Skip to content

Cyber Security

Cyber security is the coordinated protection of computers, networks, software, services, data and users against unauthorized access, alteration, disclosure, disruption, destruction or theft. It combines people, process and technology; installing one security product is therefore not a complete security programme.

The three fundamental objectives are confidentiality, integrity and availability (CIA). They must be balanced: a system that keeps data secret but cannot deliver an essential service is not secure for its intended purpose.

CIA triad with representative controls and concrete failure examples for confidentiality, integrity and availability.

CIA triad with representative controls and concrete failure examples for confidentiality, integrity and availability.

ObjectiveMeaningFailure exampleRepresentative controls
ConfidentialityInformation is disclosed only to authorized subjectsAn intruder reads customer recordsEncryption, authentication, access control and data classification
IntegrityInformation and systems remain accurate, complete and changed only in authorized waysAn account balance or software file is alteredHashes or MACs, digital signatures, permissions, validation and audit logs
AvailabilityAuthorized users receive required data and service when neededDDoS, hardware failure or ransomware makes a portal unavailableRedundancy, capacity protection, patching, backups and disaster recovery

CIA objectives, representative failures and controls.

Authentication
verifies a claimed user, service or device identity.

Authorization
decides which resources and operations an authenticated identity is permitted to use.

Accountability
makes actions attributable through unique identities, protected logs, time synchronization and review.

Non-repudiation
provides strong evidence that helps prevent a party from plausibly denying an action; it depends on trustworthy keys, identities, procedures and records, not on a cryptographic value alone.

Malware is software or code intentionally designed to disrupt, damage, spy, steal or obtain unauthorized control. Malware is the broad class; virus, worm and Trojan horse name different propagation or delivery behaviours and must not be treated as synonyms.

Virus
inserts or attaches its code to a host file, executable, document macro or boot area. It normally spreads when the infected host is opened or executed; self-replication is tied to that carrier.

Worm
is a stand-alone, self-replicating program that spreads automatically between systems, commonly through a network vulnerability or weak credential. It does not require a host file.

Trojan horse
presents itself as useful or legitimate software so that a user installs or runs it. It may steal data, establish covert access or deliver other malware, but a Trojan is not defined by self-replication.

Conceptual virus lifecycle from dormancy through propagation and triggering to payload execution or damage.

Conceptual virus lifecycle from dormancy through propagation and triggering to payload execution or damage.

FeatureVirusWormTrojan horse
Host file requiredUsually yesNoNo; the disguised application is the carrier
Initial user actionOften opening or running infected contentMay need none after the first footholdUsually a tricked download, install or launch
PropagationInfected files, removable media, boot areas or macrosAutomatic network scanning/exploitation or credential abuseSocial engineering, fake utilities or untrusted/pirated software
Typical impactFile infection/corruption and payload executionRapid spread, resource exhaustion and delivery of further payloadsCredential theft, remote access or covert persistence
Prevention focusAnti-malware, macro/media control and trusted filesRapid patching, firewalling and segmentationApplication allow-listing, signed software and user verification

Precise comparison of virus, worm and Trojan horse.

Digital Signature Creation and Verification

Section titled “Digital Signature Creation and Verification”

A digital signature is a public-key cryptographic value bound to a particular message and signer. It supports message integrity, origin authentication and, under trustworthy identity and key-management procedures, evidence for non-repudiation.

Let MM be the message, HH a secure hash function, SKASK_A signer A’s private key, PKAPK_A the corresponding public key and SS the signature. The conceptual creation equations are

In a real signature scheme the hashing and encoding may be integrated into the signature algorithm, but the exam model correctly emphasizes that the digest binds the signature to the exact message.

Digital-signature creation: hash the message, sign the digest with the protected sender private key, and transmit the message, signature and certificate; the private key never leaves the trusted environment.

Digital-signature creation: hash the message, sign the digest with the protected sender private key, and transmit the message, signature and certificate; the private key never leaves the trusted environment.

