Grade 12 Computer Science: Cyber Security Notes (Kenya) | YNetStudyHub

Cyber Security

Grade 12 · Computer Science 4 min read

Introduction

Cyber security is the practice of protecting computer systems, networks, and data from cyber attacks, theft, and damage. In today's digital world, where information is stored and transmitted electronically, cyber security is crucial to ensure confidentiality, integrity, and availability of data. Understanding key concepts in cyber security helps individuals and organizations safeguard their digital assets and privacy.

Threats and Vulnerabilities

Threats are potential dangers that can exploit vulnerabilities in a system or network. Common threats include malware, phishing, and denial of service attacks.
Vulnerabilities are weaknesses in a system's security that can be exploited by threats. For example, using weak passwords or outdated software can create vulnerabilities.

Example: Consider a scenario where an employee receives an email with a malicious attachment (threat). If the employee downloads and opens the attachment, it exploits a vulnerability in the system, potentially infecting it with malware.

Encryption

Encryption is the process of converting data into a code to prevent unauthorized access. It uses algorithms to scramble data into an unreadable format, which can only be decrypted with the correct key.
Symmetric encryption uses a single key for both encryption and decryption, while asymmetric encryption uses a public key for encryption and a private key for decryption.

Example: When Alice wants to send a secure message to Bob, she uses Bob's public key to encrypt the message. Bob then uses his private key to decrypt and read the message.

Firewalls

A firewall is a security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It acts as a barrier between a trusted internal network and untrusted external networks, filtering traffic to block potential threats.
There are two main types of firewalls: hardware firewalls (physical devices) and software firewalls (software programs).

Example: A firewall can prevent unauthorized access to a company's internal network by blocking suspicious incoming connections and filtering outgoing traffic to prevent data leaks.

Authentication and Access Control

Authentication is the process of verifying the identity of a user or device trying to access a system. Common authentication methods include passwords, biometrics, and two-factor authentication.
Access control determines what resources users can access and what actions they can perform based on their identity and permissions.

Example: When logging into an online banking account, the user must enter a username and password (authentication). Once authenticated, the user is granted access to view account balances and make transactions based on their permissions (access control).

Incident Response

Incident response is the process of managing and responding to security incidents, such as cyber attacks or data breaches. It involves detecting, containing, and recovering from security breaches to minimize damage and restore normal operations.
Security incident is any event that compromises the confidentiality, integrity, or availability of data or systems.

Example: In the event of a data breach, an organization's incident response team would investigate the breach, contain the affected systems, notify impacted individuals, and implement security measures to prevent future incidents.

Common Mistakes

  • Neglecting software updates, leaving systems vulnerable to known exploits.
  • Using weak passwords that are easily guessed or cracked.
  • Clicking on suspicious links or downloading attachments from unknown sources without verification.

Key Points

  • Cyber security aims to protect computer systems, networks, and data from cyber threats and vulnerabilities.
  • Encryption ensures data confidentiality by converting information into a secure code.
  • Firewalls monitor and control network traffic to prevent unauthorized access.
  • Authentication verifies user identities, while access control regulates user permissions.
  • Incident response is essential for managing and responding to security incidents promptly.

Practice Questions

  1. Explain the difference between threats and vulnerabilities in the context of cyber security.

Answer: Threats are potential dangers that can exploit vulnerabilities, which are weaknesses in a system's security.

  1. Describe how encryption works and differentiate between symmetric and asymmetric encryption.

Answer: Encryption converts data into a code to prevent unauthorized access. Symmetric encryption uses a single key for both encryption and decryption, while asymmetric encryption uses a public key for encryption and a private key for decryption.

  1. What is the role of a firewall in cyber security, and what are the two main types of firewalls?

Answer: A firewall monitors and controls network traffic to block potential threats. The two main types are hardware firewalls and software firewalls.

  1. How does authentication contribute to cyber security, and what are common authentication methods?

Answer: Authentication verifies user identities to control access to systems. Common methods include passwords, biometrics, and two-factor authentication.

  1. Outline the steps involved in incident response and explain the importance of managing security incidents effectively.

Answer: Incident response includes detecting, containing, and recovering from security breaches to minimize damage and restore normal operations. Effective incident response is crucial to mitigate the impact of security incidents.

Want to save these Cyber Security notes?

Create a free account to bookmark notes, download past papers, track your revision and get AI study help - free for Kenyan students.

Save & bookmark notes Download past papers Track revision progress AI study help
Create free account

Already have one? Log in

Frequently Asked Questions

Cyber Security is a Grade 12 Computer Science topic. This page gathers clear, exam-focused notes and revision material for it, all free to read online.

Yes - every note on this page is free to read online on YNetStudyHub, with no sign-up required.

Read the notes below, write a short summary of each in your own words, then practise related questions from the Computer Science past papers to check your understanding.

Other Grade 12 Computer Science topics

Get free notes & past papers by email

Join our list and we'll send fresh study notes and past papers straight to your inbox.