Skip to main content

AP® Cybersecurity

Not weighted by unit

Unit 1: Introduction to Security

This unit starts with the security you use every day: spotting scam messages, keeping your accounts safe, using public Wi-Fi wisely and seeing through new AI tricks. You'll learn how attackers manipulate people and guess passwords, and the simple habits that stop most of these attacks. You'll also see how defenders now use AI to catch attacks faster.

Study this unit

Flashcards (35)Practice questions (52)Cybersecurity must-know sheet

Free-response questions on this unit

Write your own answer, then score it with the rubric or with AI.

Big ideas

  • Many attacks start by tricking a person, not by breaking into a computer
  • Urgency and intimidation in a message are warning signs
  • Long, unique passwords plus multifactor authentication make account takeovers much harder
  • On public Wi-Fi, check the network name and rely on encryption like HTTPS or a VPN
  • AI makes attacks more convincing, but it also helps defenders sort through huge amounts of data

Full unit reviews

Longer videos that cover the whole unit. Good for a first pass or a final review.

  • AP Cybersecurity Course Overview: All 5 Units Explained

    AP CS Exam PrepWatch on YouTube (opens in a new tab)

  • Cybersecurity and crime | Internet 101 | Computer Science | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

  • Hackers & Cyber Attacks: Crash Course Computer Science #32

    CrashCourseWatch on YouTube (opens in a new tab)

  • Social Engineering - How Bad Guys Hack Users

    IBM TechnologyWatch on YouTube (opens in a new tab)

Social engineering means tricking people into giving away information, opening a harmful file or clicking a bad link. It often arrives by email, text or social media. Watch for intimidation (threats if you don't obey) and urgency (pressure to act right now). Falling for it can hand an attacker your personal details, a one-time login code, or malware that steals data saved in your browser.

Key terms

  • social engineering
  • phishing
  • elicitation
  • intimidation
  • urgency
  • one-time password (OTP)
  • AP Cybersecurity Topic 1.1 - Understanding Social Engineering. Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Phishing - CompTIA Security+ SY0-701 - 2.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • Social Engineering in Under 3 mins (AP Cybersecurity Unit 1 Topic 1) 1.1

    Maximum InsightWatch on YouTube (opens in a new tab)

  • Phishing attacks | Internet safety | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 1.1: Social Engineering — Full Lesson Walkthrough

    AP CS Exam PrepWatch on YouTube (opens in a new tab)

  • What is Phishing

    IBM TechnologyWatch on YouTube (opens in a new tab)

Read the review notes: 1.1 Understanding Social Engineering

A few quick questions on this topic, with the answers explained.

In an online password attack, someone tries common, patterned or stolen passwords on a real login page. Warning signs are many failed logins in a short time, logins at odd hours and logins from unknown devices. Attackers build guess lists from personal details like pets' names and birthdays, so use long, random, unique passwords or passphrases (a password manager helps) and turn on multifactor authentication (MFA).

Key terms

  • online password attack
  • password patterns
  • password manager
  • passphrase
  • multifactor authentication (MFA)
  • AP Cybersecurity Topic 1.2 - Suspicious Website Logins. Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Why You Should Turn On Two Factor Authentication

    Tom ScottWatch on YouTube (opens in a new tab)

  • Password Attacks - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 1.2: Password Attacks — Full Lesson Walkthrough

    AP CS Exam PrepWatch on YouTube (opens in a new tab)

  • How to Choose a Password - Computerphile

    ComputerphileWatch on YouTube (opens in a new tab)

  • Multi-factor Authentication - Cyber Safety Series

    CYBER. ORGWatch on YouTube (opens in a new tab)

Read the review notes: 1.2 Suspicious Website Logins

A few quick questions on this topic, with the answers explained.

Low-skilled attackers use tools bought online, while high-skilled ones build their own tools and find unknown flaws called zero-days. On Wi-Fi, an attacker may set up an evil twin (a fake network with a look-alike name), jam the signal so no one can connect (a denial of service), or go war driving to find networks that reach outside a building. Protect yourself by checking the network name exactly and relying on encryption like HTTPS. A VPN hides your traffic from the local network, but the VPN provider can still see it.

Key terms

  • low-skilled vs. high-skilled adversary
  • zero-day
  • evil twin
  • jamming
  • war driving
  • virtual private network (VPN)
  • Rogue Access Points and Evil Twins - SY0-601 CompTIA Security+ : 1.4

    Professor MesserWatch on YouTube (opens in a new tab)

  • Beware of the ‘Evil Twin’ Wi-Fi scam

    NBC Bay AreaWatch on YouTube (opens in a new tab)

  • Threat Actors - CompTIA Security+ SY0-701 - 2.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • VPN (Virtual Private Network) Explained

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

  • Do VPNs Really Protect Privacy? Data & Cybersecurity Insights

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • Wireless Attacks - CompTIA Security+ SY0-701 - 2.4

    Professor MesserWatch on YouTube (opens in a new tab)

Read the review notes: 1.3 Best Practices for Public Networks

A few quick questions on this topic, with the answers explained.

Attackers use AI to clone a person's voice or face for fake calls and video chats, and to write polished phishing in any language. They also coax sensitive data out of chatbots, plant false information that ends up in AI training data, and use AI to speed up research and malware writing. You can fight back with a secret word or phrase shared with family, MFA, keeping personal data out of AI tools, and checking AI answers against reliable non-AI sources.

Key terms

  • deepfake
  • voice cloning
  • large language model (LLM)
  • AI-written phishing
  • poisoned training data
  • shared secret
  • AI ATTACKS! How Hackers Weaponize Artificial Intelligence

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • How phone scammers are using AI to imitate voices

    CBS NewsWatch on YouTube (opens in a new tab)

  • Safe Phrases: Stay safe against AI voice cloning

    StarlingWatch on YouTube (opens in a new tab)

  • Can you spot an AI scam? | BBC Ideas

    BBC IdeasWatch on YouTube (opens in a new tab)

  • How to Detect Deepfakes: The Science of Recognizing AI Generated Content

    NOVA PBS OfficialWatch on YouTube (opens in a new tab)

  • What Is a Prompt Injection Attack?

    IBM TechnologyWatch on YouTube (opens in a new tab)

Read the review notes: 1.4 AI-Based Cybersecurity Attacks

A few quick questions on this topic, with the answers explained.

Networks log millions of events a day, far more than people can read. Defenders train AI tools to sort likely attacks from harmless activity, alert the security team and even take quick corrective action. AI can also review firewall rules, scan code for vulnerabilities and suggest detection rules, but a knowledgeable person should always check its suggestions before they're used.

Key terms

  • threat detection
  • triage
  • alert
  • automated response
  • AI code review
  • human review
Read the review notes: 1.5 Leveraging AI in Cyber Defense

A few quick questions on this topic, with the answers explained.