Predict the effect of a change
Before applying a new permission or firewall rule, state which traffic or action should become allowed or blocked.
| Component | Time | Weight | What students analyze |
|---|---|---|---|
| 60 MCQs | 80 minutes | 70% | Individual and linked scenarios about concepts, vulnerabilities, controls, attacks, logs and system behavior |
| One FRQ | 50 minutes | 30% | Several sources about one device, such as policies, firewall configuration, permissions, network data and application logs |
Before applying a new permission or firewall rule, state which traffic or action should become allowed or blocked.
Order authentication, file, application and network events, then identify the first reliable sign of compromise.
Explain why a proposed control addresses the observed vulnerability and what legitimate behavior it may affect.
The exam asks students to connect evidence across a device. Each artifact contributes a different part of the explanation.
Fact basisCollege Board AP Cybersecurity course and exam assessment. The named official publication defines the factual scope used here; students should match any time-sensitive rule to their exact exam administration or college entry term.
Trace artifacts, justify the threat, and connect each recommendation to the evidence that supports it.
Continue with AP