Students need enough technical detail to explain how mechanisms work, then use that knowledge to analyse impacts, limitations, and key issues in a school or kura context.
Candidates choose ONE concept: computer security or encryption. Responses may use matching lists, short answers, and extended answers, with 800-1500 words in total. For computer security, questions may cover authentication, antivirus, malware, education, VLANs, VPN uses and limitations, school security, and password management. Questions about impacts will focus on human factors and social impact.
Across the 2021-2024 computer-security papers, questions repeatedly required students to:
apply security to a named organisation, company, or school context;
explain a mechanism such as authentication, updates, antivirus, firewalls, phishing protection, or malware response;
connect technical controls to human behaviour, future risk, privacy, or wider impacts;
discuss limitations, problems, competing priorities, or the effectiveness of a proposed response.
Computer security is the protection of computer systems, networks, accounts, devices, and information from unauthorised access, damage, disruption, alteration, or loss. Good security is layered: no single control can prevent every threat.
Explain what the security method is, how it works, and how it could address a school security need.
Explain a human factor or social impact, including who is affected and why.
Explain a significant problem, limitation or trade-off, including its consequences and how it could be managed.
Asset: Something valuable that needs protection, such as student records, assessment data, staff accounts, payroll information, devices, or network availability.
Threat: A person, event, or action that could cause harm, such as phishing, malware, credential theft, an insider, equipment failure, or a deliberate attack.
Vulnerability: A weakness that a threat could exploit, such as a reused password, an unpatched device, excessive access rights, or a flat network.
Risk: The likelihood that a threat will exploit a vulnerability, combined with the likely impact.
Control: A technical or organisational measure used to reduce risk.
Confidentiality: Information is available only to authorised people.
Integrity: Information and systems remain accurate and are not changed without permission.
Availability: Authorised users can access systems and information when needed.
Defence in depth: Several different controls are used together so that one failure does not expose the whole system.
Least privilege: Users receive only the access they need to complete their role.
Check out the Computer Science Field Guide: https://www.csfieldguide.org.nz/en/chapters/computer-security/
Read through the chapters thoroughly.
Need to really understand the big picture so you can make an informed decision and relate to the topic.
Checks that a user is who they claim to be by requiring evidence such as a password, device, security code, security key, or biometric characteristic. Multi-factor authentication strengthens this process by requiring evidence from different categories. In a school, authentication protects staff access to email, cloud platforms, student-management systems, and remote services. However, even strong authentication can be defeated through phishing, stolen login sessions, weak account-recovery processes, or users finding ways around security requirements.
Involves securely creating, storing, and retrieving long, unique passwords. Password managers reduce password reuse and mean users do not have to remember every password. Schools can use them to support unique staff and student accounts, secure account recovery, and the protection of shared or administrative credentials. However, the password-manager account and its recovery process become valuable targets. Users still need a strong master password and multi-factor authentication.
Use signatures, reputation information, heuristic analysis, and behaviour monitoring to identify, block, or quarantine suspicious software. These systems help protect school laptops, desktop computers, and servers from known or potentially malicious programs. However, antivirus software may fail to detect new, modified, or disguised malware. False positives can also occur, and the system remains dependent on regular updates and appropriate decisions by users.
Reduce the likelihood that malicious software will be delivered, executed, remain on a device, or cause significant damage. These controls include email and web filtering, software patching, restricted user privileges, application control, reliable backups, and security monitoring. In a school, they can help prevent malicious attachments, infected downloads, ransomware, spyware, and unauthorised software. However, a single successful infection may spread quickly when devices share access to resources or the network is not properly segmented.
Allow a managed network switch to separate devices into logical groups. Communication between these groups is controlled through routers, firewalls, or access-control rules. A school might use VLANs to separate staff devices, student devices, guest access, servers, and Internet of Things devices. However, VLANs do not encrypt network traffic or automatically make connected devices secure. Incorrect configuration or overly broad access rules can remove much of the protection provided by segmentation.
