IBDP Computer Science A2.4 Network security SL Paper 1 - New Syllabus

Question 

An organization replaced its local area network (LAN) with a wireless local area network (WLAN).
(a) Identify three hardware components of a WLAN. [3]
(b) Outline two advantages of a WLAN for the organization. [4]
A WLAN will introduce many cybersecurity risks.
(c) Describe two ways in which the organization can avoid unauthorized interception issues. [4]
The organization allows employees to connect to the network from their homes.
(d) Explain how a virtual private network (VPN) allows employees full functionality as well as secure access to the organization’s network. [4]

Most-appropriate topic code (CED):

• TOPIC A2.1: Network fundamentals — parts (a), (b), (c) and (d)
• TOPIC A2.4: Network security — parts (c) and (d)
▶️ Answer/Explanation

(a) Answer (any three):

  • Wireless router
  • Wireless access point (WAP)
  • Wireless antenna
  • Client wireless adaptor / network interface card (NIC)
  • Wireless bridge / repeater
  • Wireless controller
  • Network switch

Award [3 max]
Award [1] for each correct hardware component, up to a maximum of [3].

(b) Answer:

AdvantageExplanation
Flexibility and mobilityEmployees can work without being restricted to dedicated computers or fixed desk locations and can remain connected while moving around the office.
Cost savingsA WLAN can be cheaper to install or extend because additional network cables and some hardware connections are not required.
Increased collaborationEmployees can work from different locations within the office while still accessing key documents and information.
ScalabilityNew employees and devices can be added to the network easily and quickly.
Simpler infrastructureDesk locations are not dictated by the position of network wires and cables, making the office layout more flexible.

Award [4 max]
Award [1] for stating a suitable advantage and [1] for an appropriate expansion, ×2.

(c) Answer:

MethodHow it prevents unauthorized interception
Use WPA2 or WPA3 encryptionWireless traffic is encrypted so that intercepted data cannot be understood without the appropriate decryption key.
Use a VPNCommunication between devices and the network is encrypted, making it difficult for an attacker who intercepts the communication to understand the data.
Multi-factor authenticationUsers must verify their identity using an additional method such as a text message, email or authenticator app, reducing the risk of unauthorized access.
MAC address filteringOnly trusted or authorized devices with permitted MAC addresses are allowed to connect to the access point.
Strong passwordsComplex passwords containing different character types and changed regularly help prevent unauthorized access and brute-force attacks.

Award [4 max]
Award [2] for each method explained, with [1] for identifying a suitable security method and [1] for explaining how it helps prevent unauthorized interception.

(d) Answer:

A VPN first authenticates the employee to ensure that only authorized users can connect to the organization’s network.

It then establishes an encrypted tunnel between the employee’s device and the organization’s network. All data passing through this tunnel is encrypted, so even if the communication is intercepted, the attacker cannot understand the data without the appropriate key.

The VPN also allows the employee to access internal resources such as files, databases, printers and applications as if they were physically connected to the organization’s LAN. Therefore, the employee can have the required functionality while maintaining secure access to the network.

Award [4 max]
Award [1] for authentication of authorized users.
Award [1] for establishing a tunnel between the employee’s device and the organization’s network.
Award [1] for encryption of data passing through the tunnel.
Award [1] for allowing access to internal resources as if the employee were physically connected to the organization’s LAN.

Scroll to Top