About This Webinar
Get ready for your first month of AP Cybersecurity with practical guidance and classroom-ready resources. We'll cover how to launch the course, navigate the curriculum, and introduce students to foundational cybersecurity concepts. You'll also explore a demo course section and see how the new CodeHS Cyber Range add-on feature brings hands-on Linux commands, simulations, and Capture the Flag (CTF) challenges.
Recommended time frame: 60 minutes
Master teaching your first month of AP Cybersecurity on CodeHS with expert guidance on lesson pacing, hands-on activities, and key classroom strategies.
Full Transcript
Read the complete transcript of this webinar
Thank you for joining. I'm going to give everybody a couple seconds to get in here. We have a couple—oh, good. We have people joining and getting in. This is great. Let me shut my bookmarks off here. Good, good, good, good. Love this. Welcome.
All right, we'll wait a couple more minutes, see if anybody else joins, and we'll go ahead and get started. If you would like to tell us where you're from in the chat as we are waiting, we'd love to hear from you. Well, let's make sure that you guys have chat access first. We should probably do that. Yep, anybody can, everybody can. Yep, good.
Where are you guys from? Let us know, or let us know if you have been teaching AP Cyber yet. I would love to know that as well. All right. Okay, we're going to go ahead and get started here.
Hello, everyone. Thank you—who is it from Florida? I think I need to make my text a little bigger; I can't see. You're in lesson 2.10? That's great, that's absolutely great. Well, for 2.10, you actually might be a little bit farther than anything we're teaching today then. That's absolutely great. Perfect. Okay.
So, what we're going to do today is—thank you for joining, first of all—we're going to talk about your first month teaching AP Cybersecurity. I do have a link to the slides here that we're going to put into the chat, and when we do that, you are free to follow along on the slides. If it's not working, please let us know. I think I shared it, I just want to be sure. But you'll have access to the slides after the webinar as well.
What I have done is, if you have an AP Cyber section, I went into everybody that had registered accounts. I made sure if you had an AP Cyber section, you could kind of follow along. If you didn't have one, I went in and created a demo section for you. So, you can follow along on some of the things that we are going to be looking at today. Every person who is in here today does have some form of demo teacher section. If it is a demo section, it'll actually say your first name, "Demo AP Cybersecurity." That is a section where it should have five fake student data entries in it, and it should be the full course. It was just kind of to save time. Okay.
So today, just to let you know, my name is Lean Grant. I'm a PD specialist here at CodeHS. I've been here for three and a half years. Before that, I was a computer science teacher in the classroom. I taught middle school and high school computer science. I actually was the one that wrote the majority of the Teaching AP Cyber course to go along with the AP Cyber student course as well, so I have a lot of information to be able to share with you today. With me, I have Danielle. Danielle is going to be in the chat and in the Q&A here with us today and kind of in the background if you guys have any questions, and we'll go from there.
All right. So, we are today going to talk about some things here. We're going to talk about basic—I kind of didn't want to do this by weeks because everybody's schedule is very, very different. So, when I say you're teaching your first month, sometimes people will be four weeks, and that might be six weeks for others. How I did this was, we're going to talk about the foundations, then threats in AI, then the next week is kind of like the big pivot, and then we go into the CodeCraft attack. That kind of gets us through where we would end technically our first month, which no matter what, takes four to six weeks. Okay? We do have a suggested pacing guide, and I am going to give that to you at the end here.
Today's attendance and AI note-takers: live attendance is required for a certificate and PD hours. AI note-taker settings need to be muted, chat disabled, everything. I don't think we have a problem today with our attendance anyway. If you do have questions, go ahead and drop them in the Q&A. Anything that is collaborative or anything that I ask you guys to give me answers back and forth on, please put them in the chat. Okay.
I think everybody that is in here today—because I saw the names before—already has a CodeHS account. But if you don't, you can go ahead and sign up for a free account at codehs.com/signup, and you will automatically get a certificate of completion emailed to you probably around 48 hours after the webinar is complete. Okay? Only live participants or attendees qualify for a certificate of completion.
So let's go ahead and get started. I am going to get this grounded basically in everyone that, when we say the first month, like I said, I'm really talking about 14 specific lessons. When I went into the AP course when I started creating the outline for the Teaching AP course, I decided it was going to be about five weeks. We tried to put it into four to five weeks; it ended up being like 21 to 25 days. So, it really depends on how long your students take and how many days you have off. Like I said, anywhere from 4 to 6 weeks, but it is lessons 1.1 through 1.10 and then again 2.1 through 2.4 in that second unit, Securing Spaces.
Several lessons do run two full days, and then some of them may take longer. Some of them might take two class periods depending on how long your class period is. If you're on a block schedule some days or not on a block schedule, everybody's lessons and classes vary. So when I say your first month, it's going to be different for everybody. Okay.
Why did we create this? This session really has one goal: by the end of the hour, you should feel oriented, not just informed. Okay? We're going to walk week by week really through the teaching at each stop and then flag specific moments that are going to trip you up as a teacher—not just what to do about them, but rather, I don't want to save them for a different segment. I want you to know what to do about those things that might trip you up or might trip your students up specifically. So, I want you to think of this as a "here's what I wish someone had kind of told me" version of your first month of teaching AP Cyber.
Okay, so let me dive in. Week one is focused on lessons 1.1 through 1.4. The priority for this week is really simple to state and really hard to execute: you really want to kill the assumption for all students on day one that cybersecurity is only for future tech professionals. It's really, really important to get that clear to your students. Also, two of the four lessons, 1.3 and 1.4, carry a lot of content, so we're going to spend a little bit more time on a couple of those.
At a glance, an overview—and we're going to do this for each of our weeks—this is four lessons, three of which carry two days. Okay? So, 1.1 is the only one that is one day in this one. Lesson 1.2 has always needed two class periods. Lesson 1.3 has enough content that it may need two class periods, and 1.4 includes a network log investigation activity, which is kind of new territory for students this early in the course, and that's why it sometimes takes a little bit longer.
All right, so let me talk about 1.1, Welcome to Cybersecurity. The whole point of the day one cybersecurity quiz that you see on day one is to lower anxiety, okay? Not to raise it. It really is generally a no-stakes quiz. It can be done as a whole class call-and-respond type thing instead of individually.
What we are actually looking at here—and I have all these tabs open here so I can look through everything for you—this is what it actually looks like here. The students are going to bring this up. It is a pre-test. Students are not expected to know anything, okay? That's why it is really low stakes. What they're actually going to do is click into "Let's Go." It's going to ask them questions—there are 20 questions. They're not expected to know these answers. For example, "A VPN, a virtual private network, helps hide your online activity." Maybe a student would say "false." Well, not quite. Okay, next: "Malware is software designed to damage or gain unauthorized access to a computer." True. Cool, I knew that one.
It gives them information on each of these. Again, you could do this as a whole class together, or you could do this individually. It's not a graded activity; it's not going to save their scores or those kinds of things. It is something just to go through and be like, "Hey, how much do you guys actually know about cybersecurity before we get started?" Okay. Like I said, very low stakes.
