Practise Threats to computer systems and networks. 11 exam-style questions plus unlimited generated ones on this subtopic, at up to four difficulty levels, with full mark schemes and a progress tracker. Free, no account needed.
Written for this site in the style of OCR exam questions. They are not taken from real past papers.
Question 1Easy4 marks
(a) State what is meant by malware.[1]
(b) Which one of the following is an example of social engineering? Tick (✓) one box.[1]
A brute-force attack
SQL injection
A phishing email
A denial of service attack
(c) Give two types of malware.[2]
Show the answer and mark scheme
(a)
software designed to cause harm / damage to a computer system or to gain unauthorised access to it
(b)Answer: A phishing email
(c)
virus
worm
trojan
ransomware
spyware / keylogger
adware
Question 2Medium4 marks
Describe what is meant by phishing and explain how a user could recognise a phishing email.[4]
Show the answer and mark scheme
a fake email / message that pretends to be from a trusted organisation, e.g. a bank
it tries to trick the user into giving personal details / clicking a link / opening an attachment
sign: a general greeting such as 'Dear customer' instead of the user's name
sign: urgent or threatening language, e.g. 'your account will be closed today'
sign: spelling and grammar mistakes
sign: the sender's address or the real address of a link does not match the organisation
sign: it asks for a password or bank details, which genuine organisations do not ask for by email
Question 3Hard6 marks
A shop's website checks a customer's login using this SQL statement. The text that the customer types into the username and password boxes replaces USERNAME and PASSWORD.
SELECT * FROM Customers
WHERE Username = 'USERNAME'
AND Password = 'PASSWORD'
(a) An attacker types x' OR '1'='1 into both boxes. Write the SQL statement that is created.[1]
(b) Explain why the attacker is logged in without knowing a valid password.[2]
(c) State the name of this type of attack.[1]
(d) Describe one way the website could prevent this attack.[2]
Show the answer and mark scheme
(a)
SELECT * FROM Customers WHERE Username = 'x' OR '1'='1' AND Password = 'x' OR '1'='1'
(b)
'1'='1' is always true
so the WHERE condition is true for every record, customer records are returned and the system treats the login as successful
(c)Answer: SQL injection
SQL injection
(d)
validate / sanitise the input
e.g. reject or escape characters such as ' so they cannot change the SQL
use parameterised queries
so the input is always treated as data, not as part of the SQL command