These worksheets are free forever. Want lessons that adapt to your child as they learn, plus progress tracking? Try Ignition Learning free.

Sign up free

Ignition Learning — Activity Sheet

Cybersecurity fundamentals

Technologies · Year 12

Name: ______________________Date: ____________

Cybersecurity protects systems, networks and data from unauthorised access, damage or theft. Common attack types include phishing (tricking someone into revealing sensitive information or clicking a malicious link), malware (software designed to damage or gain unauthorised access to a system), and social engineering (manipulating people, rather than exploiting purely technical flaws, into breaking normal security procedures). Defence relies on a layered approach — strong, unique passwords and multi-factor authentication, keeping software updated to patch known vulnerabilities, encrypting sensitive data, and maintaining a healthy scepticism toward unexpected requests for information — because a single weak point in any layer can be enough for an attacker to gain access.

Example

A phishing email might impersonate a trusted organisation, urging the recipient to "verify their account" by clicking a link to a fake login page that captures their username and password — the attack exploits human trust and urgency rather than any technical flaw in the target's system.

Key terms

Phishing:
Tricking someone into revealing sensitive information or clicking a malicious link.
Malware:
Software designed to damage or gain unauthorised access to a system.
Multi-factor authentication:
Requiring more than one form of verification to confirm identity when logging in.

Questions

  1. 1. Cybersecurity aims to protect systems, networks and data from:

    • Unauthorised access, damage or theft
    • Nothing in particular; it has no defined purpose
    • Only physical, not digital, threats
    • A concept unrelated to digital systems
  2. 2. Phishing typically works by:

    • Tricking someone into revealing sensitive information or clicking a malicious link
    • Directly hacking hardware with no human involvement at all
    • Only affecting systems with no internet connection
    • A method entirely unrelated to deception
  3. 3. Malware is:

    • Software designed to damage or gain unauthorised access to a system
    • A term unrelated to computing or security
    • Software that always improves a system's security
    • Hardware, not software, by definition
  4. 4. Multi-factor authentication requires:

    • More than one form of verification to confirm identity
    • Only a single password with no other verification
    • No verification of any kind
    • A method unrelated to confirming identity
  5. 5. Social engineering attacks primarily exploit:

    • Human trust and behaviour rather than purely technical flaws
    • Only technical software vulnerabilities, with no human element
    • Hardware defects exclusively
    • A concept unrelated to manipulating people
  6. 6. Keeping software updated helps because it:

    • Patches known vulnerabilities that attackers could otherwise exploit
    • Always makes a system less secure
    • Has no connection to a system's security
    • Only affects a device's appearance, not its security
  7. 7. A layered approach to cybersecurity means:

    • Using multiple different defensive measures together, rather than relying on just one
    • Relying on a single defensive measure with no other layers
    • Having no defensive measures of any kind
    • A concept unrelated to how systems are protected
  8. 8. Why might a phishing email be designed to create a sense of urgency, such as threatening an account will be suspended within 24 hours?

    • Urgency can push a target to act quickly without carefully evaluating whether the request is legitimate, increasing the chance they fall for the deception
    • Creating urgency has no genuine effect on how a target responds to a phishing attempt
    • Phishing emails are always immediately and easily identified by every target regardless of their tone or urgency
    • A sense of urgency always makes a target more cautious and less likely to fall for an attack
  9. 9. Why might multi-factor authentication significantly reduce the risk of unauthorised access, even if an attacker has already obtained someone's password?

    • Requiring an additional form of verification (like a code sent to a trusted device) means a stolen password alone is not enough to gain access
    • Multi-factor authentication provides no additional protection beyond what a password alone already offers
    • An attacker with a stolen password can always bypass multi-factor authentication with no additional effort
    • Additional verification steps have no genuine bearing on the security of a login process
  10. 10. Why might using the same password across multiple accounts be considered a significant security risk?

