A cyber threat is an attempt to damage, disrupt, or gain unauthorised access to a computer system or network.
Malware (malicious software) is any software designed to harm a computer system.
| Type | Description |
|---|---|
| Virus | Attaches itself to files and spreads when files are shared. Can delete data or corrupt files. |
| Worm | Self-replicating malware that spreads across networks without needing to attach to a file. |
| Trojan horse | Disguises itself as legitimate software but carries a hidden malicious payload. |
| Ransomware | Encrypts victim's files and demands payment (ransom) to restore access. |
| Spyware | Secretly monitors user activity and sends information to attackers (e.g. keystrokes, passwords). |
| Adware | Displays unwanted advertisements; may redirect browsers to harmful sites. |
Social engineering exploits human psychology rather than technical vulnerabilities.
| Threat | Description |
|---|---|
| Denial of Service (DoS) | Floods a server with traffic to make it unavailable to legitimate users |
| Distributed DoS (DDoS) | DoS attack from multiple sources (a botnet) — harder to block |
| Brute force attack | Tries all possible passwords until the correct one is found |
| SQL injection | Malicious SQL code entered into a web form to access/manipulate a database |
| Man-in-the-middle | Attacker intercepts communications between two parties |
| Measure | How it helps |
|---|---|
| Firewall | Monitors and filters incoming/outgoing network traffic based on security rules |
| Antivirus software | Detects and removes known malware; runs regular scans |
| Strong passwords | Harder to crack — use uppercase, lowercase, numbers, symbols, 12+ characters |
| Two-factor authentication (2FA) | Requires a second form of verification (e.g. phone code) in addition to password |
| Software updates/patches | Fix known security vulnerabilities in software and operating systems |
| User access control | Restricts access to data/systems based on the user's role |
| Encryption | Scrambles data so it is unreadable to unauthorised parties |
| User education | Train staff to recognise phishing, use secure passwords, and follow security policies |
| Physical security | Lock doors, use ID badges, CCTV — prevent physical access to systems |
| Backups | Regular backups ensure data can be restored if lost or corrupted by ransomware |
8 Edexcel-style questions · AI-marked
| Term | Definition |
|---|
Timed exam-style test.