📐 SAT
📝 ACT
🎓 AP Exams
📖 CLT

AP® Cybersecurity Practice Drills & Strategy Guide

Updated August 2026 for the first national AP® Cybersecurity Exam in May 2027

Start the AP® Cybersecurity Drills → Key Terms & Vocabulary →

AP® Cybersecurity is a new AP Career Kickstart course launching nationally in the 2026–27 school year. Developed with college faculty and industry leaders and aligned with the NICE Workforce Framework, it is designed around the kind of applied reasoning used in introductory college cybersecurity courses: assessing risk, choosing and configuring defenses, and detecting attacks from evidence.

The exam asks you to analyze realistic scenarios and digital evidence, not recite definitions in isolation. It may give you a phishing situation, a firewall rule list, logs, a physical-security scenario, or a file-permission table and ask you to read it accurately, identify the vulnerability or sign of an attack, choose a control that addresses the weakness, and explain the decision. Knowing the vocabulary matters, but most questions reward what you can do with it.

That is why memorizing terms is not enough. You’ll be better prepared if you can read a scenario closely, reason about how an adversary would exploit a weakness, and match a defense to the specific problem in front of you. If you need the vocabulary foundation first, use the AP® Cybersecurity key terms. For other AP subjects and guides on the site, see the AP® Exam Practice hub. Below, you’ll find the current 2027 exam structure, its three exam-weighted multiple-choice skills, the mistakes that catch prepared students, and 30 original drills for applying the course concepts.

How the AP® Cybersecurity Exam Works

The first national AP® Cybersecurity Exam is Wednesday, May 5, 2027 (Session 1). It is a fully digital Bluebook exam lasting 2 hours and 10 minutes, with multiple-choice and free-response answers submitted through the app. The multiple-choice section carries 70% of the score, so careful scenario and evidence reading is one of the highest-value skills to practice.

Section I: Multiple Choice

  • 60 questions · 80 min
  • A mix of individual questions and sets of 2, 3, or 4 around shared evidence
  • All five course units are assessed in this section
  • Analyze scenarios and digital evidence to find vulnerabilities, recommend mitigations, and detect threats
  • Explain key cybersecurity concepts
  • 70% of Exam Score

Section II: Free Response

  • 1 question · 50 min
  • Device Security Analysis: several sources from one device
  • Firewall rules, system & application logs, a file-permission list, a device policy
  • Find attacks, configure controls, and harden the device
  • Assesses Mitigate Risk and Detect Attacks
  • 30% of Exam Score

The single free-response question is a Device Security Analysis. You work across simulated sources about one digital device, such as security policy information, firewall rules or configurations, system and application logs, and file permissions. You may need to explain policy, identify evidence of attacks, change permissions or firewall rules, evaluate the effect of a control, and recommend ways to harden the device. College Board’s current CED specifically says this question assesses Skill Category 2: Mitigate Risk and Skill Category 3: Detect Attacks, and students are expected to cite evidence from the supplied sources when explaining their reasoning. Drills 29 and 30 below are cross-source, FRQ-informed practice for that style of analysis.

The Three Multiple-Choice Skill Weightings

College Board publishes the weighting for the multiple-choice section by skill, not by unit. Analyze Risk, Mitigate Risk, and Detect Attacks each account for approximately 25–40% of the multiple-choice section. The course also includes a fourth skill category, Collaborate, which is developed through coursework but is not included in the published multiple-choice weighting table. Knowing which skill a question is testing helps because each one calls for a different move: spotting and evaluating a weakness, selecting or implementing a control, or reading evidence for signs of an attack.

Exam Skill 1
Analyze Risk
Exam Skill 2
Mitigate Risk
Exam Skill 3
Detect Attacks
Coursework
Collaborate

Analyze Risk asks you to identify vulnerabilities and threats and reason about how likely and how damaging they are, including how an adversary would exploit a weakness. Mitigate Risk asks you to choose and configure security controls, assess whether they work, and plan layered defenses. Detect Attacks asks you to read logs, alerts, and network data for indicators of compromise and recognize attack patterns. All three are threaded through the course’s units, which is why the drills below mix them rather than isolating them.

The Five Units

The course content is organized into five units that move outward from foundational ideas to specific environments you have to defend: yourself and your information, physical spaces, networks, devices, and finally applications and data. All five units are in scope for the multiple-choice section, but the published weighting is given by skill rather than as a fixed percentage for each unit, so treat the units below as a map of what you need to know and the three exam-weighted skills above as how you will be asked to use it.

UnitTitleFocus
Unit 1Introduction to SecurityThreats, risk, social engineering, authentication
Unit 2Securing SpacesPhysical security and defense in depth
Unit 3Securing NetworksSegmentation, firewalls, wireless, monitoring
Unit 4Securing DevicesMalware, hardening, endpoint policy, logs
Unit 5Securing Applications & DataInput handling, permissions, encryption, hashing

What the Multiple-Choice Section Tests

Many multiple-choice questions come in sets of two, three, or four that share a single piece of source material: a scenario describing a system or facility, a log excerpt, a configuration table, a firewall rule list, or a diagram. Because several questions can draw on the same source, a careful first read pays off across all of them. Read it closely the first time, pin down what kind of system this is and what the source is telling you, and you will save time on every question in the set.

