Computer Science - 9210 OxfordAQA

Cyber Security Threats

Aperçu

The most effective way into a secure system has never been to defeat its encryption. It is to telephone somebody who works there, sound convincing, and ask. That is not a joke about human weakness; it is a description of how a large proportion of real breaches happen, and it is why the specification begins its list of threats with social engineering rather than with anything technical.

This lesson covers the six threats the specification names, then goes into detail on the two it expands: the four forms of social engineering, blagging, phishing, pharming and shouldering, and the four forms of malware, virus, trojan, spyware and adware. You will learn what each one actually is, how they differ from the ones they are confused with, and how organisations find their own weaknesses before somebody else does, through penetration testing.

Objectifs

  1. Understand and be able to explain the following cyber security threats:
  2. social engineering techniques
  3. malicious code
  4. weak and default passwords
  5. misconfigured access rights
  6. removable media
  7. unpatched and/or outdated software.
  8. Explain what penetration testing is and what it is used for.
  9. Define the term social engineering.
  10. Describe what social engineering is and how it can be protected against.
  11. Explain the following forms of social engineering:
  12. blagging (pretexting)
  13. phishing
  14. pharming
  15. shouldering (or shoulder surfing).
  16. Define the term ‘malware’.
  17. Describe what malware is and how it can be protected against. Describe the following forms of malware:
  18. computer virus
  19. trojan
  20. spyware
  21. adware.

Carte mentale

Ce theme est schematise pour montrer comment les idees se relient.

Ouvrez la carte mentale dans l'application

Note de cours

The specification names six cyber security threats and expects you to be able to explain each. They are not variations on one idea: two of them are about people, one is about hostile software, and three are about a system being left in a state that invites trouble.

Fiche complete disponible sur l'application Green Bridge

Installez l'application Green Bridge CBT sur votre telephone ou votre ordinateur pour acceder a toute la bibliotheque IGCSE : sujets d'examen, baremes, cartes mentales, fiches memo et lecons audio.

Notes de cours complètes avec diagrammes
Assistant d'apprentissage piloté par l'IA
Des examens blancs chronometres, corriges des que vous terminez
Disponible sur Android, Windows, macOS et Linux Application iOS bientot disponible

Évaluation de la leçon

Félicitations, vous avez terminé la leçon sur Cyber Security Threats. Maintenant que vous avez exploré le concepts et idées clés, il est temps de mettre vos connaissances à lépreuve. Cette section propose une variété de pratiques des questions conçues pour renforcer votre compréhension et vous aider à évaluer votre compréhension de la matière.

Vous rencontrerez un mélange de types de questions, y compris des questions à choix multiple, des questions à réponse courte et des questions de rédaction. Chaque question est soigneusement conçue pour évaluer différents aspects de vos connaissances et de vos compétences en pensée critique.

Utilisez cette section d'évaluation comme une occasion de renforcer votre compréhension du sujet et d'identifier les domaines où vous pourriez avoir besoin d'étudier davantage. Ne soyez pas découragé par les défis que vous rencontrez ; considérez-les plutôt comme des opportunités de croissance et d'amélioration.

  1. What is social engineering? A. Designing a computer network for a group of people B. The art of manipulating people so they give up confidential information C. Software that displays unwanted advertising D. A method of encrypting data before sending it Answer: B
  2. A user types their bank's correct web address and is taken to a convincing fake site. Which threat is this? A. Phishing B. Blagging C. Pharming D. Shouldering Answer: C
  3. Which form of malware is installed willingly by the user because it is disguised as something desirable? A. Computer virus B. Trojan C. Spyware D. Adware Answer: B
  4. Which of these is NOT one of the six threats named in the specification? A. Removable media B. Misconfigured access rights C. Unpatched software D. Power failure Answer: D
  5. A white-box penetration test is designed to simulate which kind of attacker? A. A malicious insider B. An external hacker with no knowledge of the system C. A piece of automated malware D. A careless employee Answer: A

Travaillez ces questions dans l'application

Travaillez ces questions dans l'application

Pratiquez des questions blanches

Vous voulez vous entraîner sur des questions blanches sur Cyber Security Threats ? Téléchargez lapplication Green Bridge CBT pour accéder à des questions blanches et à des évaluations complètes sur ce sujet.

Téléchargez l'application sur Google Play.

Tout ce dont vous avez besoin pour exceller au JAMB, WAEC et NECO.

Green Bridge CBT Mobile App
Assistant de chat d'apprentissage personnalisé par IA
Plus de 200 000 questions d'examen IGCSE, JAMB, WAEC et NECO.
Plus de 1200 notes de cours
Assistance Hors Ligne - Apprenez à Tout Moment, Partout
Horaire du Pont Vert
Résumés littéraires et questions potentielles
Suivez vos performances et votre progression
Explications Approfondies pour un Apprentissage Complet