Community resourceWorksheet

1CP2-P-5.6 Cybersecurity and robust software checkpoint

Part 6 of 6 · 1CP2-P-5 · Cyber security and robust software

The checkpoint for the whole series, sampling malware, vulnerabilities, social engineering, protection and robust software.

Students will:

  • identify a social-engineering technique from a scenario
  • explain how unpatched software leads to loss or disruption
  • recommend and justify three distinct controls for a school
  • compare audit trails with code reviews as methods of identifying misuse
  • correct two common protection misconceptions

Inside: 3 explanation cells, 3 multiple-choice questions, 2 fill-in-the-blanks cells and 5 written answers. 20 marks, about 45 minutes.

Series: 1CP2-P-5 · Cyber security and robust software, part 6 of 6.

Shared by Coding PathwayVerified teacher

  • 13 cells
  • About 45 minutes
  • CC BY-SA 4.0
  • Shared 17 Aug 2026

Preview

The whole resource, exactly as a class sees it. Answers and marking are held back.

1CP2-P-5 checkpoint

This checkpoint assesses only the Y10-5 principles series. It introduces no new content and does not include the separate network-security controls taught later in the course.

Fill in the blanks4 marks
A self-spreading standalone program is a gap 1. Disguised malicious software is a gap 2. Malware that records keystrokes is a gap 3. Malware that denies access and demands payment is gap 4.
  • keylogger
  • ransomware
  • Trojan
  • virus
  • worm
Multiple choice1 mark

An attacker invents a technician identity and urgent story to obtain a reset code. Which technique is this?

  • ABaiting
  • BPhishing
  • CPretexting
  • DQuid pro quo
Written answer2 marks

Explain how unpatched software can lead to data loss or service disruption.

Link weakness, exploitation and impact.

Students type their answer here.

Written answer2 marks

A message offers a free device in return for login details. Identify the social-engineering technique and explain how a user should respond safely.

Use the exchange and independent verification/reporting.

Students type their answer here.

Protection scenario

A school stores confidential records, depends on daily access, and must recover after deletion, disk failure or ransomware. Controls should protect confidentiality, reduce unsafe behaviour and make restoration possible.

Written answer3 marks

Recommend and justify three distinct controls for the school.

Select from encryption, anti-malware, acceptable use policy, backup and recovery procedures.

Students type their answer here.

Multiple choice1 mark

Why is RAID not sufficient as the only backup?

  • AIt cannot use disks.
  • BIt may provide current redundancy but not a separate historical copy after deletion, corruption or ransomware.
  • CIt always stores data off-site.
  • DIt prevents all malware.
Fill in the blanks3 marks
Software that handles invalid situations predictably is gap 1. A chronological record of actions is an gap 2. Human or automated inspection of source is a gap 3.
  • audit trail
  • code review
  • encrypted
  • robust
Written answer2 marks

Compare audit trails and code reviews as methods of identifying vulnerabilities or misuse.

State what evidence each examines.

Students type their answer here.

Multiple choice1 mark

Which is a software vulnerability?

  • AStrong authentication
  • BEncrypted confidential data
  • CA shared easily guessed password
  • DA tested off-site backup
Written answer1 mark

Correct both claims: 'an AUP automatically blocks malware' and 'encryption restores deleted files'.

Correct both purposes concisely.

Students type their answer here.

Checkpoint complete

You have demonstrated the required Y10-5 principles: malware mechanisms, technical and social attack routes, layered protection and recovery, robust software, audit trails and code reviews.