0% found this document useful (0 votes)
6 views34 pages

Ch5 PartB Lesson Plan - HTML

This document outlines a comprehensive lesson plan for teaching cyber security threats and solutions, structured over five lessons. It covers various types of cyber threats, including brute force attacks, DDoS attacks, malware, phishing, and social engineering, along with their definitions and prevention strategies. Additionally, it discusses security solutions such as access levels, anti-malware, authentication methods, and the importance of privacy settings and SSL.

Uploaded by

Chiranjiv Sinha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views34 pages

Ch5 PartB Lesson Plan - HTML

This document outlines a comprehensive lesson plan for teaching cyber security threats and solutions, structured over five lessons. It covers various types of cyber threats, including brute force attacks, DDoS attacks, malware, phishing, and social engineering, along with their definitions and prevention strategies. Additionally, it discusses security solutions such as access levels, anti-malware, authentication methods, and the importance of privacy settings and SSL.

Uploaded by

Chiranjiv Sinha
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IGCSE CS 0478 · CAMBRIDGE

Chapter 5 Part B
Cyber Security
Section 5.3 — Cyber Security Threats & Solutions to Keep Data Safe

🔐 Complete Lesson Plan 📝 Full Notes ✅ Solved Q&A

⏱ ~5 Lessons

§ 00

Step-by-Step Lesson Plan


This lesson plan covers Section 5.3 in full — all cyber security threats and all security
solutions — across 5 lessons of 50–60 minutes each, aligned to Cambridge IGCSE CS 0478.

LESSON PHASE TOPIC ACTIVITY & STRATEGY DURATION

1 Hook What is a cyber Show a real news headline about 8 min


security threat? a cyberattack (e.g. NHS
ransomware 2017). Ask: "How
did this happen? Could it have
been prevented?" Build curiosity
before teaching threats.

1 Teach Brute Force & Define brute force attack — 20 min


Data Interception systematic trial. Demo: show
common password list. Explain
wardriving and packet sniffers.
Why is public Wi-Fi dangerous?
Discuss.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
LESSON PHASE TOPIC ACTIVITY & STRATEGY DURATION

1 Teach DDoS Attacks & Explain DoS vs DDoS with the 18 min
Hacking analogy: "Imagine 10,000 people
all calling a single phone line at
once." Discuss hacking vs ethical
hacking — what's the difference
legally?

1 Apply Paired Students discuss: "What are 10 min


Discussion three signs a DDoS attack is
happening to you?" Share
answers with class.

1 Exit Quick recall 3 questions on whiteboard: 4 min


define brute force, wardriving,
DDoS.

2 Recap Lesson 1 recall 5-question quick quiz (brute 8 min


force, DDoS, data interception,
hacking). Mark and review.

2 Teach Malware: Use the malware mind-map (Fig. 20 min


Viruses, Worms, 5.10). Teach virus (needs host),
Trojans worm (standalone, self-
replicates across network),
Trojan (disguised as legitimate
software). Use real examples: "I
Love You" worm, fake anti-virus
pop-ups.

2 Teach Malware: Spyware monitors keystrokes → 18 min


Spyware, sends to criminal. Adware floods
Adware, with ads, redirects browser.
Ransomware Ransomware encrypts data →
demands payment. NHS
WannaCry 2017 as case study for
ransomware.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
LESSON PHASE TOPIC ACTIVITY & STRATEGY DURATION

2 Apply Malware Students match 6 descriptions to 10 min


Matching 6 malware types without looking
Activity at notes. Self-check and discuss
errors.

3 Hook Spot the Scam Display the fake PayPal email 10 min
(Fig. 5.19) on the board. Students
try to find all 10 errors in 3
minutes. Reveal answers — leads
into phishing lesson naturally.

3 Teach Phishing & Teach phishing (email-based, 20 min


Pharming user must act). Teach pharming
(DNS cache poisoning, automatic
redirect — no action needed).
Compare the two. Discuss the 5
ways to spot a phishing email.

3 Teach Social Cover: instant messaging, email 18 min


Engineering — 5 scams, baiting, phone calls,
Types scareware. Use Figure 5.11.
Discuss the 3 human emotions
exploited: fear, curiosity, trust.
Role-play: teacher acts as "IT
support" calling a student, trying
to get password.

3 Apply Activity 5.3 Q1 Students complete scenario 12 min


and Q2 questions on a company facing
multiple security threats. Full
class debrief.

4 Recap Threats mini-test 6 short definitions: students 8 min


name the threat from
description alone (brute force,
DDoS, Trojan, ransomware,

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
LESSON PHASE TOPIC ACTIVITY & STRATEGY DURATION

pharming, social engineering). 5


minutes, peer-mark.

4 Teach Security Explain access level hierarchy 18 min


Solutions: Access (hospital cleaner vs consultant
Levels, Anti- example). 4 levels of social
malware network access. Anti-virus vs
anti-spyware — how each works
(rules-based, file structures).
Features of anti-spyware.

4 Teach Authentication: Strong vs weak passwords — 20 min


Passwords & what makes a password strong?
Two-Step Teach Activity 5.4 Q1 live
Verification (classify 5 passwords). Explain
two-step verification using Fig.
5.17 (Kate buying a camera). The
3 factors of authentication:
know, have, are.