All right. After that, it goes into a career paths exercise. From there, the career paths exercise takes the students through exploring cyber careers. All right, and there is a reflection activity. Then after the reflection activity for that, it goes into an interests and goals activity. It says, "In this course, you'll explore many areas of cybersecurity. Take a moment to think about what interests you and what you hope to learn. Here are some topics that you're going to cover," and then you're going to answer these questions here. Okay, so it goes into an interests and goals thing at the end.
At the very end of this lesson, there is an activity called Cybersecurity in the News. Cybersecurity happens every day and often makes the news. For this activity, you're going to find a recent cyber attack and share what you learned. You don't need to understand all the technical details; focus on the big picture because they're looking for cybersecurity attacks. Use complete sentences, answer real questions, everything. They're going to look for these. One of the things that you need to do possibly is have one or two backup news examples ready in case students can't find them or they don't know necessarily what they're looking for. You might want to have those ready kind of in your back pocket. So, you might want to do a little bit of research on your own before this activity so you have those available for students that don't have something, or you can help them find that research there. All right. Any questions about 1.1?
All right, moving on to 1.2. This lesson opens with a slide deck called Guardians of the Digital Realm. Let me open it up here. Guardians of the Digital Realm is going to take them through this task in this cyber story where they're going to learn about this digital city, the rise of threats, and the hidden vulnerability. So, they're going to go through this little story called the Cyber Story, okay?
After that, they're going to get into a cyber term matching activity. Now, this is the most vocabulary-dense lesson in the first week, okay? It's explicitly built into two class periods. 1.2 really has a lot of vocab right off the bat. The two terms that the students are really going to get confused right off the bat are authentication and authorization, okay, within this whole unit. So, authentication—they need to remember that it is providing or proving who you are, while authorization is what you're allowed to do once you're in, okay? So that's what they need to know the difference between, but those are the two that they're really going to get tripped up on within this.
After the cyber term matching here—where they kind of just do, "Okay, authentication is proving identity, so I'm going to take that and put that here," and that's kind of how they do that matching activity—after that, they get into the AAA security framework. This can be a no-tech, offline activity if you want it to be. You can print this and they can do this completely unplugged if you would like them to, or they can do it on their computer. All right, so this is a way to get them up and moving around if you want them to do that.
After that, it moves into the Internet of Things. The Internet of Things and Cybersecurity talks about a huge network of devices, what makes a device smart, all about the internet, smart locks, and a check for understanding is at the bottom so they make sure they understand everything at the end here. Okay.
After that, one of the biggest things is the Data and CIA Triad activity. Finally, this is towards the end of the unit here. This activity has an optional handout like I said. If you want to go further, there's an article here; they're going to read this article, they're going to consider data privacy, and then they're going to answer these questions on data privacy here as well, okay? There are extension activities, so they're going to research devices, privacy policies, and things if you want to extend the activity further beyond that. Okay.
Now, I also do want to premise one thing: lesson 1.2 has four handouts. So, you might want to check out which handouts you want to use, print them, or figure out how you want to do them before class. Okay? So, there are four handouts in 1.2. All right.
All right. Next, we have 1.3, The Trick Behind Every Scam. It opens up malware basics and then it goes on to pivot to—here, let me open this up. It opens up here. They're going to go through this slideshow again. It talks about malware, and you can go in here and look at all the different things within malware: viruses, ransomware, and spyware. They're going to look through this whole interactive slideshow, and then it goes into Social Engineering: Spotting the Scam.
What they're actually going to do is listen—they can listen to the lesson or they can read it. Okay, so we do have some activities that have listening in here. They're looking at these different types here and these common tactics here, and they're going to discover these different tactics, which are psychological tactics: elicitation, intimidation, and urgency, okay? They're going to practice these at the bottom then in these different ones. They're going to look at this and they're going to say, "This one is this one," and it's going to tell them whether it's correct or not. I'm not even reading these, so I'm just going to click "intimidation" for each one. Okay, now that one's correct. Your students don't want to do that, but that's essentially what they would do after they look at each one of these. They can click on this and it expands to make it a little bit larger because on the screen it is quite small. Okay.
All right. Then it goes into our social engineering hack video, and I believe there's a reflection after that. We have a multi-factor authentication code section—the code you should never share, I'm sorry. So, we start talking about MFA. They actually use MFA, and then the whole lesson will close—hold on one second, I have another video here. This one's about phishing and how someone lost $100,000 in a phishing scam here. But this is the one here that I wanted to show you: this is all about protecting your info. Why do attackers or what do attackers do with your information? Safe habits before you get to online threats.
With this one here, they are going into these different cards and looking at the different parts of the email, the phishing email here, and they're going to decipher the different parts of the phishing email and decide whether this is a threat or not, okay? Once they decide whether it's a threat or not, they would go on to the next one. All right. So, we're going to say that that's a red flag, and that's a red flag, and I don't like that part, and that's a red flag.
After all of that, the very last activity here is they're going to go into each of these and then evaluate each one of those at the end in this reflection. And that's 1.3.
Then we move to 1.4, and it opens up with a narrative-based activity, A Tale of Authentication. 1.4 is another handout here, and again, you could print this if you wanted to; you would just have this link available for them somehow. Then there is a password test where they will have to end up doing some of this on the computer obviously, but they're going to fill out this worksheet all about password managers, passwords here, and authentication.
It also includes a dictionary attack demonstration here, so we're going to go through fictional online profiles, building a dictionary, fake login simulators, and they're going to go through all of these simulations. Finally, they're going to investigate a network log. So, this is really, really useful information to introduce this early in the course, since log reading is a student skill that keeps building throughout the rest of the unit and through the course. They're really going to have to know log reading. So if you skip over this part of the course, they might get a little bit more lost later on. This is one area that you might definitely want to spend a little bit more time on, okay—investigating network logs specifically. It gives you a scenario, and then you're going in here and looking at these different parts of the log to see what happened at these different parts and explaining it, and then there are questions here for you then to answer at the bottom.
All right. So, 1.4 doesn't specifically have a split in it, but a natural breaking point for this lesson would probably be after—let's see—yeah, it would probably be around here somewhere, like probably after this free response here and then starting into the network log. So you can spend some extra time on the network logs, or actually after the password protection if you wanted to spend a little bit more time on this stuff the next day, that would be fine too.
All right. So, week one challenge: 1.3 really can prompt students to disclose real scams. If you think about talking about scams that happened to them and their family, a lot of times students have a tendency to raise their hand and share that a family member fell for a scam, and sometimes there was real financial or emotional weight behind it. You don't want to shut it down and be cold necessarily, but you don't want it to take over the room or put that student on the spot. So, a really simple move is to acknowledge it briefly, thank them for sharing, and then redirect to the broader pattern rather than dwelling on the specifics of the story. So, just be prepared that it might happen, because students have a tendency to do that, and that's where it would happen then in the course. Okay.