  1. A hashes the exact message MM with an approved collision-resistant function to obtain hh.

  2. A’s signature algorithm uses the protected private key SKASK_A to produce SS. The private key is never transmitted.

  3. A sends MM, SS and normally a certificate that binds A’s identity to PKAPK_A; the certificate is public, while SKASK_A remains secret.

The receiver independently hashes the received message and invokes the scheme’s verification algorithm:

Digital-signature verification: validate the certificate to obtain an authenticated public key, hash the received message independently, and run the signature algorithm’s verification operation to obtain valid or invalid.

Digital-signature verification: validate the certificate to obtain an authenticated public key, hash the received message independently, and run the signature algorithm’s verification operation to obtain valid or invalid.

  1. Validate the certificate chain and confirm identity/name, permitted key usage, validity period and revocation status to obtain an authenticated PKAPK_A.

  2. Recompute h1=H(M)h_1=H(M) from the exact received message.

  3. Supply h1h_1, SS and PKAPK_A to the matching verification algorithm. Accept only a valid result under the required policy; otherwise reject and log or investigate as appropriate.

PropertyReason and qualification
IntegrityA change to MM changes H(M)H(M) with overwhelming probability, so the old signature should no longer verify
Origin authenticationA valid signature is evidence that the corresponding private key produced it, provided the public key is correctly bound to A
Non-repudiation evidenceA third party may assess the signature, certificate, timestamp, audit trail and key-custody evidence; a signature alone cannot prove who physically controlled a compromised or shared key

What a valid digital signature establishes.

Public-key infrastructure (PKI) supplies the trust framework that binds public keys to identities and manages their lifecycle. A certificate authority (CA) signs certificates; a registration process validates identity; repositories distribute certificates and status information; relying parties validate them under policy.

ComponentFunctionRequired control
Private key SKASK_ACreates A’s signaturesGenerate securely; restrict use; keep secret in protected hardware/software; never transmit
Public key and certificateEnable verification and bind PKAPK_A to A’s identityValidate CA chain, identity/name, purpose, expiry and revocation; do not trust an unauthenticated key merely because it is called public
CA and registration functionValidate identity and issue/sign certificates under policyProtect CA signing keys; audit issuance; publish status and revocation information
Hash/signature algorithmBind exact content to the signatureUse approved collision-resistant hashes, signature schemes, key sizes and parameters
Timestamp and audit recordShow when signing occurred and preserve evidenceUse a trusted timestamp, protected logs, synchronized time and long-term validation data where evidence must outlive a certificate

Digital-signature and PKI components.

Encryption, MAC and Digital Signature Compared

Section titled “Encryption, MAC and Digital Signature Compared”
MechanismMain serviceSecret arrangementCan a recipient prove origin to a third party?
EncryptionConfidentiality; authenticated encryption also protects ciphertext integritySymmetric shared key or an authenticated recipient-key arrangementNot by encryption alone
MACIntegrity and source authentication among key holdersSender and receiver share one MAC keyUsually no; either key holder could have made the MAC
Digital signatureIntegrity, origin authentication and potential non-repudiation evidenceOnly signer holds signing secret; verifier uses authenticated public keyPotentially yes, with valid PKI, policy and key custody

Different cryptographic mechanisms provide different services.

Hacking versus Cracking; Spam versus Phishing

Section titled “Hacking versus Cracking; Spam versus Phishing”

Hacking broadly means exploring, modifying or testing computer systems and weaknesses. The word alone does not establish legality: the decisive questions are authorization, scope and intent. Cracking means unauthorized, malicious defeat of security or software protection to steal, damage, disrupt or bypass controls.

