Question 1 Report
A school has received several emails that appear to be from its cloud-storage provider. The emails state that the recipient’s account will be deleted unless they use a link to sign in. The link opens a website that looks similar to the real provider’s login page. At the same time, a workstation in the school office has become very slow and displays a message demanding cryptocurrency in exchange for access to its files.
(a) Identify the social-engineering attack represented by the email and fake login site. [1]
(b) Identify the malware suggested by the cryptocurrency demand. [1]
(c) State what the attacker is trying to obtain using the fake login page. [1]
(d) State one sign that could make the email suspicious. [1]
(e) Give two actions a teacher should take on receiving this email. [2]
(f) Complete the sentence: software that detects and removes malicious programs is called ________ software. [1]
(g) Convert the hexadecimal value 3F to denary. [2]
(h) Give two measures the school can use to reduce the effect of ransomware on its files. [4]
(i) State one benefit of using multi-factor authentication in addition to a password. [2]
(a) The email and imitation login website are a phishing attack. Phishing uses a convincing-looking message or website to trick a user into disclosing information. [1 mark]
(b) Malware that demands cryptocurrency in exchange for access to files is ransomware. Ransomware commonly encrypts or otherwise blocks access to files and demands payment. [1 mark]
(c) The attacker is trying to obtain the user’s login credentials, such as their username and password. [1 mark]
(d) One suspicious sign is an urgent threat, such as claiming that the account will be deleted unless the recipient acts immediately. Genuine providers should be checked independently rather than through an unexpected email link. Other valid signs include an unfamiliar sender address, spelling or grammar errors, a mismatched URL, or an unexpected request to sign in. [1 mark]
(e) Two appropriate actions are:
Other valid actions include deleting or quarantining it, independently visiting the genuine provider website, or warning other users as instructed by IT. [2 marks]
(f) Software that detects and removes malicious programs is anti-malware software. Antivirus is also accepted. [1 mark]
(g) In hexadecimal, \(3\) represents three sixteens and \(F\) represents \(15\).
\[3F_{16}=3\times16+15=48+15=63\]
The denary value is 63. [2 marks]
(h) Two developed measures to reduce the effect of ransomware are:
Other valid developed measures include using anti-malware and endpoint protection, restricting user permissions so malware cannot access all files, training users to recognise phishing, and network segmentation to limit spread. For full credit, each measure needs its protective effect, not just a list of tools. [4 marks]
(i) Multi-factor authentication requires another factor, such as an authenticator code or biometric check, in addition to the password. Therefore, a stolen or guessed password alone is insufficient for an attacker to access the account. [2 marks]
Everything you need to excel in your exams