Complete unit-by-unit study guides for all five units of AP Cybersecurity — covering the human, physical, network, device, and application attack surfaces. Built from the official CED (effective Fall 2026) with original Tian2 content.
60 questions in 80 minutes. Questions appear as individual items and as stimulus sets of 2–4 questions sharing a scenario, log excerpt, network diagram, or firewall ruleset. Stimulus materials include firewall ACL tables, system and application logs, network topology diagrams, packet captures, and file permission listings.
No calculator permitted (no mathematics required beyond basic logic). No reference sheet — students must know all terminology from memory. All responses entered digitally in Bluebook.
One multi-document device/security analysis scenario lasting 50 minutes. Students receive multiple information sources from a single device or environment — firewall rules, system logs, application logs, file permissions, and device policy — and must:
The rubric rewards: correct identification + citation of evidence from the provided source + explanation of why the defense reduces risk. Partial credit is available.
All five units assess the same three skill categories, each weighted 25–40% of the exam:
| Skill | Weight |
|---|---|
| Analyze Risk — identify vulnerabilities, evaluate threats, assess likelihood and severity | 25–40% |
| Mitigate Risk — configure layered security controls; assess their effectiveness | 25–40% |
| Detect Attacks — monitor systems; identify IoCs and IoAs; recognize attack patterns in logs | 25–40% |
A fourth skill, Collaborate (work with teams, communicate to technical and non-technical audiences, use AI tools for documentation), is integrated throughout but not separately weighted on the exam.
Students who earn a qualifying score receive:
Entry-level career pathways: Information Security Analyst, Network Administrator, SOC Analyst.
The course mirrors NIST CSF's five functions: Identify (asset inventory, risk assessment), Protect (access controls, hardening), Detect (IDS/SIEM, log monitoring), Respond (incident handling), and Recover (business continuity). Unit 2's CIA Triad and risk framework map directly to the Identify function.
The National Initiative for Cybersecurity Education (NICE) maps course topics to workforce roles: Protect and Defend (Units 2–4), Analyze (Units 1, 3, 5 — log and threat analysis), and Investigate (Unit 4 — digital forensics and chain of custody).
AP Cybersecurity content overlaps significantly with CompTIA Security+ domain areas: Threats/Attacks/Vulnerabilities (Units 1, 3, 4), Architecture and Design (Units 2, 3), Implementation (Units 3, 5), and Identity and Access Management (Unit 4). The credential voucher makes Security+ a natural next step.
Note: No released past exam questions exist as of June 2026. The first official national exam is May 2027; FRQs are expected to be released approximately July 2027.
Our worked solutions and practice questions are original instructional content created by Tian2 AP. They are aligned to the concepts and skills described in College Board’s Course and Exam Description and are not reproductions of, or affiliated with, College Board’s official materials.