Five AP-format multiple-choice questions covering the full lesson. No predict-gate — this mirrors the real exam experience. Mix of single-best-answer, I/II/III multi-correct, spot-the-error, and EXCEPT formats. Per-option feedback after submission.
5 QuestionsAP Exam Format~15 minNo Predict-Gate
Score0 / 5
Question 1
An organization has a SIEM that generates high-quality alerts on privilege escalation events. The on-call analyst typically responds by: (a) checking the affected user in the identity provider, (b) disabling the account if unauthorized, (c) opening a ticket. The team wants this response to happen automatically within 30 seconds of alert generation, without human delay. Which technology is the correct addition?
Question 2
A security engineer is drafting a log-level policy for a new microservice. Consider the following three statements about production logging:
I. DEBUG-level logs should be shipped to the SIEM along with WARN and ERROR because more data enables better investigations. II. Authentication failures should be logged at ERROR level, not INFO, because every failure is a potential attack indicator. III. CRITICAL-level events should both ship to the SIEM and page the on-call analyst.
Which statement(s) are correct?
Question 3
A SIEM engineer writes the following correlation rule to alert on data exfiltration. It has never fired despite a known insider-threat incident last quarter where an employee exfiltrated 40 GB of customer data over three weeks.
ALERT IF user.daily_outbound_bytes > 5_000_000_000 WITHIN 24 HOURS
What structural flaw lets a 40 GB exfiltration over three weeks evade this rule?
Question 4
The following controls all protect log integrity against a post-breach attacker with root on the logging host, EXCEPT:
Question 5
During a breach response, the SOC performs the following actions. Which action is an example of eradication in the NIST SP 800-61 incident response lifecycle?
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed.
Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Typically responds within 24 hours
✓
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
34.8% of Tanner’s CSP students score 5s. The national average is 9.6%.
I’m a Student
I’m a Teacher
✓Free AP CSP Big Ideas cheat sheet (PDF)
✓Daily practice questions covering all 5 Big Ideas
✓Create Task tips that actually work — from a real AP teacher
✓Free class codes with student progress tracking
✓3 full practice exams + Top 100 questions for your class
✓Create Task guidance and pseudocode reference sheets
Which AP CS exams are you prepping for?
✓
You’re in!
Your Big Ideas cheat sheet is on its way.
No thanks, I’ll figure it out myself
Avg student improvement: 2+ score levels | Real AP teacher, not just a tutor
AP Cybersecurity — National Launch 2026–27
Get Early Access to AP Cyber
AP Cyber launches nationally fall 2026. Get in early to help shape the course — start free with Unit 1 and the free teacher gradebook.
✓
You’re in — you’re on the AP Cyber early-access list!
Tanner will follow up personally within 48 hours. Your feedback will directly shape what gets built.
Step 1 of 4
Early Access — Limited Spots
Who are you?
Are you a teacher or a student?
I’m a Teacher
I’m a Student
Free to start — Unit 1 and the teacher gradebook are always free, no credit card.
Founding teachers unlock all 5 units and get direct input on what we build.
Not interested right now
Step 2 of 4
Your School
Tell us about your class
Other AP CS courses you teach
Your Situation
Tell us about yourself
Step 3 of 4
Classroom Needs
What does your classroom need? (select all that apply)
How You Study
What would help you most? (select all that apply)
Step 4 of 4
Almost Done
Where should we send your early-access details?
Free gradebook + Unit 1 | Your feedback shapes the course | Built by a real AP teacher