aimnova.
DashboardMy LearningPaper MasteryStudy Plan

Aimnova site navigation

Stay in the loop

Get the latest study resources and updates

New features, study tips and exam insights — straight to your inbox.

IB Diploma

  • IB Past Papers
  • IB Study Notes
  • IB Question Bank
  • IB Mock Exams
  • IB Revision

IB Subjects

  • IB Math AA
  • IB Math AI
  • IB Economics
  • IB Business Management
  • IB Physics
  • IB Biology
  • View all IB subjects→

IB Past Papers

  • IB Math AA HL Past Papers
  • IB Math AA SL Past Papers
  • IB Math AI HL Past Papers
  • IB Math AI SL Past Papers
  • IB Economics HL Past Papers
  • IB Economics SL Past Papers
  • IB ESS Past Papers
  • View all past papers→

Study Resources

  • Study Notes
  • Question Bank
  • Mock Exams
  • Flashcards
  • Revision Guide
  • Exam Skills
  • Command Terms
  • Grade Calculator
  • Exam Timetable 2026

Aimnova

  • Features
  • Pricing
  • For Schools
  • For Parents
  • About Us
  • Blog
  • Contact
aimnova.

AI-powered study platform for smarter revision, past-paper analysis and examiner-style feedback.

TermsPrivacyCookies·© 2026 Aimnova. All rights reserved.8afc4e3

Aimnova is not affiliated with or endorsed by the International Baccalaureate Organization (IB).

NotesComputer Science HLTopic 2.4Network vulnerabilities
Back to Computer Science HL Topics
2.4.24 min read

Network vulnerabilities (Computer Science HL)

IB Computer Science • Unit 2

Exam preparation

Practice the questions examiners actually ask

Our question bank mirrors real IB exam papers. Practice under timed conditions and track your progress across topics.

Start Practicing

Contents

  • Where networks are actually attacked
  • The named attacks
  • Why the weakest link is usually human
  • Exam-style question
The big idea: A vulnerability is a weakness; an attack is someone using it; a threat is the person who might.

Most successful attacks do not break cryptography. They exploit software that was never updated, a password that was guessable, or a person who was helpful.
VulnerabilityWhat it isHow it is exploited
Unpatched softwareA known flaw, left unfixedAutomated scanning finds it within hours
Weak credentialsGuessable or reused passwordsDictionary attack, or credentials leaked elsewhere
Unencrypted trafficData readable in transitPacket sniffing on a shared or public network
Open ports and servicesMore running than is neededEach one is another way in
PeopleWilling to help, and busySocial engineering and phishing

Free preview

This is the free notes preview

You're reading the free notes. Aimnova Pro unlocks the full study experience — and you can try it with your first topic free to keep:

  • FlashcardsLock in vocabulary and key terms with spaced repetition.
  • Practice questionsAnswer exam-style questions and get instant AI marking.
  • Mock exams & past-paper vaultSit full mocks and see exactly how examiners award marks.
  • Personalised study planA daily plan built around your exam date and weak areas.
Start Studying Free Full access to Aimnova Pro · cancel anytime
1

Packet sniffing

2

Man-in-the-middle

3

Denial of service

4

Malware

5

Social engineering

A worm needs no one to click: A virus needs a user to run the infected file. A worm spreads by itself, machine to machine, using a network vulnerability.

That difference is why a worm can cross an organisation in minutes, and why the distinction is examined.

Memorize terms 3x faster

Smart flashcards show you cards right before you forget them. Perfect for definitions and key concepts.

Try Flashcards FreeYour first topic is free to keep • No credit card required

What makes people the reliable route in

  • Urgency defeats caution — "your account will be closed today"
  • Authority is rarely questioned — an email appearing to come from a manager
  • Under pressure, people follow the fastest path, not the safest
  • One person in a thousand clicking is enough, and thousands can be emailed for nothing
  • And the attacker used a legitimate account, so nothing looks wrong afterwards
Name the vulnerability, then the attack: "Phishing" alone is a half answer. "Staff have no way to verify an email's sender, so a phishing message asking for credentials is likely to succeed" names the weakness and how it is used.

The vulnerability is the weakness; the attack is what someone does with it.

How this is tested — you must identify specific weaknesses in a described setup and say how each would be exploited. It comes up two ways:

Paper 1 Section A

  • Describe common network vulnerabilities, 3-4 marks
  • Name the attack being described
  • Distinguish a virus from a worm

Paper 1 Section B — case study

  • Identify weaknesses in a scenario
  • Explain why people are targeted
The classic trap: Naming attacks without the weakness each one needs. A DDoS needs finite capacity; sniffing needs unencrypted traffic; phishing needs staff unable to verify a sender.
IB-style questionIdentify[5 marks]

A small firm has open guest Wi-Fi with no password, computers that are two years behind on updates, one shared admin password, and staff who have had no security training. Identify the vulnerabilities and how each could be exploited.

Model answer plan

See the mark-by-mark plan — for / against / judgement, with marking guidance — in study mode.

Claim your free topic

Try an IB Exam Question — Free AI Feedback

Test yourself on Network vulnerabilities. Write your answer and get instant AI feedback — just like a real IB examiner.

Ransomware and rootkits are two types of malware. two other types of malware. [2 marks]

Related Computer Science HL Topics

Continue learning with these related topics from the same unit:

2.1.1What networks are for
2.1.2Digital infrastructures
2.1.3Network devices
2.1.4Network protocols
View all Computer Science HL topics

Improve your exam technique

Command terms, paper structure, and mark-scheme tips for Computer Science HL

Previous
2.4.1Firewalls
Next
Network countermeasures2.4.3

2 exam-style questions ready for you

Students who practice on Aimnova improve their scores by 15% on average. Get instant feedback that shows exactly how to improve your answers.

Practice Now — FreeView All Computer Science HL Topics