Identifying and Preventing Threats
Revise Identifying and Preventing Threats for GCSE Computer Science with this free worksheet and full mark scheme — Foundation and Higher exam-style questions with worked answers. Named threats include pharming, weak and default passwords, misconfigured access rights, removable media and unpatched software.
Free downloads
These worksheets and mark schemes are original, written for Virtus Academy and checked against the current AQA specification. Every worksheet comes with a full mark scheme.
Topic overview
Preventing cyber threats requires both technical measures and changes to how people behave, because attacks target both.
Technical measures include strong passwords and two-factor authentication, keeping software patched so known vulnerabilities are closed, anti-malware software, firewalls, encryption and regular backups. Backups matter particularly against ransomware, because a recent backup means the ransom need not be paid at all.
Behavioural measures include staff training to recognise phishing, clear procedures for verifying unusual requests, locking screens when away from a desk, and not using the same password across multiple sites. Neither category is sufficient alone, which is the point most answers miss.
Revision notes
Technical measures
Strong passwords and two-factor authentication. Regular software updates to patch known vulnerabilities.
Anti-malware software, firewalls, encryption of stored and transmitted data, and regular backups kept separately from the main system.
Why backups matter against ransomware
Ransomware encrypts files and demands payment for the key.
With a recent backup stored separately, the files can be restored without paying anything. This turns a catastrophe into an inconvenience, which is why backups are the single most effective measure against it.
Behavioural measures
Staff training to recognise phishing and social engineering.
Procedures for verifying unusual requests through a separate channel. Locking screens when away from the desk. Not reusing passwords across sites, so one breach does not compromise everything.
Key points
- Prevention needs technical and behavioural measures.
- Strong passwords and two-factor authentication help.
- Software updates patch known vulnerabilities.
- Backups defeat ransomware demands.
- Staff training addresses social engineering.
- Neither category is sufficient alone.
Worked examples
Example 1
Explain why regular backups are effective against ransomware. [2 marks]
Working
Example 2
Explain why software should be kept up to date. [2 marks]
Working
Example 3
Give one technical and one behavioural measure against cyber threats. [2 marks]
Working
Common mistakes
Giving only technical measures.
Behavioural measures are equally examinable.
Saying backups prevent ransomware.
They allow recovery from it rather than preventing infection.
Not explaining why a measure works.
State the mechanism, not just the name.
Reusing passwords across sites.
One breach then compromises every account.
Exam tips
- Give both technical and behavioural measures.
- Explain the mechanism of each measure.
- Link backups specifically to ransomware recovery.
- Mention patching as closing known vulnerabilities.
Key terms
- Patch
- An update fixing a known vulnerability.
- Backup
- A separate copy of data allowing recovery.
- Anti-malware
- Software detecting and removing malicious programs.
- Two-factor authentication
- Requiring a second piece of evidence to log in.
Related topics
Written and reviewed against the current AQA specification. Spotted an error? Let us know.