Get matched
AS & A Level · AS/A Level

Computer Science

Security and software quality

Name: ____________________Date: October 10, 2026
  1. 1.

    Distinguish authentication from authorisation using a school results portal.

    [3 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. Login and access control answer different questions: who is requesting and what may they do? The server must enforce the second even when the first succeeded.

    Marking points

    • Authentication establishes the user's identity.
    • Authorisation determines which results/actions that identity may access.
    • A logged-in student should not automatically access another student's records.

    Examiner tip: Hiding a link in the interface is not an authorisation check.

  2. 2.

    Explain why a password manager's generated unique passwords reduce the impact of a breach at one website.

    [3 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. A stolen credential can only directly unlock services accepting that credential. Uniqueness limits the breach's scope; it does not undo exposure of the breached site's own data.

    Marking points

    • Reused passwords enable credential reuse at other sites.
    • Unique passwords limit this cross-site reuse.
    • Strong generated values resist guessing, though device/account compromise still needs protection.

    Examiner tip: Do not claim unique passwords prevent all phishing or endpoint compromise.

  3. 3.

    Explain how a parameterised SQL query prevents user input from becoming SQL syntax, and why escaping only apostrophes is a weaker design.

    [3 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. Concatenation lets characters alter a query's grammar. Binding parameters fixes that grammar first and then supplies values; dynamic identifiers still need allowlisted construction because value parameters do not represent every SQL component.

    Marking points

    • The query structure is supplied separately from parameter values.
    • The database binds input as data, not executable query text.
    • Ad hoc escaping is context/encoding-dependent and easier to implement incompletely.

    Examiner tip: Validation can complement binding but should not replace it for query values.

  4. 4.

    Distinguish symmetric encryption from hashing, and explain why password verification normally needs a salted password hash rather than reversible encryption.

    [3 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. Verification can recompute the stored derivation from a submitted password and recorded salt. Reversible storage creates a key whose compromise can expose every password, whereas appropriate password hashing raises offline-guessing cost without requiring recovery.

    Marking points

    • Encryption is reversible with the appropriate key.
    • A hash supports comparing a derived value without retrieving the original password.
    • A unique salt prevents identical passwords sharing stored results and frustrates precomputed attacks; use a deliberately costly password-hashing scheme.

    Examiner tip: A salt is not a secret decryption key, and a fast general-purpose hash alone is unsuitable.

  5. 5.

    A tested application encrypts traffic but logs full medical records and gives all staff administrator access. Evaluate the claim that encryption makes the system secure, proposing two targeted changes.

    [4 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. Trace information beyond the network connection. A secure channel can still deliver data into overexposed logs, and a correctly authenticated employee can misuse excessive permissions; the proposed controls address those distinct exposures.

    Marking points

    • Transport encryption protects data in transit, not all stored logs or permissions.
    • Minimise/redact sensitive log contents and control log access/retention.
    • Apply least-privilege roles rather than universal administrator access.
    • Security needs threat-based testing and layered controls; successful tests/encryption alone are insufficient.

    Examiner tip: Identify the protected threat for each control instead of calling any control a complete solution.

  6. 6.

    A classifier is 95% accurate overall but performs poorly for a small demographic group. Evaluate deploying it for high-impact decisions, identifying evidence beyond aggregate accuracy and an operational safeguard.

    [4 marks] · no calculator

    Answer explanation

    Draft walkthroughs are based on marking guidance, not independently verified derivations.

    1. A single metric weights groups by their prevalence and treats unequal error costs alike. Deployment judgement needs disaggregated evidence and a process that can catch, challenge and correct harmful decisions rather than merely a high average score.

    Marking points

    • Aggregate accuracy can conceal subgroup error rates and unequal harm.
    • Measure subgroup false positives/false negatives with sample-size and uncertainty information.
    • Assess data representativeness, error costs and privacy/consent requirements.
    • Use accountable human review/appeal and monitoring; defer deployment if unacceptable harms cannot be controlled.

    Examiner tip: An overall percentage is not a fairness guarantee or an automatic deployment threshold.