New for the 2026–27 school year

AP Cybersecurity: the new analyst-style course and first exam

A fully digital AP course that asks students to investigate systems, classify vulnerabilities, interpret logs and defend security recommendations with evidence. The preparation path must connect each security claim to the supplied device artifacts rather than reward isolated vocabulary recall.

The first AP Cybersecurity exam is a 2-hour 10-minute fully digital exam: 60 multiple-choice questions in 80 minutes worth 70%, followed by one 50-minute evidence-analysis FRQ worth 30%.

An American high school cybersecurity club student tracing a network route on a transparent board beside a correctly oriented workstation, physical node models, permission locks, and attack indicators
2 h 10 mTotal fully digital exam time.
60 MCQsEighty minutes and 70% of the score.
1 FRQFifty minutes and 30% of the score.
Multiple sourcesPolicies, firewall rules, permissions and logs converge on one device.
First exam blueprint

Find the risk, explain the evidence, recommend the control.

ComponentTimeWeightWhat students analyze
60 MCQs80 minutes70%Individual and linked scenarios about concepts, vulnerabilities, controls, attacks, logs and system behavior
One FRQ50 minutes30%Several sources about one device, such as policies, firewall configuration, permissions, network data and application logs
Analyst workflow

A strong answer connects artifacts into one explanation.

The FRQ is not a request to define cybersecurity terms. Students inspect several forms of digital evidence, identify issues, trace attacks or suspicious behavior, and explain how a change in permissions, configuration or controls affects the system.

  1. Establish normal behavior.State what the policy, permission or network route is supposed to allow.
  2. Locate the anomaly.Use a precise log entry, configuration mismatch or traffic pattern as evidence.
  3. Classify the risk.Name the vulnerability or attack behavior that the evidence supports.
  4. Evaluate the control.Explain how a firewall, permission or automated response changes device behavior.
Practice lab

Rotate through three evidence modes.

Configuration

Predict the effect of a change

Before applying a new permission or firewall rule, state which traffic or action should become allowed or blocked.

Logs

Build a timeline from artifacts

Order authentication, file, application and network events, then identify the first reliable sign of compromise.

Recommendation

Match the control to the risk

Explain why a proposed control addresses the observed vulnerability and what legitimate behavior it may affect.

Evidence map

Five artifact types can tell one attack story.

The exam asks students to connect evidence across a device. Each artifact contributes a different part of the explanation.

Security policy

The policy defines expected behavior and the controls an organization intends to enforce. Use it as a baseline, then show where a configuration, permission or observed action violates that expectation.

Firewall configuration

Trace which traffic a rule allows or blocks and in which direction. A good answer explains the effect of changing the rule, including both the threat it reduces and legitimate access it may interrupt.

File-system permissions

Identify which user or process can read, write or execute a resource. Connect excessive privilege to a concrete risk instead of naming “least privilege” without showing how the current permission creates exposure.

Network and application logs

Put events in time order, correlate related sources and separate a suspicious indicator from proof. Repeated failure, unusual access or an unexpected connection becomes meaningful when tied to normal system behavior.

Indicators of compromise

Classify what the evidence suggests and state the limits of the conclusion. The task rewards defensible reasoning, not dramatic certainty unsupported by the supplied artifacts.

Control recommendation

Choose a mitigation that addresses the observed path: a permission change, filtering rule, isolation step or automated response. Explain how it changes device or network behavior and cite the artifact that justifies it.

Questions students ask

What to know before you plan.

When does AP Cybersecurity launch?
The course launches in the 2026–27 school year, with the first AP exam in May 2027.
How long is the AP Cybersecurity exam?
The fully digital exam lasts 2 hours 10 minutes.
How many questions are on the exam?
There are 60 multiple-choice questions and one free-response question.
What evidence appears on the FRQ?
Students may receive security policies, firewall configurations, file-system permissions, network logs and application logs about a single device.
What does the FRQ score?
It assesses whether students can identify security issues, detect attacks, evaluate controls and support explanations with evidence from the supplied artifacts.
Keep planning

Place Cybersecurity in the AP computing path.

Fact basisCollege Board AP Cybersecurity course and exam assessment. The named official publication defines the factual scope used here; students should match any time-sensitive rule to their exact exam administration or college entry term.

Practice like an analyst, not a glossary.

Trace artifacts, justify the threat, and connect each recommendation to the evidence that supports it.