Cyber Security Threats
Learn Cyber Security Threats for GCSE Computer Science with this free worksheet and full mark scheme — Foundation and Higher exam-style questions with worked answers. Cyber security protects networks, computers, programs and data from attack, damage or unauthorised access.
Free downloads
These worksheets and mark schemes are original, written for Virtus Academy and checked against the current AQA specification. Every worksheet comes with a full mark scheme.
Topic overview
A cyber security threat is anything that could compromise the confidentiality, integrity or availability of data and systems.
Threats fall into two broad groups. Technical threats exploit weaknesses in software or hardware, such as malware, brute force attacks and denial of service attacks. Human threats exploit people rather than technology, such as phishing, pretexting and simply leaving a computer unlocked.
The human element matters more than students usually expect. Attackers target people because it is often easier than defeating well-designed technical protections — no firewall stops a user who has been persuaded to give away their password voluntarily. This is why staff training is as important as technical measures.
Revision notes
What a threat is
Anything that could compromise the confidentiality, integrity or availability of data and systems.
Confidentiality means only authorised people can read it. Integrity means it has not been altered. Availability means authorised users can reach it when needed.
Technical and human threats
Technical: malware, brute force attacks, denial of service, SQL injection.
Human: phishing, pretexting, shouldering, and leaving devices unlocked or unattended. Human threats exploit people rather than technology.
Why people are targeted
Attacking a person is often easier than defeating well-designed technical protections.
No firewall stops a user who gives away their password voluntarily. This is why staff training is as important as technical measures, and why questions often ask for both.
Key points
- A threat compromises data or systems.
- Confidentiality, integrity and availability are at risk.
- Technical threats exploit software or hardware.
- Human threats exploit people.
- Attackers target people because it is easier.
- Staff training matters as much as technical measures.
Worked examples
Example 1
State two technical cyber security threats. [2 marks]
Working
Example 2
Explain why attackers often target people rather than technology. [2 marks]
Working
Example 3
Explain why staff training is an important security measure. [2 marks]
Working
Common mistakes
Listing only technical threats.
Human threats are equally examinable and often more effective.
Saying technical measures are sufficient.
They cannot stop a user giving away credentials voluntarily.
Naming a threat without explaining it.
Say what the attacker actually does.
Confusing a threat with a vulnerability.
A threat is the potential attack; a vulnerability is the weakness it exploits.
Exam tips
- Cover both technical and human threats.
- Explain what each attack actually involves.
- Include staff training among prevention measures.
- Use the confidentiality, integrity, availability framing.
Key terms
- Cyber security threat
- Anything that could compromise data or systems.
- Technical threat
- An attack exploiting software or hardware weaknesses.
- Human threat
- An attack exploiting people rather than technology.
- Vulnerability
- A weakness that a threat can exploit.
Related topics
Written and reviewed against the current AQA specification. Spotted an error? Let us know.