| OCR |
GCSE (9-1) Computer Science
Mark Scheme
J277/01: Unit 1.4 User Security
|
| Question | Answer | Marks | Guidance |
|---|---|---|---|
| 1a |
1 mark for each valid method (Max 2):
|
2 |
Do not allow: "Passwords" (this is software security).
Do not allow: "Firewalls" (this is network security).
Must be a physical barrier.
|
| 1b |
|
3 |
Candidates often just define it. To get full marks, they must explain why it improves security (e.g., preventing data loss/theft).
|
| 2a |
1 mark for each characteristic (Max 3):
|
3 |
Examiner's Note: "Hard to guess" is too vague – NE (Not Enough). They must specify what makes it hard to guess.
|
| 2b |
|
2 |
Allow: "Harder to fake/steal" as a benefit.
|
| 2c |
|
2 |
Do not accept: "Make the password stronger" – the question asks for a rule to prevent the attack from succeeding, not just make it harder.
|
| 3a |
|
2 |
Crucial: Do not accept "It stops them accessing the files". Encryption doesn't stop access; it stops understanding.
|
| 3b |
Plain (text) (1) Cipher (text) (1) |
2 |
Must be in the correct order.
|
| 4a |
|
3 |
Check the context carefully. If a student argues a receptionist needs "Read-Only" to see if a file exists, allow it. But "Read-Write" for receptionist is definitely incorrect.
|
| 4b |
|
2 |
Do not allow: "Lock the door" (Question asks about the computer hardware in a public waiting area).
Allow: Tracker tags / Etching.
|
| 5a |
|
3 |
Must mention the "second device" or "separate channel" concept.
|
| 5b |
Any one:
|
1 | |
| 6 |
Indicative Content: Physical Security: Prevents physical access to the server room/terminals. Stops theft of hard drives. User Access Levels: Prevents valid users (staff) from seeing data they shouldn't (insider threat). Stops accidental deletion. Prevents a hacker who gains physical access from having "Admin" rights instantly. Interdependence: If you only have physical security, a cleaner could accidentally delete a file if logged in. If you only have access levels, a thief could steal the server and bypass the OS permissions entirely. Levels: Level 3 (5-6): Detailed discussion of both. Explains clearly how they target different threats. Justifies the need for both. Level 2 (3-4): Discusses both methods but lacks depth. Explains what they do but consequence of missing one is vague. Level 1 (1-2): Identifies the methods but descriptions are limited or generic. |
6 |
AO3 (Evaluation/Discussion)
|