All right. Week two: week two gets real with threats. In week two, we go through 1.5 through 1.8. The sequencing here is deliberate, okay? It starts with wireless attacks and threat actors, which are relatively approachable, and then it moves into increasingly unfamiliar AI territory. We're going to start talking about AI a lot in the next couple lessons here, okay?
Starting with 1.5, this lesson opens with a case file students investigate before adversary type vocabulary is named. If we look at 1.5, it's going to start out with this threat attacks activity here, and they hadn't talked about what adversary types are named yet. So then we get into 1.2, and it starts to talk about adversaries: Okay, what are adversaries? What are adversary types? You start to investigate those in an interactive notes page then as well, okay?
One of the things that I really want to focus on for this unit also is to really steer away from the hoodie hacker stereotype. Students are going to think that that's real. You really want to lean them towards real organizational actors. We want them to talk about defense. We want them to understand that AP Cyber is about defense rather than the hoodie hacker stereotype. Okay.
Getting into router security is the next one. It's a simulated admin panel that actively rejects weak passwords and default networks. They're going to talk about network security here, and then finally, it's going to wrap up with a story starter. They're going to roll the dice and create a story based on what they come up with here. So, they're going to brainstorm an outline of a fictional story about a common cyber attack, and this is what the unit ends with here, okay? After they roll the dice and create their outline, they actually create it in the last activity in the reflection here, and that is 1.5.
Like I said, one of the other things with AI starting in this lesson is that a lot of teachers will say, "I'm a cybersecurity teacher, not an AI researcher, right?" You really need to think that the one idea that makes this whole week click is that an LLM isn't actually thinking—it's just really good at guessing that next word. So, an LLM doesn't actually reason through things; it's just predicting what comes next, okay? Once that clicks with you and once it clicks with the students, the second key idea that follows naturally is the difference between what a model knows internally and what it can be manipulated into saying. If students understand that an LLM doesn't think, what can we make it do? Okay, that's what they need to understand: What can we make it do? What can we teach it to do, basically. All right. So, that's the challenge for week two—that's the first challenge for week two; I have two actually this week.
Lesson 1.6 gets into the Magneto challenge. I'm not going to go over all the lessons for this one because there's a lot in this one, but the couple of things that I want to show you are AI-Enhanced Hacking. There's an article here that talks about AI-enhanced hacking and understanding AI-powered reconnaissance and malware, and how AI has changed some things. This is a really good article and really good information for students to go through here.
This is the part that is specific: this is actually called the Gandalf challenge—that's what the activity is called—but we call it the Magneto challenge. The Magneto challenge is where students get hands-on prompt injection practice, okay? What they're actually going to do here—the directions say, "Every chatbot you have ever used has had secret instructions before you typed a single word." All the instructions are up here. This is your attack toolkit: here are all your instructions here. Then what you're going to do is choose a level; you're going to start it here. You're going to write a prompt here, okay? You're going to write a prompt here, send your prompt, and make it do something, okay? This is called prompt injection, all right? All the directions are in here, but that is exactly what they're going to do. The purpose of this is to try to get the students to level up, all right? They can choose the defenses here, or they're going to be able to see what defenses are here and get hints on how to turn these on and off. All right.
Then it also pairs really well with the other activity in this lesson called LLM Cyber Threats, which has students explore extraction attacks—tricking AI into revealing something it shouldn't. This is not the same as manipulation attacks, which corrupt AI knowledge at the source, but it's tricking AI to try to get it to give us a password, open something, or something like that. So, that's what this one is all about here. All right. Any questions about 1.6?
There is another ethics thing that I do want to point out: students are going to ask you, "Are we learning to hack?" At some point, a student's going to ask that, and it's a completely fair question. Really, if you think about it, what are we teaching them? We're teaching them all this AI reconnaissance, we're teaching them all that stuff, right? But I really need to flag that you should be ready to discuss this ethical dimension with them around AI and cybersecurity. Don't wait for the question to catch you off guard. Have your framing ready and have your understanding of how attacks work and how AI works in cybersecurity so you have this foundation and how you're going to talk about it framed ahead of time so you're not caught off guard, okay? Just know it's going to come up in your class if it hasn't already.
All right, 1.7 and 1.8. 1.7 pivots to defense. In 1.7, there is deepfake detection. The students are going to get a multi-factor authentication simulator to experience multi-factor authentication firsthand, and they're going to work through four defense pillars for safe LLM use throughout the unit in 1.7: verification, sanitation, data hygiene, and red teaming. They're going to close by building a personal AI safety plan for themselves and their families in 1.7, which is really, really cool.
Then 1.8 actually covers three ways that AI assists defenders—there are three concrete ways that it does that. There's also a Human in the Loop handout in this one specifically. That handout can run kind of long, so it can be assigned as homework if class runs short, or you can decide to take extra time the next day to do that. All right. But across both lessons, use an adversarial economics reframe: think about it as defenders don't need to stop every attack, okay? They just need to raise the cost enough that it's not worth it anymore for a hacker to try to get through, okay? That's really what students need to understand about why we put defenses up: we cannot stop every attack, but if the wall is high enough, is it really going to be worth trying to climb over? Okay. So, we can put it that way for students.
Another week two challenge is that some students might find AI-generated content entertaining rather than threatening. Not every student is going to react to deepfakes as threatening; some might find it actually funny or impressive. I would suggest as a teacher to keep it as serious as possible in the classroom, make sure that you watch the detection video yourself before assigning it, and have a plan for how to reframe their reaction if students do start finding it entertaining versus threatening or alarming. Okay.
All right, week three: for week three, this is kind of like the oddball of all the weeks because it's going to feel like three different courses all stacked together. The biggest decision isn't the quiz content or anything like that—it's how you put it all together, okay? The deepfake video is in lesson 1.7.
Like I said, this week is kind of a short week, but not a short week. We have lesson 1.9 that you're still teaching at this point, and then you have a review day, the quiz, and then you're teaching again. This is the last day of instruction for all of Unit 1, okay? 1.9 makes the case for AI-assisted detection by first making the scale of the problem really concrete: it's taking everything and putting it all together. Networks generate far more events than any human team could review manually. In 1.9, it's called The Scale Problem. It's talking about all of this, how AI helps, how AI learns to detect threats, why speed matters, and everything here, okay—and how we couldn't do it ourselves without AI now, how much longer everything would take without the use of AI.
Then it goes into AI Agents in Action. You're going to watch this video—it is a short video here. This is the IBM video. The IBM video is very short and very focused. It is a YouTube video, so you might want to preview it to make sure it works. If not, there is an alternate link right down here as well, okay?
Then there is a closing activity called Alerts and Automated Responses. The closing activity has students weigh the severity, certainty, and impact across eight scenarios to decide whether each calls for a human alert or an automated response. Which one needs which? Can we use AI alerts, or do we need to have a human in the loop? Okay, so they're taking everything back together that we needed here. All right, so that's 1.9.