4 Apply Activity 5.3 Q3 Students analyse John's 12 min


(John's passwords and suggest
passwords) improvements. Written answers,
teacher circulates.

5 Hook Biometrics demo Show smartphone fingerprint 8 min


unlock. Ask: "How does it know
it's you? What if someone cuts
their finger?" Leads into
biometrics lesson.

5 Teach Biometrics, Teach fingerprint + retina scan 20 min


Firewalls, Proxy (Table 5.3 benefits/drawbacks).
Servers Firewall: hardware vs software,
what it filters. Proxy server:
intermediary role, caching,
blocking IP addresses. Use

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
LESSON PHASE TOPIC ACTIVITY & STRATEGY DURATION

diagrams from Figures 5.21 and


5.22.

5 Teach Privacy Settings, Privacy settings: "do not track", 18 min


Automatic blacklisting. Auto updates:
Updates, SSL patches, security upgrades. SSL:
5-step handshake (Fig. 5.23), SSL
certificate, HTTPS padlock.
Where SSL is used.

5 Apply Activity 5.6 — Students work through all 10 14 min


Name that term definitions in Activity 5.6 Q1.
Peer-check. Final full chapter
review.

§ 01

Learning Objectives (Syllabus 0478)

Section 5.3.1 — Cyber Security Threats


✓ Describe the process and aim of a brute force attack
✓ Describe data interception (including wardriving and packet sniffers)
✓ Describe a Distributed Denial of Service (DDoS) attack
✓ Describe hacking (malicious and ethical)
✓ Describe malware: virus, worm, Trojan horse, spyware, adware, ransomware
✓ Describe phishing and how to identify/prevent it
✓ Describe pharming and DNS cache poisoning
✓ Describe social engineering — types and human emotions exploited

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Section 5.3.2 — Security Solutions
✓ Explain access levels and their role in data security
✓ Explain anti-malware (anti-virus and anti-spyware)
✓ Explain authentication: username/password, biometrics, two-step verification
✓ Explain automatic software updates
✓ Explain checking spelling/tone of communications and URLs
✓ Explain firewalls — purpose, tasks, and limitations
✓ Explain privacy settings
✓ Explain proxy servers — role and features
✓ Explain SSL (Secure Sockets Layer) and how it secures data

§ 5.3.1

Cyber Security Threats — Overview


Data can be corrupted, deleted, or stolen through malicious acts or accidental damage. The
following eight categories of cyber threat are required by the syllabus:

ATTACK INTERCEPTION

Brute Force Attack Data Interception


Systematically trying all possible Tapping into wired or wireless
combinations of characters until a password communication links (packet sniffers,
is found. Can be assisted by word lists of wardriving) to steal data being transmitted
common passwords. over a network.

ATTACK INTRUSION

DDoS Attack Hacking

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Flooding a server with massive amounts of Gaining illegal, unauthorised access to a
requests from many computers computer system. Can result in identity theft,
simultaneously, preventing legitimate users data corruption, or data theft.
from accessing it.

MALWARE DECEPTION

Malware Phishing
Malicious software including viruses, worms, Fake emails that trick users into clicking
Trojans, spyware, adware, and ransomware — malicious links or providing personal data.
each with different delivery and damage The user must take an action for harm to
mechanisms. occur.

REDIRECT MANIPULATION

Pharming Social Engineering


Malicious code or DNS cache poisoning Manipulating people psychologically
redirects users to a fake website (exploiting fear, curiosity, trust) into
automatically — no user action required. breaking security procedures and giving
access willingly.

Brute Force Attacks — Detail

DEFINITION — BRUTE FORCE ATTACK


A
BRUTE FORCE ATTACK
is a method where a hacker systematically tries every possible combination of characters
(letters, numbers, symbols) until the correct password is found. It requires no skill — only
computing power and time.

Hackers often reduce the time taken by first checking:


A list of the most commonly used passwords (e.g. 123456 , password , qwerty , 111111 ,
abc123 )

A "word list" — a text file with millions of common words, names, and phrases — before trying
fully random combinations

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
DEFENCE
The longer and more complex a password is (mixing uppercase, numbers, symbols), the
longer a brute force attack takes — potentially years. Systems that lock accounts after 3 failed
attempts also prevent brute force attacks.

Data Interception

DEFINITION — DATA INTERCEPTION


DATA INTERCEPTION
is stealing data by tapping into a wired or wireless communication link with the aim of
compromising privacy or obtaining confidential information.

WIRED NETWORK WIRELESS NETWORK

Packet Sniffer Wardriving


Software that examines data packets Also called Access Point Mapping. Hackers
travelling over a network. The intercepted use a laptop, antenna, and GPS device outside
packets are redirected to the hacker. a building to intercept Wi-Fi signals and
Common on wired networks. capture personal data — often without the
victim's knowledge.

DEFENCE AGAINST WARDRIVING


Use WEP encryption protocol + firewall. Use complex Wi-Fi passwords.
NEVER USE PUBLIC WI-FI FOR SENSITIVE DATA
— public networks have no encryption, making any data sent completely visible to anyone
nearby.

