2029–2031 edition · for exams from June 2029. Students sitting exams up to November 2028 follow the current course.
4. Data integrity and cybersecurity
Detecting and correcting errors (parity, checksum, echo check, check digit, ARQ), the five core principles of cybersecurity, threats from brute force to SQL injection, the defences, and encryption.
What you need to know211 learning objectives, as printed in the syllabus
- 4.1Data integritySame as now2026–2028 syllabus: §2.2
Error detection as now (check digits also on airline tickets and bank account numbers); no check digit or checksum calculations.
Learning objectives (5)
- 4.1.1Describe how errors can occur during data storage, data transmission and data entry
- 4.1.2Describe how methods detect errors and how errors are corrected, including: (a) parity bit (odd and even); (b) parity block check (odd and even); (c) echo check; (d) checksum; (e) check digit
- 4.1.3Calculate a parity bit or parity byte for a given piece of binary data
- 4.1.4Identify examples of when a check digit is used, including: (a) International Standard Book Number (ISBN); (b) bar codes; (c) airline tickets; (d) bank account numbers
- 4.1.5Describe how an automatic repeat reQuest (ARQ) can be used to acknowledge whether data is received without error, including the use of positive and negative acknowledgements
Candidates will not be required to calculate a check digit or checksum
- 4.2CybersecurityChanged2026–2028 syllabus: §5.3, §2.3
Adds the five core principles of cybersecurity, SQL injection, TLS, VPN and automated updates; encryption moves here.
Learning objectives (6)
- 4.2.1State the core principles of cybersecurity as: (a) confidentiality; (b) integrity; (c) authenticity; (d) availability; (e) non-repudiation
- 4.2.2Describe how each of the core principles of cybersecurity can be threatened
- 4.2.3Describe the aims and processes involved in cybersecurity threats, limited to: (a) brute-force attack; (b) data interception; (c) distributed denial of service (DDoS) attack; (d) hacking and unauthorised access; (e) malware (virus, worm, Trojan horse, spyware, adware, ransomware); (f) pharming; (g) phishing; (h) social engineering; (i) structured query language (SQL) injection
- 4.2.4Explain how solutions are used to help keep data safe from cybersecurity threats, limited to: (a) access levels; (b) anti-malware, including anti-virus and anti-spyware; (c) authentication (username and password, biometrics, two-step verification); (d) automating software updates; (e) checking the spelling and tone of communications; (f) checking the URL attached to a link; (g) firewalls; (h) privacy settings; (i) proxy servers; (j) transport layer security (TLS); (k) virtual private network (VPN)
- 4.2.5Describe the purpose of encryption when storing or transmitting data, including: (a) protecting confidentiality; (b) ensuring integrity; (c) supporting authenticity and non-repudiation
- 4.2.6Explain how data is encrypted using symmetric and asymmetric encryption methods
Objectives quoted from the 2029–2031 syllabus, Version 1, September 2026; © Cambridge University Press & Assessment.
Notes2every learning objective explained, with worked examples
4.1Data integrity
Data can be changed by mistake when it is stored, sent or typed in. This section explains how errors happen and the methods used to detect (and sometimes correct) them: parity bits and parity blocks, echo checks, checksums, check digits and ARQ.
How errors occur
- Data transmission: interference (electrical noise) on the cable or wireless link can flip bits; packets can be lost, arrive late or arrive damaged.
- Data storage: storage media can wear out or become damaged (bad sectors, worn flash cells), power cuts during writing can corrupt files.
- Data entry: a person can mistype data, swap two digits (transposition error, 1234 → 1243) or miss a digit out.
Parity bit (odd and even)
One bit of each byte is used as a parity bit (often the leftmost). The sender and receiver agree on even or odd parity.
- Even parity: the total number of 1s in the byte (including the parity bit) must be even.
- Odd parity: the total number of 1s must be odd.
Calculating: data 1011001 has four 1s.
- Even parity → parity bit 0 → byte 01011001 (four 1s, even).
- Odd parity → parity bit 1 → byte 11011001 (five 1s, odd).
The receiver counts the 1s; if the count is wrong for the agreed parity, an error has happened. Limitation: if two bits flip, the count is still correct, so the error is not detected; parity also cannot say which bit is wrong.
def even_parity_byte(data7: str) -> str:
p = data7.count('1') % 2
return str(p) + data7
print(even_parity_byte('1011001')) # 01011001Parity block check and the parity byte
A parity block sends several bytes, each with a parity bit, followed by a parity byte: each bit of the parity byte is the parity of that column. This can find which bit is wrong, so the error can be corrected.
