This module covers how the internet delivers a web page, how data is protected on the way, how users are tricked, and how systems defend themselves. It also covers responsible use: using technology lawfully and ethically. Questions on it reward precise vocabulary and one clear idea per sentence.
For the exact scope and current codes, read the Cambridge IGCSE Computer Science syllabus page for your exam year. This module belongs to the wider Computer Science learning guide.
What should I already know?
You will find it easier if you already understand how data travels between devices. The module on data transmission and checking covers packets and error detection, and the software and systems module explains the programs that run browsers and operating systems. You do not need programming for most of this module, apart from reading a short algorithm in the encryption lesson.
Orienting example: reading a link before you click
Here is a fictional link in a fictional message:
https://www.sunrise-bank.example.net/login/index.html
Read it in three parts. https is the protocol, www.sunrise-bank.example.net is the host name, and /login/index.html is the path to a file on that server.
The part that identifies the owner is the domain, read from the right: example.net. Everything to the left, including sunrise-bank, is a label the owner chose.
So the link points to a site run by whoever owns example.net, and the bank name is only decoration. That one reading skill links three lessons: URLs, browser-server interaction and phishing.
What order should I study the lessons in?
- Distinguish a URL domain and path: the vocabulary every later lesson uses.
- Explain a browser-server interaction: follow one page request from typing to display.
- Describe encryption conceptually: why intercepted data can still be unreadable, with a traced shift cipher.
- Identify a phishing signal in a fictional message: apply the URL skill to spot deception.
- Explain a defensive control without offensive exploitation steps: firewalls and two-factor authentication, described by what they do.
Then try the mixed practice set. Two tools help: the restricted pseudocode trace trainer for the cipher trace, and the mistake log and retest queue for tracking slips.
Which traps catch students most often?
- Reading a URL from the left. The owner is identified from the right of the host name, not the first word you see.
- Mixing up similar terms. Encryption makes data unreadable. It does not stop it being intercepted or deleted.
- Vague answers. “It keeps you safe” earns nothing. Say what the control checks, blocks or hides.
- Describing attacks instead of defences. Questions ask what happens and how it is prevented. A short factual description of a threat is enough.
How do I use the practice set?
Attempt each question on paper first, written as you would in an exam. Open the answer only afterwards and compare your wording to the model answer, looking for missing key terms rather than whole missing ideas. Log each slip in the mistake queue and retry it a few days later.
If these ideas make sense in class but your written answers keep losing detail, that gap is something our teachers can work on in online one-to-one Computer Science tuition.