📐 SAT
📝 ACT
🎓 AP Exams

AP® Cybersecurity Practice Drills & Strategy Guide

Start the AP® Cybersecurity Drills →

AP® Cybersecurity is an applied course. The exam asks you to analyze real scenarios and digital evidence, not recite definitions in isolation. It may give you a situation such as a phishing email, a firewall rule list, a set of logs, a physical-security scenario, or a file-permission table, and ask you to read it accurately, spot the vulnerability or the sign of an attack, choose a control that addresses the weakness, and justify the decision. Knowing the vocabulary matters, but most questions reward what you can do with it in a realistic security situation.

That is why memorizing terms is not enough. You’ll be better prepared if you can read a scenario closely, reason about how an attacker would exploit a weakness, and match a defense to the specific problem in front of you, rather than relying on raw recall. Vocabulary is still the foundation, though, and if you want to review the concepts first, start with the AP® Cybersecurity key terms organized by unit. Below, you’ll find how the exam is structured, what its three exam-weighted skills test, the mistakes that catch prepared students, and how to use these drills to build the habits that transfer to test day.

How the AP® Cybersecurity Exam Works

This is a fully digital exam administered in the Bluebook app, with responses submitted automatically at the end. It has two sections. The multiple-choice section carries the most weight (70%), and because many of its questions come in scenario-based sets, practicing careful evidence reading is one of the most efficient uses of prep time. The first national AP Cybersecurity Exam administration is scheduled for May 2027.

Section I: Multiple Choice

  • 60 questions · 80 min
  • A mix of individual questions and sets of 2, 3, or 4 around shared evidence
  • Analyze scenarios and digital evidence to find vulnerabilities, recommend mitigations, and detect threats
  • Explain key cybersecurity concepts
  • 70% of Exam Score

Section II: Free Response

  • 1 question · 50 min
  • Device Security Analysis: several sources from one device
  • Firewall rules, system & application logs, a file-permission list, a device policy
  • Find attacks, configure controls, and harden the device
  • 30% of Exam Score

The single free-response question is a Device Security Analysis. You are given several sources of information about the same device: a set of firewall rules, system and application logs, a list of files with their permissions, and a device policy. You then work across all of them to explain parts of the policy, find signs of attacks in the logs, configure file permissions and firewall rules, and use the evidence to recommend ways to harden the device. The multiple-choice section trains the same reading-evidence-and-recommending reasoning this question demands. Two of the drills below (29 and 30) are built as cross-source, FRQ-informed practice for it.

The Three Exam-Weighted Skills

The published multiple-choice weighting is organized by skill rather than by unit. College Board gives exam weight ranges for three skill categories: Analyze Risk, Mitigate Risk, and Detect Attacks, each in the range of 25–40%. The course also includes a fourth skill category, Collaborate, which is developed through coursework and classroom activities rather than listed in that weighting table. Knowing which skill a question is testing helps because each one calls for a different move: spotting a weakness, choosing a control, or reading evidence for signs of an attack.

Exam Skill 1
Analyze Risk
Exam Skill 2
Mitigate Risk
Exam Skill 3
Detect Attacks
Coursework
Collaborate

Analyze Risk asks you to identify vulnerabilities and threats and reason about how likely and how damaging they are, including how an adversary would exploit a weakness. Mitigate Risk asks you to choose and configure security controls, assess whether they work, and plan layered defenses. Detect Attacks asks you to read logs, alerts, and network data for indicators of compromise and recognize attack patterns. All three are threaded through the course’s units, which is why the drills below mix them rather than isolating them.

The Five Units

The course content is organized into five units that move outward from foundational ideas to specific environments you have to defend: yourself and your information, physical spaces, networks, devices, and finally applications and data. All five units are in scope for the multiple-choice section, but the published weighting is given by skill rather than as a fixed percentage for each unit, so treat the units below as a map of what you need to know and the three exam-weighted skills above as how you will be asked to use it.

UnitTitleFocus
Unit 1Introduction to SecurityThreats, risk, social engineering, authentication
Unit 2Securing SpacesPhysical security and defense in depth
Unit 3Securing NetworksSegmentation, firewalls, wireless, monitoring
Unit 4Securing DevicesMalware, hardening, endpoint policy, logs
Unit 5Securing Applications & DataInput handling, permissions, encryption, hashing

What the Multiple-Choice Section Tests

Many multiple-choice questions come in sets of two, three, or four that share a single piece of source material: a scenario describing a system or facility, a log excerpt, a configuration table, a firewall rule list, or a diagram. Because several questions can draw on the same source, a careful first read pays off across all of them. Read it closely the first time, pin down what kind of system this is and what the source is telling you, and you will save time on every question in the set.