Authenticates a remote user or device and creates an encrypted connection to a trusted network gateway. Schools can use VPNs to allow staff to securely access approved resources while working from home or using public networks. However, a VPN does not prevent phishing, malware, unsafe personal devices, or misuse by an authenticated user. VPN use may also affect network performance and increase technical-support requirements.
Develop the knowledge, habits, reporting procedures, and positive security culture needed to support technical security controls. In a school, this can include phishing simulations, clear incident-reporting processes, password-manager support, guidance on safe device use, and incident-response drills. However, one-off training is quickly forgotten. Programmes that rely on fear or blame may also discourage users from reporting mistakes or suspicious activity.
Combines accounts, authentication, access controls, software updates, backups, network segmentation, filtering, monitoring, incident response, and organisational policies. Together, these measures protect teaching and learning, school administration, assessments, financial systems, student wellbeing information, and personal data. However, schools must balance security against cost, usability, privacy, older equipment, available staffing, and dependence on external service providers.
A staff member uses a password and authenticator app before accessing confidential student information.
A school separates staff, student, guest, server, and camera or IoT devices into different VLANs.
A teacher working from home uses a school VPN to reach an internal service that is not exposed directly to the internet.
Endpoint protection detects suspicious behaviour and quarantines a malicious file while the IT team investigates.
Backups are kept separately and tested so learning and administration can continue after ransomware or equipment failure.
Staff and students know how to report a suspicious message quickly without being blamed for making a mistake.
More steps can reduce risk but can also slow work, create frustration, or encourage unsafe workarounds.
Logging and monitoring can help detect attacks, but excessive surveillance may reduce trust and collect unnecessary personal information.
People need access to do their jobs, but broad access increases the damage caused by mistakes or compromised accounts.
Controls must be updated as attackers change methods, but schools have limited budgets, old devices, and competing priorities.
A well-designed system should assume people sometimes make mistakes and should reduce the impact of those mistakes.
Cloud platforms, contractors, and software providers may improve security, but a breach or outage outside the school can still affect it.
Human factors are not simply a claim that “people are the weakest link”. Security is affected by the way systems, policies, training, workload, confidence, accessibility, incentives, and organisational culture shape behaviour.
Long or confusing login processes may cause password sharing, written-down passwords, or avoidance of secure systems.
Too many warnings can create alert fatigue, so users begin dismissing messages without reading them.
Students or staff may hide a mistake if they expect blame, allowing an incident to grow.
Accessible recovery and authentication options are needed for people who cannot use a particular device or biometric method.
A breach may expose personal information, disrupt learning, affect wellbeing, damage trust, and create financial or administrative pressure.
Security decisions can create inequity when students need newer devices, reliable internet, or a personal phone for authentication.
Cybersecurity involves identifying what needs to be protected, understanding what could cause harm, recognising weaknesses, and putting safeguards in place. Assets, threats, vulnerabilities, risks, and controls provide a framework for analysing security situations. These can then be connected to the CIA triad—confidentiality, integrity, and availability—to explain the type of harm that could occur and what aspect of information security is being protected.
An asset is something valuable that needs protection, such as student records, passwords, school laptops, assessment files, or the school network.
A threat is something that could cause harm to an asset. Examples include a hacker, ransomware, phishing, fire, theft, or an employee accidentally deleting data.
A vulnerability is a weakness that a threat could exploit. Examples include weak passwords, outdated software, an unlocked computer, poor network configuration, or staff who have not received security training.
A risk is the possibility that a threat will exploit a vulnerability and cause harm. For example, there is a risk that an attacker could use a stolen password to access student records.
A control is a safeguard used to reduce a risk. Examples include multi-factor authentication, backups, antivirus software, firewalls, staff training, and access restrictions.
You then connect the example to one or more parts of the CIA triad:
Confidentiality means information is only seen by authorised people. A stolen password could affect confidentiality because an attacker might read private student information.
Integrity means information remains accurate, complete, and trustworthy. Malware that changes assessment grades would affect integrity.
Availability means systems and information are accessible when authorised users need them. Ransomware that locks the school’s files would affect availability.
Multi-factor authentication (MFA) is a security process that requires a user to provide two or more different types of evidence before access is granted.
