Computer Science
Security and software quality
- 1.
Distinguish authentication from authorisation using a school results portal.
[3 marks] · no calculator - 2.
Explain why a password manager's generated unique passwords reduce the impact of a breach at one website.
[3 marks] · no calculator - 3.
Explain how a parameterised SQL query prevents user input from becoming SQL syntax, and why escaping only apostrophes is a weaker design.
[3 marks] · no calculator - 4.
Distinguish symmetric encryption from hashing, and explain why password verification normally needs a salted password hash rather than reversible encryption.
[3 marks] · no calculator - 5.
A tested application encrypts traffic but logs full medical records and gives all staff administrator access. Evaluate the claim that encryption makes the system secure, proposing two targeted changes.
[4 marks] · no calculator - 6.
A classifier is 95% accurate overall but performs poorly for a small demographic group. Evaluate deploying it for high-impact decisions, identifying evidence beyond aggregate accuracy and an operational safeguard.
[4 marks] · no calculator
Marking points are indicative, not an official mark scheme. Accept equivalent valid methods and supported interpretations that address the task; award each mark once without requiring the model wording.