Watch first — Craig 'n' Dave
Craig 'n' Dave · Edexcel 1CP2Network Security
Key facts
Threats to networks
- Malware — viruses, worms, ransomware, spyware installed on networked devices
- Unpatched software — outdated software with unfixed security vulnerabilities that attackers exploit
- Weak passwords — easy to guess or brute-force
- Physical access — unauthorised people accessing hardware
- Social engineering — phishing, blagging, baiting to trick users
- SQL injection — malicious code inserted into database queries
Protection measures
- Firewall — monitors traffic using a set of rules; blocks unauthorised connections
- Encryption — scrambles data so only authorised recipients with the key can read it
- Authentication — passwords, 2FA, biometrics — verify identity before access
- MAC address filtering — only known devices can connect to a network
- Anti-malware — detects and removes malicious software
- Software updates/patching — fixes known vulnerabilities
- Penetration testing — authorised attack on a network to find vulnerabilities before real attackers do
Penetration testing — exam definition
- An authorised (black box or white box) attack on a network/system
- Purpose: to identify security vulnerabilities
- Organisation knows about the test (unlike a real attack)
- Tester recommends measures to improve security
- Jun 2024 Q3(b): "an authorised attack on a network to identify security vulnerabilities" — both parts needed for 2 marks
Exam questions — 4 questions · 11 marks · from real 1CP2 past papers
1 markFirewall definition1CP2 Jun 2022 Q1(c) style
What does a firewall do?
A It prevents viruses from attaching to files on a computer
B It monitors network traffic using a set of rules to decide if data is allowed into or out of a network
C It encrypts data so it cannot be read during transmission
D It backs up data to prevent loss from attacks
2 marksPenetration testing1CP2 Jun 2024 Q3(b)
Describe what a penetration test is. (2 marks)
Hint: Two linked marks: (1) what it is (authorised attack) + (2) its purpose (find vulnerabilities / improve security).
+20 XP
2 marksPhysical security1CP2 Jun 2023 Q2(f) style
A company has a server room. Give two physical security measures (other than CCTV) they could use to prevent unauthorised access. (2 marks)
Hint: Give two distinct physical measures (not technical/software ones). Each needs the measure AND what it achieves.
+20 XP
4 marksDiscuss vulnerabilities1CP2 Jun 2022 Q2(f) style
Describe two causes of security vulnerabilities in software. For each, explain the risk it creates. (4 marks)
Hint: Give the cause → explain the specific risk. Two marks per cause: name it + explain the attack it enables.
+40 XP
Module complete! 🎉
Score loading...