GCSE Computer Science: Cyber Security and Impacts

Half of this topic is about defending a system and half is about what computing costs somebody other than the buyer. Both halves are asked as situations, and every wrong option is an answer students actually give.

An email claims to come from a school IT office and asks a pupil to confirm their login details. The right move is to check through a channel already known to be genuine, and the reason worth remembering is the one stated in the answer: a real IT office does not ask for a password. Replying to find out whether the message is genuine is among the options, because that is what people do.

Then the ordinary defences, each tied to why it works. A patch closes something the supplier has already fixed, which is why an old version is the risk. One password used on several sites is a single point of failure, and the remedy is distinct passwords plus a second factor rather than simply a longer one. Accounts that can read and change everything are contrasted with permissions matched to a role, which is the principle of least privilege. And a firm whose only copy of its records sits on the same drive as the records has no backup at all — with the second half of the answer being that the restore has to have been tried, because an untested backup is an assumption.

Penetration testing is included because the legal point is worth being precise about: the work is lawful because the owner asked for it and the limits were agreed in writing beforehand, not because the tester is skilled or well-intentioned, and what the client receives is an ordered list of what to fix.

The impacts half opens with data: an organisation collecting more than it needs and keeping it for a decade breaks two named principles. Licensing is then separated from price — a program supplied with its source under a licence permitting modification is open source, one supplied finished under a licence forbidding copying is proprietary, and a proprietary program can still cost nothing to download, which is the confusion the question exists to correct. Replacing working machines every two years is costed in manufacturing and disposal rather than only in electricity. And a service moved entirely online, where some of the people who need it have no reliable connection, is named as the digital divide and treated as something the organisation should design around.

Everything here is defensive. No attack, method, tool or form of wording is described anywhere; threats are named only alongside the measure that answers them. Every school, organisation and person is invented, and no real company, product or piece of software is named. Nothing is reproduced from any exam board specification, past paper or mark scheme.

Zestly is an independent study tool. It is not affiliated with any exam board and it is not an exam centre.

  • Respond to a suspicious request by verifying through a known channel, and say why
  • Explain what installing a patch achieves
  • Give the remedy for a reused password, including a second factor
  • Name the principle behind permissions matched to a role
  • Say what makes a backup usable, including the tested restore
  • State what makes security testing lawful and what it produces
  • Name the data protection principles a described practice breaks
  • Separate an open source licence from a proprietary one, and both from price
  • Cost the replacement of working hardware in manufacturing and disposal
  • Name the digital divide and treat it as a design problem

Ten invented situations: an email asking a pupil to confirm a login, an accounting program several versions behind, one password used everywhere, a school where every account can change every file, a firm whose backup shares a drive with the records, a retailer commissioning a security test under a written agreement, an agency keeping data for a decade, two products under two licences, an office replacing working machines every two years, and a service moved wholly online. Twelve flashcards carry the vocabulary — social engineering, malware, patch, two-factor authentication, user access level, least privilege, backup, penetration testing, data minimisation, open source and proprietary licences, digital divide.

Sample question

A student at Oakwood Academy receives an email claiming to be from the school IT office, asking them to click a link and confirm their login details. What is the most secure way for the student to handle this?

See the answer

Contact the IT office through a known, trusted channel to report the email, as they would never ask for a password.

A genuine IT department will never ask for your password. Replying or clicking links in suspicious emails risks exposing your credentials to attackers. Always use a known, trusted contact method to verify requests.

Try this quiz →Try this exam →Practice these flashcards →Try this written work →

← Computer Science

↑ GCSE