BasisEthical or authorized hackingCracking
PermissionWritten authorization with named assets, time window and rules of engagementPermission absent or exceeded
PurposeFind, explain and help remediate weaknessesTheft, damage, misuse, covert access or protection bypass
Method/outputControlled tests, protected evidence and responsible reportCovert exploitation, evasion and unauthorized persistence
Legal/ethical statusLawful only while every action remains within valid permission and applicable lawUnlawful and unethical

Authorized ethical hacking and cracking compared.

The objective is to demonstrate and reduce risk with the minimum necessary impact, not to obtain enduring access. Evidence must be proportionate, confidential data protected, and unexpected effects reported immediately under the rules of engagement.

Ethical security-testing workflow from written permission and scope through reconnaissance, scanning, controlled validation, reporting and remediation verification.

Ethical security-testing workflow from written permission and scope through reconnaissance, scanning, controlled validation, reporting and remediation verification.

The workflow is permission and scope →\rightarrow reconnaissance →\rightarrow vulnerability scanning →\rightarrow controlled validation →\rightarrow reporting →\rightarrow remediation verification. A useful report distinguishes verified findings from automated-tool indications, states business impact and evidence, and gives prioritized corrective action.

Spam is unsolicited bulk electronic communication. Phishing is deceptive communication that impersonates a trusted party to induce a victim to disclose credentials, open malicious content, transfer value or approve an unsafe action. Not every spam message is phishing, and targeted phishing need not be bulk spam.

ThreatMain indicatorMain controls
SpamUnrequested, repetitive or high-volume mail, often promotionalReputation/content filters, SPF/DKIM/DMARC evidence, rate/abuse controls and a safe unsubscribe process for legitimate senders
PhishingUrgent impersonation, look-alike domain, false login/payment link, unexpected attachment or request to bypass normal procedureUser verification, URL/domain checks, secure email gateway, MFA and out-of-band confirmation through a known contact path

Spam and phishing indicators and controls.

A cyber attack is a deliberate attempt to violate confidentiality, integrity or availability by exploiting technology, configuration or people. A countermeasure should be matched to both the attack mechanism and the asset at risk.

AttackMechanism and impactDirect countermeasures
Malware / ransomwareMalicious code steals, damages, encrypts or denies data and systemsPatching, application allow-listing/EDR, least privilege, segmentation and offline tested backup
Phishing / social engineeringDeception obtains credentials, payment or an unsafe user actionAwareness, secure email filtering, MFA and out-of-band verification
Password attacksOnline guessing, spraying common passwords or stuffing credentials reused from another breachUnique passphrases, password manager, rate limiting, MFA and breached-password screening
DoS / DDoSTraffic or requests exhaust links, hosts or application resourcesRate limiting, upstream scrubbing/CDN, capacity planning, filtering and resilient replicas
Man-in-the-middleAn intermediary intercepts or alters communicationTLS or VPN, strict certificate validation, secure Wi-Fi and mutual authentication where appropriate

Common attacks, impacts and direct countermeasures.

Defense in depth places independent preventive, detective and recovery controls at successive trust boundaries so that one failed control does not directly expose the final asset. Repeating identical controls is not enough; layers should address different failure modes.

Defense-in-depth architecture from the untrusted Internet through perimeter, DMZ and internal trust boundaries to segmented endpoints and servers, with IAM, endpoint protection, centralized monitoring and an isolated immutable recovery path.

Defense-in-depth architecture from the untrusted Internet through perimeter, DMZ and internal trust boundaries to segmented endpoints and servers, with IAM, endpoint protection, centralized monitoring and an isolated immutable recovery path.

AttackSecurity objective at riskLayered response
Web injectionDatabase confidentiality and integrityParameterized queries, input validation, least-privilege database role, WAF and code review
Vulnerability exploitationPotentially all CIA objectivesAsset inventory, risk-based patching, secure configuration, scanning and segmentation
Insider misuseConfidentiality and integrityLeast privilege, separation of duties, DLP, protected/immutable logs and independent review
Supply-chain compromiseSoftware integrity and authenticitySigned releases, dependency/SBOM review, provenance verification, controlled builds and sandboxing
DNS/cache spoofingTraffic redirection and credential theftValidated, randomized resolution; DNSSEC where supported; and TLS certificate checks at the application endpoint

Layered responses to additional attack classes.