Within a set, questions often move among several tasks: reading the source, identifying a concept or attack, evaluating a control, explaining why an adversary or defender would act a certain way, or choosing the best mitigation. Do not assume every set follows the same order; use the question stem to identify the task in front of you instead of expecting a fixed sequence.

How to Read an AP® Cybersecurity Question

Whether the source is a paragraph, a log, or a rule list, the same approach applies. Before reading the answer choices, read the question stem carefully and form your own answer. Doing this gives you a clearer target before the distractors can pull you off course, which matters here because so many wrong answers are controls that sound right but do not address the weakness.

When you work through a question set, ask:

  1. What does the source show, in plain language? (What is this system, and what is the situation?)
  2. Which skill is this question testing: analyzing a risk, choosing a mitigation, or detecting an attack?
  3. What is the specific weakness or indicator here, and how would an attacker use it?
  4. What is my own answer before I look at the choices?
  5. For each choice: is it factually wrong, a misreading, a real control that doesn’t fix this weakness, or the right answer?

For any question built on logs, a firewall rule list, or a permission table, find the exact line in question before you start reasoning. Wrong answers are often lifted from neighboring lines: an adjacent firewall rule, a different log entry, a permission on the wrong file. Naming the right line first keeps those traps from catching you. On the hardest items it helps to expect each wrong choice to fail in a different way: one misreads the source, one is a real control that doesn’t fix this particular weakness, one answers a different skill than the stem asked for, and one is just a plausible mistake. When you can name the flaw in each, the right answer is the one left standing.

Free-Response Practice
The exam’s single free-response question is a Device Security Analysis that draws on several sources from one device at once. Two cross-source drills below are FRQ-informed multiple-choice sets that practice the same kind of multi-source analysis the FRQ rewards:

The Biggest Mistakes Students Make on AP® Cybersecurity Multiple Choice

1. Choosing a control that sounds secure but doesn’t fix the actual weakness.

This is a common trap. A scenario describes one specific vulnerability, and several answer choices name real, legitimate controls that simply don’t address what is wrong. Encryption does not stop a phishing click; a stronger password policy does not close an exposed service. Name the specific weakness first, then pick the control that targets it, not the control that sounds the most secure.

2. Confusing similar threats by ignoring channel and target.

Phishing, spear phishing, and whaling differ by how narrowly they target; vishing and smishing differ by delivery channel; pretexting and quid pro quo differ by the social tactic. Questions reward students who sort by how the attack is delivered and who it targets rather than by a vague sense of which term sounds right. Read the scenario for the channel and the target before naming the attack.

3. Misreading which line of a log, rule list, or permission table the question wants.

When a firewall or ACL question uses ordered rules, read the list in order and watch which rule applies first; logs have many entries that look alike; permission tables list several files. A question about one rule, entry, or file is not asking about its neighbor, even when both are easy to find, and harder questions hide the relevant line a few rows down.

4. Confusing detecting an attack with preventing one.

Detection and mitigation are different skills, and the exam tests whether you can tell them apart. Reading a log for indicators of compromise (Detect Attacks) is not the same as choosing a control to stop the attack (Mitigate Risk). A question asking what the evidence shows is not satisfied by an answer about what you would do about it. Match your answer to the task the stem names.

5. Treating one strong control as enough instead of thinking in layers.

Defense in depth assumes any single control can fail, so the strongest answer often layers physical, network, device, and data protections rather than relying on one. Distractors offer a single “best” control where the situation calls for overlapping safeguards, or they add a redundant control in a layer that is already covered while leaving a real gap open. Ask which layer is left unprotected.

How to Use These Drills Effectively

The 30 drills below cover the five units of the AP® Cybersecurity course, moving from foundational security and physical spaces through networks, devices, and finally applications and data. Each drill is built around an original scenario, such as a phishing email, a firewall rule list, a permission table, or an incident log, with realistic details and five multiple-choice questions that build from reading the source to identifying a concept or attack, evaluating or configuring a control, reasoning about why, and choosing a mitigation or recommendation.

Two of the drills are cross-source, FRQ-informed multiple-choice sets that practice the kind of multi-source reading used in the Device Security Analysis question, where you reason across firewall rules, logs, permissions, and policy at once. After completing a drill, read every explanation, including the ones for questions you answered correctly. Each explanation names the specific error behind a wrong answer, including the “sounds secure but doesn’t fix it” controls that catch students who skim the scenario too quickly.

