Establishing precise terminology
Cyber security consists of the processes, practices and technologies designed to protect networks, computers, programs and data from attack, damage or unauthorised access. That is the definition worth committing to memory precisely, because exam answers in this area are graded on the accuracy of the terminology used, not merely on a general sense of the right idea. Students who describe a threat correctly but then reach for an imprecise catch-all term such as hacking, when the specification actually distinguishes several named categories of threat, will typically lose marks that a precise answer would have kept. This oxfordaqa igcse computer science cyber security guide sets out the three sections of the specification in the order they are examined: the concept of cyber security itself, the specific threats a system faces, and the methods used to detect and prevent those threats.
Cyber security
The definition above establishes the scope of the subject: cyber security is not one single technology or technique, but the entire combined set of processes, practices and technologies aimed at protection. When asked to describe the main purposes of cyber security, a precise answer identifies what is being protected, networks, computers, programs and data, and from what, attack, damage and unauthorised access, rather than offering a vague statement about keeping systems safe.
Cyber security threats
The specification identifies six categories of threat: social engineering techniques, malicious code, weak and default passwords, misconfigured access rights, removable media, and unpatched or outdated software. Precision matters here too: each of these is a distinct route by which a system's security can be compromised, and an exam answer should name the correct category rather than describing symptoms in general terms.
Social engineering
Social engineering is the art of manipulating people so that they divulge confidential information, exploiting human trust rather than a technical vulnerability. Four specific forms are named on this specification, and each has a precise definition that should not be blurred with the others.
| Term | Precise definition |
|---|---|
| Blagging (pretexting) | Creating and using an invented scenario to engage a targeted victim, increasing the likelihood they will divulge information or perform an action they would not ordinarily perform |
| Phishing | Fraudulently obtaining private information, often using email or SMS designed to appear legitimate |
| Pharming | A cyberattack intended to redirect a website's traffic to another, fraudulent site |
| Shouldering (shoulder surfing) | Observing a person's private information directly, such as a PIN entered at a cash machine |
Note the precise distinction between phishing and pharming: phishing typically relies on a deceptive message prompting the victim to act, while pharming redirects traffic without necessarily requiring the victim to click anything at all, which is what makes it a distinct threat rather than a variant of phishing.
Malicious code
Malware is an umbrella term referring to a variety of forms of hostile or intrusive software. Four specific forms are named, and again, precision in distinguishing them is what an exam answer is graded on.
| Term | Precise definition |
|---|---|
| Computer virus | Malicious code that attaches itself to a legitimate file or program and spreads when that host is executed or shared |
| Trojan | Malicious code disguised as legitimate, harmless software to trick a user into installing it |
| Spyware | Software that covertly gathers information about a user's activity without their informed consent |
| Adware | Software that automatically displays or downloads unwanted advertising material |
The remaining threat categories
Weak and default passwords are precisely what the name suggests: credentials that are either easily guessed or left unchanged from a manufacturer's default setting, both of which give an attacker an unnecessarily easy route into a system. Misconfigured access rights occur when a user or process has been granted more access than their role actually requires, widening the potential damage if that account is compromised. Removable media, such as a USB drive, poses a risk both by carrying malware onto a secure network and by allowing data to be carried off it without authorisation. Unpatched or outdated software is software still carrying known vulnerabilities that a vendor has already issued a fix for, but which has not been applied.
Penetration testing
Penetration testing is the process of attempting to gain access to resources without prior knowledge of usernames, passwords and other normal means of access, carried out deliberately to find and fix weaknesses before a real attacker does. Two forms are distinguished precisely on this specification: a white-box penetration test simulates a malicious insider, someone who already has knowledge of, and possibly basic credentials for, the target system; a black-box penetration test simulates an external attack, carried out with no prior knowledge of the system at all. Using exactly this white-box and black-box terminology, rather than looser phrases such as inside attack or outside attack, is what an examiner is specifically looking for.