The factors usually come from three categories:
Something you know: a password or PIN
Something you have: a phone, authenticator app, security key, or access card
Something you are: a fingerprint, face scan, or other biometric
For example, a staff member may enter their password and then approve a notification on their phone. Even if an attacker steals the password, they may still be unable to log in because they do not have the staff member’s phone.
MFA is stronger when the factors come from different categories. A password followed by another security question is less secure because both are things the user knows.
MFA greatly reduces the risk of account compromise, but it is not perfect. Attackers may still use phishing, fake login pages, stolen browser sessions, or repeated approval requests to trick users. Authenticator apps and physical security keys are generally safer than codes sent by text message.
Scenario: A school stores attendance, wellbeing, assessment, payroll, and contact information. Students and staff use cloud services, shared printers, Wi-Fi, laptops, and several older IoT devices. Some staff work remotely.
Classify each example as an asset, threat, vulnerability, risk, or control. Then connect it to confidentiality, integrity, or availability.
A shared administrator password.
Student assessment records.
A phishing message that steals a staff login.
Multi-factor authentication.
An unpatched camera connected to the main network.
A ransomware infection that prevents access to the student-management system.
Offline, tested backups.
A student changes attendance data without permission.
Student assessment records are an asset. Unauthorised disclosure affects confidentiality; unauthorised changes affect integrity; an outage affects availability.
A shared administrator password is a vulnerability because several people can use a powerful account and actions cannot be reliably attributed to one person.
Phishing is a threat and attack method. If it captures a staff login, it may exploit weak authentication and excessive access rights.
Multi-factor authentication and tested backups are controls. MFA reduces the usefulness of a stolen password, while backups reduce the impact of ransomware on availability.
An unpatched camera on the main network is a vulnerability. It may provide a path into more important systems, especially if the network is not segmented.
Sort each method into something you know, something you have or something you are. Then decide whether each login is genuinely multi-factor.
Password + PIN .
Password + authenticator-app code
Fingerprint + facial recognition
Security key + device PIN
Password + security question
Why does MFA reduce the risk from a stolen password?
How could an attacker still defeat or bypass MFA?
What accessibility or usability issues could MFA create in a school?
What should happen when a staff member loses the registered device
Password + PIN Two knowledge factors - not true multi-factor authentication.
Password + authenticator-app code Knowledge + possession - multi-factor authentication.
Fingerprint + facial recognition Two inherence factors - not necessarily multi-factor.
Security key + device PIN Possession + knowledge - multi-factor authentication.
Password + security question Two knowledge factors, often with weak recovery information.
MFA reduces risk because a password alone is not enough. The attacker also needs the second factor or must trick the user into approving a login.
It is not perfect. Attackers may use real-time phishing, repeated approval prompts, stolen browser sessions, social engineering against help desks, or a compromised device.
A school needs secure recovery that verifies identity without making support impossible.
It should also provide alternatives for users who cannot use a personal phone or a particular biometric method.
Strategy A: one memorable password reused for school email, social media, and shopping.
Strategy B: long, unique passwords generated and stored in a password manager, with MFA on the manager account.
Strategy C: an eight-character complex password changed every month, usually by changing the final number.
Strategy D: a long unique passphrase for the main account, with secure recovery and MFA.
Strategy B is usually the strongest overall because every service receives a different password and the user does not need to memorise them all. If one website is breached, the stolen password cannot be reused elsewhere. The manager and its recovery process must be protected carefully because they concentrate access.
Strategy D can also be strong for a small number of important accounts. Its effectiveness depends on genuine uniqueness, sufficient length, and secure recovery.
Strategy A is weak because credential stuffing can turn one breached password into several compromised accounts.
Strategy C appears strict but may cause predictable changes, forgotten passwords, support workload, or passwords being written down. Regular changes are useful after suspected compromise, but forced frequent changes do not automatically create strong passwords.
This ia project from Own Your Online, here to help New Zealanders stay secure online.
