Skip to main content

Privacy law, cyber threats, CIA, AAA and ethical hacking: WACE Computer Science Unit 4

Syllabus dot point

“Explain privacy obligations for organisations (including Australian Privacy Principle 11 and the Notifiable Data Breaches scheme), identify common cyber security threats and matching countermeasures, and apply the CIA triad, the AAA framework and ethical hacking practices”

WACEComputer ScienceUnit 4: Cyber security9 min read

Quick answer

Organisations must protect personal information (APP 11) and notify serious breaches to individuals and the OAIC. Match each threat, such as phishing, ransomware, DoS, SQL injection or man-in-the-middle, with countermeasures. Use the CIA triad to analyse impact, AAA to control access, and authorised ethical hacking (red and blue teams) to find weaknesses.

Jump to a section
  1. What this dot point is asking
  2. The answer
  3. Practice questions

What this dot point is asking

Unit 4's cyber security content combines law, threats and principles. You need to explain organisations' legal obligations, match threats to countermeasures, apply the CIA triad and AAA framework, and describe ethical hacking.

The answer

Privacy law

  • Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) govern how many organisations handle personal information.
  • APP 11 (security of personal information): take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify information no longer needed.
  • Notifiable Data Breaches scheme: if a breach is likely to result in serious harm, notify affected individuals and the Office of the Australian Information Commissioner (OAIC).

Threats and countermeasures

Threat Countermeasures
Phishing and social engineering Awareness training, email filtering, MFA
Malware and ransomware Anti-malware, patching, least privilege, offline backups
Denial of service (DoS/DDoS) Filtering, rate limiting, DDoS protection, redundancy
SQL injection Parameterised queries, input validation, least-privilege accounts
Man-in-the-middle TLS/HTTPS, VPNs, certificate checking
Brute force and weak passwords Strong password policy, lockout, MFA, hashing with salt
Insider threats Role-based access, logging, separation of duties

CIA and AAA

Two frameworks
  • CIA triad: Confidentiality (only authorised people can read data), Integrity (data is accurate and unaltered), Availability (systems work when needed).
  • AAA: Authentication (verify identity), Authorisation (grant appropriate permissions), Accounting (log activity).

Ethical hacking

Ethical hackers (penetration testers) attack systems with permission to find weaknesses before criminals do. Red teams simulate attackers; blue teams defend, detect and respond. Ethical hacking requires written authorisation, a defined scope and responsible reporting.

Worked example

A café's free Wi-Fi shares the same network as its point-of-sale terminals.

  1. Threat: a customer's infected laptop, or an attacker, could reach the payment terminals.
  2. CIA impact: confidentiality (card data) and availability (terminals disrupted).
  3. Countermeasures: separate guest and business networks (VLANs or separate SSIDs), firewall rules between them, WPA3 on the business network, and patching.
  4. Accounting: router logs reviewed weekly.
Common traps
Naming a threat without a matching control
Always pair them.
Confusing authentication with authorisation
Logging in proves identity; permissions decide access.
Forgetting the legal side
Breaches of personal information have notification obligations.

Practice questions

Original practice questions graded from foundation to exam level, each with a full worked solution. Try them before revealing the solution.

foundation4 marks
For each threat give one countermeasure: (a) ransomware, (b) denial of service, (c) brute-force password attacks, (d) man-in-the-middle on public Wi-Fi.
Show worked solution →

(a) Ransomware: offline or immutable backups plus patching and anti-malware.

(b) Denial of service: traffic filtering, rate limiting and DDoS protection services.

(c) Brute force: account lockout or rate limiting, strong passwords and multi-factor authentication.

(d) Man-in-the-middle: encryption with TLS (HTTPS) and a VPN.

Marking guide: 1 mark each.

core4 marks
Explain how the AAA framework applies to a school's student management system.
Show worked solution →
Authentication
staff log in with a username, password and a one-time code, proving their identity.
Authorisation
role-based access control lets teachers see their own classes' marks, while only administrators can change enrolment details.
Accounting
the system logs who viewed or changed each record and when, so misuse can be detected and investigated.

Together they protect confidentiality and integrity and support accountability.

