All topics › OCR GCSE Computer Science › Identifying and preventing vulnerabilities
1.4.2 Identifying and preventing vulnerabilities
OCR GCSE Computer Science (J277) · Computer systems (Paper 1) › Network security
Practise Identifying and preventing vulnerabilities. 11 exam-style questions on this subtopic, at up to four difficulty levels, with full mark schemes and a progress tracker. Free, no account needed.
Build a paper on this topic
▶ Watch videos on Identifying and preventing vulnerabilities (Craig 'n' Dave OCR on YouTube) · Practise all of Network security
Sample questions Written for this site in the style of OCR exam questions. They are not taken from real past papers.
Question 1 Easy 4 marks
(a) State what is meant by penetration testing.[1]
(b) Which method would best protect the equipment in a server room from theft? Tick (✓) one box.[1]
A firewall Anti-malware software Encryption Physical security, e.g. locked doors and key cards (c) Give two features of a strong password.[2]
Show the answer and mark scheme (a) an authorised, simulated attack on a system to find security weaknesses (b) Answer: Physical security, e.g. locked doors and key cards
(c) long, e.g. at least 8 characters a mix of uppercase and lowercase letters, numbers and symbols not a dictionary word / name / personal information not used for any other account Question 2 Medium 3 marks
Describe how a firewall helps to protect a network.[3]
Show the answer and mark scheme it monitors incoming and outgoing network traffic it checks packets against a set of rules, e.g. allowed IP addresses or ports it blocks traffic that does not meet the rules / prevents unauthorised access it can be hardware or software Question 3 Hard 5 marks
A bank hires a security company to carry out penetration testing on its systems.
(a) Explain the purpose of penetration testing.[2]
(b) The bank gives the testers no information about its systems. Explain why.[2]
(c) Explain why the testers must have written permission from the bank before they start.[1]
Show the answer and mark scheme (a) to find vulnerabilities / weaknesses in the system so they can be fixed before criminals find and exploit them (b) this simulates an attack by an outsider / hacker who has no inside knowledge so it shows what a real external attacker could discover and do (c) without permission, accessing the systems would be unauthorised access, which is an offence under the Computer Misuse Act 1990 Related subtopics
Stuck? Get 1-to-1 help. Chhetri Academy tutors GCSE and A level Maths and Science online, with a free 30-minute trial lesson.
Book a free trial