The National Cyber Security Centre (NCSC) provides cyber security services to all New Zealanders. Through the Own Your Online platform, we help New Zealanders and small-to-medium businesses to understand the importance of being secure online and take proactive action to protect themselves.
and try and see how much is known about your email. try with other emails that you know. It does not release any information, but does show what information is available.
This tool sources data from the Have I Been Pwned service. It works by analysing live data from public global breaches, with a growing database of over 73 billion data points to expose what information scammers might have access to. A data point is a piece of personal information exposed in a breach. If a data breach contains one million people’s email addresses and one million passwords, that’s two million data points.
The exposure score you receive is indicative only and should be used as a starting point for prioritising online security practices.
Phishing is a social-engineering attack in which someone pretends to be a trusted person or organisation to trick a user into giving away information, opening a harmful attachment, clicking a fake link, or approving a login request.
Phishing messages often imitate banks, schools, Microsoft, Google, delivery companies, or senior staff. Common warning signs include urgent language, unusual requests, unexpected attachments, misleading web addresses, spelling errors, and requests for passwords or security codes.
In a school, phishing could be used to steal staff login details, access student records, redirect payments, spread malware, or compromise email accounts. It mainly threatens confidentiality, but it can also affect integrity and availability if attackers alter data or install ransomware.
Useful controls include multi-factor authentication, email filtering, staff education, password managers, checking links carefully, and reporting suspicious messages quickly.
Analyse two messages rather than recording only the final score.
Which visible clues influenced your decision?
Which clue was strongest, and why?
What action should the recipient take without using any link or contact detail in the message?
Which technical control would reduce the damage if the user made the wrong decision?
Which human factors make this message persuasive? Consider urgency, authority, fear, reward, familiarity, and workload.
Warning signs may include a misleading sender domain, a link whose destination does not match the visible text, an unexpected attachment, unusual urgency, a request for credentials, or a message that does not fit the normal process.
The user should avoid the embedded link, open the known service independently, confirm the request through a trusted channel, and report the message. Deleting it without reporting may leave other users exposed.
MFA, mail filtering, browser protection, limited account privileges, and rapid session revocation reduce impact, but none removes the need for safe reporting and well-designed processes.
Cisco Packet Tracer is a free network-simulation tool provided through Cisco Networking Academy. Students can use it to build a small school network, configure switches and VLANs, assign IP addresses, and test which devices can communicate without requiring physical networking equipment.
Open the Cisco Networking Academy page for Getting Started with Cisco Packet Tracer.
Select Get Started, Enrol, or Sign Up. The wording may vary slightly depending on the page displayed.
Create a free Cisco Networking Academy account using an email address. Complete any email-verification message sent by Cisco.
Sign in and enrol in the free Getting Started with Cisco Packet Tracer course. Full completion of a paid Cisco course is not required.
While signed in, open the Resource Hub or Lab Downloads section.
Download the appropriate version for the computer:
Windows 64-bit
macOS 64-bit
Ubuntu Linux 64-bit
Run the installation file, accept the licence agreement, and follow the installation prompts.
Open Packet Tracer and sign in using the same Cisco Networking Academy account.
Packet Tracer must be installed on a Windows, macOS, or Ubuntu computer. Cisco states that it is not available for phones or tablets. On school-managed computers, students may need the school’s IT administrator to install it because they might not have installation permissions.
Build a network containing staff, student, server, and guest devices.
Place the devices into separate VLANs,
Configure the switch ports,
Use ping tests to determine which devices can communicate.
Add routing or access-control rules to permit selected communication between VLANs.
Build a small school network, configure VLANs, and test which devices can communicate. Free access requires Cisco learning enrolment.
Design a school network with at least four VLANs: staff, students, guests, and IoT or infrastructure. Add a server or administration VLAN if appropriate.
Complete an access matrix. Use ALLOW, DENY, or RESTRICTED and justify each decision.
From / To Staff Students Guests IoT Admin/Servers
Staff
Students
Guests
IoT
Admin/Servers
how the switch uses VLAN membership to separate broadcast domains;
how a router, layer-3 switch, firewall, or access-control list controls traffic between VLANs;
how segmentation limits the spread of malware or unauthorised access;
why VLANs are not the same as encryption and do not replace endpoint security.