Within a set, questions often move among several tasks: reading the source, identifying a concept or attack, evaluating a control, explaining why an adversary or defender would act a certain way, or choosing the best mitigation. Do not assume every set follows the same order; use the question stem to identify the task in front of you instead of expecting a fixed sequence.

How to Read an AP® Cybersecurity Question

Whether the source is a paragraph, a log, or a rule list, the same approach applies. Before reading the answer choices, read the question stem carefully and form your own answer. Doing this gives you a clearer target before the distractors can pull you off course, which matters here because so many wrong answers are controls that sound right but do not address the weakness.

When you work through a question set, ask:

  1. What does the source show, in plain language? (What is this system, and what is the situation?)
  2. Which skill is this question testing: analyzing a risk, choosing a mitigation, or detecting an attack?
  3. What is the specific weakness or indicator here, and how would an attacker use it?
  4. What is my own answer before I look at the choices?
  5. For each choice: is it factually wrong, a misreading, a real control that doesn’t fix this weakness, or the right answer?

For any question built on logs, a firewall rule list, or a permission table, find the exact line in question before you start reasoning. Wrong answers are often lifted from neighboring lines: an adjacent firewall rule, a different log entry, a permission on the wrong file. Naming the right line first keeps those traps from catching you. On the hardest items it helps to expect each wrong choice to fail in a different way: one misreads the source, one is a real control that doesn’t fix this particular weakness, one answers a different skill than the stem asked for, and one is just a plausible mistake. When you can name the flaw in each, the right answer is the one left standing.

Free-Response Practice
The exam’s single free-response question is a Device Security Analysis that draws on several sources from one device at once. Two cross-source drills below are FRQ-informed multiple-choice sets that practice the same kind of multi-source analysis the FRQ rewards:

The Biggest Mistakes Students Make on AP® Cybersecurity Multiple Choice

1. Choosing a control that sounds secure but doesn’t fix the actual weakness.

This is a common trap. A scenario describes one specific vulnerability, and several answer choices name real, legitimate controls that simply don’t address what is wrong. Encryption does not stop a phishing click; a stronger password policy does not close an exposed service. Name the specific weakness first, then pick the control that targets it, not the control that sounds the most secure.

2. Confusing similar threats by ignoring channel and target.

Phishing, spear phishing, and whaling differ by how narrowly they target; vishing and smishing differ by delivery channel; pretexting and quid pro quo differ by the social tactic. Questions reward students who sort by how the attack is delivered and who it targets rather than by a vague sense of which term sounds right. Read the scenario for the channel and the target before naming the attack.

3. Misreading which line of a log, rule list, or permission table the question wants.

When a firewall or ACL question uses ordered rules, read the list in order and watch which rule applies first; logs have many entries that look alike; permission tables list several files. A question about one rule, entry, or file is not asking about its neighbor, even when both are easy to find, and harder questions hide the relevant line a few rows down.

4. Confusing detecting an attack with preventing one.

Detection and mitigation are different skills, and the exam tests whether you can tell them apart. Reading a log for indicators of compromise (Detect Attacks) is not the same as choosing a control to stop the attack (Mitigate Risk). A question asking what the evidence shows is not satisfied by an answer about what you would do about it. Match your answer to the task the stem names.

5. Treating one strong control as enough instead of thinking in layers.

Defense in depth assumes any single control can fail, so the strongest answer often layers physical, network, device, and data protections rather than relying on one. Distractors offer a single “best” control where the situation calls for overlapping safeguards, or they add a redundant control in a layer that is already covered while leaving a real gap open. Ask which layer is left unprotected.

How to Use These Drills Effectively

The 30 drills below cover the five units of the AP® Cybersecurity course, moving from foundational security and physical spaces through networks, devices, and finally applications and data. Each drill is built around an original scenario, such as a phishing email, a firewall rule list, a permission table, or an incident log, with realistic details and five multiple-choice questions that build from reading the source to identifying a concept or attack, evaluating or configuring a control, reasoning about why, and choosing a mitigation or recommendation.

Two of the drills are cross-source, FRQ-informed multiple-choice sets that practice the kind of multi-source reading used in the Device Security Analysis question, where you reason across firewall rules, logs, permissions, and policy at once. After completing a drill, read every explanation, including the ones for questions you answered correctly. Each explanation names the specific error behind a wrong answer, including the “sounds secure but doesn’t fix it” controls that catch students who skim the scenario too quickly.

If you work through these steadily, they give you repeated practice with the reading, analysis, and decision-making the exam asks for. Because the exam is fully digital, also practice in Bluebook before test day. College Board says the AP Cybersecurity test preview is scheduled to become available in January 2027; once it is released, use it to get comfortable navigating sources and typing your free-response answer in the actual testing interface.