DDoS Attacks

DEFINITION — DDOS
A
DISTRIBUTED DENIAL OF SERVICE (DDOS) ATTACK

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
floods a server or network with thousands of requests from many different computers
simultaneously, overwhelming it so that legitimate users cannot gain access.

The difference between DoS and DDoS: in a DoS attack the requests come from one source;
in a DDoS attack they originate from many different computers (often botnet-infected
machines), making it very hard to block.

Signs of a DDoS attack on your system:


Slow network/internet performance when opening files or websites
Inability to access certain websites at all
Unusually large amounts of spam email arriving

Hacking

DEFINITION — HACKING
HACKING
is the act of gaining illegal, unauthorised access to a computer system. It can result in identity
theft, data corruption, data deletion, or data being passed to third parties.

Type Malicious Hacking Ethical Hacking

Permission No permission — illegal Authorised by the company — legal

Intent Personal gain, disruption, theft Testing security robustness

Outcome Data stolen, deleted, corrupted Security weaknesses identified and fixed

Also known as "Black hat" hacking "White hat" / penetration testing

⚠️ IMPORTANT NOTE ON ENCRYPTION & HACKING


Encryption does NOT stop hacking. It makes stolen data unreadable to the hacker, but the
hacker can still delete, corrupt, or pass on the encrypted data. Encryption only protects
the meaning of the data, not its existence.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
§ 5.3.1 cont.

Malware — All Six Types


DEFINITION — MALWARE
MALWARE
(malicious software) is any software designed to damage, disrupt, or gain unauthorised access
to a computer system. It is one of the biggest threats to data security.

Type How it Works Key Characteristics Prevention

Virus Replicates (copies Needs an active host program Anti-virus


itself) and attaches to to trigger. Deletes/corrupts software, don't
programs/files. files, causes malfunction. open unknown
Executes when Spreads via email email
infected program is attachments, infected attachments,
run. downloads. update software

Worm Self-replicates and Does not need user to open a Anti-virus, email
spreads across file. Spreads silently. One filters, network
networks through infected email in a network firewalls, patch
security weaknesses. can infect all connected security
Standalone — no host computers. More dangerous vulnerabilities
needed. than viruses.

Trojan Horse Disguises itself as Needs user to execute it (e.g. Don't install
legitimate/useful fake anti-virus pop-up). Once unverified
software. User installs installed: gives criminals software; check
it voluntarily. access to data, passwords, IP source of
addresses. Often installs downloads;
spyware/ransomware. ignore pop-up
Firewalls often useless — user warnings
overrides them.

Spyware Silently monitors all Includes keylogging software Anti-spyware


user activity. Sends (records every keystroke). software; use
captured data User unaware it is running. drop-down
(passwords, card Often installed via Trojans or menus instead of
details) back to the social engineering. typing passwords;
cybercriminal. run malware
scans

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Type How it Works Key Characteristics Prevention

Adware Floods user with Not always directly harmful Anti-malware


unwanted but highlights security bundle; browser
advertising. Redirects weaknesses. Difficult to pop-up blockers;
browser to remove — hard to determine if avoid suspicious
promotional websites. harmful. Can hijack browser free software
Creates pop-ups or search results.
hijacks toolbar.

Ransomware Encrypts all files on Installed via Trojan or social Regular backups
victim's computer. engineering. Screen locked of key files; avoid
Demands ransom until ransom paid. Once phishing emails;
payment for executed — nearly impossible up-to-date anti-
decryption key. to reverse. Example: WannaCry virus; don't pay
Sometimes key is attacked NHS 2017. ransom
never sent even after
payment.

💡 VIRUS VS WORM — KEY EXAM DISTINCTION


A
VIRUS
needs the user (or an infected host program) to be triggered before it causes damage. A
WORM
is standalone and can spread across a network without any user action at all. This makes
worms generally more dangerous than viruses.

§ 5.3.1 cont.

Phishing & Pharming

Phishing

DEFINITION — PHISHING
PHISHING
occurs when a cybercriminal sends fake, legitimate-looking emails to users. These emails
trick recipients into clicking malicious links (leading to fake websites) or providing personal

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
information (bank details, passwords, card numbers). The user must take an action for the
attack to succeed.

SPEAR PHISHING VS REGULAR PHISHING


REGULAR PHISHING

targets random, non-specific victims (mass emails).


SPEAR PHISHING

targets specific individuals or companies to gain sensitive financial data or conduct industrial
espionage.

How to Identify a Phishing Email — 5 Red Flags

SUSPICIOUS EMAIL ADDRESS


1
No legitimate company uses a @[Link] address. Check the part after the @
symbol — it must match the company's domain. Example of fake: paypal@customer-
[Link]

POOR SPELLING & GRAMMAR


2
Legitimate professional organisations do not send emails with spelling mistakes,
grammatical errors, or poorly constructed sentences. "We not able to take payments"
is a clear red flag.

MISSPELLED DOMAIN NAMES (TYPO SQUATTING)


3
Scammers use URLs like [Link] or [Link] — almost identical to
real ones. This is called typo squatting. Always check URL spelling carefully.

