This set covers the whole internet security and responsible use module: reading URLs, browser-server steps, encryption with one traced cipher, phishing signals and defensive controls. All addresses and messages are fictional.
Questions run from easy to harder. Write your answer first, then open the working. The restricted pseudocode trace trainer helps with the cipher questions, and the mistake log and retest queue is the place to record slips.
Questions
1. In https://www.library.example.org/books/maths.html, state the protocol, the domain and the path.
Show answer
Protocol: https. Host name: www.library.example.org, so reading from the right the domain is example.org. Path: /books/maths.html.
2. What is the domain in https://www.example.my.checkout.example.com/pay?
Show answer
The host name is www.example.my.checkout.example.com. From the right, the ending is .com, the registered name is example, so the domain is example.com. The words example.my and checkout are subdomain labels.
3. Put these steps in order: (a) the web server sends the page, (b) the browser renders the page, (c) the DNS server returns an IP address, (d) the browser asks DNS for the IP address, (e) the browser sends a request for the page.
Show answer
d, c, e, a, b. The browser asks DNS, DNS replies with the IP address, the browser requests the page, the server sends it, and the browser renders it.
4. Which device converts a domain name into an IP address?
Show answer
A DNS server (domain name system server), not the web server that hosts the website.
5. Define plaintext and ciphertext.
Show answer
Plaintext is the original, readable data before encryption. Ciphertext is the scrambled data produced after encryption, which cannot be understood without the key.
6. Using the shift cipher from the encryption lesson, with Pos = ASC(letter) − 65 and NewPos = (Pos + Key) MOD 26, encrypt ZEBRA with key 3.
Show answer
Z: 25 + 3 = 28, 28 MOD 26 = 2, so C. E: 4 + 3 = 7, so H. B: 1 + 3 = 4, so E. R: 17 + 3 = 20, so U. A: 0 + 3 = 3, so D.
Ciphertext: CHEUD. The wrap-round on Z is the step most often missed.
7. FRGH was encrypted with key 3. Decrypt it.
Show answer
Subtract 3: F(5) gives 2 = C; R(17) gives 14 = O; G(6) gives 3 = D; H(7) gives 4 = E. Plaintext: CODE. Check by encrypting CODE with key 3: FRGH.
8. State one difference between symmetric and asymmetric encryption.
Show answer
Symmetric encryption uses the same key to encrypt and decrypt. Asymmetric encryption uses a public key to encrypt and a different, private key to decrypt.
9. A message says: “Dear account holder, your account is suspended. Confirm your PIN at https://www.mybank.example.com.confirm.example.net within 6 hours.” Give three signs it is phishing.
Show answer
Any three: generic greeting; urgent time limit; asks for a PIN; the link’s domain, read from the right, is example.net, not the bank’s own domain; the padlock or https does not prove the owner is genuine.
10. Is a password plus a fingerprint two-factor authentication? Is a password plus a PIN?
Show answer
Password plus fingerprint: yes, one is something you know and the other is something you are. Password plus PIN: no, both are things you know, so they are the same type of factor.
11. Match each action to a control: (a) checks network traffic against rules, (b) scans files for harmful programs, (c) fixes known weaknesses in software. Controls: anti-malware, firewall, software update.
Show answer
(a) firewall; (b) anti-malware; (c) software update.
12. A PIN has 4 digits, each 0 to 9. A system locks after 3 wrong attempts. How many PINs are possible, and what fraction of them can be tried before lock-out? Why is lock-out a sensible control?
Show answer
Possible PINs: 10 × 10 × 10 × 10 = 10 000. Three attempts cover 3 of 10 000, which is 3/10 000 = 0.03%. Lock-out makes guessing impractical because only a tiny fraction can be tried before access is blocked. Check: 3 ÷ 10 000 = 0.0003 = 0.03%.
If you got these wrong
| What went wrong | Go to |
|---|---|
| Domain read from the left, or path and domain confused (Q1, Q2) | Distinguish a URL domain and path |
| Steps in the wrong order, or DNS and web server mixed up (Q3, Q4) | Explain a browser-server interaction |
| Definitions, key types or cipher trace errors (Q5 to Q8) | Describe encryption conceptually |
| Missed warning signs, or trusted https alone (Q9) | Identify a phishing signal |
| Controls confused, or two-factor misjudged (Q10 to Q12) | Explain a defensive control |
Return to the module overview for the study route.
If the same type of error keeps returning after you have reread the lessons, that is where a teacher in online one-to-one Computer Science tuition can help most. The safe Python reasoning sandbox is another way to test a trace.