Network security + A2 Paper 1 synthesis
Network security is a layered risk-management problem: identify threats, understand vulnerabilities and select proportionate countermeasures. Networks exist to move data and share resources reliably across connected devices and infrastructures.
What you need to be able to do
- DiscussThe effectiveness of firewalls at protecting a network
- DescribeCommon network vulnerabilities
- DescribeCommon network countermeasures
- DescribeThe process of encryption and digital certificates
- RetrieveReconnect today’s new material to previously taught content from this topic.
Rapid Recall Deck
Say the answer aloud before flipping. Mark secure knowledge quickly and spend time on the gaps.
- What does a firewall do?: It inspects and filters incoming and outgoing network traffic using rules such as allow/deny lists and other policy conditions.
- Why can a firewall not provide complete network security by itself?: It cannot stop every threat, especially attacks using allowed traffic, compromised insiders, social engineering, unknown vulnerabilities, or poorly configured rules.
- What are common network vulnerabilities?: DDoS, insecure protocols, malware, MitM, phishing, SQL injection, XSS, unpatched software, weak authentication, and zero-day exploits.
- What is the difference between an IDS and an IPS?: An IDS detects and alerts on suspicious activity; an IPS can actively block or prevent detected malicious traffic.
- Which countermeasures reduce authentication and communication risk?: Examples include MFA, strong password policies, encrypted protocols, TLS certificates, VPNs, software updates, filtering, and security testing/training.
- What is the difference between symmetric and asymmetric cryptography?: Symmetric cryptography uses the same secret key for encryption and decryption; asymmetric cryptography uses a mathematically related public/private key pair.
- What is the role of a digital certificate?: It binds an identity to a public key through a trusted certificate process, helping establish authenticated secure network connections.
- Why is encryption key management important?: Keys must be generated, stored, distributed, rotated, and protected securely because exposed or mismanaged keys can defeat the encryption.
Core knowledge and application
The effectiveness of firewalls at protecting a network
Network security is a layered risk-management problem: identify threats, understand vulnerabilities and select proportionate countermeasures.
Explain it without notes
Discuss: The effectiveness of firewalls at protecting a network in the context of a school network responding to phishing, malware and interception risks.
- The function of firewalls in inspecting and filtering incoming and outgoing traffic based on whitelists, blacklists and rules
- The strengths and limitations of firewalls
- Role of NAT to enhance network security
Common network vulnerabilities
Network security is a layered risk-management problem: identify threats, understand vulnerabilities and select proportionate countermeasures.
Explain it without notes
Describe: Common network vulnerabilities in the context of a school network responding to phishing, malware and interception risks.
- Distributed denial of service (DDoS), insecure network protocols, malware, man-in-the-middle (MitM) attacks, phishing attacks, SQL injection, cross-site scripting (XSS), unpatched software, weak authentication, zero-day exploits
Core knowledge and application
Common network countermeasures
Network security is a layered risk-management problem: identify threats, understand vulnerabilities and select proportionate countermeasures.
Explain it without notes
Describe: Common network countermeasures in the context of a school network responding to phishing, malware and interception risks.
- Content security policies, complex password policies, DDoS mitigation tools, email filtering solutions, encrypted protocols, input validation (filtering, whitelisting), intrusion detection systems (IDS), intrusion prevention systems (IPS), multifactor authentication (MFA), secure socket layer (SSL) certificate, transport layer security (TLS) certificate, update software, VPNs
- The importance of regular security testing and employee training
- Wireless security measures may include media access controllers (MAC), whitelists and blacklists
The process of encryption and digital certificates
Network security is a layered risk-management problem: identify threats, understand vulnerabilities and select proportionate countermeasures.
Explain it without notes
Describe: The process of encryption and digital certificates in the context of a school network responding to phishing, malware and interception risks.
- Compare symmetric and asymmetric cryptography
- Role of digital certificates in establishing secure network connections
- Use of public and private keys in asymmetric cryptography
- The significance of encryption key management
Transfer to a new scenario
- The function of firewalls in inspecting and filtering incoming and outgoing traffic based on whitelists, blacklists and rules
- The strengths and limitations of firewalls
- Distributed denial of service (DDoS), insecure network protocols, malware, man-in-the-middle (MitM) attacks, phishing attacks, SQL injection, cross-site scripting (XSS), unpatched software, weak authentication, zero-day exploits
- Content security policies, complex password policies, DDoS mitigation tools, email filtering solutions, encrypted protocols, input validation (filtering, whitelisting), intrusion detection systems (IDS), intrusion prevention systems (IPS), multifactor authentication (MFA), secure socket layer (SSL) certificate, transport layer security (TLS) certificate, update software, VPNs
- The importance of regular security testing and employee training
- Compare symmetric and asymmetric cryptography
- Role of digital certificates in establishing secure network connections
Paper 1 practice
- Discuss: The effectiveness of firewalls at protecting a network in the context of a school network responding to phishing, malware and interception risks.
- Describe: Common network vulnerabilities in the context of a school network responding to phishing, malware and interception risks.
- Describe: Common network countermeasures in the context of a school network responding to phishing, malware and interception risks.
Generative AI research checkpoint
Build a reusable evidence bank for Paper 1 Section B. Keep claims technical, specific and supported.
Research checkpoint
Research deployment infrastructure: what networking/security/resource constraints matter when serving generative models?
Challenge focus: Explain how iterative denoising creates images and evaluate the computational demands of the process.
Finish the learning cycle
IA — main task
Complete Criterion E and final IA quality checks. Evaluate the product against success criteria and propose specific, feasible improvements.
Syllabus — short
Complete a short Paper 1 retrieval task; keep the IA as the main workload.