Incident response limits harm and restores trustworthy operation. The exam-ready sequence is

prepare →\rightarrow detect, identify and triage →\rightarrow contain →\rightarrow eradicate →\rightarrow recover from known-good sources →\rightarrow monitor, learn and improve

Preparation establishes roles, contacts, logging, tools, playbooks and tested recovery capability before an incident. Documentation, evidence preservation, communication and legal/privacy decisions begin during identification and continue across the lifecycle; urgent containment and volatile-evidence capture may proceed in parallel according to the response plan. Containment should not unnecessarily destroy evidence. Recovery is not merely powering systems back on: credentials may need rotation, systems must be rebuilt or cleaned from trusted sources, backups verified before use, and heightened monitoring maintained for recurrence. Legal, regulatory, contractual and organizational rules determine whom to notify and when.

Malware labels can overlap: for example, ransomware may arrive disguised as a Trojan and a worm may deliver a ransomware payload. Classification should therefore state the defining behaviour rather than assume each sample belongs to exactly one box.

TypeDescriptionKey feature
VirusAttaches to a host file, program, macro or boot area and spreads when the infected host runsHost-dependent replication
WormStand-alone code that self-replicates across systems or networksAutomatic propagation
Trojan horseDisguises itself as legitimate or desirable software to induce installation/executionDeceptive delivery
RansomwareEncrypts data or locks systems and demands payment or another concessionExtortion and denied availability
SpywareSecretly monitors activity or gathers data without informed consentSurveillance and data theft
AdwareDisplays unwanted advertising and may track behaviourAdvertising and tracking
RootkitHides malicious presence or maintains privileged access by altering or subverting system visibilityStealth at elevated privilege
KeyloggerRecords keystrokes or equivalent input to capture secretsCredential and data capture

Common malware classes and their defining features.

TypeDescription
File virusInfects executable or other program files and activates when the host program runs
Boot-sector virusInfects a storage device’s boot record or boot area and may run during startup
Macro virusUses a document application’s macro language and spreads through macro-enabled documents/templates
Multipartite virusInfects more than one target class, commonly both files and a boot area
Polymorphic virusChanges or re-encodes its observable form across copies to reduce simple signature detection while retaining behaviour
Resident virusLoads into memory and can infect files while the system continues operating

Frequently examined virus types.

Possible indicators include:

  • unusually slow performance, unexplained resource use or frequent crashes;

  • files that are missing, corrupted, unexpectedly renamed or changed;

  • unwanted pop-ups, unknown programs, processes or configuration changes;

  • anti-malware, logging or update services disabled unexpectedly; and

  • unexplained storage, processor or network activity.

These symptoms are indicators, not proof: failing hardware, software bugs or legitimate maintenance can look similar. Confirm with trusted tools, logs and an incident process rather than deleting evidence impulsively.

  1. Use centrally managed, updated antivirus/anti-malware or EDR where appropriate, and investigate detections.

  2. Keep operating systems, applications, browsers and firmware patched according to risk.

  3. Avoid unexpected attachments and links, and do not install pirated or untrusted software.

  4. Disable unnecessary macros; permit signed or trusted macros only where the business process requires them.

  5. Use least-privilege user and service accounts, with administrative access separated from everyday activity.

  6. Maintain regular protected backups, including offline or immutable copies, and test restoration.

  7. Control and scan removable media before use, while recognizing that scanning cannot guarantee safety against an unknown threat.

Backups do not prevent infection; they reduce recovery loss after infection. Likewise, anti-malware complements patching, allow-listing, segmentation and safe user behaviour rather than replacing them.