SUSPICIOUS LINKS
4
Hover over links before clicking. If the destination URL shown does not match the
company name (e.g. a "Netflix" email linking to [Link] ),
it is a scam.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
URGENT / RUSHING TONE
5
Phishing emails create urgency to panic the user into acting without thinking: "action
needed immediately," "your account will be closed in 24 hours." Genuine companies
give you time to verify.

Pharming

DEFINITION — PHARMING
PHARMING
is malicious code (installed on a user's computer or a DNS server) that automatically redirects
the user's browser to a fake website — without the user needing to take any action. It exploits
the DNS system.

DNS CACHE POISONING — HOW PHARMING WORKS

Normally: user types URL → DNS resolves it to the real IP address → correct website loads
With DNS cache poisoning: the real IP address in the DNS cache has been replaced with the IP
address of a fake website
Result: the user types a legitimate URL but their browser is sent to a fake, hacker-controlled
site
The fake site may look identical to the real one — the user enters their login details and the
hacker captures them

Feature Phishing Pharming

Requires user ✅ Yes — user must click a link ❌ No — automatic redirect


action?

Method Fake email with malicious link DNS cache poisoning or


malicious code

Harder to Identifiable via email red flags Much harder — URL looks
detect? correct

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Feature Phishing Pharming

Defence Anti-phishing toolbars, check HTTPS Anti-virus, check HTTPS


padlock, read emails carefully padlock, check URL spelling

⚠️ EXAM TIP — PHISHING VS PHARMING


The critical difference examiners test: phishing requires the user to click something.
Pharming happens automatically — even a careful user can be a victim. If DNS server itself
is infected (not just the user's computer), it is much harder to mitigate.

§ 5.3.1 cont.

Social Engineering
DEFINITION — SOCIAL ENGINEERING
SOCIAL ENGINEERING
is the manipulation of people into breaking their normal security procedures by exploiting
human psychology. The cybercriminal creates a social situation that causes the victim to
willingly give access, share data, or download malware — without any technical hacking
involved.

The 3 Human Emotions Exploited

EMOTION EMOTION

😨 Fear 🤔 Curiosity
The user is panicked into believing their The user is tricked by something too
computer is in immediate danger. They act interesting to ignore. Example: a malware-
without thinking. Example: "Your computer infected USB stick left in a car park —
is infected! Download now to fix it someone picks it up to see what's on it.
immediately!"

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
EMOTION

🤝 Empathy & Trust


The user assumes emails or calls from
genuine-sounding companies are safe.
Example: a fake "Microsoft support" call
saying your PC has been compromised.

The 5 Types of Social Engineering Attack

📱 INSTANT MESSAGING 📧 EMAIL / PHISHING


Exploits: Curiosity Exploits: Trust

Malicious links embedded in instant User trusts a well-known company's name


messages — often disguised as important and opens a link in the email, redirecting to a
software upgrades. fake site.

💾 BAITING 📞 PHONE CALLS


Exploits: Curiosity Exploits: Fear

A malware-infected USB stick is left A fake "IT professional" calls claiming the
somewhere it will be found. The finder plugs user's device has been compromised. The
it in to see who it belongs to, unwittingly user is told to download software — giving the
installing malware. criminal remote access.

⚠️ SCAREWARE

Exploits: Fear

A pop-up message claims the computer is


infected. User is told to download fake anti-
virus immediately. The "fix" is actually
malware (Trojan horse).

The 4 Stages of a Social Engineering Attack

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
IDENTIFY & RESEARCH
1
Victims are identified. Information about the target is gathered (social media, public
records). The method of attack is chosen based on the victim's profile.

TARGET THE VICTIM


2
The attack is initiated — through email, phone call, baiting, or Trojan horse — tailored
to the specific victim.

EXECUTE THE ATTACK


3
The attack is carried out — the cybercriminal obtains the desired information or
causes the planned disruption.

COVER TRACKS
4
The cybercriminal removes all traces of the malware or attack to avoid detection.

§ 5.3.2

Keeping Data Safe — Security Solutions

🔐 Access Levels 🛡 Anti-Malware

Restricting what data different users can see, Anti-virus and anti-spyware software that
read, write, or delete based on their role or detects, blocks, and removes malicious
security clearance. programs.

🔑 Authentication 🔄 Auto Updates


Verifying a user's identity via passwords, Keeping software up-to-date ensures the
biometrics, or two-step verification before latest security patches and bug fixes are
granting access. applied.

📧 Check Emails/URLs 🔥 Firewalls


Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Checking spelling, tone, domain names, and Hardware or software that filters all
link destinations before clicking anything in incoming and outgoing network traffic
an email. against a set of rules.

⚙️ Privacy Settings 🌐 Proxy Servers


Browser/social network controls that limit An intermediary between the user and web
who can access personal data and prevent server that filters traffic, hides IP addresses,
tracking. and caches content.

🔒 SSL
Secure Sockets Layer — encrypts data
between browser and web server to prevent
interception.

Access Levels

DEFINITION — ACCESS LEVELS


ACCESS LEVELS
control what data a specific user is permitted to read, write, edit, or delete within a system.
Different users are granted different levels of access based on their role and security
clearance.