    • If one account's password is exposed in a data breach, attackers can attempt to use that same password to access the person's other accounts
    • Reusing a password across multiple accounts has no genuine bearing on the overall security risk faced
    • A data breach on one account never has any effect on the security of a person's other, unrelated accounts
    • Using identical passwords across accounts always makes every account equally secure regardless of any breach
  11. 11. Why might a business train staff on recognising social engineering tactics, rather than relying purely on technical security measures?

    • Since social engineering targets human behaviour rather than technical systems, even strong technical defences can be bypassed if a person is tricked into granting access
    • Technical security measures alone are always completely sufficient to prevent every possible social engineering attack
    • Staff training has no genuine bearing on an organisation's overall vulnerability to social engineering
    • Social engineering attacks are always successfully blocked by technical security measures with no human factor involved
  12. 12. Why might encrypting sensitive data provide protection even if an attacker manages to access the storage device it's held on?

    • Encrypted data appears as unreadable, scrambled information without the corresponding decryption key, meaning access to the storage alone doesn't reveal the actual content
    • Encryption has no genuine effect on whether accessed data can actually be read by an attacker
    • An attacker who accesses a storage device can always read encrypted data with no additional requirement
    • Encryption only ever protects data while it is being transmitted, never while it is being stored
  13. 13. Why might a public Wi-Fi network be considered a higher security risk for sensitive activities like online banking, compared to a trusted private network?

    • An open or shared network can make it easier for someone else on the same network to intercept unencrypted traffic, increasing the risk of sensitive information being exposed
    • Public Wi-Fi networks are always exactly as secure as a trusted private network for any activity
    • The type of network used has no genuine bearing on the security of sensitive online activities
    • Sensitive activities like online banking are never at any additional risk regardless of the network used
  14. 14. Why might regularly backing up important data be considered an essential cybersecurity practice, even though it doesn't directly prevent an attack from occurring?

    • If an attack like ransomware does succeed in damaging or locking data, having a recent backup allows recovery without needing to give in to an attacker's demands
    • Backing up data has no genuine bearing on how well an organisation can recover from a successful cyberattack
    • Preventing an attack from occurring is always the only meaningful goal relevant to cybersecurity practice
    • Data backups provide no genuine benefit once an attack has already successfully occurred
  15. 15. Why might a "zero-day" vulnerability (a flaw unknown to the software developer) be particularly dangerous compared to a known, already-patched vulnerability?

    • Since no patch yet exists, systems have no available defence against an attack exploiting that specific flaw until the developer becomes aware and releases a fix
    • A zero-day vulnerability is always exactly as dangerous as any already-patched, well-known vulnerability
    • Patched vulnerabilities are always more dangerous to a system than one that remains completely unknown to developers
    • The existence of a patch has no genuine bearing on how dangerous a given vulnerability actually is
  16. 16. Why might organisations conduct regular "penetration testing" (authorised, simulated attacks on their own systems) as part of their cybersecurity strategy?

    • Proactively identifying weaknesses through simulated attacks allows an organisation to fix vulnerabilities before a real attacker can exploit them
    • Penetration testing provides no genuine benefit to an organisation's actual cybersecurity posture
    • Simulated attacks always identify exactly the same vulnerabilities that a real attacker would ultimately exploit
    • Organisations never actually benefit from testing their own systems for security weaknesses
  17. 17. Why might cybersecurity be considered an ongoing process rather than a one-time task that, once completed, guarantees permanent protection?

    • New vulnerabilities and attack techniques constantly emerge, meaning defences that were once effective can become outdated without continuous monitoring and updates
    • Cybersecurity measures, once correctly implemented, always remain permanently effective with no further attention required
    • New attack techniques and vulnerabilities never actually emerge once a system has initially been secured
    • Ongoing monitoring and updates provide no genuine additional protection beyond an initial, one-time security setup
  18. 18. Why might the human element often be described as the "weakest link" in cybersecurity, even in organisations with strong technical defences?

