arrow_backกลับไปที่บันทึกภาคสนาม
COMPUTER SCIENCE เผยแพร่แล้ว 4 Aug 2026

GCSE Computer Science: Cyber Security Explained

A clear breakdown of the cyber security topics covered in GCSE Computer Science, from malware types to social engineering and prevention methods.

GCSE Computer Science exam boards (AQA, OCR, Edexcel) all include a cyber security unit, usually sitting inside a broader networks or systems security topic. Students are expected to know common threats, why they matter, and how organisations defend against them. It's a small but frequently tested slice of the syllabus, and it trips people up because the terms sound similar but mean different things.

What counts as a threat

The specifications group threats into two broad categories: malicious code and human weakness. On the malware side you need to know the differences between:

  • Viruses — attach themselves to files and need a host program to spread, usually via infected downloads or removable media.
  • Worms — self-replicating and spread across networks without needing a host file or user action.
  • Trojans — disguised as legitimate software to trick a user into installing them.
  • Spyware/keyloggers — quietly monitor activity, often to capture passwords or card details.
  • Ransomware — encrypts a victim's files and demands payment for the decryption key.

Exam answers often lose marks by mixing up viruses and worms, so the key distinguishing fact worth memorising is that a worm doesn't need a host file or user interaction to spread; a virus does.

Social engineering and human error

Much of the GCSE content is about the fact that people, not just code, are the weak point. Key techniques to know:

  • Phishing — fraudulent emails or messages designed to trick someone into revealing credentials or clicking a malicious link.
  • Pharming — redirecting a user to a fake website, often by corrupting DNS lookups, without them realising anything's wrong.
  • Shouldering (shoulder surfing) — simply watching someone type in a PIN or password.
  • Blagging — inventing a scenario or pretext to get someone to hand over information.

Examples in past papers often ask you to identify which technique is described in a scenario, so it's worth practising against real mock questions rather than just memorising definitions in isolation.

Network-level attacks

A few technical attack types come up regularly:

  • SQL injection — entering malicious SQL code into an input field to manipulate or extract data from a database. Students should know the basic defence: input validation and parameterised queries.
  • DoS/DDoS attacks — flooding a server with traffic so legitimate users can't access a service. Spec-level answers usually just need

เขียนด้วยความช่วยเหลือของ AI ตรวจสอบและเผยแพร่โดย Michal Pilch (CISSP), Korra Studio

พร้อมที่จะไปต่อหรือไม่

นี่คือบันทึกหนึ่งจากฐานความรู้ของ Korra Studio — แพลตฟอร์มจับคู่หัวข้อแต่ละหัวข้อกับการฝึกสอนแบบ 1-to-1

เริ่มใช้งานฟรีarrow_forward