Community resourceWorksheet
1CP2-P-5.6 Cybersecurity and robust software checkpoint
Part 6 of 6 · 1CP2-P-5 · Cyber security and robust software
The checkpoint for the whole series, sampling malware, vulnerabilities, social engineering, protection and robust software.
Students will:
- identify a social-engineering technique from a scenario
- explain how unpatched software leads to loss or disruption
- recommend and justify three distinct controls for a school
- compare audit trails with code reviews as methods of identifying misuse
- correct two common protection misconceptions
Inside: 3 explanation cells, 3 multiple-choice questions, 2 fill-in-the-blanks cells and 5 written answers. 20 marks, about 45 minutes.
Series: 1CP2-P-5 · Cyber security and robust software, part 6 of 6.
Shared by Coding PathwayVerified teacher
- 13 cells
- About 45 minutes
- CC BY-SA 4.0
- Shared 17 Aug 2026
Preview
The whole resource, exactly as a class sees it. Answers and marking are held back.
1CP2-P-5 checkpoint
This checkpoint assesses only the Y10-5 principles series. It introduces no new content and does not include the separate network-security controls taught later in the course.
- keylogger
- ransomware
- Trojan
- virus
- worm
An attacker invents a technician identity and urgent story to obtain a reset code. Which technique is this?
- ABaiting
- BPhishing
- CPretexting
- DQuid pro quo
Explain how unpatched software can lead to data loss or service disruption.
Link weakness, exploitation and impact.
Students type their answer here.
A message offers a free device in return for login details. Identify the social-engineering technique and explain how a user should respond safely.
Use the exchange and independent verification/reporting.
Students type their answer here.
Protection scenario
A school stores confidential records, depends on daily access, and must recover after deletion, disk failure or ransomware. Controls should protect confidentiality, reduce unsafe behaviour and make restoration possible.
Recommend and justify three distinct controls for the school.
Select from encryption, anti-malware, acceptable use policy, backup and recovery procedures.
Students type their answer here.
Why is RAID not sufficient as the only backup?
- AIt cannot use disks.
- BIt may provide current redundancy but not a separate historical copy after deletion, corruption or ransomware.
- CIt always stores data off-site.
- DIt prevents all malware.
- audit trail
- code review
- encrypted
- robust
Compare audit trails and code reviews as methods of identifying vulnerabilities or misuse.
State what evidence each examines.
Students type their answer here.
Which is a software vulnerability?
- AStrong authentication
- BEncrypted confidential data
- CA shared easily guessed password
- DA tested off-site backup
Correct both claims: 'an AUP automatically blocks malware' and 'encryption restores deleted files'.
Correct both purposes concisely.
Students type their answer here.
Checkpoint complete
You have demonstrated the required Y10-5 principles: malware mechanisms, technical and social attack routes, layered protection and recovery, robust software, audit trails and code reviews.