Chhetri AcademyGCSE & A level Paper Builder

1.4.2Identifying and preventing vulnerabilities

OCR GCSE Computer Science (J277) · Computer systems (Paper 1) › Network security

Practise Identifying and preventing vulnerabilities. 11 exam-style questions on this subtopic, at up to four difficulty levels, with full mark schemes and a progress tracker. Free, no account needed.

Build a paper on this topic

▶ Watch videos on Identifying and preventing vulnerabilities (Craig 'n' Dave OCR on YouTube) · Practise all of Network security

Sample questions

Written for this site in the style of OCR exam questions. They are not taken from real past papers.

Question 1Easy4 marks
(a) State what is meant by penetration testing.[1]
(b) Which method would best protect the equipment in a server room from theft?
Tick (✓) one box.[1]
  • A firewall
  • Anti-malware software
  • Encryption
  • Physical security, e.g. locked doors and key cards
(c) Give two features of a strong password.[2]
Show the answer and mark scheme
(a)
  • an authorised, simulated attack on a system to find security weaknesses
(b) Answer: Physical security, e.g. locked doors and key cards
(c)
  • long, e.g. at least 8 characters
  • a mix of uppercase and lowercase letters, numbers and symbols
  • not a dictionary word / name / personal information
  • not used for any other account
Question 2Medium3 marks
Describe how a firewall helps to protect a network.[3]
Show the answer and mark scheme
  • it monitors incoming and outgoing network traffic
  • it checks packets against a set of rules, e.g. allowed IP addresses or ports
  • it blocks traffic that does not meet the rules / prevents unauthorised access
  • it can be hardware or software
Question 3Hard5 marks
A bank hires a security company to carry out penetration testing on its systems.
(a) Explain the purpose of penetration testing.[2]
(b) The bank gives the testers no information about its systems. Explain why.[2]
(c) Explain why the testers must have written permission from the bank before they start.[1]
Show the answer and mark scheme
(a)
  • to find vulnerabilities / weaknesses in the system
  • so they can be fixed before criminals find and exploit them
(b)
  • this simulates an attack by an outsider / hacker who has no inside knowledge
  • so it shows what a real external attacker could discover and do
(c)
  • without permission, accessing the systems would be unauthorised access, which is an offence under the Computer Misuse Act 1990

Related subtopics

Stuck? Get 1-to-1 help. Chhetri Academy tutors GCSE and A level Maths and Science online, with a free 30-minute trial lesson.

Book a free trial