Then the next thing we do in the course is go on to that quiz. Before the quiz, though, we do have a review day built in if you need it. I would suggest taking a whole day for review, okay? Like I said here—I'll go back to the slides—it's entirely up to you. CodeHS doesn't provide a scripted review, and that's deliberate. Each class is different, each student is different, and we don't know what your students are struggling with. So, you can create whatever you need to for your students specifically. If you have a Pro account, you could use QuizIQ to create it, or if you have AI Creator, you could create your own quiz review. But if you don't, you could have your students create a review, or you could create a review. There are a lot of different ways to review units with content: you could use your own AI chatbot to create review units, or anything that you want to do based on content, okay? But I would do this ahead of time and make sure that you do have something available for the students to review the content.
Then we get into lesson 1.10. That is a full quiz day, and we do recommend taking a full day to give the students the quiz. If the students finish early, you could always ask a reflection prompt so the room doesn't get restless, right? Ask them to identify one question that made them think the hardest, or one habit that they'll apply in the unit—something from the quiz that made them think. Then treat the next class really as a fresh opening: we're going to start a new unit, we're not doing it right after the quiz. Just give them a full quiz day, and then that'll be it. Now, if you have a block schedule or an extra long time, that might not apply, but for a 45-minute class time, that's probably what I would do with this. Okay.
Right after that, we start into our next unit, the beginning of Unit 2, lesson 2.1, The Art of Deception. This lesson is the genuine centerpiece for this next part, okay? The seven social engineering tactics taught are going to be taught through a simulated text message scam where students name the tactic behind each message, and then they watch the attacker escalate pressure after each refusal. It's very, very cool. It also includes five adversary types as its own caseboard activity, plus real-world grounding. There are two videos in this one: a Defcon video and a Colonial Pipeline ransomware attack video. You want to make sure that you watch that Defcon video again before class. It shows a researcher gaining account access in under two minutes, and you'll want to be ready to pause and discuss it, okay?
So in 2.1, like I said, here are our social engineering tactics—these are all the seven tactics that you're going to want to know. Here's that Defcon video that you're going to want to preview here, and the adversary types that they're going to go through here.
One of the other things that they're going to do is create a phishing email. Your challenge for week three is that you're going to teach students to write phishing emails, and you need to be familiar with all seven of those social engineering tactics before grading student submissions. When they write the phishing emails, they need to be able to use four of them in the email, so you need to be familiar with all seven of these tactics when you grade them so you understand if they're using them correctly, because in this activity, it is a free response question. Okay, so that is very important there.
Week four, the last week: it's the payoff for the entire CodeCraft arc. It's coming up, so everything from here forward is cumulative. If students come to each of these days without notes, they're not going to be able to move forward, okay? All of these days are two-day units, just so you know, okay? It's really the most complex technical content of the month, and it ends with them writing a full penetration report as well.
In the beginning of Unit 2, they're going to learn about the phases of cybersecurity. These are each of the phases, and they lead into the next one here, okay? These are the different phases of cybersecurity. Then also, they're going to learn about passive reconnaissance. They're going to watch a video here and there are some guiding questions that they're going to learn, and then they're going to learn about active reconnaissance right after that, okay? Active reconnaissance here is where they're going to learn about ports, command line interfaces, and what to look for. There is a simulated terminal down here that they will interact with on this, okay? You really need to know there is an answer here specifically, and pairing students as driver and navigator for this activity is really going to work well for this here, okay?
All right. 2.3 is Breaking In and Staying In. In this one, there are six malware types: they're going to learn about the six malware types, passwords, social engineering, and malware attacks against CodeCraft. This is the first time in the arc that they're going to defend rather than attack, also. Then it flips back, asking the students to plan how the attacker would maintain access and move laterally through the network. So they're going to plan, they're going to defend, and then they're going to go back and plan again. This contains the most common vocabulary mixup here: lateral movement versus privilege escalation, and it's worth calling out here. Planning persistence, C2, and lateral movement is what they're going to actually be working through in 2.3.
Finally, their last one is 2.4. 2.4 is the biggest written deliverable of the entire month. Students are working through two log analysis activities: in this one, they're comparing a clean log to a tampered one, and then they're going to flag suspicious network records. Then they're going to write a full penetration report at the end. What it's going to do is ask them to synthesize everything from reconnaissance through evading detection into one professional-format document through this fictional CodeCraft company. It explicitly builds to extend beyond one class period—it's definitely going to be beyond one class period; it's meant to be two. So, don't be afraid to let it run into homework, even if it goes past two class periods for this one. Okay.
Your challenge for week four, though, is log analysis is really hard for teachers, too, not just students. Most teachers haven't read a security log, and naming that openly to students is going to land better than pretending to have all the answers. If you say, "This is new to me, let's figure this out together," students are going to understand that and be more open to that than pretending maybe that you have all the answers.
All right, some wrap-up and some resources: that pacing guide I wanted to show you. I'm going to open this here and show you how this works. On this pacing guide here, you can click your schedule, whether you have a 45-minute daily, a 90-day daily, or a 90-minute every other day schedule. We understand there might be different ones than this; these are just our most general. Enter your first day of school and AP exam date. Then you can click whether you want review days or how many kickoff days you want. Do you want to do midterm exam day, final exam day, or AP exam review blocks? Then you come down here, and it will produce a planning guide for you. If you have two periods and you only want it in one, you can click this little button and it'll change it. If you don't want a certain day, you can mark it as "no class"—say maybe you're off school that day, you can mark it as "no class." Or you can insert something before or after this—you can add projects or supplemental stuff before or after this day. This is adjustable here, and it does go through the entire course, not just the first month. So this is yours to have, okay?
The other thing is, I only had an hour with you. The teaching course for the first month is like an eight-hour unit. There's so much more in depth for the first month. The full Teaching AP Cybersecurity course is 40 hours, and if you are interested in doing it, we do have it available. There is a link there that Danielle just dropped that you can go to if you would like more information on how to make that available to you.
We have our webinar feedback survey if you would kindly fill that out for us today. Does anybody have any questions that we can help answer for you before we let you go today about teaching AP Security? You can just drop them in the chat or put them in the Q&A, whichever one.
Again, your certificate of completion will be emailed to you. We do have some other free webinars coming up on our free PD page that you can look at, also. We also have codehs.com/webinars where you can watch recordings and explore different takeaways from CodeHS webinars and other things as well. Does anybody have any questions that I can answer for you on anything? It doesn't even have to be the first month—anything teaching AP Cybersecurity.
You can ask questions. What if you want to add Chapter 1 to your CodeHS course? If you currently teach AP Computer Science Principles, but there is some cybersecurity on there, can you add some of it, or is there a way to take three weeks' worth of it and shorten it? You absolutely can. When you are in a course—I'm going to go into my demo course just to show you here—what you're going to do is go over to the "Add" button on the right-hand side here and click "Add CodeHS Course." When you go to add a CodeHS course, you search for the one that you want. You can select whether you want the whole module or only specific lessons, and then click "Assign Selected." It will then be added to the bottom of your course, and you can move it up to wherever you need it. You can do that on the free version as well.