Marking guide: 1 mark each for authentication, authorisation and accounting applied, 1 mark for the link to security goals.

exam6 marks
A medical clinic's database of patient records is stolen after an attacker uses SQL injection through the online booking form. Analyse the breach using the CIA triad, explain the clinic's obligations under Australian privacy law, and recommend technical controls.
Show worked solution →
CIA analysis
Confidentiality was breached (records were stolen). If the attacker also changed or deleted records, integrity was breached, and any downtime to fix the system affects availability.
Legal obligations
Health information is sensitive personal information. Under APP 11 the clinic had to take reasonable steps to secure it. Because stolen health records are likely to cause serious harm, this is an eligible data breach: the clinic must notify affected patients and the Office of the Australian Information Commissioner, describing the breach and recommended steps.
Controls
Use parameterised queries and input validation to stop SQL injection; apply least-privilege database accounts for the web application; encrypt sensitive data at rest; add a web application firewall; log and monitor database access (accounting); and commission regular penetration testing (ethical hacking) to find weaknesses.

Marking guide: 2 marks for CIA analysis, 2 marks for legal obligations, 2 marks for relevant controls.

core4 marks
For each incident, identify the part of the CIA triad most directly affected and explain why. (a) A flood of traffic takes a council's online payment site offline for a day. (b) A student gains access to the marks database and raises their own results. (c) An employee emails a spreadsheet of client addresses to the wrong external contact. (d) Ransomware encrypts a small business's files so staff cannot open them.
Show worked solution →

(a) Availability: the denial of service means the site does not work when residents need it.

(b) Integrity: the data has been altered without authorisation, so the marks are no longer accurate.

(c) Confidentiality: personal information has been disclosed to someone not authorised to see it.

(d) Availability: the files still exist but cannot be used. (Confidentiality may also be affected if the attackers copied the files before encrypting them.)

Marking guide: 1 mark each for the correct property with a reason.

exam6 marks
A regional business hires a security firm to carry out ethical hacking of its network and web applications. (a) Explain three conditions that make this hacking ethical rather than criminal. (3 marks) (b) Distinguish between the red team and the blue team in this exercise. (2 marks) (c) Explain one benefit to the business. (1 mark)
Show worked solution →

(a)

  • Written authorisation: the business formally gives permission before any testing, so the testers are not accessing systems without consent.
  • Defined scope: the agreement sets which systems, methods and times are allowed, so testing does not stray into systems the business does not own or disrupt operations unexpectedly.
  • Responsible reporting: weaknesses found are reported privately to the business so they can be fixed, and any data seen is kept confidential rather than exploited or published.

(b) The red team simulates real attackers, trying to find and exploit weaknesses. The blue team defends the systems, detecting, responding to and recovering from the red team's attacks.

(c) Weaknesses are found and fixed before criminals exploit them, reducing the risk of a breach (and of harm to customers whose personal information the business holds).

Marking guide: (a) 1 mark per condition explained; (b) 1 mark each for red and blue team roles; (c) 1 mark for a benefit.

exam15 marks
A non-government secondary school, which is covered by the Privacy Act, stores student reports, contact details and health notes in a cloud-based portal. A teacher receives an email that appears to come from the portal, clicks the link and enters their password on a fake login page. The attacker then logs in as the teacher and downloads the personal information of 300 students. The school had no multi-factor authentication and kept records of students who left years ago. (a) Identify the threat used and explain how it worked. (2 marks) (b) Analyse the incident using the CIA triad. (3 marks) (c) Explain the school's obligations under Australian Privacy Principle 11, referring to the details of the scenario. (3 marks) (d) Explain what the Notifiable Data Breaches scheme would require of the school in this case. (3 marks) (e) Recommend improvements to the portal using each part of the AAA framework. (4 marks)
Show worked solution →

(a) Phishing (a form of social engineering). The attacker sent an email disguised as coming from the trusted portal and linked to a fake login page. The teacher was tricked into entering their password, which the attacker captured and used to log in.

(b)

  • Confidentiality was breached: students' reports, contact details and health notes were accessed and copied by an unauthorised person.
  • Integrity is now in doubt: with the teacher's access the attacker might have changed records, so the school must check them.
  • Availability may be affected if the school has to lock the account or take the portal offline while it investigates.

(c) APP 11 requires the school to take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Relying on a password alone for a system holding sensitive health information is weak protection, and staff awareness training could have reduced the phishing risk. APP 11 also requires information no longer needed to be destroyed or de-identified, so keeping records of students who left years ago unnecessarily increased the amount of information exposed.