Even parity block sent:
| P | 1 | 2 | 3 | 4 | 5 | 6 | 7 | |
|---|---|---|---|---|---|---|---|---|
| Byte 1 | 0 | 1 | 0 | 1 | 1 | 0 | 0 | 1 |
| Byte 2 | 0 | 0 | 1 | 1 | 0 | 1 | 1 | 0 |
| Byte 3 | 1 | 1 | 1 | 1 | 0 | 0 | 0 | 0 |
| Byte 4 | 1 | 0 | 0 | 0 | 1 | 0 | 1 | 1 |
| Parity byte | 0 | 0 | 0 | 1 | 0 | 1 | 0 | 0 |
Every row and every column has an even number of 1s.
Finding an error: suppose byte 3 arrives as 11010000. Byte 3 now has three 1s (odd) and column 3 has three 1s (odd). The bit where the wrong row and wrong column cross — byte 3, column 3 — is the error; flip it back from 0 to 1.
Echo check
- The sender sends the data.
- The receiver sends the same data back to the sender.
- The sender compares the returned data with the original. If they are different, an error has happened and the data is sent again.
Limitation: it cannot tell whether the error happened on the way there or on the way back, and it doubles the data sent.
Checksum
- Before sending, the sender calculates a value (the checksum) from the data using an agreed algorithm, and sends it with the data (e.g. in the packet trailer).
- The receiver recalculates the checksum from the data it received using the same algorithm.
- If the two checksums do not match, the data has an error and is requested again.
(You will not have to calculate a checksum.)
Check digit
A check digit is an extra digit, calculated from the other digits of a number and added to the end. It detects data entry errors such as a wrong digit or swapped digits.
- The check digit is calculated when the number is created.
- When the number is entered, the computer recalculates the check digit from the other digits.
- If it does not match the entered check digit, the number was entered wrongly and must be re-entered.
Used in: ISBNs (book numbers), bar codes on products, airline ticket numbers and bank account numbers. (You will not have to calculate one.)
Automatic repeat request (ARQ)
- The receiver checks each packet it gets for errors (e.g. with a checksum or parity).
- If it is correct, the receiver sends a positive acknowledgement (ACK) back to the sender.
- If it has an error, the receiver sends a negative acknowledgement (NAK), asking for it to be resent.
- The sender also starts a timer (timeout) when it sends a packet. If no acknowledgement arrives before the timeout, it resends the packet automatically.
- This repeats until the packet is received correctly (or a set number of tries is reached).
Exam tips
- Say whether each method finds errors in transmission (parity, echo, checksum, ARQ) or in data entry (check digit).
- When calculating a parity bit, state your count of 1s so the examiner can see your method.
- For a parity block, explain how the bit is located: the row with wrong parity and the column with wrong parity meet at the error.
- ARQ answers need ACK, NAK (or 'negative acknowledgement'), timeout, and resend.
Mistakes that lose marks
- Saying a parity bit can find which bit is wrong — only a parity block can.
- Saying parity always finds errors — two flipped bits pass unnoticed.
- Confusing a check digit (data entry) with a checksum (transmission).
- Saying in an echo check the receiver compares the data — the sender does.
4.2Cybersecurity
Cybersecurity is about keeping data and systems safe. This section starts with the five core principles (confidentiality, integrity, authenticity, availability, non-repudiation), explains the common threats — from brute force and phishing to SQL injection — and the ways to defend against them, and ends with how symmetric and asymmetric encryption work.
The five core principles and how each is threatened
| Principle | Meaning | Threatened by |
|---|---|---|
| Confidentiality | only authorised people can read the data | data interception, hacking, spyware, phishing |
| Integrity | data is accurate and has not been changed without permission | hackers or malware altering or deleting data, SQL injection, interception and changing data in transit |
| Authenticity | data and users are genuine — who or what they claim to be | phishing and pharming (fake sites), stolen passwords, fake emails pretending to be from someone else |
| Availability | data and systems are there when needed by authorised users | DDoS attacks, ransomware locking files, viruses deleting data |
| Non-repudiation | someone cannot deny they sent a message or did an action | shared or stolen log-ins, unsigned messages, faked records |
Threats (1): brute force, interception, DDoS, hacking
- Brute-force attack — aim: find a password. Process: software tries every possible combination (or a list of common passwords) until one works.
- Data interception — aim: steal data in transit. Process: data travelling over a network is captured (e.g. with a packet sniffer, or on unsecured Wi-Fi) and read.
- Distributed denial of service (DDoS) — aim: stop a website or server working. Process: a huge number of requests are sent from many computers (often a botnet of infected machines) so the server is overwhelmed and real users can't get through.
- Hacking / unauthorised access — aim: get into a system without permission, to steal, change or delete data. Process: exploiting weak passwords or security flaws.
