Security Controls, Vulnerability Testing and Secure Design
Identifying weaknesses and selecting preventive, detective and corrective controls throughout design, creation, testing and use.
How to study for GCSE Computer Science
Move repeatedly between problem, algorithm, trace, code, test evidence and system explanation; use the exact language and assessment format required by your current board.
Core concepts
Concept 1
Vulnerability assessment, penetration testing and monitoring identify different evidence about weaknesses and attempted compromise.
Exam cue: Match each control to the threat or vulnerability it reduces and state its limitation.
Concept 2
Layered controls include authentication, least privilege, patching, firewalls, encryption, backups, physical protection and user processes.
Exam cue: Distinguish authorised security testing from unauthorised access.
Concept 3
Secure design considers threats and misuse from the start, validates input, minimises privilege and fails safely rather than adding protection only after release.
Exam cue: Use defence in depth so one failed control does not expose the entire asset.
Risk pitfalls and guardrails
Claiming encryption prevents all data loss or malware.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Treating a firewall as complete network security.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Running penetration tests without defined permission and scope.
Guardrail: Do not substitute one board's syntax, protocol list, language version or extension topic for the multi-board core; check the current specification and exam year.
Memory anchors
Defence in depth
Using multiple independent layers of security control.
Least privilege
Giving an identity only the access needed for its task.
Penetration test
An authorised attempt to find and demonstrate exploitable weaknesses.
Encryption
Transforming data using a key so unauthorised readers cannot understand it.
Patch
A software update intended to correct defects or vulnerabilities.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
What is the purpose of a firewall?
What is encryption?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 247 UK exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