EXAMPLE — HOSPITAL SYSTEM

A hospital cleaner should not have access to patient medical records, but a consultant must.
Access levels are enforced via usernames and passwords tied to role-based permissions.

Social network access levels (e.g. Facebook):


Public: Any member of the public can see this data
Friends: Only approved contacts can see this data
Custom: The user finely controls who sees what content
Data owner only: Only the account owner can see this data

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Anti-Malware

The two main types are anti-virus and anti-spyware.

Anti-spyware works using one of two methods: rules-based (looking for typical features of
spyware) or file structure analysis (identifying file structures associated with known
spyware).

Key features of anti-spyware software:


Detects and removes spyware already installed on a device
Prevents users from downloading spyware in the first place
Encrypts files to protect data from being "spied on"
Encrypts keyboard strokes to counter keyloggers
Blocks access to webcam and microphone by spyware
Scans for signs of personal information theft and warns the user

§ 5.3.2 cont.

Authentication
DEFINITION — AUTHENTICATION
AUTHENTICATION
is the process of verifying a user's identity before granting access to a system or data. There
are three factors:

FACTOR 1 FACTOR 2

Something You Know Something You Have


Password, PIN code, security question Mobile phone (receives one-time code),
answer tablet, hardware token

FACTOR 3

Something You Are

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Biometrics — fingerprint, retina, face, voice

Strong vs Weak Passwords

✅ STRONG PASSWORDS ❌ WEAK PASSWORDS

Sy12@#TT90kj=0 GREEN

ChapTer@06 280290

AbC*N55! John04

A strong password must contain:


At least one capital letter
At least one number
At least one special character (e.g. @ , * , # , & )
A minimum length — the longer, the better
Should not relate to personal information (pet names, birthdays, favourite colour)

Password best practices:


Change passwords regularly in case they have been compromised
Never save passwords on shared devices
Run anti-spyware to ensure passwords aren't being intercepted
Systems should lock the user out after 3 failed attempts (prevents brute force)
Never use the same password across multiple websites

Two-Step Verification (2SV)

DEFINITION — TWO-STEP VERIFICATION


TWO-STEP VERIFICATION

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
requires the user to provide
TWO SEPARATE PIECES OF AUTHENTICATION EVIDENCE
before access is granted. It significantly reduces the risk of unauthorised access even if a
password is stolen.

EXAMPLE — ONLINE PURCHASE (KATE BUYING A CAMERA)

STEP 1:

Kate enters her username and password on the website (something she knows)
STEP 2:

An 8-digit one-time pass code is sent as a text message to her pre-registered mobile phone
(something she has). She enters this code to complete authentication.
Even if a hacker steals Kate's password, they cannot log in without also having her mobile
phone.

💡 EXAM TIP — ACTIVITY 5.4 PASSWORDS


25-MAY-2000
— Weak (likely a birthday, only numbers and dashes, no symbols/uppercase mix).
PAS5WORD
— Weak (obvious substitution, easily guessed).
CHAPTER@06
— Strong (capital letters, number, special character).
ABC*N55!
— Strong (capitals, special characters, numbers).
12345X
— Weak (only one capital, mostly sequential numbers).

§ 5.3.2 cont.

Biometrics
DEFINITION — BIOMETRICS
BIOMETRICS

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
is a form of authentication that uses unique physical or behavioural characteristics of a
human being to verify identity. Examples: fingerprint scans, retina scans, face recognition,
voice recognition.

Technique Benefits Drawbacks

Fingerprint Most developed biometric technique; Some find it intrusive (associated


Scan easy to use; small data storage with criminal ID); errors if skin is
Accuracy: ~1 in requirement; very difficult to dirty, cut, or damaged; relatively
5,000 replicate; can't be lost or stolen expensive to install

Retina Scan Extremely high accuracy; no known Very intrusive (infrared light, must
Accuracy: ~1 in way to duplicate retina pattern; sit still 10–15 seconds); slow
10,000,000 virtually impossible to fake verification; very expensive;
unpleasant for users

Face Non-intrusive; relatively cheap; no Affected by lighting changes, hair,


Recognition physical contact needed age, glasses; lower accuracy than
retina

Voice Non-intrusive; fast (under 5 seconds); Voice can be recorded for


Recognition inexpensive unauthorised access; illness (cold)
can change voice; low accuracy

💡 BIOMETRIC APPLICATION — RETINA SCANNER DOOR SYSTEM


Person faces scanner → scanned data goes through ADC → microprocessor compares with
database → if match: signal sent via DAC, light turns green, door unlocks → if no match:
access denied, light stays red. This links to Chapter 3 (sensors, ADC/DAC, actuators).

§ 5.3.2 cont.

Firewalls & Proxy Servers

Firewalls

DEFINITION — FIREWALL
A

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
FIREWALL
is hardware or software that sits between a user's computer (or internal network) and an
external network (e.g. the internet). It inspects all incoming and outgoing traffic and blocks
anything that does not meet its security criteria.

