Practise Network security and identifying vulnerabilities. 11 exam-style questions on this subtopic, at up to four difficulty levels, with full mark schemes and a progress tracker. Free, no account needed.
Cover the answers and test yourself. The app has these as flashcards that come back just before you'd forget them.
Define the term 'penetration testing'.
An authorised mock attack to find weaknesses before criminals do.
A company hires an ethical hacker to find weaknesses in its network. Define the term 'ethical hacking'.
Hacking with the owner's permission to find weaknesses so they can be fixed.
Sample questions
Written for this site in the style of Edexcel exam questions. They are not taken from real past papers.
Question 1Easy3 marks
(a) Define the term 'penetration testing'.[1]
(b) Give two possible impacts on an organisation of a network security breach.[2]
Show the answer and mark scheme
(a)Answer: An authorised mock attack to find weaknesses before criminals do.
an authorised, simulated attack on a network or system to find vulnerabilities before criminals can exploit them
(b)Answer: Any two from: data stolen; financial loss; fines; reputational damage; downtime; data corrupted.
data, e.g. customers' personal data, is stolen or leaked
financial loss, e.g. stolen money, ransom demands or the cost of repairing systems
fines or legal action, e.g. for failing to protect personal data
damage to its reputation / loss of customers' trust
systems are unavailable, so the organisation cannot operate (downtime)
data is deleted, changed or corrupted
Question 2Medium4 marks
(a) Explain the difference between ethical hacking and malicious hacking.[2]
(b) Explain why an organisation would pay an ethical hacker to attack its network.[2]
Show the answer and mark scheme
(a)Answer: Ethical hackers are authorised and report the flaws they find; malicious hackers act without permission to cause harm or profit.
ethical hackers have the organisation's permission to try to break into its systems
they report the weaknesses they find so that they can be fixed, whereas malicious hackers break in without permission to steal data, cause damage or make money
(b)Answer: To discover weaknesses first so they can be fixed before criminals exploit them.
to find vulnerabilities before real criminals find and exploit them
so they can be fixed, reducing the risk of a costly breach or loss of data
Question 3Hard4 marks
Explain why network security is especially important for a hospital.[4]
Show the answer and mark scheme
Answer: Patient data is sensitive and legally protected, and systems must stay available and accurate because lives depend on them.
hospitals store confidential patient records, which are sensitive personal data
the hospital has a legal duty to keep personal data secure and could be fined if it is leaked
leaked medical information could cause patients distress or be used for fraud or blackmail
systems must be available at all times: an attack such as ransomware could stop staff accessing records or equipment, putting lives at risk
records must not be altered by attackers, because wrong information (e.g. allergies or doses) could harm patients