MethodFunctionImportant qualification
Spam filterScores message, sender, links, content and behaviour, then moves, quarantines or rejects likely spamFalse positives/negatives require tuning, review and an abuse-reporting process
Blacklist / blocklistBlocks known abusive sender addresses, domains or IP reputationEntries age and attackers move; reputation alone is insufficient
Whitelist / allow-listAllows named trusted senders or pathsA compromised trusted account can abuse the exception, so keep scope narrow
SPFA DNS policy lets a receiving server check whether the connecting IP is authorized to send for the SMTP envelope domainSPF does not authenticate message content or necessarily the visible From: domain, and ordinary forwarding can affect results
DKIMA sending domain signs selected headers and the body; the receiver uses the domain’s DNS public key to test integrity and domain responsibilityA valid DKIM signature does not prove the message is honest or that a named person authored it
DMARCRequires SPF and/or DKIM to pass with alignment to the visible From: domain, then publishes monitoring/enforcement policy and reportsEffective reject/quarantine policy should follow correct deployment and monitoring; DMARC still does not judge message intent

Spam-control and domain-authentication methods.

TypeDescription
White-hatSecurity professional who tests under explicit authorization and helps improve security
Black-hatUnauthorized malicious attacker seeking theft, damage, disruption or illicit control
Gray-hatActs without full authorization even if direct harm is not intended or a weakness is later reported
Script kiddieUses existing tools or scripts with limited understanding; limited skill does not mean limited harm or legal responsibility
HacktivistConducts attacks to promote a political or social cause; motive does not itself make access lawful

Common hacker categories.

Cryptography uses mathematical algorithms and keys to protect information and communication. Encryption transforms readable plaintext into ciphertext for confidentiality; other cryptographic mechanisms provide integrity, authentication or signatures rather than secrecy.

TermMeaning
Plaintext PPOriginal readable data supplied to encryption
Ciphertext CCEncrypted representation intended to be unintelligible without the authorized key
EncryptionTransformation from plaintext to ciphertext
DecryptionAuthorized inverse transformation from ciphertext to plaintext
KeySecret or public parameter controlling a cryptographic operation; the algorithm may be public, while security depends on correct key use/custody

Basic cryptographic terms.

For a symmetric cipher with key KK, the basic correctness relationship is

Modern systems normally prefer authenticated encryption, which also detects unauthorized ciphertext modification; confidentiality-only encryption does not automatically guarantee integrity.

FeatureSymmetric keyAsymmetric / public key
KeysSame secret key, or efficiently related secret keys, for encryption and decryptionMathematically related public/private key pair; private key is secret and public key must be authenticated
SpeedFast and efficient for large data volumesSlower and used for small values, key establishment and signatures rather than ordinary bulk data
Key distributionParties need a secure way to establish the shared secretPublic key may be distributed openly, but certificates or another trusted method must bind it to the intended owner
Typical useBulk data encryption and authenticated encryptionDigital signature, key establishment and recipient-key encryption where supported
ExamplesAES; DES is a historical example with an inadequate modern key sizeRSA and elliptic-curve schemes (ECC families)

Symmetric-key and asymmetric/public-key cryptography compared.

Most secure protocols are hybrid: public-key methods authenticate peers and establish a fresh session secret, then fast symmetric authenticated encryption protects the data. A public key is not confidential, but it must be authentic; a private key must remain secret.

A cryptographic hash function maps input of arbitrary practical length to a fixed-length digest, h=H(M)h=H(M). It has no decryption key and is intended to be one-way; hashing is not encryption.

PropertyMeaning
DeterministicThe same input under the same algorithm always gives the same digest
Fixed-length outputInput length can vary while digest length is fixed by the algorithm
Preimage resistance / one-wayGiven a digest, finding an input that produces it should be computationally infeasible
Second-preimage and collision resistanceIt should be infeasible to find a different input matching a chosen message’s digest or any two distinct inputs with the same digest
Avalanche effectA small input change should unpredictably change many output bits

Required hash properties and meanings.

