Cybersecurity basics: passwords, malware and phishing

遊んで学ぼう

問題に答えてエネルギーを集めたら、釣りや探検を楽しもう。アカウント不要。

教育者の方へ: Cybersecurity basics: passwords, malware and phishing(KS3 Computing、Digital Literacy)向けのすぐ使えるレッスンスライド, 復習ノート, 図解 — レッスンで使うか、学習者がライブゲームとして遊ぶインタラクティブなクラス活動としてトピックを実施できます。

レッスンノート

Strong Passwords

  • A strong password is long, random, and unique for each account.
  • Use a mix of upper and lower case letters, numbers, and symbols.
  • Avoid using personal information like names, birthdays, or common words.
  • Consider using a passphrase – a sequence of random words – which is easier to remember and harder to crack.
  • Never reuse passwords across different accounts; if one is compromised, others are at risk.
  • Use a password manager to store and generate strong passwords securely.

Long, unique passphrases with a password manager and multi-factor authentication resist guessing far better than short reused passwords.

Long, unique passphrases with a password manager and multi-factor authentication resist guessing far better than short reused passwords.

Malware Types

  • Malware is malicious software designed to harm or exploit devices and data.
  • A virus attaches itself to a file or program and spreads when the infected file is opened.
  • A worm spreads automatically across networks without needing a host file.
  • Ransomware locks your files or device and demands payment to restore access.
  • Malware can be delivered via email attachments, malicious links, or compromised websites.
  • Keeping software updated helps patch vulnerabilities that malware exploits.

Phishing and Social Engineering

  • Phishing is a scam where attackers trick people into revealing sensitive information or installing malware.
  • It is a form of social engineering – manipulating people rather than hacking systems.
  • Phishing messages often pretend to be from trusted sources like banks or government agencies.
  • They create urgency or fear, e.g., 'Your account has been compromised – click here now.'
  • The goal is usually to steal login credentials, financial details, or install malware.
  • Phishing is the most common type of cybercrime globally.

Types of Phishing

  • Email phishing – bulk emails sent to many people, often with fake login links.
  • Spear phishing – targeted attacks on specific individuals using personal information to seem credible.
  • Vishing (voice phishing) – fake phone calls, often using VoIP and number spoofing.
  • Smishing (SMS phishing) – fraudulent text messages with links or phone numbers.
  • Quishing – phishing using QR codes that lead to malicious sites.
  • Page hijacking – redirecting users from legitimate websites to malicious ones.

Staying Safe Online

  • Always think critically before clicking links or opening attachments, even if they look familiar.
  • Check the sender's email address or phone number for unusual details.
  • Hover over links to see the real URL before clicking.
  • Never enter personal information on a site reached via a suspicious link.
  • Use multi-factor authentication (MFA) where possible for extra security.
  • Keep all software and devices updated to protect against known vulnerabilities.

Software Updates

  • Software updates fix security holes (vulnerabilities) that attackers can exploit.
  • Enable automatic updates for your operating system, apps, and antivirus.
  • Updates often include patches for newly discovered malware threats.
  • Ignoring updates leaves your device at higher risk of infection.
  • Only download updates from official sources to avoid fake update scams.

A security update patches the vulnerability an attacker could otherwise exploit.

A security update patches the vulnerability an attacker could otherwise exploit.

Account and Device Safety

  • Use a different strong password for each important account.
  • Log out of accounts on shared or public devices.
  • Be cautious when using public Wi-Fi – avoid accessing sensitive accounts without a VPN.
  • Install and maintain reputable antivirus software.
  • Back up important data regularly to recover from ransomware attacks.
  • Report phishing attempts to your school, workplace, or relevant authorities.

A phishing message uses urgency to make you click; the safe response is stop, check independently, report.

The malware infection chain: delivery, execution, infection, impact, then persistence and spread.

Social engineering relies on urgency, impersonation and requests for sensitive information; pause, verify, report.

スライド

Sign up free to view the lesson slides

Step through every slide for this topic — plus flashcards and revision notes — with a free account.

練習問題

無料プレビュー — 58問中8問。すべて見るには登録を。
  1. 1.Phishing is a type of social engineering attack.

    Easy

    True or false?

  2. 2.What does the term 'phishing' refer to?

    Easy
    • AUsing a fishing rod to catch fish
    • BA type of computer virus
    • CA scam that uses lures to 'fish' for sensitive information
    • DA method of securing passwords
  3. 3.Malware only includes viruses.

    Easy

    True or false?

  4. 4.Which of the following are types of malware mentioned in the source? (Select all that apply)

    Easy
    • AVirus
    • BWorm
    • CRansomware
    • DPhishing
    • EAdware
  5. 5.Spear phishing targets a specific individual or group.

    Easy

    True or false?

  6. 6.What is 'smishing'?

    Easy
    • APhishing via email
    • BPhishing via SMS text messages
    • CPhishing via voice calls
    • DPhishing via QR codes
  7. 7.Keeping software up to date is not important for cybersecurity.

    Easy

    True or false?

  8. 8.Match each phishing type to its description.

    Medium
    • Vishing
    • Smishing
    • Quishing
    • Voice phishing
    • SMS phishing
    • QR code phishing

Unlock all 58 questions, flashcards & more

無料アカウントを作って、このトピックのすべての問題・スライド・フラッシュカード・復習ノートを見よう。

過去問

このトピックの過去問練習は近日公開。
近日公開