All right. Thank you guys so much for joining us today. If you have any questions in the future, you can email us or click that little button in the lower right-hand corner. Have a great day and enjoy teaching AP Cybersecurity!
All right, we'll wait a couple more minutes, see if anybody else joins, and we'll go ahead and get started. If you would like to tell us where you're from in the chat as we are waiting, we'd love to hear from you. Well, let's make sure that you guys have chat access first. We should probably do that. Yep, anybody can, everybody can. Yep, good.
Where are you guys from? Let us know, or let us know if you have been teaching AP Cyber yet. I would love to know that as well. All right. Okay, we're going to go ahead and get started here.
Hello, everyone. Thank you—who is it from Florida? I think I need to make my text a little bigger; I can't see. You're in lesson 2.10? That's great, that's absolutely great. Well, for 2.10, you actually might be a little bit farther than anything we're teaching today then. That's absolutely great. Perfect. Okay.
So, what we're going to do today is—thank you for joining, first of all—we're going to talk about your first month teaching AP Cybersecurity. I do have a link to the slides here that we're going to put into the chat, and when we do that, you are free to follow along on the slides. If it's not working, please let us know. I think I shared it, I just want to be sure. But you'll have access to the slides after the webinar as well.
What I have done is, if you have an AP Cyber section, I went into everybody that had registered accounts. I made sure if you had an AP Cyber section, you could kind of follow along. If you didn't have one, I went in and created a demo section for you. So, you can follow along on some of the things that we are going to be looking at today. Every person who is in here today does have some form of demo teacher section. If it is a demo section, it'll actually say your first name, "Demo AP Cybersecurity." That is a section where it should have five fake student data entries in it, and it should be the full course. It was just kind of to save time. Okay.
So today, just to let you know, my name is Lean Grant. I'm a PD specialist here at CodeHS. I've been here for three and a half years. Before that, I was a computer science teacher in the classroom. I taught middle school and high school computer science. I actually was the one that wrote the majority of the Teaching AP Cyber course to go along with the AP Cyber student course as well, so I have a lot of information to be able to share with you today. With me, I have Danielle. Danielle is going to be in the chat and in the Q&A here with us today and kind of in the background if you guys have any questions, and we'll go from there.
All right. So, we are today going to talk about some things here. We're going to talk about basic—I kind of didn't want to do this by weeks because everybody's schedule is very, very different. So, when I say you're teaching your first month, sometimes people will be four weeks, and that might be six weeks for others. How I did this was, we're going to talk about the foundations, then threats in AI, then the next week is kind of like the big pivot, and then we go into the CodeCraft attack. That kind of gets us through where we would end technically our first month, which no matter what, takes four to six weeks. Okay? We do have a suggested pacing guide, and I am going to give that to you at the end here.
Today's attendance and AI note-takers: live attendance is required for a certificate and PD hours. AI note-taker settings need to be muted, chat disabled, everything. I don't think we have a problem today with our attendance anyway. If you do have questions, go ahead and drop them in the Q&A. Anything that is collaborative or anything that I ask you guys to give me answers back and forth on, please put them in the chat. Okay.
I think everybody that is in here today—because I saw the names before—already has a CodeHS account. But if you don't, you can go ahead and sign up for a free account at codehs.com/signup, and you will automatically get a certificate of completion emailed to you probably around 48 hours after the webinar is complete. Okay? Only live participants or attendees qualify for a certificate of completion.
So let's go ahead and get started. I am going to get this grounded basically in everyone that, when we say the first month, like I said, I'm really talking about 14 specific lessons. When I went into the AP course when I started creating the outline for the Teaching AP course, I decided it was going to be about five weeks. We tried to put it into four to five weeks; it ended up being like 21 to 25 days. So, it really depends on how long your students take and how many days you have off. Like I said, anywhere from 4 to 6 weeks, but it is lessons 1.1 through 1.10 and then again 2.1 through 2.4 in that second unit, Securing Spaces.
Several lessons do run two full days, and then some of them may take longer. Some of them might take two class periods depending on how long your class period is. If you're on a block schedule some days or not on a block schedule, everybody's lessons and classes vary. So when I say your first month, it's going to be different for everybody. Okay.
Why did we create this? This session really has one goal: by the end of the hour, you should feel oriented, not just informed. Okay? We're going to walk week by week really through the teaching at each stop and then flag specific moments that are going to trip you up as a teacher—not just what to do about them, but rather, I don't want to save them for a different segment. I want you to know what to do about those things that might trip you up or might trip your students up specifically. So, I want you to think of this as a "here's what I wish someone had kind of told me" version of your first month of teaching AP Cyber.
Okay, so let me dive in. Week one is focused on lessons 1.1 through 1.4. The priority for this week is really simple to state and really hard to execute: you really want to kill the assumption for all students on day one that cybersecurity is only for future tech professionals. It's really, really important to get that clear to your students. Also, two of the four lessons, 1.3 and 1.4, carry a lot of content, so we're going to spend a little bit more time on a couple of those.
At a glance, an overview—and we're going to do this for each of our weeks—this is four lessons, three of which carry two days. Okay? So, 1.1 is the only one that is one day in this one. Lesson 1.2 has always needed two class periods. Lesson 1.3 has enough content that it may need two class periods, and 1.4 includes a network log investigation activity, which is kind of new territory for students this early in the course, and that's why it sometimes takes a little bit longer.
All right, so let me talk about 1.1, Welcome to Cybersecurity. The whole point of the day one cybersecurity quiz that you see on day one is to lower anxiety, okay? Not to raise it. It really is generally a no-stakes quiz. It can be done as a whole class call-and-respond type thing instead of individually.
What we are actually looking at here—and I have all these tabs open here so I can look through everything for you—this is what it actually looks like here. The students are going to bring this up. It is a pre-test. Students are not expected to know anything, okay? That's why it is really low stakes. What they're actually going to do is click into "Let's Go." It's going to ask them questions—there are 20 questions. They're not expected to know these answers. For example, "A VPN, a virtual private network, helps hide your online activity." Maybe a student would say "false." Well, not quite. Okay, next: "Malware is software designed to damage or gain unauthorized access to a computer." True. Cool, I knew that one.
It gives them information on each of these. Again, you could do this as a whole class together, or you could do this individually. It's not a graded activity; it's not going to save their scores or those kinds of things. It is something just to go through and be like, "Hey, how much do you guys actually know about cybersecurity before we get started?" Okay. Like I said, very low stakes.
All right. After that, it goes into a career paths exercise. From there, the career paths exercise takes the students through exploring cyber careers. All right, and there is a reflection activity. Then after the reflection activity for that, it goes into an interests and goals activity. It says, "In this course, you'll explore many areas of cybersecurity. Take a moment to think about what interests you and what you hope to learn. Here are some topics that you're going to cover," and then you're going to answer these questions here. Okay, so it goes into an interests and goals thing at the end.
