Potential Risks to Data (Edexcel IGCSE ICT): Flashcards

Exam code: 4IT1

1/48

0Still learning

Know0

  • Define unauthorised access.

Cards in this collection (48)

  • Define unauthorised access.

    Unauthorised access is when a user gains access to a network without permission.

  • What is the difference between direct and indirect entry?

    Direct entry is a user trying to gain access themselves or with software that repeatedly tries username and password combinations, while indirect entry is exploiting vulnerabilities in software or users.

  • Software that repeatedly tries username and password combinations is carrying out a                      attack.

    Software that repeatedly tries username and password combinations is carrying out a brute force attack.

  • Define botnet.

    A botnet is a group of computers used without their owners' knowledge to carry out harmful activities or spread malware.

  • Give three ways accidental deletion of data can occur.

    A user might press the wrong key on a keyboard, format media on the wrong device, or lose power unexpectedly.

  • Define malware.

    Malware is any software created with malicious intent to cause harm to a computer system.

  • Give three issues caused by malware.

    Files being deleted, corrupted or encrypted, the internet connection becoming slow or unusable, and the computer crashing or shutting down.

  • What is a virus?

    A virus is a program which can replicate itself on a user's computer, containing code that causes unwanted and unexpected events such as corrupting files or deleting data.

  • What is the main difference between a worm and a virus?

    A worm will spread to other drives and computers on the network, whereas a virus replicates on the computer it has infected.

  • What is a Trojan?

    A Trojan disguises itself as legitimate software but contains malicious code in the background.

  • What can spyware do once it is on a device?

    Spyware can record the screen and log keystrokes to gain access to passwords, allowing a person to spy on the user's activities.

  • What does ransomware do?

    Ransomware locks the computer and encrypts documents and other important files, then makes a demand for money in return for the password to decrypt them.

  • True or False?

    Paying a ransomware demand guarantees the user will get their data back.

    False.

    There is no guarantee that paying the ransom will result in the user getting their data back.

  • Define phishing.

    Phishing is a form of social engineering that sends fraudulent, legitimate-looking emails to many addresses, claiming to be from a reputable company, to gain access to a user's details.

  • Why are phishing messages sent to many users at once?

    It increases the chances of a user responding, because not all users are vulnerable and many people are aware of phishing.

  • Define pharming.

    Pharming is when a user types a website address into a browser and is redirected to a 'fake' website, to trick them into typing in sensitive information such as passwords.

  • Give three ways pharming can be prevented.

    Keeping anti-malware software up to date, checking URLs regularly, and making sure the padlock icon is visible.

  • Give four features of a strong password.

    A strong password has more than eight characters, a mixture of letters, numbers and symbols, a mixture of uppercase and lowercase letters, and uses uncommon words or phrases.

  • Define biometrics.

    Biometrics are a way of authenticating a user by their unique human characteristics, such as fingerprint scans, retina scans and facial recognition.

  • Give two advantages of biometrics over passwords.

    Biometric data is unique to the person and cannot be copied, so it is always with them, and it eliminates attacks such as shoulder surfing and key-logging, whereas passwords can be copied, forgotten, guessed or cracked.

  • Give three disadvantages of biometrics.

    They can be intrusive, scans may not be recognised (for example a fingerprint scan with dirty hands), they are very expensive to install, low light affects facial recognition, and people may be uncomfortable having their characteristics stored in a database.

  • What does a CAPTCHA test for?

    A CAPTCHA tests whether a website request originates from a human or a machine (bot).

  • Name the three types of CAPTCHA.

    Text, where users decipher characters from a distorted text box, image, where users select all images containing a specific object, and checkbox, where a user confirms they are not a robot.

  • Name the three types of software combined in anti-malware.

    Anti-virus, anti-spam and anti-spyware.

  • How does anti-malware software work?

    It scans email attachments, websites and downloaded files for issues, blocks anything matching its list of known malware signatures, and checks for updates to keep its database current.

  • Name the three levels of access right a user can be given.

    Full access to open, create, edit and delete files, read-only access to open files without editing or deleting, and no access, which hides the file from the user.

  • On what basis are access rights set?

    Access rights are set based on a user's role, responsibility or clearance level.

  • How do access rights typically differ between staff and students on a school network?

    Teaching staff are partially restricted and can access all student data but not other staff members' data, while students are restricted to their own data and files; administrators are unrestricted.

  • What does HTTP allow?

    Hypertext Transfer Protocol allows communication between clients and servers for website viewing, letting clients receive data from the server and send data to it.

  • HTTPS works in the same way as HTTP, but all data sent and received is                     .

    HTTPS works in the same way as HTTP, but all data sent and received is encrypted.

  • What is HTTPS used to protect?

    HTTPS protects sensitive information such as passwords, financial information and personal data.

  • Give four warning signs that an email may be unsafe.

    The email is from an unknown sender, the text is general or impersonal, it contains spelling, punctuation or grammar mistakes, attached files are executable (.exe) files, the tone is one of urgency, or the URL is unrecognised.

  • What is the difference between a full backup and an incremental backup?

    A full backup copies all files, which is safest but slow, while an incremental backup copies only files added or modified since the last backup, which is faster but less secure.

  • True or False?

    Backups must always be run manually by the user.

    False.

    Backups can be automated and scheduled to happen at less busy periods of the day, so they do not take up valuable system resources.

  • Where can backups be stored?

    Backups can be stored locally on secondary storage or remotely in the cloud.

  • Define online payment system.

    An online payment system eliminates the need for physical cash by facilitating the payment for goods and services online.

  • Name four benefits offered by online payment systems.

    Convenience, since you can pay for anything, anytime, from anywhere; security, since encryption protects sensitive information; increased reach for international transactions; and transparency, since digital records are kept.

  • Why does transparency matter in an online payment system?

    Digital records are kept, which makes it easy to monitor payments and resolve disputes.

  • Name the three most common types of online payment system.

    Third party payment processors, bank cards and contactless (NFC) payments.

  • Third party payment processors facilitate online payments using an                      as identification.

    Third party payment processors facilitate online payments using an email address as identification.

  • Why might a retailer link a third party payment processor to its online shop?

    It makes the purchasing process easier and faster for the customer.

  • What three pieces of information from a bank card are required to make an online purchase?

    The 16 digit card number, the expiry date and the security number (CVC).

  • What role do other financial institutions play when a bank card is used online?

    They may be used to authenticate the transaction.

  • How does a contactless payment take place?

    If a contactless card is in close proximity of a reader requesting a payment, the transaction can take place using near field communication (NFC).

  • Why is there a limit on the amount of a contactless payment?

    No extra authentication takes place, so the limit is there to deter criminals, because only small amounts can be stolen.

  • Why does NFC speed up the payment process?

    Users can scan or tap their card rather than inserting it and entering a PIN, because NFC is a contactless payment method.

  • Name four ways online payments can be protected.

    Banks monitoring payments and analysing spending patterns, encryption, two factor authentication (2FA), and using secure websites (HTTPS).

  • True or False?

    A contactless payment requires the user to enter a PIN for authentication.

    False.

    No extra authentication takes place on a contactless payment, which is why the amount is limited.

Sign up to unlock flashcards

or