RevisionTown course hub

AP® Cybersecurity

Study AP® Cybersecurity concepts unit by unit with focused lessons designed for clear, practical revision. This course hub covers security fundamentals, physical spaces, networks, devices, applications, data security, artificial intelligence, and cryptography.

Unit 1 – Introduction to Security

Build awareness of human-centered threats, suspicious login pages, public-network risks, and the changing role of artificial intelligence in attacks and defense.

Topic 1.1

Understanding Social Engineering

Learn how attackers influence people through phishing, pretexting, urgency, impersonation, and other psychological techniques—and how to recognize and resist them.

Study Understanding Social Engineering →
Topic 1.2

Suspicious Website Logins

Practice checking domains, URLs, HTTPS, certificates, page design, redirects, and other clues before entering account credentials.

Study Suspicious Website Logins →
Topic 1.3

Best Practices for Public Networks

Understand evil twins, traffic interception, session risks, and the practical protections that make public Wi-Fi use safer.

Study Public Wi-Fi Safety →
Topic 1.4

AI-Based Cybersecurity Attacks

Explore how artificial intelligence can make phishing, impersonation, automation, and malicious activity faster or more convincing while staying focused on defensive awareness.

Study AI-Based Cybersecurity Attacks →
Topic 1.5

Leveraging AI in Cyber Defense

Learn how defenders use AI for anomaly detection, behavior analysis, malware and fraud detection, prioritization, and response—with essential human oversight.

Study AI in Cyber Defense →

Unit 2 – Securing Spaces

Connect digital cybersecurity with facilities, restricted areas, environmental safeguards, physical access, surveillance, and safe incident reporting.

Topic 2.1

Cyber Foundations

Master the CIA triad, assets, threats, vulnerabilities, risks, controls, least privilege, defense in depth, access control, and basic risk assessment.

Study Cyber Foundations →
Topic 2.2

Physical Vulnerabilities and Attacks

Identify how unsecured facilities, tailgating, device theft, malicious peripherals, improper disposal, insiders, and environmental hazards can expose digital systems.

Study Physical Vulnerabilities and Attacks →
Topic 2.3

Protecting Physical Spaces

Study layered controls including boundaries, locks, badges, visitor procedures, surveillance, secure rooms, device protection, and environmental resilience.

Study Protecting Physical Spaces →
Topic 2.4

Detecting Physical Attacks

Recognize unauthorized entry, badge misuse, tampering, suspicious peripherals, visual exposure, environmental threats, and the evidence needed for safe escalation.

Study Detecting Physical Attacks →

Unit 3 – Securing Networks

Learn how network weaknesses are attacked, then apply policy, wireless security, segmentation, firewalls, monitoring, and investigation to reduce risk.

Topic 3.1

Network Vulnerabilities and Attacks

Distinguish vulnerabilities, threats, exploits, attacks, and risks while examining insecure configurations, spoofing, interception, denial of service, and unauthorized access.

Study Network Vulnerabilities and Attacks →
Topic 3.2

Protecting Networks: Managerial Controls and Wireless Security

Connect organizational policies, training, reviews, vendors, and change management with WPA2/WPA3, secure authentication, guest isolation, and wireless monitoring.

Study Managerial Controls and Wireless Security →
Topic 3.3

Protecting Networks: Segmentation

Learn how subnets, VLANs, zones, DMZs, microsegmentation, firewalls, and access rules limit unauthorized access and lateral movement.

Study Network Segmentation →
Topic 3.4

Protecting Networks: Firewalls

Understand inbound and outbound filtering, firewall rules, stateful inspection, proxies, WAFs, next-generation firewalls, logs, limitations, and safe rule review.

Study Firewalls →
Topic 3.5

Detecting Network Attacks

Use baselines, network and authentication logs, IDS/IPS, traffic analysis, SIEM correlation, indicators of compromise, and alert triage to investigate suspicious activity.

Study Detecting Network Attacks →

Unit 4 – Securing Devices

Protect computers, phones, tablets, servers, and IoT endpoints by understanding vulnerabilities, verifying identities, layering safeguards, and recognizing compromise.

Topic 4.1

Device Vulnerabilities and Attacks

Examine outdated software, weak authentication, unsafe applications, malware, physical access, wireless exposure, malicious peripherals, and IoT weaknesses.

Study Device Vulnerabilities and Attacks →
Topic 4.2

Authentication

Compare identity, authentication, and authorization while studying authentication factors, MFA, biometrics, passkeys, SSO, recovery, session controls, and common account attacks.

Study Authentication →
Topic 4.3

Protecting Devices

Combine updates, secure configuration, endpoint protection, firewalls, encryption, backups, application control, mobile management, physical safeguards, and secure disposal.

Study Protecting Devices →
Topic 4.4

Detecting Attacks on Devices

Recognize suspicious performance, unauthorized changes, malware indicators, security alerts, unusual connections, and logs—then isolate, document, report, and recover safely.

Study Detecting Attacks on Devices →

Unit 5 – Securing Applications and Data

Explore application and data risks, access governance, cryptography, secure development, monitoring, and incident response across software and information lifecycles.