AP® Cybersecurity Drills

Scenario-based AP® Cybersecurity practice questions organized by unit. Each drill is built around one security scenario, with five questions that move from reading the source through identifying a threat or concept, evaluating a control, reasoning, and a recommendation. Every answer choice gets a full explanation, including the specific error behind each wrong one. These drills use original scenarios rather than College Board cases or sample questions. New to the terminology? Review the AP® Cybersecurity key terms first, then practice applying them here.

Unit 1: Introduction to Security

Foundational security: recognizing threats and social engineering, spotting suspicious logins and weak authentication, and staying safe on public networks and against AI-driven scams.

Unit 2: Securing Spaces

Foundational risk assessment and physical security: scoring asset risk to decide what to fix first, observing a facility for weaknesses, controlling access to sensitive rooms, reading door logs and camera coverage, and layering protections.

Unit 3: Securing Networks

Defending the network: reducing exposed internet-facing services, wireless configuration, segmenting LANs, placing public servers in a DMZ, reading firewall rule lists, monitoring alerts, and securing connected IoT devices.

Unit 4: Securing Devices

Endpoint defense: identifying malware by its behavior, securing password storage and login attempts, setting shared-workstation policy, hardening devices, and reading post-incident logs.

Unit 5: Securing Applications & Data

Protecting software and information: sanitizing web-form input, classifying sensitive records, setting file permissions, encrypting data at rest, public/private keys, secure defaults, hashing for integrity, and spotting anomalies in web logs.

Mixed AP® Exam Practice (Cross-Unit / FRQ-Style)

Cross-source multiple-choice drills that combine evidence across units the way the Device Security Analysis free-response question does — reasoning over firewall rules, logs, permissions, and policy at once. FRQ-informed practice for the kind of multi-source analysis the free-response question rewards.

All drills contain original scenario-based multiple-choice questions aligned with the skills and topics in AP® Cybersecurity, with detailed explanations for every answer choice. Developed by Brian Stewart, author of Barron’s SAT and ACT prep books, completely free.

Frequently Asked Questions

When is the 2027 AP® Cybersecurity exam?

The first national AP® Cybersecurity Exam is Wednesday, May 5, 2027, in Session 1. It is a fully digital Bluebook exam. For most schools in the lower 48 United States, Session 1 begins at 8:00 a.m. local time, but students should confirm their reporting time with their school.

What is on the AP® Cybersecurity exam?

The exam is 2 hours and 10 minutes long and has two sections. Section I is multiple choice: 60 questions in 80 minutes, made up of individual questions and sets of two, three, or four built around shared evidence such as a scenario, a log, a configuration table, or a firewall rule list. Section II is a single free-response question in 50 minutes—a Device Security Analysis using several sources about one device. The whole exam is taken digitally in the Bluebook app.

How many multiple-choice questions are on the exam?

There are 60 multiple-choice questions, and you have 80 minutes for them. They count for 70% of your total exam score. Questions appear both individually and in sets of two, three, or four around shared evidence.

What does the free-response question look like?

There is one free-response question, worth 30% of the exam, with 50 minutes to complete it. Called a Device Security Analysis, it presents several simulated sources about one device, such as policy information, firewall rules or configurations, logs, and file permissions. You analyze the evidence, identify attacks or security issues, configure or evaluate controls, and explain how to make the device more secure. The current CED says the FRQ assesses Mitigate Risk and Detect Attacks, and students should cite evidence from the supplied sources in their reasoning.

How is the exam weighted: by unit, or by skill?

For the multiple-choice section, College Board publishes weights by skill rather than by unit: Analyze Risk, Mitigate Risk, and Detect Attacks are each approximately 25–40% of Section I. The course also includes Collaborate, which is developed through coursework but is not listed in the multiple-choice weighting table. All five units are assessed in Section I; College Board does not publish fixed multiple-choice percentages for individual units.

What are the five units?

Unit 1: Introduction to Security; Unit 2: Securing Spaces; Unit 3: Securing Networks; Unit 4: Securing Devices; and Unit 5: Securing Applications and Data. Together they move from foundational security and physical spaces outward to networks, individual devices, and finally applications and data.

Are these official College Board AP® Cybersecurity questions?

No. These are original practice questions. AP® is a trademark of the College Board, which does not endorse this site.

Is AP® Cybersecurity part of AP Career Kickstart?

Yes. AP® Cybersecurity is an AP Career Kickstart course that combines college-level coursework with career-focused technical and professional skills. Students who complete the yearlong course and earn a qualifying AP Cybersecurity Exam score earn the AP Cybersecurity employer-endorsed credential. College credit and placement still depend on each institution’s policy; College Board says the first set of institutions granting credit for AP Cybersecurity scores will be released in spring 2027.

AP® is a registered trademark of the College Board, which was not involved in the production of, and does not endorse, this website or its content. Exam information on this page is based on the AP Cybersecurity Course and Exam Description effective fall 2026 and the current AP Cybersecurity Exam page. See full Trademark & Disclaimer.