Cyber Threats, Attacks and Vulnerabilities
Technical weaknesses, malicious software and behavioural manipulation as routes to compromise confidentiality, integrity or availability.
How to study for GCSE Computer Science
Move repeatedly between problem, algorithm, trace, code, test evidence and system explanation; use the exact language and assessment format required by your current board.
Core concepts
Concept 1
A threat is a potential cause of harm, a vulnerability is an exploitable weakness and an attack is an attempt to cause compromise.
Exam cue: Identify the asset, threat actor, vulnerability, attack path and consequence.
Concept 2
Malware and technical attacks exploit software, configuration or protocol weaknesses, while social engineering exploits human trust or behaviour.
Exam cue: Separate the attack mechanism from the outcome it seeks.
Concept 3
Risk depends on likelihood, impact, exposure and existing controls, so the same vulnerability may create different priorities.
Exam cue: Use current NCSC or board examples for evolving threat names while retaining the stable security model.
Risk pitfalls and guardrails
Using virus, malware and hacking as exact synonyms.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Calling a threat a vulnerability.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Ranking risk from likelihood alone without impact.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Memory anchors
Threat
A potential cause of harm to a system or asset.
Vulnerability
A weakness that could be exploited.
Attack
An attempt to exploit weaknesses or otherwise compromise a system.
Malware
Software intentionally designed to cause harm or unauthorised action.
Social engineering
Manipulating people into revealing information or performing unsafe actions.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
What is a cyber security threat?
A security audit finds an unpatched weakness that an attacker could exploit. How should this weakness be classified?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 247 UK exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