Guests should normally reach the internet only. Students may reach curriculum services and approved printers but not staff or administration systems. IoT devices should communicate only with the services needed to manage them. Staff should receive access based on role rather than unrestricted access to everything.
The switch separates devices logically, even when they use the same physical hardware. Traffic between VLANs must pass through a routing or security device where rules can allow or deny specific connections.
This reduces lateral movement: malware on a student or IoT device cannot automatically scan or reach confidential systems. However, segmentation can fail through incorrect tagging, overly broad rules, compromised administrator accounts, insecure endpoints, or unmonitored exceptions.
Scenario: A teacher connects to public Wi-Fi and uses the school VPN to access an internal file service.
The VPN can encrypt traffic between the teacher device and the school VPN gateway.
The VPN proves that every website visited is trustworthy.
The VPN prevents malware already running on the teacher laptop.
The school can require authentication before the tunnel is created.
Traffic may still be exposed or misused after it leaves the trusted VPN endpoint.
A stolen staff account can become more dangerous if the VPN gives broad internal access.
VPN performance may be affected by bandwidth, distance, encryption overhead, or routing.
Students label each statement TRUE, FALSE, or DEPENDS, then explain the boundary of protection.
A remote-access VPN creates an encrypted tunnel from the authorised device to the school gateway. This protects data from local eavesdropping and allows the school to expose fewer internal services directly to the internet.
The VPN does not make the endpoint trustworthy. A compromised laptop can send harmful traffic through the tunnel, and a phishing site remains a phishing site. The school should combine the VPN with MFA, device checks, limited access, logging, updates, endpoint protection, and rapid account revocation.
A well-justified school policy may provide VPN access only to staff who need it and only to the systems required for their role, because unrestricted remote network access increases the impact of stolen credentials.
Compare two schools after a staff member clicks a malicious link.
School A publicly blames the user, sends another long policy, and warns that future mistakes may be disciplined.
School B thanks the user for reporting quickly, isolates the account, explains what happened, improves the process, and uses a short follow-up activity for staff.
Which school is more likely to receive early reports in the future?
How do workload, confidence, fear, interface design, and organisational culture influence behaviour?
Why is education more effective when it is repeated, contextual, and supported by technical controls?
How can a school measure improvement without creating excessive surveillance?
School B is more likely to detect future incidents early because staff are rewarded for reporting rather than encouraged to conceal mistakes. Faster reporting reduces the time an attacker can use a stolen account.
Education should teach an action that is easy to perform, such as a visible report-phishing button or a known help channel. The system should also limit damage through MFA, least privilege, filtering, and session revocation because training cannot guarantee perfect decisions.
A school could measure reporting rates, time to report, completion of short practice activities, repeated patterns of mistakes, and incident-recovery time. It should avoid collecting more personal monitoring data than is needed and communicate clearly how results are used.
The school has limited time and funding.
account security and MFA;
password-manager deployment and recovery;
patching and endpoint management;
VLANs and network access rules;
VPN and secure remote access;
backups and recovery testing;
security awareness and reporting culture;
monitoring and incident response.
Identify one control that appears highly effective but could create a new problem if implemented badly. Explain the trade-off and propose an improvement.
A sensible plan gives high priority to account security, patching, backups, segmentation, and incident response because these controls reduce both the likelihood and impact of several threats. Education remains important, but it should not be used as a substitute for safe system design.
For example, strict MFA could reduce account compromise but create inequity if every user must own a modern phone. The school could provide hardware tokens or managed alternatives, use risk-based requirements, and design a secure recovery process.
The strongest conclusion is not one fixed allocation. It is a defence-in-depth plan that matches the school’s highest-value assets, likely threats, existing weaknesses, and ability to maintain each control over time.
Use your own example scenario to write four connected responses. Your scenario could involve a school, business, healthcare provider, community organisation, online service, or local government system.
Explain:
Assets
Threats
Vulnerabilities
Risks
Controls
Confidentiality
Integrity
Availability
Connect each concept to specific people, information, devices, accounts, and systems in your scenario.