Main tasks of a firewall:


Examines all traffic between internal network and internet
Checks whether incoming/outgoing data meets set criteria
Blocks traffic that fails the criteria and warns the user
Logs all incoming and outgoing traffic for later analysis
Prevents access to blacklisted IP addresses and undesirable sites
Warns users when software on their system tries to access the internet (e.g. for updates)
Helps prevent viruses and hackers from entering

Limitations of firewalls (when they can't help):


Cannot prevent internal network users from using their own devices (smartphones, modems) to
bypass the firewall
Cannot control employee misconduct (e.g. sharing passwords)
Users on standalone computers can simply disable the firewall
Cannot stop Trojan horses that the user willingly installs

Proxy Servers

DEFINITION — PROXY SERVER


A
PROXY SERVER
acts as an intermediary between the user's computer and the web server. All requests from
the user pass through the proxy server first, which filters, validates, and forwards them.

Key features and benefits of a proxy server:


Filters internet traffic — can block access to specific websites or IP addresses
Keeps the user's real IP address secret — improves anonymity and security

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Validates traffic: allows valid requests, denies invalid ones
If an attack is launched, it hits the proxy server — not the real web server
Redirects invalid traffic away from web servers (protection against DDoS and hacking)
Caching: stores a copy of visited pages; future visits load from cache — faster access
Can also act as a firewall

Feature Firewall Proxy Server

Primary role Filter traffic by rules; block Intermediary; filter, cache, hide
threats IP

IP protection No Yes — hides user's real IP

Caching No Yes — speeds up web access

Hardware or Both Usually software / server


software?

Can act as each Can include proxy features Can act as a firewall
other?

§ 5.3.2 cont.

Privacy Settings, Auto Updates & SSL

Checking Spelling / Tone / URL Links

Before acting on any email, always verify:


The sender's email address — does the domain match the claimed company?
Spelling and grammar — legitimate companies don't send emails full of errors
Domain names in links — check for typo squatting (e.g. [Link] vs [Link] )
Hover over links — check the actual destination URL shown matches the claimed company
Tone — is the email rushing you? Creating fear? Legitimate emails are calm and professional

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Privacy Settings

Privacy settings allow users to control what data is shared and collected about them. They
include:
"Do not track" — stops websites collecting browsing data for advertising
Checking whether payment methods are saved on websites
Safer browsing — alerts when a potentially dangerous (blacklisted) site is visited
Controlling web browser storage (history, cookies)
Advertising opt-outs — prevent third parties tracking browsing behaviour
App settings — e.g. turning off location sharing in map applications

Automatic Software Updates

WHY UPDATES MATTER


Software updates may contain
PATCHES
— fixes for security vulnerabilities that malware could exploit. Without regular updates, a
system is vulnerable to known, documented threats that have already been fixed in newer
versions.

DOWNSIDE OF UPDATES
Sometimes an update can disrupt or break existing software. If this happens, users must wait
for a follow-up patch or roll back the system to before the update using system restore
features.

Secure Sockets Layer (SSL)

DEFINITION — SSL
SECURE SOCKETS LAYER (SSL)
is a security protocol — a set of rules that enables encrypted, authenticated communication
between a user's browser and a web server. Data sent via SSL is encrypted so only the browser

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
and web server can read it. Indicated by https:// and the padlock icon in the browser
address bar.

The SSL Handshake — 5 Steps

1 The user's browser sends a request to connect to a website secured by SSL.

2 The browser asks the web server to identify itself.

3 The web server responds by sending a copy of its SSL certificate (a digital certificate that
authenticates the website's identity).

4 The browser verifies (authenticates) the SSL certificate. If valid, it sends a message back to
the server confirming it trusts the certificate and requests that communication begins.

5 The web server acknowledges the browser's message and SSL-encrypted two-way data
transfer begins. All data is now encrypted in both directions.

Where SSL is used:


Online banking and all financial transactions
Online shopping and e-commerce
Sending and receiving emails securely
Cloud storage facilities
Intranets and extranets
VoIP (video and audio chatting over the internet)
Instant messaging and social networking
Distributing software to restricted user lists

⚠️ SSL VS TLS
TLS (Transport Layer Security) is the modern, more secure successor to SSL. In practice,
when we say "SSL" we often mean TLS. Both ensure encrypted communication. The exam

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
uses "SSL" — know that it means encrypted HTTPS communication with certificate-based
authentication.

§ QA

Solved Questions & Answers


QUESTION 1 (ACTIVITY 5.3 Q2)

Explain the following three terms: worm, ransomware, Trojan horse.

ANSWER
WORM:
A type of standalone malware that can self-replicate and spread to other computers across a
network without needing an active host program or any user action. Worms exploit security
weaknesses in networks to spread, and can infect an entire network from a single infected
email — making them more dangerous than viruses.
RANSOMWARE:

A type of malware that encrypts all the data on a victim's computer, effectively "holding it
hostage." The cybercriminal demands a ransom payment in exchange for the decryption key
(though the key may not always be provided). Ransomware is often delivered via a Trojan
horse or social engineering. Regular backups are the best defence since the encryption is
nearly impossible to reverse.
TROJAN HORSE:

A malicious program disguised as legitimate or useful software. The user is tricked into
installing it (e.g. a fake anti-virus program). Once installed, it gives cybercriminals access to
personal data (passwords, IP addresses, card details) and often installs additional malware
such as spyware or ransomware. Firewalls are largely ineffective because the user willingly
runs the program.

