AP Cybersecurity is an introductory, college-level cybersecurity course that trains students in defense-in-depth strategies across a variety of domains: physical spaces, computer networks, devices, applications, and data. This course is part of AP Career Kickstart — students with qualifying AP Exam scores earn both potential college credit and an employer-endorsed credential. Developed with college faculty and industry leaders, the course aligns with the NICE Workforce Framework and emphasizes scenario-based, hands-on learning.
Five Domains
- Introduction to Security
- Securing Spaces (physical security)
- Securing Networks
- Securing Devices
- Securing Applications and Data
Scenario-Based Labs
Each unit is anchored to an authentic workplace scenario: Xtensr Labs (physical), Hospital Network (network), Company Devices (devices), and Web Application (applications & data).
Upon completion of this course, students will be able to:
- Analyze Risk — Identify vulnerabilities, threats, and attacks; evaluate their likelihood and impact.
- Mitigate Risk — Select and implement layered security controls across all domains.
- Detect Attacks — Monitor systems, analyze logs, and classify cyberattacks from digital evidence.
- Collaborate — Work with teammates and use AI tools responsibly on cybersecurity tasks.
- Apply Defense-in-Depth — Design multi-layered protection strategies across all five course domains.
- Uphold Professional Ethics — Follow legal requirements and professional norms for cybersecurity practice.
Each semester is graded independently using the same standard. The midterm assessment accounts for 40% of the semester grade and the final assessment for 60%. Each is composed as follows:
Midterm Assessment — 40% of Semester Grade
| Category | Weight |
| Attendance | 15% |
| Class Participation | 15% |
| Homework | 20% |
| Midterm Exam | 50% |
Final Assessment — 60% of Semester Grade
| Category | Weight |
| Attendance | 15% |
| Class Participation | 15% |
| Homework | 20% |
| Final Exam | 50% |
Academic Integrity & Legal Norms
- Cybersecurity tools must only be used in instructor-authorized lab environments for educational purposes.
- Using course knowledge or tools against any system you do not own or have explicit written permission to test is a legal violation — it will result in course failure and school disciplinary action.
- Treat all lab findings as confidential; do not share or publish vulnerability information outside class.
Exam Window: May 3–14, 2027
| Section | Content | Time | Weight |
| Section I: Multiple Choice | ~70 scenario-based questions | 120 min | 60% |
| Section II: Free Response | 2 extended scenario analysis questions | 90 min | 40% |
Free-Response Expectations
Both FRQs present an authentic cybersecurity workplace scenario. Students must:
- Identify vulnerabilities and classify their risk level
- Recommend and justify layered security controls
- Analyze configuration data or logs as evidence of an attack
- Explain how detection methods work and evaluate their impact
Cybersecurity Skills Framework
- Analyze Risk — Identify vulnerabilities/threats; evaluate likelihood & impact; document risks.
- Mitigate Risk — Identify and implement layered controls.
- Detect Attacks — Monitor systems and analyze digital evidence.
- Collaborate — Team objectives, role assignment, responsible AI use.
Foundational preparation for NICE work roles: Cybersecurity Analyst, Vulnerability Assessment Analyst, Incident Responder, and more.