Operation FIREWALL — Teacher Guide
A classroom cyber escape room for AP Cybersecurity. Seven “cells” (teams) each race to contain the same attacker, NIGHTJAR, by solving five breach layers plus a final patch. This guide walks you through setup and running the game.
Why run this — AP Cybersecurity Unit 1 & professional skills
Operation FIREWALL lives in Unit 1: Introduction to Security. In one sitting students do the Unit 1 objectives — spotting social engineering, catching a suspicious login, practicing safe habits, and facing an AI-powered attack — while building the professional skills employers ask for. Objectives are grouped by the challenge that exercises them; shared ones follow, then the professional skills.
Puzzle 1 · Social Engineering (phishing mailbox)
- 1.1.A Identify common indicators of social engineering.
- 1.1.B Explain how social engineering is used by adversaries.
- 1.1.C Describe possible impacts for victims of social engineering attacks.
Puzzle 2 · Weak Authentication (OSINT password + Caesar cipher)
- 1.2.A Identify common signs of a password attack.
- 1.2.B Explain how adversaries take advantage of weak authentication.
- 1.2.C Explain how to make authentication stronger.
Puzzle 3 · Log Analysis (catching the unauthorized login)
- 1.2.A Identify common signs of a password attack — the failed-then-successful sign-ins in the log. Mirrors CED lab 1B · Detecting Unauthorized Logins.
- 1.2.B Explain how adversaries take advantage of weak authentication.
Puzzle 4 · Evil Twin (rogue Wi-Fi + network trace)
- 1.3.C Describe actions individuals can take to protect sensitive data on the internet — recognizing an untrusted / rogue network. Mirrors CED lab 1C · Impacts of Using Public Wi-Fi.
- 1.1.A Identify indicators of deception (a look-alike access point).
Puzzle 5 · AI Deepfake Call
- 1.4.A Explain how adversaries use AI-powered cyberattacks (a cloned-voice deepfake). Mirrors CED lab 1D · AI-Powered Cyberattacks.
- 1.4.B Explain how to protect against AI-augmented cyberattacks (verify with an out-of-band shared secret).
- 1.1.B Explain how social engineering is used.
Capstone · Deploy the Patch
- 1.2.C Explain how to make authentication stronger (the fix forces a password reset).
- 1.3.C Describe protective actions that shut the adversary out.
Reinforced across the whole mission
- 1.3.A Identify the type of adversary (the NIGHTJAR threat actor).
- 1.3.C Everyday best practices for protecting data online — the defensive mindset throughout.
- 1.5.A–B Explain how AI-powered tools help defenders detect and respond faster (the SOC / CIRT tools framing).
Professional skills it builds
- Relentless Curiosity — chasing unfamiliar clues and puzzles all the way to a solution.
- Critical Analysis — reading logs, phishing headers, and data sets where the answer is never clearcut.
- Real-World Research — OSINT: seeking out and acting on posted information to crack the password.
- Cognitive Flexibility — switching between cipher types and attack scenarios under the clock.
- Inclusive Collaboration — a team “cell” where diverse strengths solve the breach together.
- Effective Communication — talking through findings to assemble the five-part patch key.
- Ethical Decision-Making — choosing to patch and defend rather than take the bait of “counterstrike.”
- Precise Documentation — accurately recording recovered fragments, cipher halves, and agent IDs.
Candid Feedback and Professional Networking are the two professional skills a single run touches least — natural follow-ups for a class debrief.
Aligned to the AP Cybersecurity Course and Exam Description (Effective Fall 2026), Unit 1: Introduction to Security. Codes follow the CED’s topic.objective numbering; italic labels reference the matching CED classroom labs.
Before you start — what you’ll need
- A computer for each participating team — up to 7 total.
- One shared computer for all teams to use as the Maze Station.
- One teacher computer to run Mission Control and administer the game.
- All the printouts and clues — the seven team kits, the ID scan cards, and the Caesar keys.
- Anything you’d like to add or present — intro slides, a projected timer, prizes, and so on.
- A post-game reflection or assignment — ready-made questions are in section 7.
1 · How it works
Each team sits at a console (a web page) and works through five challenges — social engineering, weak passwords, log analysis, an evil-twin Wi-Fi trace, and an AI deepfake call — then assembles a final patch key. Every answer is found on that team’s printed dossier and room clues, not on the screen. You run the whole game from one Mission Control (admin) page, and a shared Maze Station computer handles the Wi-Fi trace.
You’re reading this from the
Control Center — the site’s home page and the launch point for everything: Mission Control, the Maze Station, all seven consoles, all seven print kits, the ID scan cards, and the master answer key. It’s already deployed and live — nothing to install.
2 · Set up the game (Mission Control)
From the Control Center, open Mission Control (the admin page). This is where you configure the game — don’t press Start yet; that comes once everyone is in the room (step 5).
