Computer Science - 9210 OxfordAQA

Cyber Security Threats

Resumen

The most effective way into a secure system has never been to defeat its encryption. It is to telephone somebody who works there, sound convincing, and ask. That is not a joke about human weakness; it is a description of how a large proportion of real breaches happen, and it is why the specification begins its list of threats with social engineering rather than with anything technical.

This lesson covers the six threats the specification names, then goes into detail on the two it expands: the four forms of social engineering, blagging, phishing, pharming and shouldering, and the four forms of malware, virus, trojan, spyware and adware. You will learn what each one actually is, how they differ from the ones they are confused with, and how organisations find their own weaknesses before somebody else does, through penetration testing.

Objetivos

  1. Understand and be able to explain the following cyber security threats:
  2. social engineering techniques
  3. malicious code
  4. weak and default passwords
  5. misconfigured access rights
  6. removable media
  7. unpatched and/or outdated software.
  8. Explain what penetration testing is and what it is used for.
  9. Define the term social engineering.
  10. Describe what social engineering is and how it can be protected against.
  11. Explain the following forms of social engineering:
  12. blagging (pretexting)
  13. phishing
  14. pharming
  15. shouldering (or shoulder surfing).
  16. Define the term ‘malware’.
  17. Describe what malware is and how it can be protected against. Describe the following forms of malware:
  18. computer virus
  19. trojan
  20. spyware
  21. adware.

Mapa mental

Este tema esta esquematizado para ver como se conectan las ideas.

Abre el mapa mental en la app

Nota de la lección

The specification names six cyber security threats and expects you to be able to explain each. They are not variations on one idea: two of them are about people, one is about hostile software, and three are about a system being left in a state that invites trouble.

Apunte completo disponible en la aplicacion Green Bridge

Instala la aplicacion Green Bridge CBT en tu movil u ordenador para acceder a toda la biblioteca IGCSE: examenes anteriores, criterios de correccion, mapas mentales, tarjetas de estudio y lecciones en audio.

Notas de lección completas con diagramas
Asistente de aprendizaje con IA
Simulacros cronometrados que se corrigen en cuanto terminas
Disponible en Android, Windows, macOS y Linux App para iOS proximamente

Evaluación de la lección

Felicitaciones por completar la lección del Cyber Security Threats. Ahora que has explorado el conceptos e ideas clave, es hora de poner a prueba tus conocimientos. Esta sección ofrece una variedad de prácticas Preguntas diseñadas para reforzar su comprensión y ayudarle a evaluar su comprensión del material.

Te encontrarás con una variedad de tipos de preguntas, incluyendo preguntas de opción múltiple, preguntas de respuesta corta y preguntas de ensayo. Cada pregunta está cuidadosamente diseñada para evaluar diferentes aspectos de tu conocimiento y habilidades de pensamiento crítico.

Utiliza esta sección de evaluación como una oportunidad para reforzar tu comprensión del tema e identificar cualquier área en la que puedas necesitar un estudio adicional. No te desanimes por los desafíos que encuentres; en su lugar, míralos como oportunidades para el crecimiento y la mejora.

  1. What is social engineering? A. Designing a computer network for a group of people B. The art of manipulating people so they give up confidential information C. Software that displays unwanted advertising D. A method of encrypting data before sending it Answer: B
  2. A user types their bank's correct web address and is taken to a convincing fake site. Which threat is this? A. Phishing B. Blagging C. Pharming D. Shouldering Answer: C
  3. Which form of malware is installed willingly by the user because it is disguised as something desirable? A. Computer virus B. Trojan C. Spyware D. Adware Answer: B
  4. Which of these is NOT one of the six threats named in the specification? A. Removable media B. Misconfigured access rights C. Unpatched software D. Power failure Answer: D
  5. A white-box penetration test is designed to simulate which kind of attacker? A. A malicious insider B. An external hacker with no knowledge of the system C. A piece of automated malware D. A careless employee Answer: A

Resuelve estas preguntas en la aplicacion

Resuelve estas preguntas en la aplicacion

Practica preguntas simuladas

¿Quieres practicar preguntas simuladas sobre Cyber Security Threats? Descarga la aplicación Green Bridge CBT para acceder a preguntas simuladas y evaluaciones completas sobre este tema.

Descarga la aplicación en Google Playstore.

Todo lo que necesitas para destacar en JAMB, WAEC y NECO.

Green Bridge CBT Mobile App
Asistente de Chat de Aprendizaje Personalizado con IA
Más de 200.000 preguntas de examen de IGCSE, JAMB, WAEC y NECO.
Más de 1200 notas de lecciones
Soporte sin conexión: Aprende en cualquier momento y lugar.
Horario del Puente Verde
Resúmenes de Literatura y Preguntas Potenciales
Controla tu rendimiento y progreso.
Explicaciones detalladas para un aprendizaje integral