Skip to main content
Free · No account needed

AP® Cybersecurity Practice Test

Test yourself with 25 original multiple-choice questions written by Prep Den, five from each unit of AP Cybersecurity: Introduction to Security, Securing Spaces, Securing Networks, Securing Devices, and Securing Applications and Data. The questions range from core definitions to scenarios where you analyze a risk, choose a mitigation, or read a log for signs of an attack.

Answer every question, then submit to get your score out of 25, a breakdown by unit, and an explanation for each answer. The real exam allows about 80 seconds per multiple-choice question; to practice that pace, start the optional 33-minute timer.

An independent Prep Den resource. Original practice material written for the current course framework; not official College Board material.

0 of 25 answered · suggested time 33 min

  1. Question 1

    An adversary floods a company website with traffic until it goes offline. Which goal of the CIA triad is violated?

  2. Question 2

    An adversary slips through a secure door immediately behind an employee who does not notice them. This attack is BEST described as:

  3. Question 3

    An adversary sends falsified ARP packets to the default gateway so the target's IP address is linked to the adversary's MAC address. This is an example of:

  4. Question 4

    An adversary releases malware that copies itself across the network from machine to machine without anyone clicking anything. Which type is it?

  5. Question 5

    An application sends user input directly into a database query without checking it. An attacker types a string of SQL commands into the input box and deletes records. What attack is this, and what would have prevented it?

  6. Question 6

    Which statement correctly describes the relationship between vulnerability, threat, and risk?

  7. Question 7

    A company installs cameras and motion sensors so it can identify intrusions as they happen. These are examples of which control FUNCTION?

  8. Question 8

    Which control most directly prevents a MAC flooding attack on a switch?

  9. Question 9

    An organization needs detection on low-power embedded devices that cannot spare much memory or CPU. Which is the better fit?

  10. Question 10

    A company assigns access based on roles such as 'accountant,' so only subjects in that role can use the payroll software. Which access control model is this?

  11. Question 11

    A caller claims to be from IT and warns that your account will be locked in five minutes unless you read back the one-time code just texted to you. Which tactics are in play, and what should you do?

  12. Question 12

    A defender stops a risky activity entirely because it is not essential to the organization's mission. Which risk management option is this?

  13. Question 13

    A firewall ACL has Rule 1: ALLOW inbound TCP port 22 from ALL, then Rule 2: DENY inbound TCP ALL from ALL. What happens to inbound SSH traffic?

  14. Question 14

    An adversary steals an organization's password-hash database and runs an automated tool that hashes millions of candidate passwords on their own machine, looking for matches. Why does account lockout NOT stop this?

  15. Question 15

    A defender hashes a file, records the digest, and re-hashes it a week later to find the digest unchanged, yet the data was secretly copied by an attacker. Why did the hash check miss the breach?

  16. Question 16

    A server log shows dozens of failed logins for one account within a minute, from an unfamiliar device, at 3 a.m. This is best described as:

  17. Question 17

    After phishing an employee's password, an adversary installs a remote access trojan (RAT) so they can keep controlling the PC even if the password changes. Which attack phase is this?

  18. Question 18

    A screened subnet (DMZ) is best described as:

  19. Question 19

    A login policy stores each user's last 8 password hashes and locks the account after 4 failed attempts. These two settings are, respectively:

  20. Question 20

    A Linux file should let its owner read, write, and execute, let the group read and execute, and give everyone else no access. Which command sets this?

  21. Question 21

    A beginner with no programming skill buys a ready-made attack kit online that exploits a well-known flaw, hoping to impress other hackers. How is this adversary best classified?

  22. Question 22

    A receptionist's PC sits in the reception area, beyond which access is controlled. It stores no sensitive data but joins the internal wireless network and has exposed USB ports. Which risk level fits best?

  23. Question 23

    A firewall log shows the external address 203.0.113.25 sending TCP SYN packets to ports 21, 22, 23, 25, 445, and 3389 on one server within three seconds. Which network-based indicator of compromise does this most directly show?

  24. Question 24

    A device's auth log shows: "03:14:07 Failed password for admin from 198.51.100.23", "03:14:08 Failed password for root from 198.51.100.23", "03:14:09 Failed password for test from 198.51.100.23", "03:14:10 Failed password for guest from 198.51.100.23". Which password attack do these entries indicate?

  25. Question 25

    A file is encrypted with a 40-bit key. On average, how many guesses would an adversary who guesses keys at random need to find the correct key?

25 unanswered: they'll count as incorrect.

What to study next

  • Start with your weakest unit. The unit breakdown shows where points slipped. One unit at a time beats rereading everything.
  • Learn from each miss. Read the explanation, then restate the idea in your own words: why the right answer works and why the option you picked does not.
  • Practice with new questions. Retaking the same 25 questions measures memory more than understanding, so move on to fresh questions once you have reviewed.
  • Practice applying ideas. Many exam questions describe a situation and ask you to apply a concept to it, so practice explaining your reasoning, not just recalling terms.

Want structured review for every unit? The Prep Den AP® Cybersecurity study guide has study notes, flashcards, and more practice questions for each one.

Continue with the AP® Cybersecurity Course Companion

The full Prep Den AP® Cybersecurity study guide picks up where this free page leaves off. It includes:

  • 6 topics with full study notes
  • All 141 flashcards
  • 107 practice questions with explanations
  • 23 free-response practice problems with worked solutions
  • Term-matching games
  • A 129-term key-terms bank
  • Exam tips throughout
See the AP® Cybersecurity guide

$24.99 one-time payment, 12 months of access.