DoRevision

Threat Spotter

Define cyber security like the mark scheme wants. Then spot the weakness in real scenarios and learn what penetration testing is for.

⏱️ 15 min 🎯 14 activities
Best used for
Starter Homework Independent study

Work it through together, step by step

A free interactive activity that works the method through with a class, step by step.

Start revising free

What you'll cover

Threat Spotter

Systems get attacked because they leave a door open. Your job on this case: know what **cyber security** actually means, learn the everyday weaknesses attackers exploit, and spot them in real situations. First, the definition. Because it is worth easy marks if you state it precisely.

What is cyber security?

**Cyber security** is the processes and practices designed to **protect** computer systems, networks and **data** from **attack, damage or unauthorised access**.

Define it precisely

For one mark, which is the best definition of **cyber security**?

  • Protecting computer systems and data from attack or unauthorised access
  • A type of antivirus software you install
  • Keeping computers safe
  • Choosing strong passwords

Where the doors are left open

Most breaches exploit ordinary, avoidable weaknesses. These four are the ones the spec names, so learn them by their exam wording.

Why is each a risk?

  • Weak / default passwords
  • Misconfigured access rights
  • Removable media
  • Unpatched software
  • Easily guessed, letting attackers log straight in
  • Users can reach data they should not
  • Can carry malware in, or sensitive data out
  • Known security holes are left open

Spot the weakness: the USB

Staff routinely bring in USB sticks from home to move work files between office PCs. Which weakness is that?

  • Removable media
  • Weak passwords
  • Unpatched software
  • Misconfigured access rights

Read the audit note

Three of these findings are good practice. Tap the ONE that describes a security weakness.

  • Audit notes:
  • backups run nightly to an off-site server
  • ,
  • the Wi-Fi router still uses the login it shipped with, admin and admin
  • ,
  • all workstations installed last month's security updates
  • , and
  • staff completed phishing-awareness training in April

Fix the weaknesses

A charity finds that all its staff share one login, and that its servers have not been updated for two years. Pick the TWO actions that directly fix those weaknesses.

  • Give every member of staff their own account with a unique password
  • Apply the outstanding security updates and keep them current
  • Ask staff to make the shared password considerably longer
  • Put tape over the webcam on every laptop in the building
  • Move the office printer away from the reception desk

Audit the studio

You are auditing a small design studio. Work through what you find, and choose the weakness AND the fix each time.

  • Every machine signs in with the same account. The password is `studio2020` and has not changed since the studio opened.
  • The studio runs a design package the vendor stopped supporting three years ago.
  • The new intern can open the payroll folder on their first morning.
  • You have listed the weaknesses you could see. What should the studio do next to be confident none were missed?

Testing your own defences

How does an organisation find these weaknesses before criminals do? **Penetration testing**, or pen testing. Testers deliberately **simulate an attack** on the system, probing it the way a real attacker would, to **find the vulnerabilities** so they can be fixed before they are exploited for real.

Say what it does

Penetration testing simulates an _____ on a system to find its _____ before a real attacker can exploit them.

attack weaknesses upgrade backup

Why pay for it?

A bank hires an outside firm to try to break into its online banking system, with permission, and report everything it finds. Why is that worth paying for?

  • It exposes the vulnerabilities the bank has, so they can be fixed before criminals find them
  • It guarantees the system can never be broken into again afterwards
  • It makes the online banking system respond faster for its customers
  • It removes the bank's legal duty to protect its customers' data

In the exam

Case closed. Grade-9 habits for cyber security fundamentals: • **Define precisely**: cyber security = protecting systems and data from attack / unauthorised access. • Know the **four common weaknesses**: weak/default passwords, misconfigured access rights, removable media, unpatched software, and match a scenario to the right one. • **Penetration testing** = simulate an attack to find vulnerabilities before real attackers do.

Write it up

A small school runs its office PCs on software that stopped receiving updates last year, and every member of staff signs in with the same password. Name the TWO weaknesses this shows, explain the risk of each, and state what penetration testing would add.

  • Name each weakness in the spec wording, not as a description of the situation.
  • For each one, say what an attacker could actually DO as a result. That is the risk.
  • Say what penetration testing IS: a deliberately simulated attack.
  • Then say what it is FOR: finding vulnerabilities before real attackers exploit them.
  • If you use the term cyber security, define it precisely: protecting systems and data from attack or unauthorised access.