Topic 5.1

Application and Data Vulnerabilities and Attacks

Study insecure design, coding and configuration mistakes, vulnerable dependencies, broken access control, unsafe data handling, APIs, encryption weaknesses, and supply-chain risk.

Study Application and Data Vulnerabilities →
Topic 5.2

Protecting Applications and Data: Managerial Controls and Access Controls

Learn how policies, data governance, roles, least privilege, access models, account lifecycles, MFA, reviews, logging, vendors, and recovery work together.

Study Managerial and Access Controls →
Topic 5.3

Protecting Stored Data with Cryptography

Understand data at rest, symmetric and asymmetric encryption, hashing, salts, password storage, integrity, storage-encryption layers, and the complete key lifecycle.

Study Stored-Data Cryptography →
Topic 5.4

Asymmetric Cryptography

Explore public-private key pairs, digital signatures, PKI, certificates, certificate validation, HTTPS, key establishment, RSA, ECC, and private-key protection.

Study Asymmetric Cryptography →
Topic 5.5

Protecting Applications

Apply secure SDLC, DevSecOps, safe coding, input validation, authorization, session security, dependency protection, API controls, testing, monitoring, and recovery.

Study Protecting Applications →
Topic 5.6

Detecting Attacks on Data and Applications

Use application and database logs, SIEM, FIM, DLP, baselines, anomaly detection, event correlation, evidence preservation, and incident response to follow suspicious signals.

Study Application and Data Attack Detection →

How to use this AP® Cybersecurity study guide

The five units move from human and foundational security decisions to the protection and detection controls used across facilities, networks, endpoints, applications, and data.

  1. Start with peopleRecognize social engineering, unsafe logins, public-network risks, and AI-enabled threats.
  2. Secure spacesConnect physical access and environmental safeguards with digital security.
  3. Protect networksControl communication paths using policy, wireless security, segmentation, firewalls, and monitoring.
  4. Secure endpointsProtect identities and the devices where users, applications, and data meet.
  5. Defend software and dataApply access control, cryptography, secure development, detection, and response.

What students will learn

You will practice identifying assets, threats, vulnerabilities, attacks, and risks; explaining confidentiality, integrity, and availability; selecting preventive, detective, and recovery controls; and evaluating limitations and tradeoffs.

Recommended study approach

  1. Read one lesson and define its key terms in your own words.
  2. Connect every threat to an asset, possible impact, warning sign, and layered defense.
  3. Complete the lesson quiz without notes, then study each explanation.
  4. Revisit missed concepts later and compare similar controls across units.

Use real-world reasoning

Cybersecurity questions are rarely solved by naming one tool. Ask who or what is being protected, where trust changes, which control prevents harm, what evidence detects failure, how recovery works, and what the control cannot do.

Why cybersecurity knowledge matters

Schools, homes, businesses, public facilities, cloud services, mobile devices, and critical systems all depend on trustworthy technology. Security awareness helps people make safer decisions, protect privacy, reduce disruption, and report suspicious activity responsibly.

AP® Cybersecurity frequently asked questions

1. What is AP® Cybersecurity?

AP® Cybersecurity is a course of study focused on understanding security risks and applying defensive concepts to people, physical spaces, networks, devices, applications, and data. This RevisionTown hub organizes those concepts into five units and 24 focused lessons.

2. Where should I start studying AP® Cybersecurity?

Begin with Unit 1 if the material is new. It introduces human-centered threats and everyday security decisions before later units add physical, network, device, application, data, and cryptographic controls.

3. Do I need programming experience for these lessons?

No programming experience is required to understand the defensive concepts. Some application and API topics use technical terms, but the lessons explain them conceptually without requiring executable attack code.

4. What security concepts appear across all five units?

The CIA triad, assets, threats, vulnerabilities, risk, least privilege, authentication, authorization, defense in depth, monitoring, incident response, backups, human responsibility, and control limitations recur throughout the course.

5. How should I use the lesson quizzes?

Complete each quiz after reading its lesson. Review every explanation—not only incorrect answers—then retake the quiz later without notes to check whether the concept is retained.

6. What is the difference between prevention and detection?

Preventive controls reduce the chance or impact of harmful activity, while detective controls identify suspicious events or control failures. Recovery controls restore safe operations. Strong cybersecurity combines all three.

7. Why are physical security and cybersecurity taught together?

Physical access can expose devices, credentials, network equipment, documents, and stored data. Locks, visitor procedures, secure rooms, surveillance, and environmental protections therefore support digital confidentiality, integrity, and availability.

8. Why is cryptography included in application and data security?

Cryptography can protect stored and transmitted data, verify integrity, authenticate systems, support digital signatures, and establish secure session keys. It still depends on access control, key management, patching, monitoring, and backups.

9. Are these lessons focused on ethical and defensive cybersecurity?

Yes. The lessons emphasize awareness, prevention, detection, reporting, authorized testing, incident response, and responsible use. They do not provide malicious payloads, bypass instructions, or unauthorized exploitation steps.

10. How can I prepare for scenario-based cybersecurity questions?

Identify the asset and threat, distinguish the weakness from the attack, explain the likely confidentiality, integrity, or availability impact, select layered controls, describe detection evidence and recovery, and state each control’s limitations.

AP® is a trademark registered by the College Board, which is not affiliated with and does not endorse this RevisionTown course hub.