Threats to data — each needs a matched prevention
Hacking = gaining unauthorised access. The phishing family tricks the user into handing over data: phishing (a fraudulent email/message), pharming (code that redirects to a fake site, no click needed), smishing (by SMS text) and vishing (by phone call). A virus self-replicates and corrupts files; malware is the umbrella term. Card fraud covers shoulder surfing, card cloning and key logging. Learn every threat with its OWN matched prevention, not a generic "use anti-virus".
Seven protection methods, each working differently
Biometrics uses a unique characteristic (fingerprint, iris, face). A digital certificate proves a website or sender is genuine. SSL creates an encrypted link between server and browser. Encryption scrambles data so it is unreadable if intercepted. A firewall blocks network data that fails set rules. Two-factor authentication demands two different types of proof. A user id identifies who logs in and grants access; a password protects the data and must be kept secret.
Strong password vs weak password
A strong password is long and mixes upper- and lower-case letters, numbers and symbols, avoids any dictionary word or personal detail (a name or birthday), and is not reused across accounts. A weak password is short, a dictionary word, a name, a birthday, or lacks numbers and symbols — any one of these makes it easy for an attacker to guess or crack. Both matter together: length AND character variety. It protects an account only if it is also kept secret and not shared.
Drawn from real examiner reports.
Weak password: the reason, not the result
Asked WHY an example password is weak, candidates describe what happens as a result ("the account will be hacked") instead of the flaw itself. Correct: "it is only 4 characters long and a dictionary word, so it is easily guessed." A second trap in the same question: invent your OWN example — copying the weak/strong passwords printed in the stem is often not credited.
Explain-why-weak questions: state the password's own flaw, not the consequence, and give your own example (w22 P11 Q3 / w22 P12 Q4 / w23 P11 Q7a).
Forced password changes lock users out
Making users change their password on a regular schedule sounds purely positive, but it carries a genuine drawback the mark scheme rewards: a user forced to keep changing it is more likely to forget the current password and be locked out of the system, creating an access and support problem. State the drawback, not just the benefit.
Regular forced password changes ⇒ user may forget and be locked out — a drawback candidates missed (s23 P12 Q6a).
User id ≠ password (not just "a login")
A user id uniquely identifies WHO is logging in and grants access to the system; it does not have to be kept secret. A password proves that person is genuine and protects the data, and MUST be kept secret — it is not necessarily unique to one user. Describing the two as "the same thing" or simply "a login" loses the distinction the mark scheme rewards.
User id and password treated as the same thing (w23 P13 Q4a / s22 P11 Q12c).
Hacking ≠ cracking a password
Hacking is gaining unauthorised access to a system or data — a password can be hacked even if it has never been reused anywhere. Cracking is working out or decoding what the password IS; once cracked it can then be reused to log in to that person's OTHER accounts, but only where they used the same password. Hacking = access; cracking = decoding the password itself for reuse.
Hacking and cracking confused (w23 P11 Q7c).
Encryption doesn't stop hacking
Encryption scrambles data with a key so it is meaningless if intercepted, and only the correct key decrypts it. It does NOT stop hacking: it protects the DATA from being read, it does not stop the unauthorised access happening. "Encryption stops the account being hacked" is wrong — a firewall, strong passwords and two-factor authentication are what stop the access itself.
Encryption = scrambling data so it can't be understood if intercepted; it does NOT stop hacking (w22 P13 Q15b).
Digital certificate needs the company name
A digital certificate proves a website or sender is genuine, but writing that it contains "a name" gains little. The mark scheme wants the specific COMPANY/organisation name it was issued to — alongside details such as the certificate authority's signature, a serial number and an expiry date. "A name" with no company detail is too vague to score.
Digital certificate needs the company name, not just "name" (s23 P12 Q6b/c).
Phishing ≠ pharming (a click vs a redirect)
Phishing is a fraudulent email or message that lures the user into acting — clicking a link or replying. Pharming is malicious code (on the computer or a DNS server) that automatically redirects the user to a fake website even when the correct URL is typed, with NO click needed. Smishing and vishing are phishing by SMS text and by phone call — same trick, different channel.
Discuss = a positive AND a negative each
For a "discuss" question, give each named method a clear advantage AND a clear drawback — e.g. a firewall blocks unauthorised traffic BUT cannot stop an authorised user misusing their access. Just listing "passwords, firewalls, anti-virus" with no discussion scores very little.
Two-factor auth: name two categories
Two-factor authentication uses two DIFFERENT categories: something you KNOW (a password), something you HAVE (a phone code or token) and something you ARE (a fingerprint). Name which two, with an example of each — "it adds another layer", with no named factors, is not enough.
Name → explain why → matched prevention
Threat questions reward a three-step answer: NAME the specific threat (say "smishing", not just "phishing", if it came by text), EXPLAIN why it is dangerous with a reason, then give a prevention that actually matches that threat — not a generic "be careful online".
Threats to data
| Threat | Definition |
|---|---|
| Hacking | Gaining unauthorised access to a computer system or network, often to steal, change or delete data |
| Phishing | A fraudulent email/message that appears genuine, luring the user into revealing data or clicking a malicious link |
| Pharming | Malicious code that redirects a user to a fake website even when the correct URL is typed — no click needed |
| Smishing | Phishing carried out by SMS text message |
| Vishing | Phishing carried out by a voice/phone call |
Full notes, flashcards, Q&A and the topic quiz for every premium subject.
Premium plans are US$8.99/month or US$49.99/year — first month free.
Studying with a parent's blessing? Show them this.