    • A person can be deceived, rushed or manipulated into bypassing security procedures in ways that purely technical systems generally cannot be
    • The human element is never actually considered a meaningful factor in an organisation's overall cybersecurity posture
    • People are always exactly as resistant to deception and manipulation as a well-configured technical security system
    • Technical defences alone are always sufficient to guarantee an organisation's complete cybersecurity, regardless of human behaviour
  19. 19. Why might a genuinely effective cybersecurity strategy need to assume that some breaches will eventually occur, rather than relying solely on preventing every possible attack?

    • Since no defence can guarantee complete prevention against every possible attack, planning for detection, response and recovery helps limit the damage when prevention alone inevitably falls short
    • A well-designed cybersecurity strategy can always guarantee complete prevention of every possible attack with no need for any further planning
    • Planning for detection and response after a breach provides no genuine additional value beyond prevention alone
    • The possibility of a breach occurring despite strong defences has no genuine bearing on how a cybersecurity strategy should be designed
  20. 20. Why might attackers often target smaller organisations with weaker security budgets, even though larger organisations may hold more valuable data overall?

    • Smaller organisations may have fewer resources dedicated to cybersecurity, making them comparatively easier targets even if the potential reward per attack is smaller than targeting a larger organisation
    • Attackers only ever target the very largest organisations with the most valuable data, regardless of the strength of their defences
    • The size of an organisation's security budget has no genuine bearing on how attractive a target it presents to attackers
    • Smaller organisations are always exactly as difficult to successfully attack as the largest, best-resourced organisations
  21. 21. Understanding cybersecurity fundamentals mainly helps you to:

    • Recognise common attack methods and apply layered defensive practices to protect systems and data
    • Assume a single security measure always guarantees complete protection with no further action needed
    • Ignore the role human behaviour plays in many successful security breaches
    • Treat software updates as unrelated to a system's overall security

Answer key (parent copy)

  1. 1. Unauthorised access, damage or theft
  2. 2. Tricking someone into revealing sensitive information or clicking a malicious link
  3. 3. Software designed to damage or gain unauthorised access to a system
  4. 4. More than one form of verification to confirm identity
  5. 5. Human trust and behaviour rather than purely technical flaws
  6. 6. Patches known vulnerabilities that attackers could otherwise exploit
  7. 7. Using multiple different defensive measures together, rather than relying on just one
  8. 8. Urgency can push a target to act quickly without carefully evaluating whether the request is legitimate, increasing the chance they fall for the deception
  9. 9. Requiring an additional form of verification (like a code sent to a trusted device) means a stolen password alone is not enough to gain access
  10. 10. If one account's password is exposed in a data breach, attackers can attempt to use that same password to access the person's other accounts
  11. 11. Since social engineering targets human behaviour rather than technical systems, even strong technical defences can be bypassed if a person is tricked into granting access
  12. 12. Encrypted data appears as unreadable, scrambled information without the corresponding decryption key, meaning access to the storage alone doesn't reveal the actual content
  13. 13. An open or shared network can make it easier for someone else on the same network to intercept unencrypted traffic, increasing the risk of sensitive information being exposed
  14. 14. If an attack like ransomware does succeed in damaging or locking data, having a recent backup allows recovery without needing to give in to an attacker's demands
  15. 15. Since no patch yet exists, systems have no available defence against an attack exploiting that specific flaw until the developer becomes aware and releases a fix
  16. 16. Proactively identifying weaknesses through simulated attacks allows an organisation to fix vulnerabilities before a real attacker can exploit them
  17. 17. New vulnerabilities and attack techniques constantly emerge, meaning defences that were once effective can become outdated without continuous monitoring and updates
  18. 18. A person can be deceived, rushed or manipulated into bypassing security procedures in ways that purely technical systems generally cannot be
  19. 19. Since no defence can guarantee complete prevention against every possible attack, planning for detection, response and recovery helps limit the damage when prevention alone inevitably falls short
  20. 20. Smaller organisations may have fewer resources dedicated to cybersecurity, making them comparatively easier targets even if the potential reward per attack is smaller than targeting a larger organisation
  21. 21. Recognise common attack methods and apply layered defensive practices to protect systems and data