At the very end of this lesson, there is an activity called Cybersecurity in the News. Cybersecurity happens every day and often makes the news. For this activity, you're going to find a recent cyber attack and share what you learned. You don't need to understand all the technical details; focus on the big picture because they're looking for cybersecurity attacks. Use complete sentences, answer real questions, everything. They're going to look for these. One of the things that you need to do possibly is have one or two backup news examples ready in case students can't find them or they don't know necessarily what they're looking for. You might want to have those ready kind of in your back pocket. So, you might want to do a little bit of research on your own before this activity so you have those available for students that don't have something, or you can help them find that research there. All right. Any questions about 1.1?
All right, moving on to 1.2. This lesson opens with a slide deck called Guardians of the Digital Realm. Let me open it up here. Guardians of the Digital Realm is going to take them through this task in this cyber story where they're going to learn about this digital city, the rise of threats, and the hidden vulnerability. So, they're going to go through this little story called the Cyber Story, okay?
After that, they're going to get into a cyber term matching activity. Now, this is the most vocabulary-dense lesson in the first week, okay? It's explicitly built into two class periods. 1.2 really has a lot of vocab right off the bat. The two terms that the students are really going to get confused right off the bat are authentication and authorization, okay, within this whole unit. So, authentication—they need to remember that it is providing or proving who you are, while authorization is what you're allowed to do once you're in, okay? So that's what they need to know the difference between, but those are the two that they're really going to get tripped up on within this.
After the cyber term matching here—where they kind of just do, "Okay, authentication is proving identity, so I'm going to take that and put that here," and that's kind of how they do that matching activity—after that, they get into the AAA security framework. This can be a no-tech, offline activity if you want it to be. You can print this and they can do this completely unplugged if you would like them to, or they can do it on their computer. All right, so this is a way to get them up and moving around if you want them to do that.
After that, it moves into the Internet of Things. The Internet of Things and Cybersecurity talks about a huge network of devices, what makes a device smart, all about the internet, smart locks, and a check for understanding is at the bottom so they make sure they understand everything at the end here. Okay.
After that, one of the biggest things is the Data and CIA Triad activity. Finally, this is towards the end of the unit here. This activity has an optional handout like I said. If you want to go further, there's an article here; they're going to read this article, they're going to consider data privacy, and then they're going to answer these questions on data privacy here as well, okay? There are extension activities, so they're going to research devices, privacy policies, and things if you want to extend the activity further beyond that. Okay.
Now, I also do want to premise one thing: lesson 1.2 has four handouts. So, you might want to check out which handouts you want to use, print them, or figure out how you want to do them before class. Okay? So, there are four handouts in 1.2. All right.
All right. Next, we have 1.3, The Trick Behind Every Scam. It opens up malware basics and then it goes on to pivot to—here, let me open this up. It opens up here. They're going to go through this slideshow again. It talks about malware, and you can go in here and look at all the different things within malware: viruses, ransomware, and spyware. They're going to look through this whole interactive slideshow, and then it goes into Social Engineering: Spotting the Scam.
What they're actually going to do is listen—they can listen to the lesson or they can read it. Okay, so we do have some activities that have listening in here. They're looking at these different types here and these common tactics here, and they're going to discover these different tactics, which are psychological tactics: elicitation, intimidation, and urgency, okay? They're going to practice these at the bottom then in these different ones. They're going to look at this and they're going to say, "This one is this one," and it's going to tell them whether it's correct or not. I'm not even reading these, so I'm just going to click "intimidation" for each one. Okay, now that one's correct. Your students don't want to do that, but that's essentially what they would do after they look at each one of these. They can click on this and it expands to make it a little bit larger because on the screen it is quite small. Okay.
All right. Then it goes into our social engineering hack video, and I believe there's a reflection after that. We have a multi-factor authentication code section—the code you should never share, I'm sorry. So, we start talking about MFA. They actually use MFA, and then the whole lesson will close—hold on one second, I have another video here. This one's about phishing and how someone lost $100,000 in a phishing scam here. But this is the one here that I wanted to show you: this is all about protecting your info. Why do attackers or what do attackers do with your information? Safe habits before you get to online threats.
With this one here, they are going into these different cards and looking at the different parts of the email, the phishing email here, and they're going to decipher the different parts of the phishing email and decide whether this is a threat or not, okay? Once they decide whether it's a threat or not, they would go on to the next one. All right. So, we're going to say that that's a red flag, and that's a red flag, and I don't like that part, and that's a red flag.
After all of that, the very last activity here is they're going to go into each of these and then evaluate each one of those at the end in this reflection. And that's 1.3.
Then we move to 1.4, and it opens up with a narrative-based activity, A Tale of Authentication. 1.4 is another handout here, and again, you could print this if you wanted to; you would just have this link available for them somehow. Then there is a password test where they will have to end up doing some of this on the computer obviously, but they're going to fill out this worksheet all about password managers, passwords here, and authentication.
It also includes a dictionary attack demonstration here, so we're going to go through fictional online profiles, building a dictionary, fake login simulators, and they're going to go through all of these simulations. Finally, they're going to investigate a network log. So, this is really, really useful information to introduce this early in the course, since log reading is a student skill that keeps building throughout the rest of the unit and through the course. They're really going to have to know log reading. So if you skip over this part of the course, they might get a little bit more lost later on. This is one area that you might definitely want to spend a little bit more time on, okay—investigating network logs specifically. It gives you a scenario, and then you're going in here and looking at these different parts of the log to see what happened at these different parts and explaining it, and then there are questions here for you then to answer at the bottom.
All right. So, 1.4 doesn't specifically have a split in it, but a natural breaking point for this lesson would probably be after—let's see—yeah, it would probably be around here somewhere, like probably after this free response here and then starting into the network log. So you can spend some extra time on the network logs, or actually after the password protection if you wanted to spend a little bit more time on this stuff the next day, that would be fine too.
All right. So, week one challenge: 1.3 really can prompt students to disclose real scams. If you think about talking about scams that happened to them and their family, a lot of times students have a tendency to raise their hand and share that a family member fell for a scam, and sometimes there was real financial or emotional weight behind it. You don't want to shut it down and be cold necessarily, but you don't want it to take over the room or put that student on the spot. So, a really simple move is to acknowledge it briefly, thank them for sharing, and then redirect to the broader pattern rather than dwelling on the specifics of the story. So, just be prepared that it might happen, because students have a tendency to do that, and that's where it would happen then in the course. Okay.
All right. Week two: week two gets real with threats. In week two, we go through 1.5 through 1.8. The sequencing here is deliberate, okay? It starts with wireless attacks and threat actors, which are relatively approachable, and then it moves into increasingly unfamiliar AI territory. We're going to start talking about AI a lot in the next couple lessons here, okay?
