T Level Digital: Core Knowledge

The Digital core is examined on paper, which means it is not testing whether you can build anything. It is testing whether you can take a described organisation with a described constraint and say what follows. So every question here is a workplace: a retailer with free text in a database column, a construction firm whose staff keep typing passwords into fake login pages, a care organisation whose risk register names ransomware, a start-up whose traffic rises fiftyfold for a few hours a month.

Several of the wrong options are the ones that sound like good practice and do not answer the question asked. Encryption at rest is a genuine control and does nothing at all against ransomware, because the attacker is not reading your data — they are locking it, on top of your encryption. Blocking all incoming external email would stop phishing and would also stop the firm trading. Owning your own servers gives you physical control, which is an argument for on-premises rather than an advantage of the cloud. Each explanation says why the correct answer follows from the situation as stated and what the tempting alternative gets wrong.

The legislation questions turn on the distinctions that carry marks: who is the controller when one firm decides what to send and another firm sends it, and why using a colleague's password to open a payroll system engages the Computer Misuse Act at the moment of access rather than only once something is copied.

Every organisation named here is invented. T Level technical qualifications are awarded by several organisations under licence, each with its own specification and assessment materials, and nothing here is reproduced from any of them — what is practised is the technical content the course covers whichever version you are on.

Zestly is an independent study tool. It is not affiliated with any awarding organisation, and it is not an exam centre.

  • Classify data as structured or unstructured from its own shape rather than from where it is stored
  • Say what cleaning a dataset achieves, and what happens to an analysis run without it
  • Match a security control to the harm it actually limits, including why encryption at rest does not answer ransomware
  • Identify the data controller when processing is split between two organisations
  • Say which legislation an unauthorised access breaches, and at what moment
  • Choose between agile and waterfall from what the client knows about their own requirements
  • State what a requirements specification is for, and judge cloud against on-premises hosting from the shape of the demand
  • Identify who gains and who bears the cost when an organisation automates a service

Aldermoor Care, an invented organisation, keeps its records on a server in its office. Its risk register names ransomware as the biggest threat: an attacker encrypting the server and demanding payment for the key. Which control does most to limit the harm if that happens? — one of ten workplace scenarios written for this set.

Sample question

Marlowe Prints, an invented online retailer, stores customer feedback as free-text comments in a column of its orders database. How should that feedback be classified?

See the answer

As unstructured data, because it follows no predefined model

Unstructured data has no predefined model. Free text is a sentence rather than a field with a known type and range, and two comments have nothing in common structurally. The closest wrong answer is the first, and it is the commonest mistake here: sitting inside a database does not make data structured, because structure is a property of the data itself and not of what is holding it. Metadata is data about data, such as when the comment was left, and counting how many comments exist does not make the comments quantitative.

Try this quiz →Try this exam →Try this written work →

← Digital

↑ T Levels and BTEC