Community resourceWorksheet
1CP2-P-5.2 Attackers and technical vulnerabilities
Part 2 of 6 · 1CP2-P-5 · Cyber security and robust software
The vulnerability worksheet, building a linked chain from a technical weakness to the harm an attacker causes with it.
Students will:
- explain why unpatched software increases risk
- describe how an unpatched vulnerability could disrupt school systems
- compare updating software with updating anti-malware
- recommend proportionate immediate controls for a published vulnerability
- replace a vague cause with a strong causal explanation
Inside: 5 explanation cells, 4 multiple-choice questions, 1 fill-in-the-blanks cell and 4 written answers. 18 marks, about 45 minutes.
Series: 1CP2-P-5 · Cyber security and robust software, part 2 of 6.
Shared by Coding PathwayVerified teacher
- 14 cells
- About 45 minutes
- CC BY-SA 4.0
- Shared 17 Aug 2026
Preview
The whole resource, exactly as a class sees it. Answers and marking are held back.
Attackers and technical vulnerabilities
In Pearson specification point 5.3.1, hackers refers to criminals who gain or attempt unauthorised access by exploiting technical vulnerabilities. A vulnerability is a weakness that could be exploited; an exploit is the method used to take advantage of it.
1. Build a linked attack chain
Software patches correct known faults or weaknesses. Delaying a security patch leaves an avoidable route open. Out-of-date anti-malware may also fail to recognise newer known malicious patterns. Strong explanations connect weakness, exploitation and consequence.
- exploit
- patch
- permission
- vulnerability
Why can unpatched software increase risk?
- AIt may retain a known weakness that an attacker can exploit.
- BIt automatically encrypts every backup.
- CIt prevents all network connections.
- DIt changes a worm into a virus.
Explain how an attacker could use an unpatched vulnerability to disrupt a school's systems.
Write a linked weakness → action → impact chain.
Students type their answer here.
2. Two different updates
A software patch changes the vulnerable program. An anti-malware update refreshes signatures or detection information. They address related risks through different mechanisms, so one does not replace the other.
Which action directly corrects a known weakness in an application?
- AUpdate the application's security patch
- BRename the application's shortcut
- CCompress the application's files
- DMake an incremental backup only
Compare updating software with updating anti-malware.
Explain the different mechanism of each.
Students type their answer here.
3. Apply controls proportionately
Organisations test and schedule changes, but a known critical security weakness should not be ignored. Risk depends on exposure, likelihood and potential impact. Examination answers should justify the chosen action from the scenario rather than repeat 'update everything'.
A public-facing booking system is running a version with a published critical vulnerability. Recommend two immediate actions and justify each.
Stay within patching and anti-malware scope.
Students type their answer here.
Which combination most directly reduces the two technical weaknesses taught here?
- AApply the security patch and update anti-malware
- BRename the software and compress its files
- CChange the wallpaper and make one backup
- DLeave the known weakness and wait for an attack
Correct this claim: 'The attack happened because the computer was old.'
Replace the vague cause with a technically precise, evidenced explanation.
Students type their answer here.
Which is the strongest causal explanation?
- AThe hacker was clever, so the system broke.
- BThe system was bad.
- CA known flaw remained unpatched, so malicious input could exploit it and gain unauthorised access.
- DThe computer contained files.
Route forward
You can explain technical exploitation precisely. Next you will contrast this with social engineering, where an attacker manipulates a person into revealing information or taking an unsafe action.