No single defence stops every attack. Security is built in layers, and each layer stops particular threats. The system here is a teacher's laptop at Wentworth Computer Science College, which also signs in to the school's online system. Switch the defences on and off on the left, then run the attacks on the right: the red attack travels towards the data, jumps any wall that isn't in its way, and stops at the first wall that defeats it.
- Password (something you know). Strength comes mostly from length and from mixing upper case, lower case, digits and symbols. A common word with numbers on the end (
Kiwi2026!) is guessed quickly, because cracking programs try those first. A strong password stops brute-force attacks and guessing, but not someone who watches you type it or tricks you into typing it into a fake page.
- Biometrics (something you are): a fingerprint or face scan. Quick to use and nothing to remember, but the scanner costs money, and a fingerprint can't be changed if it is ever copied. Here it protects signing in to the laptop.
- Two-factor authentication (2FA): two different kinds of proof, such as your password and a code sent to your phone (something you have). A stolen password alone is then not enough: it stops phishing, shoulder surfing and brute force. The cost is an extra step every time you sign in.
- Firewall: checks the traffic between a computer or network and the internet against rules, and blocks connections that haven't been asked for, such as a hacker scanning for open ports. It doesn't stop what you let in yourself (an email attachment) or what you send out.
- Encryption: scrambles data with a key, so it is unreadable without the key. It protects data that is stolen (a laptop's drive taken out) or intercepted (on public Wi-Fi). It doesn't stop someone who signs in as you or as another user, because the data is decrypted for anyone who is signed in.
- Anti-malware (anti-virus): scans files, email attachments and downloads against known malware and suspicious behaviour, and quarantines what it finds. It must be kept up to date.
- Access rights: each user can read or change only what their job needs (least privilege). They stop an insider who is a genuine user but has no reason to open certain files.
Trade-offs. Every layer has a cost: money (a scanner, a subscription, someone's time to set it up) and usability (an extra step, something to remember, waiting for a scan, asking for access). The readouts show both. Use Missions in the title bar to defend six different systems within a budget, then see a review of what you got wrong, with the cheapest set of layers that works.
Common exam mistakes: saying a firewall stops viruses in email (it filters connections, not the files you choose to open); saying encryption stops data being stolen (it stops stolen data being read); saying a strong password stops phishing or shoulder surfing (the attacker gets the password itself, however strong it is); writing "a password with symbols" without saying why (it makes the number of possible passwords far larger, so a brute-force attack takes too long); and describing two-factor authentication as "two passwords" (it is two different kinds of proof).
Objective: Cambridge IGCSE ICT (0417) section 8, safety and security: threats to data (hacking, phishing, malware, shoulder surfing) and how to protect it (passwords, biometrics, two-factor authentication, firewalls, encryption, anti-malware and access rights). Cambridge International AS Level Information Technology (9626): the security of data and networks, authentication and encryption. The strength meter is a simple estimate: real meters also check long lists of leaked passwords.
Where this fits
- AP: AP Computer Science Principles
- AQA: AQA A Level Computer Science (7517) Goes beyond AQA A Level Computer Science (7517): Passwords, biometrics, 2FA and access rights go beyond AQA 7517; firewalls, encryption and malware are in it.
- Cambridge: Cambridge IGCSE Information and Communication Technology (0417); Cambridge IGCSE Computer Science (0478); Cambridge A Level Computer Science (9618); Cambridge AS Level Computer Science (9618); Cambridge A Level Information Technology (9626); Cambridge AS Level Information Technology (9626)
- IB: IB Computer Science HL; IB Computer Science SL
- NCEA Level 2 Digital Technologies: 91898 Demonstrate understanding of a computer science concept; 91898 Demonstrate understanding of a computer science concept
- Pearson Edexcel International: Edexcel International GCSE Computer Science (4CP0); Edexcel International GCSE ICT (4IT1); Edexcel International A Level Information Technology
- USDP: USDP Computer Science