6 marks (2 per term)

QUESTION 2 (ACTIVITY 5.3 Q3A)

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
John's possible passwords: (i) 280290 (ii) FiLix1234 (iii) John04 . Why is each not a good
choice?

ANSWER

(I) 280290:

This is most likely John's date of birth (28th February 1990). Personal information like
birthdays is one of the first things a hacker will try. It also contains only numbers — no letters
or special characters — making it a weak password easily cracked by brute force.
(II) FILIX1234:

This is based on the name of John's cat (Felix), slightly altered. Personal pet names are well-
known to be commonly used passwords and would appear on any word list used in a brute
force attack. The numbers 1234 are sequential and commonly used.
(III) JOHN04:

Contains John's own first name — an obvious, personal choice. It is very short, contains no
special characters, and is trivial to guess for anyone who knows John.

3 marks (1 per explanation)

QUESTION 3 (ACTIVITY 5.3 Q3B)


Describe how John could improve his passwords and how he should maintain them to
maximise database security.

ANSWER

Use a password with


AT LEAST ONE CAPITAL LETTER, ONE NUMBER, AND ONE SPECIAL CHARACTER

(e.g. @ , * , # ) — for example: Db@39!kJx2


The password should
NOT RELATE TO PERSONAL INFORMATION

(no birthdays, pet names, or names)


The password should be
LONG
— the longer, the harder to brute-force
CHANGE THE PASSWORD REGULARLY
(e.g. every 30–60 days) in case it has been compromised without John's knowledge
NEVER REUSE THE SAME PASSWORD

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
across multiple systems or websites
Run
ANTI-SPYWARE SOFTWARE

to ensure passwords are not being intercepted by keyloggers


NEVER SAVE PASSWORDS

on the device when prompted (as asked in Q3c)

4 marks

QUESTION 4 (ACTIVITY 5.3 Q3C)


When John enters his password, the screen shows: "Would you like to save the password on
this device?" Why is it important that John always says No?

ANSWER

If the password is saved on the device and the device is


LOST OR STOLEN

, anyone who finds it could access the database without needing to know the password.
If
MALWARE (SUCH AS SPYWARE) IS INSTALLED

on the device, it could read stored passwords from the browser or system and transmit them
to the cybercriminal.
Other users who have access to the same device (colleagues, family) could
LOG IN TO THE DATABASE

without authorisation.
Saved passwords undermine the purpose of authentication —
ANY PERSON USING THAT DEVICE COULD ACCESS SENSITIVE PERSONAL DATA

in the database.

3 marks (any 3 valid points)

QUESTION 5 (ACTIVITY 5.6 Q1 — NAME THAT TERM)

Match each description to the correct computer term used in this chapter: (a) two pieces of
evidence to verify identity, (b) cache to speed up web pages, (c) social network access controls,
(d) secure data protocol over internet, (e) hardware/software monitoring network traffic, (f)
finds IP addresses from domain names, (g) unique human characteristics for authentication,

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
(h) know/have/are authentication, (i) manipulation into breaking security procedures, (j)
redirects browser to fake site without knowledge.

ANSWER

(A)

Two-step verification (2SV)


(B)

Proxy server
(C)

Privacy settings
(D)

SSL (Secure Sockets Layer) / TLS


(E)
Firewall
(F)
DNS (Domain Name Server)
(G)
Biometrics
(H)

Authentication
(I)

Social engineering
(J)

Pharming

10 marks (1 per correct answer)

QUESTION 6 (EXTENDED — ACTIVITY 5.6 Q3B)

Identify at least three problems with this email from "Watson, Williams and Co":
From: WW and Co <accounts@customer nr 012305555> | Subject: Payment of January 2021
account | "We not able to take payments… Please re-submit account details immediatly to the
following address: Customer accounts link"

ANSWER

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
EMAIL ADDRESS IS SUSPICIOUS:

accounts@customer nr 012305555 is not a valid professional email address — it contains


spaces and a customer number rather than a company domain name. A legitimate company
would use something like accounts@[Link] .
POOR GRAMMAR:

"We not able to take payments" is grammatically incorrect. Legitimate professional


organisations send properly written emails. This is a strong indicator of a phishing attempt.
SPELLING MISTAKE:

"immediatly" is misspelled (should be "immediately"). Real company communications are


proofread.
VAGUE LINK:

"Customer accounts link" gives no information about the actual destination URL. The user
cannot verify where they will be taken before clicking.
REQUESTING ACCOUNT DETAILS VIA EMAIL:

No legitimate company asks customers to re-submit sensitive financial account details by


clicking an unverified email link — this is a classic phishing tactic.

3 marks (any 3 valid, fully explained points)

QUESTION 7 (ACTIVITY 5.3 Q1 — COMPANY SCENARIO)


A company has offices in four countries. Describe three data security issues they might
encounter, why each is a threat, and how each can be mitigated.

