevent and deter attacks.
    • Recognize common attacks and how technical controls mitigate them.

Standards:

  • CompTIA Security+ Compatibility Standard(s)
    • 1.1 Compare and contrast various types of security controls.
      • Technical

Guiding Question:

  • What are technical security controls and how do they relate and work in tandem with the other types of security controls to create a strong security posture for an organization?

Resources:

Assignment:

  1. Follow along with the Lesson Slides Cyber2 3.3.1.pptx presentation in today’s class.

Posted: September 22nd, 2026
Teacher Pacing Due Date: September 23rd, 2026

CYBER.ORG: AP Cybersecurity – Rainbow Table Lab

Objective:

  • Students will analyze potential indicators to determine the type of attack.

Standards:

  • CompTIA Security+ SYO-701 Objective:
  • 2.4 – Given a scenario, analyze indicators of malicious activity
    • Password Attacks
      • Rainbow Table

Guiding Question:

  • What are the different types of password attacks and how can a malicious actor use them?

Resources:

  • Lab Activity Lab – Rainbow Table.pptx presentations available on Google Classroom

Assignment:

  1. Review the Lesson 2.4.14 – Password Attacks.pptx presentation, if needed.
  2. Complete the Lab – Rainbow Table.pptx Activity in class. To demonstrate completion of the lab, upload a screenshot of the Terminal window displaying the results of the Rainbowcrack attack, including all solved hashes from slide 16 of the Lab presentation.

Posted: September 21st, 2026
Teacher Pacing Due Date: September 22nd, 2026

CYBER.ORG: AP Cybersecurity – Brute Force Online Lab

Objective:

  • Students will analyze potential indicators to determine the type of attack.

Standards:

  • CompTIA Security+ SYO-701 Objective:
  • 2.4 – Given a scenario, analyze indicators of malicious activity
    • Password Attacks
      • Spraying
      • Brute force

Guiding Question:

  • What are the different types of password attacks and how can a malicious actor use them?

Resources:

  • Lab Activity Lab – Brute Force Online.pptx presentations available on Google Classroom

Assignment:

  1. Review the Lesson 2.4.14 – Password Attacks.pptx presentation, if needed.
  2. Complete the Lab – Brute Force Online.pptx Activity in class. To demonstrate completion of the lab, upload a screenshot of the Cracked Username/Passwords displayed in the response window of the Fuzzing Brute Force attack executed in the OWASP ZAP application on the DVWA application from slide 21 of the Lab presentation.

Posted: September 18th, 2026
Teacher Pacing Due Date: September 21st, 2026

CYBER.ORG: AP Cybersecurity – Lesson 8 – Topic 2.4.14 – Password Attacks & Brute Force Offline Lab

Objective:

  • Students will analyze potential indicators to determine the type of attack.

Standards:

  • CompTIA Security+ SYO-701 Objective:
  • 2.4 – Given a scenario, analyze indicators of malicious activity
    • Password Attacks
      • Spraying
      • Brute force

Guiding Question:

  • What are the different types of password attacks and how can a malicious actor use them?

Resources:

  • Lesson Slides Lesson 2.4.14 – Password Attacks.pptx and Lab Activity Lab – Brute Force Offline.pptx presentations available on Google Classroom

Assignment:

  1. Follow along with the Lesson 2.4.14 – Password Attacks.pptx presentation in today’s class.
  2. Complete the Lab – Dictionary.pptx Activity in class by tomorrow. To demonstrate completion of the lab, upload a screenshot of the Terminal window showing the results of the John the Ripper Brute Force attack on the “shadow” file from slide 13 of the Lab presentation.

Posted: September 17th, 2026
Teacher Pacing Due Date: September 18th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 7 – Topic 4.6.3 – Passwords & Dictionary Attack Lab

Objective:

  • Students will investigate common password concepts.

Standards:

  • CompTIA Security+ SYO-701 Objective:
  • 4.6 – Given a scenario, implement and maintain identity and access management
    • Password concepts
    • Password best practices
      • Length
      • Complexity
      • Reuse
      • Expiration
      • Age
    • Password managers
    • Passwordless

Guiding Question:

  • What are some common password concepts?

Resources:

  • Lesson Slides Lesson 4.6.3 – Passwords.pptx and Lab Activity Lab – Dictionary.pptx presentations available on Google Classroom

Assignment:

  1. Follow along with the Lesson 4.6.3 – Passwords.pptx presentation in today’s class.
  2. Complete the Lab – Dictionary.pptx Activity in class by tomorrow. To demonstrate completion of the lab, upload a screenshot of the Terminal window showing the results of the John the Ripper dictionary attack on the “shadow” file from slide 13 of the Lab presentation.

Posted: September 15th, 2026
Teacher Pacing Due Date: September 16th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 6 – Topic 6.3.1 – Password Best Practices

Objective:

  • Students will explore the best practices for having safe and secure passwords.

Standards:

  • CompTIA Tech+ FC0-U71 Objective:
    • 6.3 – Explain password best practices.
      • Password length
      • Password complexity
      • Password history
        • Password expiration
      • Password reuse across sites
      • Password managers
      • Password privacy
      • Password reset process
      • Changing default usernames and passwords
      • Enabling passwords

Guiding Question:

  • How can following password best practices keep my accounts safe and secure?

Resources:

  • Lesson Slides Lesson Slides 6.3.1 – Password Best Practices.pptx and Lab Activity Activity 6.3.1 – Password Power.pptx presentations available on Google Classroom

Assignment:

  1. Follow along with the Lesson Slides 6.3.1 – Password Best Practices.pptx presentation in today’s class.
  2. Complete the Activity 6.3.1 – Password Power.pptx Activity in class by tomorrow.

Posted: September 14th, 2026
Teacher Pacing Due Date: September 15th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 5 – Topic 2.2.3 – Phishing and Spam

Objective:

  • Understand the different methods of phishing.

Standards:

  • CompTIA Security+ SYO-701 Objective:
    • 2.2 – Explain common threat vectors and attack surfaces
      • Human vectors/social engineering
        • Phishing
      • Vishing
      • Smishing

Guiding Question:

  • What are the different types of phishing and spam?

Resources:

  • Lesson Slides Lesson 2.2.3 – Phishing And Spam.pptx and Lab Activity Lab – Phishing.pptx presentations available on Google Classroom

Assignment:

  1. Follow along with the Lesson 2.2.3 – Phishing And Spam.pptx presentation in today’s class.
  2. Complete the Lab – Phishing.pptx Activity in class by tomorrow. Upload a screenshot to today’s Google Classroom assignment post of the successfully harvested Windows Victim’s credentials in Kali Linux to confirm completion of the Lab.

Posted: September 10th, 2026
Teacher Pacing Due Date: September 11th, 2026

CYBER.ORG: AP Cybersecurity – Lesson 4 – Topic 2.2.1 – Phishing

Objective:

  • Define phishing as the use of fake emails/websites to trick users into providing secrets.
  • Emphasize that phishing is one of the largest digital threats in the world and it is growing exponentially.
  • Explain that phishing started with the “advance fee scam” (aka Nigerian prince letter).
  • Identify key characteristics that help identify a phishing email.

Standards:

  • CSTA Compatibility Standards
    • 3A-IC-29: Explain the privacy concerns related to the collection and generation of data through automated processes that may not be evident to users.

Guiding Question:

  • Why is phishing considered the largest source of malware delivery and identity theft?

Resources:

Assignment:

  1. Follow along with the Lesson Slides Cyber1 2.2.1.pptx presentation in today’s class.
  2. We will complete a Phishing Lab Activity in class tomorrow using the information provided today.

Posted: September 9th, 2026