Starting with 1.5, this lesson opens with a case file students investigate before adversary type vocabulary is named. If we look at 1.5, it's going to start out with this threat attacks activity here, and they hadn't talked about what adversary types are named yet. So then we get into 1.2, and it starts to talk about adversaries: Okay, what are adversaries? What are adversary types? You start to investigate those in an interactive notes page then as well, okay?
One of the things that I really want to focus on for this unit also is to really steer away from the hoodie hacker stereotype. Students are going to think that that's real. You really want to lean them towards real organizational actors. We want them to talk about defense. We want them to understand that AP Cyber is about defense rather than the hoodie hacker stereotype. Okay.
Getting into router security is the next one. It's a simulated admin panel that actively rejects weak passwords and default networks. They're going to talk about network security here, and then finally, it's going to wrap up with a story starter. They're going to roll the dice and create a story based on what they come up with here. So, they're going to brainstorm an outline of a fictional story about a common cyber attack, and this is what the unit ends with here, okay? After they roll the dice and create their outline, they actually create it in the last activity in the reflection here, and that is 1.5.
Like I said, one of the other things with AI starting in this lesson is that a lot of teachers will say, "I'm a cybersecurity teacher, not an AI researcher, right?" You really need to think that the one idea that makes this whole week click is that an LLM isn't actually thinking—it's just really good at guessing that next word. So, an LLM doesn't actually reason through things; it's just predicting what comes next, okay? Once that clicks with you and once it clicks with the students, the second key idea that follows naturally is the difference between what a model knows internally and what it can be manipulated into saying. If students understand that an LLM doesn't think, what can we make it do? Okay, that's what they need to understand: What can we make it do? What can we teach it to do, basically. All right. So, that's the challenge for week two—that's the first challenge for week two; I have two actually this week.
Lesson 1.6 gets into the Magneto challenge. I'm not going to go over all the lessons for this one because there's a lot in this one, but the couple of things that I want to show you are AI-Enhanced Hacking. There's an article here that talks about AI-enhanced hacking and understanding AI-powered reconnaissance and malware, and how AI has changed some things. This is a really good article and really good information for students to go through here.
This is the part that is specific: this is actually called the Gandalf challenge—that's what the activity is called—but we call it the Magneto challenge. The Magneto challenge is where students get hands-on prompt injection practice, okay? What they're actually going to do here—the directions say, "Every chatbot you have ever used has had secret instructions before you typed a single word." All the instructions are up here. This is your attack toolkit: here are all your instructions here. Then what you're going to do is choose a level; you're going to start it here. You're going to write a prompt here, okay? You're going to write a prompt here, send your prompt, and make it do something, okay? This is called prompt injection, all right? All the directions are in here, but that is exactly what they're going to do. The purpose of this is to try to get the students to level up, all right? They can choose the defenses here, or they're going to be able to see what defenses are here and get hints on how to turn these on and off. All right.
Then it also pairs really well with the other activity in this lesson called LLM Cyber Threats, which has students explore extraction attacks—tricking AI into revealing something it shouldn't. This is not the same as manipulation attacks, which corrupt AI knowledge at the source, but it's tricking AI to try to get it to give us a password, open something, or something like that. So, that's what this one is all about here. All right. Any questions about 1.6?
There is another ethics thing that I do want to point out: students are going to ask you, "Are we learning to hack?" At some point, a student's going to ask that, and it's a completely fair question. Really, if you think about it, what are we teaching them? We're teaching them all this AI reconnaissance, we're teaching them all that stuff, right? But I really need to flag that you should be ready to discuss this ethical dimension with them around AI and cybersecurity. Don't wait for the question to catch you off guard. Have your framing ready and have your understanding of how attacks work and how AI works in cybersecurity so you have this foundation and how you're going to talk about it framed ahead of time so you're not caught off guard, okay? Just know it's going to come up in your class if it hasn't already.
All right, 1.7 and 1.8. 1.7 pivots to defense. In 1.7, there is deepfake detection. The students are going to get a multi-factor authentication simulator to experience multi-factor authentication firsthand, and they're going to work through four defense pillars for safe LLM use throughout the unit in 1.7: verification, sanitation, data hygiene, and red teaming. They're going to close by building a personal AI safety plan for themselves and their families in 1.7, which is really, really cool.
Then 1.8 actually covers three ways that AI assists defenders—there are three concrete ways that it does that. There's also a Human in the Loop handout in this one specifically. That handout can run kind of long, so it can be assigned as homework if class runs short, or you can decide to take extra time the next day to do that. All right. But across both lessons, use an adversarial economics reframe: think about it as defenders don't need to stop every attack, okay? They just need to raise the cost enough that it's not worth it anymore for a hacker to try to get through, okay? That's really what students need to understand about why we put defenses up: we cannot stop every attack, but if the wall is high enough, is it really going to be worth trying to climb over? Okay. So, we can put it that way for students.
Another week two challenge is that some students might find AI-generated content entertaining rather than threatening. Not every student is going to react to deepfakes as threatening; some might find it actually funny or impressive. I would suggest as a teacher to keep it as serious as possible in the classroom, make sure that you watch the detection video yourself before assigning it, and have a plan for how to reframe their reaction if students do start finding it entertaining versus threatening or alarming. Okay.
All right, week three: for week three, this is kind of like the oddball of all the weeks because it's going to feel like three different courses all stacked together. The biggest decision isn't the quiz content or anything like that—it's how you put it all together, okay? The deepfake video is in lesson 1.7.
Like I said, this week is kind of a short week, but not a short week. We have lesson 1.9 that you're still teaching at this point, and then you have a review day, the quiz, and then you're teaching again. This is the last day of instruction for all of Unit 1, okay? 1.9 makes the case for AI-assisted detection by first making the scale of the problem really concrete: it's taking everything and putting it all together. Networks generate far more events than any human team could review manually. In 1.9, it's called The Scale Problem. It's talking about all of this, how AI helps, how AI learns to detect threats, why speed matters, and everything here, okay—and how we couldn't do it ourselves without AI now, how much longer everything would take without the use of AI.
Then it goes into AI Agents in Action. You're going to watch this video—it is a short video here. This is the IBM video. The IBM video is very short and very focused. It is a YouTube video, so you might want to preview it to make sure it works. If not, there is an alternate link right down here as well, okay?
Then there is a closing activity called Alerts and Automated Responses. The closing activity has students weigh the severity, certainty, and impact across eight scenarios to decide whether each calls for a human alert or an automated response. Which one needs which? Can we use AI alerts, or do we need to have a human in the loop? Okay, so they're taking everything back together that we needed here. All right, so that's 1.9.
