Oxford Cambridge and RSA
GCSE (9-1) Computer Science
Computer Systems
J277/01
Topic: Unit 1.4 Prevention & Management
Time allowed: 30 minutes
Centre number Candidate number
First name Last name
INSTRUCTIONS INFORMATION
Turn over
1
Complete the table below by placing a tick (✓) in the correct column to show which security measure is described.
[3]
Description Anti-malware Firewall Penetration Testing
Scans files against a database of known signatures to detect viruses.
Simulates a cyberattack to identify vulnerabilities in a system.
Monitors incoming and outgoing network traffic based on a set of rules.
2
A software company has just finished developing a new web application. Before launching it, they hire an external company to perform Penetration Testing.

(a) Describe the process of penetration testing.
[2]

(b) Explain the purpose of performing this test before the software is released to the public.
[2]

(c) State the type of "hacker" who typically carries out this work legally.
[1]
Turn over
3
A school network uses a Firewall.
[Image of firewall network security diagram]
(a) Describe two actions a firewall performs to protect the network.
[4]
Action 1:
Action 2:

(b) A student brings a USB stick from home containing a virus. They plug it into a school computer.
Explain why the Firewall will not prevent the virus from infecting the computer in this specific situation.
[2]
4
Most computer systems come with Anti-malware software installed.

(a) Apart from scanning the hard drive, identify one other time or event when anti-malware software typically scans a file.
[1]

(b) Describe the steps the anti-malware software takes when it detects a file that matches a known virus signature.
[3]
Turn over
5
A small business owner, Sarah, is setting up her office network. She installs a Firewall but decides she does not need Anti-malware software because "the firewall blocks everything."

(a) Explain why Sarah is incorrect. You must refer to the difference in how these two tools work.
[4]

(b) Sarah is concerned about Social Engineering.
State one form of non-software "prevention" Sarah could use to help her staff avoid social engineering attacks.
[1]

(c) Sarah considers taking a Backup of her data.
Explain whether taking a backup is a method of prevention or recovery, and justify your answer.
[3]
END OF QUESTION PAPER