Threats: learn the mechanism, not the aim
The spec lists nine threats; the mark is the mechanism, not just the aim. Learn each by the attacker's action: brute force tries every combination automatically until the password is found; data interception reads packets with a packet sniffer; a DDoS floods a server with requests from bots; hacking is unauthorised access. Key contrast: phishing sends a message to the victim; pharming redirects the victim's own request.
Malware: the six types and their behaviour
Malware = malicious software; the spec names six types. A virus attaches to a file/program and replicates when it runs (needs user action). A worm is standalone and self-replicates across a network. A Trojan horse is disguised as legitimate software. Spyware secretly records activity (e.g. a key logger). Adware floods the device with adverts. Ransomware encrypts files and demands payment. Anti-malware is the defence, not a type.
Match each defence to the threat it counters
The spec lists eleven prevention methods; the marks come from naming the right one and saying how it helps. E.g. access levels restrict what a user can view/edit; anti-malware removes malware; authentication (password, biometrics, two-step verification) confirms identity; a firewall blocks unauthorised access; SSL encrypts data in transit. Key pairing: data interception is beaten by encryption/SSL, not a firewall.
Drawn from real examiner reports.
Anti-virus is a defence, not malware
Asked for a type of malware, candidates often write anti-virus or anti-malware — but these are defences against malware, not kinds of it. The valid types are virus, worm, Trojan horse, spyware, adware, ransomware. Keep the two sides apart: malware is the attack; anti-malware is the protection that scans for and removes it.
Nov 2023 examiner report, Q1(b): "Most candidates were able to give another type of malware. The most common incorrect answers were anti-malware and anti-virus."
Wrong defence for the threat
Two mismatches recur. A brute-force attack is not stopped by anti-virus — defeat guessing with lockout, two-step verification, strong passwords, biometrics. Data interception in transit is not stopped by a firewall — the data is already moving, so the fix is encryption/SSL. Ask: does this method block this mechanism?
June 2023 examiner report, Q8(c): "The most common incorrect answer given was using anti-virus software" (for a brute-force solution). Nov 2023 report, Q8(b): for data interception "the most common incorrect answer was firewall; however, a firewall cannot help keep the data safe mid-transmission."
Giving the aim, not the mechanism
State the mechanism, not the aim. Brute force — not "guess a password" but trying every combination until found. Social engineering — not "tricking someone" but making a person break security rules. Pharming — a redirect to a fake site via malware. Access levels — not "levels of access" but restricting the data a user can use.
June 2023 examiner report: Q8(a) brute force "most common mark point... trying to guess a password" (insufficient detail); Q11(b) "Very few candidates were able to describe the act of social engineering"; Q11(c) "Very few... able to describe what is meant by access levels"; Q10(b) pharming process poorly described.
Phishing and pharming are not the same
These two are easily swapped. Phishing is a fraudulent message sent to the victim (an email posing as a bank) that tricks them into clicking a link — it comes to you. Pharming uses malicious code to redirect the victim's own request to a fake site, even with the correct URL — no message needed. Phishing comes to you; pharming hijacks your request.
Virus needs a host; a worm does not
A virus and a worm are not interchangeable. A virus attaches to a host file/program and replicates only when that file runs — it needs user action. A worm is standalone and self-replicates across a network by itself, with no host file needed. Saying "a worm attaches to a file" or "a virus spreads on its own" reverses them.
Hacking steals access; DDoS denies service
Hacking and a DDoS attack have different goals. Hacking gains unauthorised access to a system or its data. A DDoS does not steal data; a botnet of bots floods the server so it is overloaded and cannot serve legitimate users. Do not describe a DDoS as "getting into" the system — it knocks the service offline, it does not break in.
Threat → mechanism → effect → prevention
Most 5.3 questions ask for a threat, its effect, or a prevention. Use a four-link chain: threat (name it) → mechanism (what the attacker does) → effect (the harm) → prevention (the defence that counters it). Check the defence matches the threat.
State the mechanism in two elements
State two elements — what is done plus what it achieves — not just an aim. Not circular: "access levels are levels of access" scores nothing — they restrict the data a user can use. Brute force = every combination tried automatically, not "guessing".
Justify a security method and check it fits
Justify a method's how and match it to the threat: encryption/SSL for interception; lockout/two-step for brute force; anti-malware/updates for malware; firewall for unauthorised access; URL/spelling checks for phishing.
Cyber security is about protecting computer systems, networks and data from threats (attacks that aim to steal, damage or block access to data) using a range of prevention and detection methods. The exam tests two things: can you describe each threat's mechanism, and can you match the correct defence to a threat?
Brute-force attack — repeatedly trying every possible combination of characters (usually automatically) until the correct password is found.
Full notes, flashcards, Q&A and the topic quiz for every premium subject.
Premium plans are US$8.99/month or US$49.99/year — first month free.
Studying with a parent's blessing? Show them this.