1.4.1
Threats to Computer Systems and Networks
The key to network security questions is identifying the attack, explaining how it works, and saying what the attacker is trying to achieve. The attack types you need to know include malware, phishing, brute-force attacks, denial of service, data interception, and SQL injection.
On this page7 sectionsHide
What you need to know
- Describe how different attack types are used.
- Explain the purpose of malware, phishing, brute-force attacks, DoS attacks, and SQL injection.
- Recognise the attack being described in a scenario.
- Link attacks to the damage or risk they create.
Big Picture
Why network threats matter
Security threats can lead to lost data, stolen information, damaged systems, and services becoming unavailable.
You should know both how an attack works and why an attacker might use it. That might be to steal data, gain access, cause disruption, or trick users into revealing information.

- Some attacks target the device or software.
- Some attacks target the network connection.
- Some attacks target the human user as the weak point.
Access and Disruption
Brute-force attacks and denial of service
These two attacks have different aims, so do not mix them up.
- Brute-force attacks repeatedly try password combinations until the correct one is found.
- Weak or short passwords are much easier to break using brute force.
- A denial of service attack floods a system or network with traffic so legitimate users cannot access it properly.
- The aim of a DoS attack is disruption rather than secretly logging in.
Strong comparison
Brute force is mainly about gaining access. Denial of service is mainly about making a service unavailable.
Data Theft
Data interception, theft, and SQL injection
You need to recognise both network-based theft and attacks on data systems.
Data interception means capturing data while it is travelling across a network. If that data is not protected, an attacker may read or steal it.
SQL injection happens when an attacker enters code into an input field so the database query is changed in a harmful way. This can allow unauthorised access to data.
- Interception targets data in transit.
- SQL injection targets database queries.
- Both can lead to stolen confidential data.
SQL injection in one sentence
SQL injection is when harmful input changes the meaning of a database query.
Key takeaways
- Different attacks work in different ways, so accurate exam language matters.
- Social engineering attacks exploit people rather than hardware.
- A brute-force attack tries many password combinations until one works.
- A denial of service attack tries to stop legitimate users accessing a service.
- SQL injection targets database queries by inserting malicious input.
Glossary
- Malware
- Malicious software designed to damage, disrupt, or gain unauthorised access.
- Phishing
- A scam that tricks users into revealing sensitive information.
- Brute-force attack
- Trying many password combinations until the correct one is found.
- Denial of service
- An attack that floods a service with traffic so it cannot respond properly.
- SQL injection
- An attack where malicious input changes a database query.
Test yourself
4 questions
What is the aim of a phishing attack?
To trick the user into revealing sensitive information such as passwords or bank details.
What does a brute-force attack do?
It repeatedly guesses password combinations until one works.
What is the main aim of a denial of service attack?
To make a service unavailable to legitimate users.
Why is SQL injection dangerous?
Because it can give unauthorised access to data or let an attacker change what a database does.
Common questions
Is phishing the same as malware?
No. Phishing is a social engineering attack that tricks the user, while malware is harmful software installed on a device.
What is the difference between brute force and phishing?
Brute force guesses passwords automatically, while phishing tries to trick a user into revealing them.
Does a DoS attack always steal data?
No. Its main purpose is to disrupt access to a service rather than secretly steal information.