The big idea: A vulnerability is a weakness; an attack is someone using it; a threat is the person who might.
Most successful attacks do not break cryptography. They exploit software that was never updated, a password that was guessable, or a person who was helpful.
| Vulnerability | What it is | How it is exploited |
|---|---|---|
| Unpatched software | A known flaw, left unfixed | Automated scanning finds it within hours |
| Weak credentials | Guessable or reused passwords | Dictionary attack, or credentials leaked elsewhere |
| Unencrypted traffic | Data readable in transit | Packet sniffing on a shared or public network |
| Open ports and services | More running than is needed | Each one is another way in |
| People | Willing to help, and busy | Social engineering and phishing |
Free preview
This is the free notes preview
You're reading the free notes. Aimnova Pro unlocks the full study experience — and you can try it with your first topic free to keep:
- FlashcardsLock in vocabulary and key terms with spaced repetition.
- Practice questionsAnswer exam-style questions and get instant AI marking.
- Mock exams & past-paper vaultSit full mocks and see exactly how examiners award marks.
- Personalised study planA daily plan built around your exam date and weak areas.
Packet sniffing
Man-in-the-middle
Denial of service
Malware
Social engineering
A worm needs no one to click: A virus needs a user to run the infected file. A worm spreads by itself, machine to machine, using a network vulnerability.
That difference is why a worm can cross an organisation in minutes, and why the distinction is examined.
Memorize terms 3x faster
Smart flashcards show you cards right before you forget them. Perfect for definitions and key concepts.
What makes people the reliable route in
- Urgency defeats caution — "your account will be closed today"
- Authority is rarely questioned — an email appearing to come from a manager
- Under pressure, people follow the fastest path, not the safest
- One person in a thousand clicking is enough, and thousands can be emailed for nothing
- And the attacker used a legitimate account, so nothing looks wrong afterwards
Name the vulnerability, then the attack: "Phishing" alone is a half answer. "Staff have no way to verify an email's sender, so a phishing message asking for credentials is likely to succeed" names the weakness and how it is used.
The vulnerability is the weakness; the attack is what someone does with it.
How this is tested — you must identify specific weaknesses in a described setup and say how each would be exploited. It comes up two ways:
Paper 1 Section A
- Describe common network vulnerabilities, 3-4 marks
- Name the attack being described
- Distinguish a virus from a worm
Paper 1 Section B — case study
- Identify weaknesses in a scenario
- Explain why people are targeted
The classic trap: Naming attacks without the weakness each one needs. A DDoS needs finite capacity; sniffing needs unencrypted traffic; phishing needs staff unable to verify a sender.
A small firm has open guest Wi-Fi with no password, computers that are two years behind on updates, one shared admin password, and staff who have had no security training. Identify the vulnerabilities and how each could be exploited.
Model answer plan
See the mark-by-mark plan — for / against / judgement, with marking guidance — in study mode.