Hashes support file-integrity checks against a trusted reference, digital signatures, content identification and hash-based constructions such as MACs. A bare hash received beside a file cannot resist an active attacker who can replace both; authenticate the reference with a signature, MAC or trusted channel. Collision-resistant algorithms such as SHA-256/SHA-3 are preferred for modern integrity use; MD5 and SHA-1 are unsuitable where collision resistance matters.

ControlPurpose and qualification
Antivirus / EDRDetects, blocks and investigates known or suspicious endpoint behaviour; needs updates, telemetry, tuning and response
FirewallFilters traffic by address, port, state, protocol or application policy; rules require least privilege, logging and review
IDS / IPSDetects suspicious network activity and, for IPS, may block it; coverage and false positives/negatives must be managed
EncryptionProtects confidentiality of data at rest or in transit; authenticated encryption also protects ciphertext integrity, while key management remains essential
BackupEnables recovery after deletion, failure or ransomware; copies must be protected, isolated where appropriate and restoration tested
Patch managementInventories, prioritizes, tests and deploys fixes for known vulnerabilities while tracking exceptions
Multi-factor authenticationRequires independent factor types so password loss alone is insufficient; phishing-resistant methods are preferred for high-risk access
Access controlLimits resources and actions to required identities, roles, devices or services; enforce least privilege and promptly remove stale access

Core technical controls, purposes and qualifications.

Controls are effective only when configured, monitored and connected to a response process. Defense in depth also needs asset inventory, secure configuration, segmentation, protected logging, physical safeguards, policy and trained people.

  1. Use strong, unique passwords—prefer long passphrases over short, artificially complex strings—and store them in a reputable password manager.

  2. Enable multi-factor authentication, especially for email, administrator, financial and remote-access accounts.

  3. Treat unexpected links, attachments, QR codes and urgent requests as untrusted until independently verified.

  4. Apply operating-system, browser, application and device updates promptly according to risk and organizational policy.

  5. Download software only from trusted sources and verify publisher signatures or approved distribution channels where available.

  6. Lock devices, encrypt portable systems and do not leave authenticated sessions unattended.

  7. Back up important data regularly and ensure at least one protected copy can actually be restored.

  8. Before entering sensitive data, verify HTTPS, the exact domain and any certificate warning; remember that a padlock protects the connection but does not prove the site’s content or operator is honest.

  • CIA triad: confidentiality limits disclosure, integrity protects accuracy/authorized change, and availability delivers service when required.

  • Malware distinction: a virus attaches to a host, a worm self-replicates across systems, and a Trojan is disguised as legitimate software.

  • Spam versus phishing: spam is unsolicited bulk communication; phishing impersonates a trusted party to induce an unsafe disclosure or action.

  • Authorization: cracking is unauthorized malicious security defeat; ethical testing requires written permission, exact scope and controlled reporting.

  • Signature creation: h=H(M)h=H(M) and S=Sign⁡SKA(h)S=\operatorname{Sign}_{SK_A}(h); keep SKASK_A secret and send MM, SS and normally A’s certificate.

  • Signature verification: authenticate PKAPK_A through PKI, recompute H(M)H(M) and run verification with PKAPK_A; this is not generic public-key decryption.

  • Signature limitation: a valid signature supports integrity, origin authentication and non-repudiation evidence, but not confidentiality.

  • Cryptography: symmetric encryption uses a shared secret and is fast; asymmetric schemes use a public/private pair for signatures, key establishment and selected encryption uses.

  • Hashing: a secure hash is deterministic, fixed-length, one-way, collision-resistant and avalanche-like; passwords require a salted adaptive password KDF, not a bare fast hash.

  • Email authentication: SPF authorizes the sending path, DKIM signs selected message data, and DMARC requires visible-domain alignment and supplies policy/reporting.

  • Defense in depth: place independent preventive, detective and recovery controls at successive trust boundaries so one failure does not expose the final asset.