Threat Spotter II
Naming a threat earns almost nothing. Naming it and saying which detail of the scenario proves it is what earns the mark. The four social engineering attacks, the three kinds of malicious code, and how to tell the close pairs apart.
Get the method right under pressure
Free interactive practice on the steps that lose marks under exam pressure.
Start revising freeWhat you'll cover
The attacks that use the door
In the first Threat Spotter module you learned what cyber security means and went looking for weaknesses: the unlocked doors in how an organisation works. This module is about the attacks that walk through them. Your specification names seven, in two groups. Four are social engineering, which means attacking the person rather than the machine: persuading somebody to hand over information or access, without needing to defeat any technology at all. Three are malicious code, which is software written to do harm. Before any of it, understand how this topic is actually examined, because it changes how you should revise. Questions give you a scenario and ask which threat it describes. Naming the threat earns almost nothing on its own. The mark is in the justification. "Phishing" is not an answer. "Phishing, because a fraudulent email invited them to click a link" is. That is why this module never just asks you to recognise a definition: every identification asks which detail of the scenario proves it. And it is why the pairs that look alike matter so much, since a justification is what separates them. Two of those pairs come up almost every year, and both have a step of their own here.
Words for attacks and code
The seven threats your specification names. Read each definition for the feature that makes it distinct, because that feature is your justification in an exam.
Match each trick to its giveaway
- The attacker invents a reason for needing the information, and asks for it directly
- A message that looks genuine asks the victim to click a link and enter their details
- The attacker simply watches the victim type, and needs no technology at all
- The victim types the correct web address and still arrives at a fake site
- Blagging
- Phishing
- Shouldering
- Pharming
Name it, then say why
An employee receives a phone call from someone claiming to be from their IT department, who says there is an urgent problem and asks them to confirm their password. Which answer would earn full marks?
- Blagging, because the caller invented a scenario to give themselves a reason to ask for the password
- Blagging
- Phishing, because the attacker is pretending to be someone trustworthy
- Spyware, because the attacker is trying to obtain a password
Clicked, or redirected
The first pair that examiners rely on. Both end with the victim on a fake website giving away their details, so the difference is entirely in how they got there.
Which two describe pharming
Select the TWO statements that are true of pharming and not of phishing.
- The victim reaches the fake site even though they typed the correct address themselves
- It relies on malicious code performing a redirection rather than on a message
- The victim is sent a fraudulent email that appears to come from their bank
- It can only succeed if the victim is careless
Spreads itself, or waits to be let in
The second pair examiners rely on, and the one most often answered wrongly: virus and trojan. Students treat them as two words for the same thing, and they are not. A virus replicates itself. It attaches to a file or a program, and when that file is run it copies itself into others, so the infection spreads without anybody choosing to spread it. Self-replication is its defining property, and it is what you should say in a justification. A trojan does not replicate. It spreads by disguise: it appears to be legitimate, useful software, and the user installs it themselves believing it is something they want. Once running it can do harm, but it has no mechanism for copying itself onward. So the justification for each is different in kind. For a virus you point at the spreading: "a virus, because it attached itself to a file and copied itself to others". For a trojan you point at the disguise and the user's own action: "a trojan, because the user installed it believing it was a legitimate program". The third kind, spyware, is defined by what it does rather than how it arrives: it records the user's activity, such as the keys they press, and sends that back to the attacker. It might well arrive as a trojan, which is worth knowing, because a scenario can involve more than one of these at once.
The threats in words
Attacks on the person rather than the machine are called _____ engineering. Inventing a scenario to persuade someone to hand over information is _____, while a fraudulent message inviting the victim to click a link is _____. Being redirected to a fake site without clicking anything is _____. Among malicious code, a virus is defined by the fact that it _____ itself, whereas a trojan spreads by disguise and is installed by the user.
The answer that names but stops
Four answers to scenario questions. Select the ONE that names a threat without justifying it.
- Shouldering, because the attacker watched the victim type their PIN at the machine.
- This is a trojan.
- Pharming, because the user typed the correct address and was still taken to a fake site.
- A virus, because it attached itself to a file and copied itself into other files when that file was run.
Naming and justifying, worked
Here is a scenario answered properly, and then a harder one. The scenario: a member of staff downloads what they believe is a free photo editing tool. It installs and works, but afterwards the attacker knows everything the person types, including their banking password. A weak answer: "This is spyware." True, but it earns very little, and it also misses half of what happened. A strong answer: "This describes a trojan and spyware together. It is a trojan because the user installed it themselves, believing it was legitimate software, and a trojan spreads by disguise rather than by replicating. The software then acted as spyware, because it secretly recorded what the user typed and sent that information to the attacker." Look at what the strong version does. It names both threats, because the scenario contains both. It justifies each one separately, pointing at the specific detail that identifies it: the disguise and the user's own installation for the trojan, the secret recording for the spyware. And it never says "because it was harmful", which would identify nothing, since all seven threats are harmful. The test to apply to your own answer is simple: could this justification also be used for a different threat? If it could, it is not a justification yet. "Because the attacker wanted their password" fits five of the seven. "Because the user installed it believing it was legitimate" fits exactly one.
How the loss happens
Put the stages of this incident into order, from the victim's point of view.
- A user installs software they believe is legitimate and useful
- Hidden within it, spyware begins running without the user noticing
- The spyware records what the user types, including account details
- Those recorded details are sent back to the attacker
- The attacker uses the details to access the account, and the loss is discovered afterwards
Build the justified answer
Assemble an answer in the form the mark scheme rewards.
Four incidents, one week
You are asked to identify the threat in each of four reports at a small company. Name it and check your justification each time.
- A member of staff read their password aloud to a caller who said they were checking an account problem. What is it, and why?
- Someone entered their PIN at a payment terminal while a stranger stood close behind. What is it, and why?
- A file opened from a shared folder, and afterwards several other files on the system were found to be infected too. What is it, and why?
- You are writing the report and want to make one general recommendation. What is best supported by these four incidents?
Explain the threats and how to spot them
Explain the cyber security threats named on your specification, and how you would identify each one from a scenario. Justify every identification.
- Explain what social engineering means, and why it needs no technical attack on a machine
- Describe blagging, phishing, shouldering and pharming, and give the identifying feature of each
- Explain clearly how pharming differs from phishing
- Describe a virus, a trojan and spyware
- Explain the difference between a virus and a trojan in terms of how each spreads
- Explain why naming a threat without justifying it earns few marks
- Give one example of a justification that would not distinguish between threats, and say why
- Finish by explaining why a scenario can involve more than one threat at once