Then the next thing we do in the course is go on to that quiz. Before the quiz, though, we do have a review day built in if you need it. I would suggest taking a whole day for review, okay? Like I said here—I'll go back to the slides—it's entirely up to you. CodeHS doesn't provide a scripted review, and that's deliberate. Each class is different, each student is different, and we don't know what your students are struggling with. So, you can create whatever you need to for your students specifically. If you have a Pro account, you could use QuizIQ to create it, or if you have AI Creator, you could create your own quiz review. But if you don't, you could have your students create a review, or you could create a review. There are a lot of different ways to review units with content: you could use your own AI chatbot to create review units, or anything that you want to do based on content, okay? But I would do this ahead of time and make sure that you do have something available for the students to review the content.
Then we get into lesson 1.10. That is a full quiz day, and we do recommend taking a full day to give the students the quiz. If the students finish early, you could always ask a reflection prompt so the room doesn't get restless, right? Ask them to identify one question that made them think the hardest, or one habit that they'll apply in the unit—something from the quiz that made them think. Then treat the next class really as a fresh opening: we're going to start a new unit, we're not doing it right after the quiz. Just give them a full quiz day, and then that'll be it. Now, if you have a block schedule or an extra long time, that might not apply, but for a 45-minute class time, that's probably what I would do with this. Okay.
Right after that, we start into our next unit, the beginning of Unit 2, lesson 2.1, The Art of Deception. This lesson is the genuine centerpiece for this next part, okay? The seven social engineering tactics taught are going to be taught through a simulated text message scam where students name the tactic behind each message, and then they watch the attacker escalate pressure after each refusal. It's very, very cool. It also includes five adversary types as its own caseboard activity, plus real-world grounding. There are two videos in this one: a Defcon video and a Colonial Pipeline ransomware attack video. You want to make sure that you watch that Defcon video again before class. It shows a researcher gaining account access in under two minutes, and you'll want to be ready to pause and discuss it, okay?
So in 2.1, like I said, here are our social engineering tactics—these are all the seven tactics that you're going to want to know. Here's that Defcon video that you're going to want to preview here, and the adversary types that they're going to go through here.
One of the other things that they're going to do is create a phishing email. Your challenge for week three is that you're going to teach students to write phishing emails, and you need to be familiar with all seven of those social engineering tactics before grading student submissions. When they write the phishing emails, they need to be able to use four of them in the email, so you need to be familiar with all seven of these tactics when you grade them so you understand if they're using them correctly, because in this activity, it is a free response question. Okay, so that is very important there.
Week four, the last week: it's the payoff for the entire CodeCraft arc. It's coming up, so everything from here forward is cumulative. If students come to each of these days without notes, they're not going to be able to move forward, okay? All of these days are two-day units, just so you know, okay? It's really the most complex technical content of the month, and it ends with them writing a full penetration report as well.
In the beginning of Unit 2, they're going to learn about the phases of cybersecurity. These are each of the phases, and they lead into the next one here, okay? These are the different phases of cybersecurity. Then also, they're going to learn about passive reconnaissance. They're going to watch a video here and there are some guiding questions that they're going to learn, and then they're going to learn about active reconnaissance right after that, okay? Active reconnaissance here is where they're going to learn about ports, command line interfaces, and what to look for. There is a simulated terminal down here that they will interact with on this, okay? You really need to know there is an answer here specifically, and pairing students as driver and navigator for this activity is really going to work well for this here, okay?
All right. 2.3 is Breaking In and Staying In. In this one, there are six malware types: they're going to learn about the six malware types, passwords, social engineering, and malware attacks against CodeCraft. This is the first time in the arc that they're going to defend rather than attack, also. Then it flips back, asking the students to plan how the attacker would maintain access and move laterally through the network. So they're going to plan, they're going to defend, and then they're going to go back and plan again. This contains the most common vocabulary mixup here: lateral movement versus privilege escalation, and it's worth calling out here. Planning persistence, C2, and lateral movement is what they're going to actually be working through in 2.3.
Finally, their last one is 2.4. 2.4 is the biggest written deliverable of the entire month. Students are working through two log analysis activities: in this one, they're comparing a clean log to a tampered one, and then they're going to flag suspicious network records. Then they're going to write a full penetration report at the end. What it's going to do is ask them to synthesize everything from reconnaissance through evading detection into one professional-format document through this fictional CodeCraft company. It explicitly builds to extend beyond one class period—it's definitely going to be beyond one class period; it's meant to be two. So, don't be afraid to let it run into homework, even if it goes past two class periods for this one. Okay.
Your challenge for week four, though, is log analysis is really hard for teachers, too, not just students. Most teachers haven't read a security log, and naming that openly to students is going to land better than pretending to have all the answers. If you say, "This is new to me, let's figure this out together," students are going to understand that and be more open to that than pretending maybe that you have all the answers.
All right, some wrap-up and some resources: that pacing guide I wanted to show you. I'm going to open this here and show you how this works. On this pacing guide here, you can click your schedule, whether you have a 45-minute daily, a 90-day daily, or a 90-minute every other day schedule. We understand there might be different ones than this; these are just our most general. Enter your first day of school and AP exam date. Then you can click whether you want review days or how many kickoff days you want. Do you want to do midterm exam day, final exam day, or AP exam review blocks? Then you come down here, and it will produce a planning guide for you. If you have two periods and you only want it in one, you can click this little button and it'll change it. If you don't want a certain day, you can mark it as "no class"—say maybe you're off school that day, you can mark it as "no class." Or you can insert something before or after this—you can add projects or supplemental stuff before or after this day. This is adjustable here, and it does go through the entire course, not just the first month. So this is yours to have, okay?
The other thing is, I only had an hour with you. The teaching course for the first month is like an eight-hour unit. There's so much more in depth for the first month. The full Teaching AP Cybersecurity course is 40 hours, and if you are interested in doing it, we do have it available. There is a link there that Danielle just dropped that you can go to if you would like more information on how to make that available to you.
We have our webinar feedback survey if you would kindly fill that out for us today. Does anybody have any questions that we can help answer for you before we let you go today about teaching AP Security? You can just drop them in the chat or put them in the Q&A, whichever one.
Again, your certificate of completion will be emailed to you. We do have some other free webinars coming up on our free PD page that you can look at, also. We also have codehs.com/webinars where you can watch recordings and explore different takeaways from CodeHS webinars and other things as well. Does anybody have any questions that I can answer for you on anything? It doesn't even have to be the first month—anything teaching AP Cybersecurity.
You can ask questions. What if you want to add Chapter 1 to your CodeHS course? If you currently teach AP Computer Science Principles, but there is some cybersecurity on there, can you add some of it, or is there a way to take three weeks' worth of it and shorten it? You absolutely can. When you are in a course—I'm going to go into my demo course just to show you here—what you're going to do is go over to the "Add" button on the right-hand side here and click "Add CodeHS Course." When you go to add a CodeHS course, you search for the one that you want. You can select whether you want the whole module or only specific lessons, and then click "Assign Selected." It will then be added to the bottom of your course, and you can move it up to wherever you need it. You can do that on the free version as well.
All right. Thank you guys so much for joining us today. If you have any questions in the future, you can email us or click that little button in the lower right-hand corner. Have a great day and enjoy teaching AP Cybersecurity!