ANSWER
ISSUE 1: DATA INTERCEPTION

When data is transmitted between offices over the internet, it can be intercepted by hackers
using packet sniffers. This threatens the confidentiality of commercial and personal data.
Mitigation: Use SSL/TLS encryption for all communications so intercepted data is unreadable.
Avoid public Wi-Fi; use VPNs for inter-office communication.
ISSUE 2: MALWARE (E.G. RANSOMWARE)

Malware could be installed on a company computer via a phishing email or social engineering
attack, encrypting all company data and demanding a ransom.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Mitigation: Install and maintain up-to-date anti-malware software. Train employees to identify
phishing emails. Keep regular, off-site backups of all critical data.
ISSUE 3: HACKING / UNAUTHORISED ACCESS

Hackers may attempt to gain illegal access to the company database, potentially stealing
customer records or financial data, leading to fraud or legal liability.
Mitigation: Use firewalls and proxy servers. Enforce strong password policies and two-step
verification. Implement access levels so only authorised staff can view sensitive data.

9 marks (3 per issue: 1 describe + 1 threat + 1 mitigation)

QUESTION 8 (ACTIVITY 5.4 Q2)

An airport uses a computer system for security, bookings, passenger lists, admin, and
customer services. (a) How can senior staff see all data while customers can only see flight
times and duty-free offers? (b) How can the airport guard against malware from outside and
from customers using airport services?

ANSWER (A) — ACCESS LEVELS

Implement a
HIERARCHICAL ACCESS LEVEL SYSTEM

using unique usernames and passwords for each employee role.


SENIOR STAFF

(e.g. security managers, administrators) are given the highest access level — permission to
read, write, and delete all data across all modules.
CUSTOMERS

use a public-facing interface with no login required — they can only view flight
arrivals/departures and duty-free information stored in a separate, restricted database view.
Different
DATABASE VIEWS

are created for each access level so users cannot even see data they are not authorised to
access.
ANSWER (B) — MALWARE PROTECTION

Install a
FIREWALL

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
(hardware and/or software) between the internet and the airport's internal network to filter
all incoming and outgoing traffic.
Use a
PROXY SERVER
to hide the IP addresses of internal systems and block invalid traffic.
Ensure all systems run
UP-TO-DATE ANTI-MALWARE SOFTWARE

with automatic updates enabled.


Separate the
PUBLIC-FACING CUSTOMER WI-FI

network from the internal staff network so customer devices cannot access internal systems
even if they carry malware.
Train staff on recognising
PHISHING AND SOCIAL ENGINEERING
attacks.

8 marks

§ KT

Key Terms Glossary


Brute Force Data Interception Packet Sniffer
Systematically trying all Stealing data by tapping into Software that intercepts and
character combinations until wired or wireless reads data packets travelling
a password is found. communication links. over a network.

Wardriving DDoS Attack Hacking


Using antenna + laptop + GPS Flooding a server with Illegal, unauthorised access to
to intercept Wi-Fi signals from requests from many a computer system.
outside a building. computers to prevent
legitimate access.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Ethical Hacking Malware Virus
Authorised penetration Any malicious software Self-replicating code that
testing to find and fix security designed to damage or gain needs an active host program
weaknesses. unauthorised access. to trigger and cause damage.

Worm Trojan Horse Spyware


Standalone malware that self- Malware disguised as Silently monitors user activity
replicates across networks legitimate software; requires and sends captured data to
without user action. user to execute it. criminals.

Keylogger Adware Ransomware


Type of spyware that records Floods user with unwanted Encrypts user's data and
every keystroke typed by the ads; redirects browser to demands payment for the
user. promotional sites. decryption key.

Phishing Spear Phishing Typo Squatting


Fake emails that trick users Targeted phishing aimed at Using misspelled domain
into clicking malicious links specific individuals or names (e.g. [Link]) to
or submitting personal data. organisations. fool users.

Pharming DNS Cache Poisoning Social Engineering


Auto-redirecting a browser to Replacing real IP addresses in Manipulating people using
a fake site via DNS cache DNS cache with those of fear, curiosity, or trust to
poisoning — no user action fake/malicious websites. break security procedures.
needed.

Baiting Scareware Access Levels


Leaving infected USB drives to Fake virus warnings that trick Role-based permissions
be found and plugged in by users into downloading controlling what data users
unsuspecting users. malware immediately. can read, write, or delete.

Anti-Spyware Authentication Two-Step Verification


Software that detects, Verifying identity via: Requires two separate forms
removes, and prevents something you know, have, or of evidence to authenticate a
spyware installation. are (biometrics). user.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF
Biometrics Firewall Proxy Server
Using unique physical Hardware/software filtering Intermediary between user
characteristics (fingerprint, all incoming and outgoing and web server; filters,
retina, face, voice) for ID. network traffic. caches, and hides IP.

Privacy Settings SSL / TLS SSL Certificate


Browser/social media controls Security protocol encrypting Digital certificate
limiting who accesses your data between browser and authenticating a website's
data and activity. web server (HTTPS). identity in the SSL handshake.

Patch WEP
A software update that fixes Wired Equivalency Privacy —
security vulnerabilities or encryption protocol for
bugs. wireless networks.

Explore our developer-friendly HTML to PDF API Printed using PDFCrowd HTML to PDF

You might also like