(d) Personal information, including health notes, was accessed without authorisation, and this is likely to result in serious harm to the students. The school must therefore notify the affected individuals (the students and their families) and the Office of the Australian Information Commissioner (OAIC), describing the breach and the steps people should take.

(e)

  • Authentication: require multi-factor authentication, so a stolen password alone does not give access.
  • Authorisation: apply role-based access and least privilege, so a teacher can see only their own students' information and not download records in bulk.
  • Accounting: log every login and download and monitor for unusual activity (such as 300 records downloaded at once) so misuse is detected and investigated quickly.
  • One further control for any part, for example alerting on logins from new locations (accounting) or locking accounts after suspicious attempts (authentication).

Marking guide: (a) 1 mark for phishing, 1 mark for how it worked; (b) 1 mark per CIA element applied; (c) 1 mark for reasonable steps, 1 mark for applying it to weak login protection, 1 mark for destroying or de-identifying old records; (d) 1 mark for serious harm, 1 mark for notifying individuals, 1 mark for notifying the OAIC; (e) 1 mark each for authentication, authorisation and accounting improvements, 1 mark for an additional justified control. Total 15.

exam19 marks
An online homewares retailer, which is covered by the Privacy Act, runs a website with customer accounts and a staff system for processing orders. It keeps customer records dating back many years. (a) Explain three threats the retailer faces from ransomware, denial of service and insiders, pairing each with an appropriate countermeasure. (6 marks) (b) The login form builds its database query by joining the text the user types into an SQL statement. Explain how an attacker could use SQL injection against this form and how the developer should prevent it. (4 marks) (c) Explain the retailer's obligation under Australian Privacy Principle 11 regarding customer records it no longer needs. (2 marks) (d) The retailer plans a red team and blue team exercise. Describe the role of each team and one condition that must be in place before the exercise begins. (4 marks) (e) Evaluate multi-factor authentication as a control for staff accounts, referring to the AAA framework. (3 marks)
Show worked solution →

(a)

  • Ransomware: malware encrypts the retailer's order and customer files and demands payment, halting the business. Countermeasures: offline backups so data can be restored, plus patching, anti-malware and least privilege to stop it spreading.
  • Denial of service: attackers flood the website with traffic so real customers cannot shop, losing sales. Countermeasures: traffic filtering, rate limiting, a DDoS protection service and redundancy.
  • Insider threat: a staff member misuses their access to copy customer details or alter orders. Countermeasures: role-based access so staff see only what their job needs, logging of activity, and separation of duties.

(b) Because the typed text is joined straight into the SQL, an attacker can enter SQL code instead of a normal value. For example, typing ' OR '1'='1 in the password box can turn the condition into one that is always true, so the query returns a matching user and logs the attacker in without a password; other input could read or change customer data. Prevention: use parameterised queries, which send the input separately as data so it is never run as SQL; also validate input and connect with a least-privilege database account.

(c) APP 11 requires the retailer to take reasonable steps to protect personal information and to destroy or de-identify personal information it no longer needs (unless a law requires it to be kept). Keeping old customer records it has no use for increases the harm of any breach, so they should be securely deleted or de-identified.

(d) The red team simulates attackers, trying to break into the website and staff system to find weaknesses. The blue team defends, detecting, responding to and recovering from the red team's attacks, which tests the retailer's monitoring and response. Condition (any one): written authorisation from the retailer; a clearly defined scope of systems and methods; agreement on responsible, confidential reporting of findings.

(e) MFA strengthens authentication: staff must provide something extra (such as a one-time code) as well as a password, so a password stolen by phishing or guessed by brute force is not enough to log in. It is therefore a highly effective control for staff accounts. However, it does not deal with authorisation (what a logged-in user may do) or accounting (logging what they did), so it will not stop a legitimate insider misusing access. It should be combined with role-based access and activity logging.

Marking guide: (a) 1 mark per threat explained and 1 mark per matching countermeasure (6); (b) 1 mark for input being run as SQL, 1 mark for a valid example or effect, 1 mark for parameterised queries, 1 mark for an additional control; (c) 1 mark for reasonable steps, 1 mark for destroy or de-identify; (d) 1 mark each for red and blue team roles, 2 marks for a condition explained; (e) 1 mark for strengthening authentication, 1 mark for why stolen passwords are not enough, 1 mark for limits regarding authorisation and accounting. Total 19.

Practise this

Sources & how we know this

ExamExplained