Computer Science - 9210 OxfordAQA

Cyber Security Threats

Overview

The most effective way into a secure system has never been to defeat its encryption. It is to telephone somebody who works there, sound convincing, and ask. That is not a joke about human weakness; it is a description of how a large proportion of real breaches happen, and it is why the specification begins its list of threats with social engineering rather than with anything technical.

This lesson covers the six threats the specification names, then goes into detail on the two it expands: the four forms of social engineering, blagging, phishing, pharming and shouldering, and the four forms of malware, virus, trojan, spyware and adware. You will learn what each one actually is, how they differ from the ones they are confused with, and how organisations find their own weaknesses before somebody else does, through penetration testing.

Objectives

  1. Understand and be able to explain the following cyber security threats:
  2. social engineering techniques
  3. malicious code
  4. weak and default passwords
  5. misconfigured access rights
  6. removable media
  7. unpatched and/or outdated software.
  8. Explain what penetration testing is and what it is used for.
  9. Define the term social engineering.
  10. Describe what social engineering is and how it can be protected against.
  11. Explain the following forms of social engineering:
  12. blagging (pretexting)
  13. phishing
  14. pharming
  15. shouldering (or shoulder surfing).
  16. Define the term ‘malware’.
  17. Describe what malware is and how it can be protected against. Describe the following forms of malware:
  18. computer virus
  19. trojan
  20. spyware
  21. adware.

Mind map

This topic is mapped out so you can see how the ideas connect.

Open the mind map in the app

Lesson Note

The specification names six cyber security threats and expects you to be able to explain each. They are not variations on one idea: two of them are about people, one is about hostile software, and three are about a system being left in a state that invites trouble.

Complete Note Available on the Green Bridge App

Get the Green Bridge CBT app on your phone or computer for the complete IGCSE library: past papers, mark schemes, mind maps, flashcards and audio lessons.

Full lesson notes with diagrams
AI-powered learning assistant
Timed mock exams marked the moment you finish
Available on Android, Windows, macOS, and Linux iOS app coming soon

Lesson Evaluation

Congratulations on completing the lesson on Cyber Security Threats. Now that youve explored the key concepts and ideas, its time to put your knowledge to the test. This section offers a variety of practice questions designed to reinforce your understanding and help you gauge your grasp of the material.

You will encounter a mix of question types, including multiple-choice questions, short answer questions, and essay questions. Each question is thoughtfully crafted to assess different aspects of your knowledge and critical thinking skills.

Use this evaluation section as an opportunity to reinforce your understanding of the topic and to identify any areas where you may need additional study. Don't be discouraged by any challenges you encounter; instead, view them as opportunities for growth and improvement.

  1. What is social engineering? A. Designing a computer network for a group of people B. The art of manipulating people so they give up confidential information C. Software that displays unwanted advertising D. A method of encrypting data before sending it Answer: B
  2. A user types their bank's correct web address and is taken to a convincing fake site. Which threat is this? A. Phishing B. Blagging C. Pharming D. Shouldering Answer: C
  3. Which form of malware is installed willingly by the user because it is disguised as something desirable? A. Computer virus B. Trojan C. Spyware D. Adware Answer: B
  4. Which of these is NOT one of the six threats named in the specification? A. Removable media B. Misconfigured access rights C. Unpatched software D. Power failure Answer: D
  5. A white-box penetration test is designed to simulate which kind of attacker? A. A malicious insider B. An external hacker with no knowledge of the system C. A piece of automated malware D. A careless employee Answer: A

Work through these questions in the app

Work through these questions in the app

Practice Mock Questions

Want to practice mock questions on Cyber Security Threats? Download the Green Bridge CBT app to access mock questions and full practice assessments for this topic.

Download The App On Google Playstore

Everything you need to excel in your exams

Green Bridge CBT Mobile App
Personalized AI Learning Chat Assistant
200,000+ Exam Questions Across IGCSE, JAMB, WAEC & NECO
Over 3,900 Lesson Notes
Offline Support - Learn Anytime, Anywhere
Green Bridge Timetable
Literature Summaries & Potential Questions
Track Your Performance & Progress
In-depth Explanations for Comprehensive Learning