Methods to detect and prevent cyber security threats
Five specific measures are named, each addressing a different point in the chain between a legitimate user and an attacker.
- Biometric measures, particularly for mobile devices: authentication based on a physical characteristic, such as a fingerprint or facial recognition, which is far harder for an attacker to replicate than a memorised credential.
- Password systems: authentication based on a secret known only to the legitimate user, whose effectiveness depends heavily on password strength and how carefully it is protected.
- CAPTCHA, or similar: a test designed to distinguish a genuine human user from an automated program, typically used to prevent automated attacks such as repeated password guessing.
- Email confirmation of identity: verifying a user's identity by requiring a response to a message sent to a previously verified email address, adding a layer of confirmation beyond a single password.
- Automatic software updates: reducing the window of exposure to a known vulnerability by applying a vendor's fix as soon as it becomes available, directly addressing the unpatched and outdated software threat named above.
A precise exam answer connects a given prevention method back to the specific threat it addresses, rather than listing prevention methods and threats as two unrelated sets of facts. Automatic software updates address unpatched and outdated software directly; strong password systems and biometric measures both address weak and default passwords; CAPTCHA addresses automated attempts to exploit weak credentials at scale.
Worked example: matching a scenario to the correct threat category
Consider a scenario in which an employee receives an email that appears to come from their organisation's IT department, asking them to confirm their login details by clicking a link to a website that closely resembles the real company portal. The precise term for this scenario is phishing, since it uses a deceptive message to prompt the victim into an action, rather than pharming, which would redirect the employee to a fraudulent site without any such message being sent. If, instead, the employee's browser had been silently redirected to a fake banking site despite typing the correct address directly, that would be pharming. Being able to distinguish these two scenarios precisely, using the exact vocabulary above, is a reliable way to demonstrate the level of understanding this topic rewards.
A second useful exercise is matching prevention methods to threats directly. A misconfigured access right is best addressed not by any of the five listed prevention measures alone, but by careful management of user permissions, which is a reminder that not every threat maps neatly onto a single named prevention method; some threats are addressed through good administrative practice rather than a specific technology.
Common mistakes to avoid
- Using phishing and pharming interchangeably, when they are precisely defined as distinct techniques.
- Describing malware in general terms without naming the specific form, virus, trojan, spyware or adware, that the scenario actually describes.
- Confusing white-box and black-box penetration testing, or reversing which one assumes prior knowledge of the system.
- Naming a prevention method without connecting it explicitly to the threat it is intended to address.
- Treating cyber security as synonymous with antivirus software alone, rather than the full combined set of processes, practices and technologies the definition actually covers.
Self-check questions
- State the precise definition of cyber security as given by this specification.
- Distinguish precisely between blagging and phishing, using the definitions above.
- Explain the difference between a computer virus and a trojan.
- Explain the difference between a white-box and a black-box penetration test.
- For each of the five prevention methods listed, state which threat category it most directly addresses.
Precision of language is the single most examinable skill in this topic, more so than in almost any other part of the specification, so treat every definition above as something to reproduce exactly rather than approximately. These oxfordaqa igcse computer science revision notes on cyber security are written with that precision deliberately built in, term by term, and working through a fresh round of oxfordaqa igcse computer science practice questions against these exact definitions is the most reliable way to prepare.
Connecting this to computer networks
Several of the prevention methods here, encryption, firewalls and MAC address filtering among them, are examined together with the computer networks section of the specification, so revising the two topics closely together strengthens both. Keep this page among your core oxfordaqa igcse computer science notes for the igcse 9210 cyber security content, and treat every term above as fully oxfordaqa igcse computer science explained, precise and ready to be reproduced under exam conditions rather than approximated from memory. Any student researching cyber security oxfordaqa igcse material should expect exactly this level of definitional precision to be demanded in return.
Oxfordaqa igcse computer science cyber security explained: threats, social engineering, malware and detection methods with precise definitions.
Comment(s)