If you work through these steadily, they give you repeated practice with the reading, analysis, and decision-making the exam asks for.


AP® Cybersecurity Drills

Scenario-based AP® Cybersecurity practice questions organized by unit. Each drill is built around one security scenario, with five questions that move from reading the source through identifying a threat or concept, evaluating a control, reasoning, and a recommendation. Every answer choice gets a full explanation, including the specific error behind each wrong one. These drills use original scenarios rather than College Board cases or sample questions. New to the terminology? Review the AP® Cybersecurity key terms first, then practice applying them here.

Unit 1: Introduction to Security

Foundational security: recognizing threats and social engineering, spotting suspicious logins and weak authentication, and staying safe on public networks and against AI-driven scams.

Unit 2: Securing Spaces

Foundational risk assessment and physical security: scoring asset risk to decide what to fix first, observing a facility for weaknesses, controlling access to sensitive rooms, reading door logs and camera coverage, and layering protections.

Unit 3: Securing Networks

Defending the network: reducing exposed internet-facing services, wireless configuration, segmenting LANs, placing public servers in a DMZ, reading firewall rule lists, monitoring alerts, and securing connected IoT devices.

Unit 4: Securing Devices

Endpoint defense: identifying malware by its behavior, securing password storage and login attempts, setting shared-workstation policy, hardening devices, and reading post-incident logs.

Unit 5: Securing Applications & Data

Protecting software and information: sanitizing web-form input, classifying sensitive records, setting file permissions, encrypting data at rest, public/private keys, secure defaults, hashing for integrity, and spotting anomalies in web logs.

Mixed AP® Exam Practice (Cross-Unit / FRQ-Style)

Cross-source multiple-choice drills that combine evidence across units the way the Device Security Analysis free-response question does — reasoning over firewall rules, logs, permissions, and policy at once. FRQ-informed practice for the kind of multi-source analysis the free-response question rewards.

All drills contain original scenario-based multiple-choice questions aligned with the skills and topics in AP® Cybersecurity, with detailed explanations for every answer choice. Created by Brian Stewart, author of Barron’s SAT and ACT prep books, completely free.

Frequently Asked Questions

What is on the AP® Cybersecurity exam?

The exam has two sections. Section I is multiple choice: 60 questions in 80 minutes, made up of individual questions and sets of two, three, or four built around shared evidence such as a scenario, a log, a configuration table, or a firewall rule list. Section II is a single free-response question in 50 minutes—a Device Security Analysis that gives you several sources from one device (firewall rules, system and application logs, a file-permission list, and a device policy) and asks you to find security issues, configure controls, and harden the device. The whole exam is taken digitally in the Bluebook app.

How many multiple-choice questions are on the exam?

There are 60 multiple-choice questions, and you have 80 minutes for them. They count for 70% of your total exam score. Questions appear both individually and in sets of two, three, or four around shared evidence.

What does the free-response question look like?

There is one free-response question, worth 30% of the exam, with 50 minutes to complete it. Called a Device Security Analysis, it presents several sources of information about the same device—firewall rules, system and application logs, a list of files with their permissions, and a device policy. You explain parts of the policy, find signs of attacks in the logs, configure file permissions and firewall rules, and recommend ways to make the device more secure.

How is the exam weighted: by unit, or by skill?

By skill. College Board publishes exam weights for three skill categories: Analyze Risk, Mitigate Risk, and Detect Attacks. The course also includes a fourth skill category, Collaborate, which is developed through coursework rather than included in the published multiple-choice weighting table. College Board does not publish a fixed percentage weight for each of the five units.

What are the five units?

Unit 1: Introduction to Security; Unit 2: Securing Spaces; Unit 3: Securing Networks; Unit 4: Securing Devices; and Unit 5: Securing Applications and Data. Together they move from foundational security and physical spaces outward to networks, individual devices, and finally applications and data.

Are these official College Board AP® Cybersecurity questions?

No. These are original practice questions. AP® is a trademark of the College Board, which does not endorse this site.

Is AP® Cybersecurity part of AP Career Kickstart?

Yes. AP® Cybersecurity is an AP Career Kickstart course, one of a group of AP offerings that pair college-level coursework with career-focused technical and professional skills. Students who take the yearlong course and earn a qualifying score on the AP Cybersecurity Exam can earn the AP Cybersecurity employer-endorsed credential; college credit or placement depends on each institution’s policy. The first national AP Cybersecurity Exam administration is scheduled for May 2027.

AP® is a registered trademark of the College Board, which was not involved in the production of, and does not endorse, this website or its content. See full Trademark & Disclaimer.