Community resourceWorksheet
OCR H446 1.3.3 Network threats and attack paths
Part 5 of 10 · H446 1.3.3 · Networks
Naming a threat earns very little on its own. This is the diagnosis half of the H446 1.3.3 security material, connecting each threat to its attack route, its target and its consequence; the following worksheet turns to the controls that answer them.
Students will:
- describe the mechanism behind common network threats
- work from incident evidence to a named threat rather than from the name backwards
- distinguish threats that attack availability from those that attack confidentiality or integrity
- diagnose several incidents reported together and keep the explanations distinct
Inside: 5 explanation cells, 1 multiple-choice question, 2 fill-in-the-blanks cells and 2 written answers. 26 marks, about 40 to 50 minutes.
Series: H446 1.3.3 · Networks, part 5 of 10.
Shared by Coding PathwayVerified teacher
- 10 cells
- About 45 minutes
- CC BY-SA 4.0
- Shared 31 Aug 2026
- Updated 3 Sept 2026
Preview
The whole resource, exactly as a class sees it. Answers and marking are held back.
Network threats and attack paths
A threat name is useful only when it is connected to a mechanism, a target and a consequence. This worksheet diagnoses threats first; NW06 then selects controls.
Mechanism → target → consequence
- Unauthorised access/hacking: a person gains access without permission, threatening confidentiality, integrity or service operation.
- Virus: malicious code attaches to a host/file and replicates when executed or shared, potentially corrupting or changing data.
- Spyware: secretly observes/collects activity or data and sends it elsewhere.
- Denial of service: excessive or abusive traffic/resources make a service unavailable to legitimate users.
- SQL injection: unvalidated input is treated as part of a database command, so unintended queries/actions may occur. No exploit strings are needed to understand the boundary failure.
- Phishing: a deceptive message/site lures a person into revealing data or taking an unsafe action.
- Pharming: name/address resolution or redirection is manipulated so a user reaches a fraudulent destination even after using the intended name.
Worked diagnosis
Evidence: staff receive a convincing account-reset message; one person follows its link and enters credentials on a fake page.
Diagnosis: phishing. The lure and impersonated message are the mechanism; credentials are the target; unauthorised account access is the likely consequence.
Contrast: if the user entered the correct remembered address but was silently redirected through manipulated name resolution, pharming would be the better diagnosis.
Which incident most directly attacks availability?
- AA flood of requests prevents legitimate users reaching a service
- BSpyware records browser activity
- CA fake message asks for a password
- DAn unauthorised user reads a file
- phishing
- pharming
- spyware
- SQL injection
- denial of service
Diagnose three incidents and give mechanism plus likely consequence: (A) thousands of compromised devices overwhelm a booking service; (B) a downloaded program silently records keystrokes; (C) a form value is interpreted as part of a database query and exposes records.
Use evidence from the incident, not just a label. Keep SQL injection conceptual and non-operational.
Students type their answer here.
Apply the model independently
The remaining tasks change the context or reduce the support. Complete them without copying the worked model, then check that each explanation connects a mechanism to its consequence.
A college reports: some learners received fake storage-warning emails; others typed the correct portal name but reached a copy site; one server became unavailable during a traffic flood; several files then changed after an infected attachment ran. Identify four distinct threats and explain why each label fits better than one nearby alternative.
Use phishing/pharming/DoS/virus and explicitly contrast a nearby misconception.
Students type their answer here.
Review your understanding
Before submitting, check that you can explain the main distinction in your own words, apply it in an unfamiliar context and justify each consequence rather than only naming a feature.