Skip to main content

WACE Computer Science ATAR Unit 4: data management and cyber security exam question types

WACEComputer ScienceStudy guide6 min read

How WACE Computer Science ATAR Unit 4 data management and cyber security content is examined: keys and normalisation, SQL queries, integrity and ACID, encryption, signatures and TLS, threats and countermeasures, and privacy obligations, with a method for each and links to the dot points. Pairs with a 13-question practice quiz.

Jump to a section
  1. What this guide covers
  2. Question types you should expect
  3. Worked example
  4. Keep going

What this guide covers

Unit 4 of the WACE Computer Science ATAR course covers data management (relational design, normalisation, SQL and transactions) and cyber security (cryptography, threats, security frameworks and privacy law). Scenario questions in the exam often join the two: a business database that must be designed well and protected properly. The practice quiz on this page drills the core facts; the sections below show the question types that use them.

Question types you should expect

1. Design and normalise a database

You may be given an unnormalised table and asked to identify problems (update, insertion and deletion anomalies) and normalise it to 3NF, or to draw an ER diagram and write relational notation. Check each rule in turn:

Normal form Test
1NF Every value is atomic and there are no repeating groups
2NF No non-key field depends on only part of a composite key
3NF No non-key field depends on another non-key field

Revise relational databases, ER diagrams and normalisation.

2. Write or read SQL

Expect to write SELECT queries with WHERE, ORDER BY, JOIN, GROUP BY, aggregates and HAVING, and data changes with INSERT, UPDATE and DELETE. Build a query clause by clause: which tables (FROM and JOIN on the key), which rows (WHERE), which groups (GROUP BY), which groups to keep (HAVING), which columns (SELECT) and in what order (ORDER BY).

Common trap

Putting an aggregate condition in WHERE, such as WHERE COUNT(*) > 5. Conditions on aggregates belong in HAVING.

Revise SQL and database development issues.

3. Explain integrity and transactions

Name the type of integrity at risk (entity, referential, domain) and the ACID property that protects a transaction (atomicity, consistency, isolation, durability), using the scenario's details. A bank transfer that half-completes is the classic atomicity example.

4. Explain how cryptography protects communication

Know which key does what: the receiver's public key encrypts for confidentiality; the sender's private key signs a hash for authenticity and integrity; certificates bind public keys to identities; TLS uses asymmetric cryptography during the handshake to agree a symmetric session key, then encrypts the data symmetrically for speed.

Revise cryptography, encryption, certificates and TLS.

5. Match threats to countermeasures and obligations

Scenario questions describe an attack and ask for its impact and a fix. Use the CIA triad for impact (ransomware hits availability, data theft hits confidentiality, tampering hits integrity), pair each threat with a specific countermeasure (parameterised queries for SQL injection, user training and MFA for phishing, backups for ransomware), and state the organisation's obligations under APP 11 and the Notifiable Data Breaches scheme.

Revise privacy law, threats and security principles.

Worked example

Question (exam style, 3 marks). Write an SQL query that lists each product category with the number of products in it, showing only categories with at least 10 products, largest first. The table is Product(ProductID, Name, Category, Price).

Answer.

SELECT Category, COUNT(*) AS NumProducts
FROM Product
GROUP BY Category
HAVING COUNT(*) >= 10
ORDER BY NumProducts DESC;

GROUP BY makes one row per category, HAVING keeps categories with at least 10 products, and ORDER BY sorts from largest to smallest.

Keep going

Continue with the Unit 3 programming and networks practice, then work through the practice questions on each dot point page.

Sources & how we know this

  • computer-science
  • wace-computer-science
  • databases
  • sql
  • cyber-security
  • cryptography
  • exam-technique
  • quiz
ExamExplained