AP Cybersecurity
Think like an adversary, defend in layers, and read the logs that prove an attack happened.
- Category
- Career and technical
- Units
- 5 units
- Exam
- Exam May 5, 2027 (in 220 days)
What the course covers
AP Cybersecurity is a College Board AP Career Kickstart course equivalent to a one-semester college introduction to cybersecurity. You learn how threats exploit vulnerabilities to create risk, how to rate and manage that risk, and how to stop and catch attacks with a defense-in-depth strategy across five layers: people, physical spaces, networks, devices, and applications and data. The exam is built on evidence: firewall rule tables, authentication and web server logs, ls -l permission listings, phishing emails, and security policies. Expect to configure things too: order firewall rules, write chmod commands, set login policies, and choose the right key for asymmetric encryption.
5 units
Unit 1
Introduction to Security
FreeThree everyday ways adversaries get in: social engineering that pressures you to click or disclose, weak passwords, and hostile public Wi-Fi. Then how AI sharpens attacks and how defenders use AI to keep up. About 10 class periods.5 topics
- 1.1Understanding Social Engineering
- 1.2Suspicious Website Logins
- 1.3Best Practices for Public Networks
- 1.4AI-Based Cybersecurity Attacks
- 1.5Leveraging AI in Cyber Defense
Unit 2
Securing Spaces
The vocabulary of the whole course (threats, vulnerabilities, risk, controls, defense in depth) built in the most concrete domain: physical space. Physical attacks, rating physical risk, choosing and placing locks, cameras, sensors, and guards, and catching intruders in badge logs. About 21 class periods.4 topics
- 2.1Cyber Foundations
- 2.2Physical Vulnerabilities and Attacks
- 2.3Protecting Physical Spaces
- 2.4Detecting Physical Attacks
Unit 3
Securing Networks
How data in transit gets intercepted, redirected, or flooded, and how to stop it: network policies, wireless hardening, segmentation into zones, ordered firewall rules, and automated detection tools that read network logs for indicators of compromise. About 26 class periods.5 topics
- 3.1Network Vulnerabilities and Attacks
- 3.2Protecting Networks: Managerial Controls and Wireless Security
- 3.3Protecting Networks: Segmentation
- 3.4Protecting Networks: Firewalls
- 3.5Detecting Network Attacks
Unit 4
Securing Devices
Servers, laptops, phones, and embedded IoT devices: the malware that targets them, how passwords are hashed and cracked, authentication factors and login settings, device policies, anti-malware, patching, host firewalls, and reading authentication logs for password attacks. About 23 class periods.4 topics
- 4.1Device Vulnerabilities and Attacks
- 4.2Authentication
- 4.3Protecting Devices
- 4.4Detecting Attacks on Devices
Unit 5
Securing Applications and Data
Data is usually the prize. Injection, cross-site scripting, buffer overflow, and directory traversal attacks; data states and regulated data; access control models and Linux permissions with chmod; symmetric and asymmetric encryption; secure design and input sanitization; and detecting data and application attacks with logs, honeypots, and hashes. About 30 class periods.6 topics
- 5.1Application and Data Vulnerabilities and Attacks
- 5.2Protecting Applications and Data: Managerial Controls and Access Controls
- 5.3Protecting Stored Data with Cryptography
- 5.4Asymmetric Cryptography
- 5.5Protecting Applications
- 5.6Detecting Attacks on Data and Applications
The exam, part by part
2 parts, 2 h 10 min in all.
Section I: Multiple Choice
- Questions
- 60
- Time
- 1 h 20 min
- Weight
- 70%
No calculator
Format details
Four answer choices (A-D). Individual questions plus sets of 2, 3, or 4 questions that share one stimulus (an email, article, log excerpt, firewall table, permission listing, or report). All five units are assessed; the section is weighted by skill category: Analyze Risk 25-40%, Mitigate Risk 25-40%, Detect Attacks 25-40%.
Section II: Free Response
- Questions
- 1
- Time
- 50 min
- Weight
- 30%
No calculator
Format details
Task types: device-security-analysis
One multipart Device Security Analysis question built on several simulated sources from a single device. Assesses Mitigate Risk and Detect Attacks.
How the 1 to 5 score is set
Section I (60 multiple-choice questions, scored by machine with no penalty for wrong answers) counts for 70% of the composite and Section II (one 14-point Device Security Analysis) counts for 30%. The weighted section scores are combined into a composite that is converted to the 1-5 AP scale. A qualifying score also earns the AP Career Kickstart Employer-Endorsed Credential. May 2027 is the first operational administration; the first college credit policies for this exam are expected in spring 2027.
What you bring and get
Fully digital exam in the Bluebook app. No calculator is permitted (Cybersecurity is not on the AP calculator list) and no reference sheet is provided, so port numbers, chmod values, attack indicators, and control types must be known cold. All evidence you need (firewall tables, logs, permission listings, policies, emails) is supplied inside each question.
Skills the exam scores
1.AExplain threats and vulnerabilities
Analyze Risk. Identify vulnerabilities, threats, and attack methods (with or without AI assistance) and explain how together they create risk.1.BTrace how an exploit works
Analyze Risk. Determine the path an adversary would take to exploit a specific vulnerability and compromise an asset.1.CEvaluate likelihood and impact
Analyze Risk. Judge how likely a risk is to be realized and how severe the damage would be, with or without AI support.1.DDocument risk
Analyze Risk. Record the likelihood, impact, and final rating (high, moderate, low, or a numeric or dollar score) for identified risks.2.AExplain security controls
Mitigate Risk. Identify a security control and explain how it reduces a specific risk.2.BLayer controls
Mitigate Risk. Choose layered, defense-in-depth controls that address the vulnerabilities in a scenario.2.CEvaluate a mitigation
Mitigate Risk. Judge the effects of a protective strategy, including its side effects on legitimate users and traffic, with or without AI support.2.DImplement mitigations
Mitigate Risk. Configure and record mitigations such as firewall rules, file permissions, login policies, and encryption settings.3.AExplain monitoring methods
Detect Attacks. Identify ways to monitor systems (logs, IDS, SIEM, cameras, honeypots, hashes) and explain how each detects attacks.3.BPlan detection
Detect Attacks. Determine a strategy or method for detecting attacks that fits the environment, such as signature, anomaly, or hybrid detection.3.CEvaluate detection
Detect Attacks. Judge a detection method by its speed, cost, performance load, false positive rate, and false negative rate.3.DDetect and classify attacks
Detect Attacks. Analyze digital evidence such as log files and packet data to detect an attack and name its type.4.ASet shared team objectives
Collaborate. Develop clear objectives a team shares for a cybersecurity task. Built in class projects; not assessed on the AP Exam.4.BDefine team roles
Collaborate. Establish clear roles and responsibilities for members of a cybersecurity team. Not assessed on the AP Exam.4.CUse AI as a collaborator
Collaborate. Use AI tools as a collaboration aid individually and in a group, checking their output. Not assessed on the AP Exam.4.DComplete assigned team work
Collaborate. Carry out your assigned part of a collaborative cybersecurity task. Not assessed on the AP Exam.