For example:
Student assessment records are an asset because they contain valuable and sensitive information. A stolen staff password is a threat because it could allow an attacker to access those records. Weak authentication is a vulnerability that increases the risk of unauthorised access, affecting the confidentiality and integrity of the information.
A strong response should show how the concepts connect rather than giving isolated definitions.
Choose relevant security measures and explain how they work. These could include:
Authentication and multi-factor authentication
Password management
Antivirus or endpoint protection
Malware prevention and incident response
VLANs and network segmentation
Virtual private networks
Backups
Access controls and permissions
Filtering and monitoring
Security education and awareness
School or organisational security procedures
Explain:
The security problem each measure addresses
How the mechanism, system, or procedure works
How it would be implemented in your scenario
Which assets it protects
Its important limitations
A strong response should explain how the security measure operates rather than only naming it.
For example:
A VLAN separates devices into logical network groups, even when they use the same physical network equipment. In a school, staff devices, student devices, servers, guest devices, and Internet of Things devices could be placed on separate VLANs. Traffic between the VLANs would be controlled by firewall or routing rules. This could prevent a compromised student device from directly accessing assessment servers. However, VLANs do not encrypt traffic and can be ineffective if the access rules are incorrectly configured.
Analyse:
How users create, store, and share passwords
Phishing and social engineering
Security awareness and reporting
Access to authentication devices
Privacy and monitoring
Usability and accessibility
Trust in the organisation
Staff workload and technical support
The consequences of a security incident
How technical choices affect different people and communities
Students should connect the technical issue to a human or social consequence.
For example:
Requiring multi-factor authentication may reduce the chance that a stolen password can be used. However, some staff may not have access to a suitable personal phone or may be uncomfortable using a personal device for work authentication. Without an accessible alternative, the control could prevent legitimate users from accessing important systems.
Another example:
If staff are blamed or punished for clicking phishing links, they may delay reporting future mistakes. This gives malware or attackers more time to access information and spread through the network. A supportive reporting culture can therefore improve both security and incident response.
Compare two perspectives, such as:
School leaders and students
Network administrators and ordinary users
Staff and parents
Security teams and privacy advocates
Employers and employees
Government agencies and citizens
Technology providers and affected communities
Schools and third-party cloud-service providers
Consider important problems and trade-offs, such as:
Security versus convenience
Monitoring versus privacy
Access versus confidentiality
Cost versus level of protection
Strong authentication versus accessibility
Filtering versus access to legitimate information
Centralised password storage versus the consequences of one account being compromised
Remote access versus the risks created by unmanaged devices
Automated security decisions versus human review
Dependence on third-party services
Recommend improvements such as:
Introducing multi-factor authentication
Removing shared accounts
Using password managers
Separating devices with VLANs
Applying least-privilege access
Regularly updating and patching devices
Testing backups
Providing accessible authentication alternatives
Improving phishing education
Creating clear incident-reporting procedures
Auditing access and security configurations
Consulting affected users
Providing human review of automated security decisions
Establishing clear privacy and data-governance rules
Finish with a justified conclusion explaining:
Which controls should be used
Why several layers of security are needed
Which risks cannot be removed completely
When the system would be sufficiently secure to use
When access or operation should be restricted or stopped
Computer security is not achieved by installing one product or introducing one rule. It depends on layers of technical controls, well-designed procedures, informed users, and effective incident response.
Security measures can reduce risk, but they can also create costs, inconvenience, privacy concerns, and barriers for legitimate users. A system should therefore be judged not only by whether it blocks attackers, but also by whether it protects confidentiality, integrity, and availability in a way that is usable, fair, maintainable, and appropriate for the people affected.
Computer-security systems are most effective when their limitations are recognised, access is carefully controlled, users can report problems without fear, controls are regularly reviewed, and human judgement can respond when automated systems or procedures fail.
DTTA will provide one at the start of Term 3. This will be advertised on the DTTA Mobilse forum.
This the DTTA Derived Grade Exam Resources for 91898 provided in 2024
Your teacher will provide this. Do your best and remember to give specific examples!