- School name — type it once in Setup. It flows automatically to every console and every printed dossier, so you never edit the team pages.
- Stop time — set the end-of-mission clock that every team races. A typical run is 30–45 minutes; adjust it before you start.
- End message — in Setup, type what a team should do the moment it finishes (win or lose). It appears on their end screen, so use it to point them at whatever comes next — the reflection questions, an assignment, or “come see me.” (See section 7.)
- Maze scanner mode — choose how teams enter their agent ID at the Maze Station:
- Scanner — teams scan the barcode on their ID card with a USB barcode scanner. Fast and hands-off; pick this if you have a scanner at the maze computer and want the room moving quickly.
- Scanner + type — also lets teams type the 4-digit number by hand. Pick this if you don’t have a scanner, if scanners are flaky, or if you want students to prove they decoded the binary Field Credential themselves.
Leave Mission Control open on your computer for the whole game — it’s your live board and your reset controls.
3 · Print & prep the room
- Print each team’s kit (Control Center → Team Print Kits). Print in colour and keep Background graphics on so the colour stripes and posters come through.
- Each kit is pre-sorted into two piles: the first pages (“Set up the room”) list what to post & scatter; everything after the “Everything here goes in the Dossier” divider is the packet you hand the team.
- Every page carries that cell’s colour stripe and a “RED CELL”-style corner tag, so you can mix all seven cells’ clues around the room and teams can still find their own.
- Print the ID Scan Cards sheet once (30 cards). Cut them apart and scatter them by the Maze Station — only 7 open a maze; 23 are decoys.
- Hide each cell’s Caesar keys (small coloured key cut-outs) around the room — teams count their own colour to find their cipher shift.
4 · Set up the stations & test
- One console per team. At each spot where you want a team (up to seven computers), open the Control Center and click that team’s button under Team Consoles — Blue Hat at the blue table, Red Hat at the red table, and so on. Leave each on its boot / keypad screen.
- Maze Station on its own computer. On a separate shared computer near the scan cards, open the Maze Station. A team scans (or types) their 4-digit ID and the correct number opens their maze: they trace from the start to the halfway point (first half of the Wi-Fi password), then on to the finish (second half). A wrong move shows their path for 3 seconds and logs them out so the next team can take a turn — but once a team reaches halfway that progress is banked, so a slip only sends them back for the second half.
- Sound on. Turn up the volume on every console and the maze computer — the briefing, the deepfake call, and the win / lose videos all use audio.
- Quick check. Confirm each console reaches its keypad screen, the Maze Station accepts a test scan, and Mission Control lists every cell you’re using. Fix anything now, before students arrive.
5 · Brief the teams & start
- Gather the teams and go over the rules and expectations: every answer is on their printed materials, not the screen; the console must stay in fullscreen — leaving it starts a 30-second counter and can fail the cell; copy / paste is disabled, so type carefully; take turns politely at the shared Maze Station; and the clock is running for everyone at once.
- In Mission Control, press Start to open the mission and begin the countdown.
- Each team then solves the keypad puzzle at its own console — the answer comes from that cell’s dossier access puzzle. Solving it unlocks the mission-briefing video, and from there the console opens and they’re loose to play. Short on time? Just give each team its keypad answer so they jump straight into the briefing.
- Keep an eye on the live board — each cell shows progress, fragments recovered, and status.
6 · Answers, resets & troubleshooting
- All answers live on the Master Answer Key — keep it open on your computer or print it. It is not in any dossier.
- Reset a cell (or all cells) from Mission Control to start a fresh round; this also restores the maze’s original two-half behaviour.
- Stuck team? Every answer is on their printed materials; the answer key tells you exactly what to nudge toward.
- Audio not playing? Make sure the computer’s volume is up; the briefing and end videos need a click to start, which the game provides.
7 · When a team finishes — wrap-up & reflection
When a cell wins (or the clock beats them), its console plays the outcome video and shows the End message you set in step 2 — students should simply follow those directions. Point them straight into a reflection or assignment so finishers stay engaged while other cells play on — either set it up on your class LMS (Schoology, Canva, Google Classroom) or just have them do it on paper.
A quick ticket out the door — have each team answer these before they’re done. They push past “what did you do” into “what does it mean,” which is exactly the analysis AP Cybersecurity is after:
- Of the five breaches you contained, which is the most dangerous to a real school, and why?
- Your team cracked a password using someone’s public information. What habits made that possible, and how would you advise someone to prevent it?
- The caller’s voice was faked by AI. If a voice can’t be trusted, how should people verify who they’re talking to — and why does a pre-agreed shared secret work?
- This mission relied on five layers of defense. Explain how they worked together, and what an attacker gains when just one layer is weak.
- AI powered today’s attack, but defenders use AI too. Argue whether AI makes organizations safer or more vulnerable overall, and defend your position.
Good luck, and watch the clock. — Back to Control Center