Threats (2): malware
Malware is malicious software.
| Type | What it does |
|---|---|
| Virus | attaches to a file or program and replicates when that file is run; can delete or corrupt data |
| Worm | replicates by itself across a network without needing a user to run it; uses up bandwidth |
| Trojan horse | disguised as legitimate software; once installed it lets other malware in or gives an attacker access |
| Spyware | secretly records what the user does (e.g. key presses) and sends it to a third party — to steal passwords |
| Adware | shows unwanted adverts; may redirect the browser |
| Ransomware | encrypts the user's files and demands payment for the key |
Threats (3): pharming, phishing, social engineering, SQL injection
- Phishing — fake emails or messages that look like they come from a real organisation, with a link to a fake site where the user enters personal details.
- Pharming — malicious code on the user's computer or a DNS server redirects them to a fake website even when they type the correct URL.
- Social engineering — manipulating people (by phone, message or in person, using fear, urgency or trust) into giving away information or access.
- SQL injection — the attacker types SQL code into an input box on a website (e.g. a log-in form). If the site places the input straight into its database query, the attacker's code runs, letting them bypass log-in or read, change or delete data. For example typing
' OR '1'='1as a password can make the condition always true.
The defence is to never build a query by joining the user's text into it; use a parameterised query and validate input:
import sqlite3
db = sqlite3.connect(':memory:')
db.execute('CREATE TABLE Users (Name TEXT, Pw TEXT)')
name, pw = 'ali', "' OR '1'='1"
# safe: the ? placeholders treat the input as data, never as SQL
rows = db.execute('SELECT Name FROM Users WHERE Name = ? AND Pw = ?', (name, pw)).fetchall()
print(rows) # []Solutions (1)
| Solution | How it helps |
|---|---|
| Access levels | users only see and change the data their role needs (e.g. read-only), limiting the damage from mistakes or a stolen account |
| Anti-malware (anti-virus, anti-spyware) | scans files against a database of known threats and for suspicious behaviour; quarantines or deletes malware; must be kept up to date |
| Authentication — username and password | only people who know the password can log in; strong passwords resist brute force |
| Authentication — biometrics | uses a unique body feature (fingerprint, face, iris) that is hard to copy or guess |
| Two-step verification | after the password, a code is sent to (or generated on) a second device; a stolen password alone is not enough |
| Automating software updates | updates fix security flaws as soon as they are released, without relying on the user |
Solutions (2)
| Solution | How it helps |
|---|---|
| Checking the spelling and tone of communications | phishing messages often have errors, generic greetings and urgent or threatening tone — spotting these stops users clicking |
| Checking the URL attached to a link | hovering shows the real address; a misspelt or unexpected domain reveals a fake site |
| Firewall | monitors traffic between the computer/network and the internet, checks it against rules and blocks traffic that is unauthorised or suspicious; can block certain sites or ports |
| Privacy settings | control who can see a user's information on social media and websites |
| Proxy server | sits between the user and the internet; requests go through it, so it hides the user's IP address, can filter traffic and block sites, and can cache pages; absorbs some DDoS traffic |
| Transport layer security (TLS) | a protocol that encrypts data sent between two devices (e.g. browser and web server) and uses digital certificates to authenticate the server; it is what makes HTTPS secure |
| Virtual private network (VPN) | creates an encrypted tunnel across the internet between the user's device and a VPN server, so intercepted data can't be read and the user's real IP address is hidden; lets staff reach a private network securely from home |
The purpose of encryption
Encryption scrambles data (plaintext) into ciphertext using an algorithm and a key, so it can only be read by someone with the right key. It does not stop data being intercepted — it makes intercepted data useless.
- Protecting confidentiality: only the holder of the key can read the data, whether stored or transmitted.
- Ensuring integrity: changing encrypted data without the key produces nonsense when decrypted, so tampering is detected.
- Supporting authenticity and non-repudiation: data encrypted with someone's private key (a digital signature) can only have come from them, so they cannot deny sending it.
Symmetric and asymmetric encryption
Symmetric encryption uses the same key to encrypt and decrypt.
- The sender encrypts the plaintext with the secret key.
- The ciphertext is sent.
- The receiver decrypts it with the same key.
It is fast, but the key itself must be shared — if it is intercepted, all the data can be read.
Asymmetric encryption uses a pair of keys: a public key (anyone may have it) and a private key (kept secret by its owner).
- The receiver sends their public key to the sender.
- The sender encrypts the data with the receiver's public key.
- Only the receiver's private key can decrypt it, so interception of the public key or the data does not help an attacker.
It solves the key-sharing problem but is slower, so in practice (e.g. TLS) asymmetric encryption is used to share a symmetric key safely, then symmetric encryption is used for the rest.
Exam tips
- For a threat, describe the aim AND the process (what the attacker does, step by step).
- For a solution, explain HOW it protects — 'a firewall checks incoming and outgoing traffic against rules and blocks it' beats 'a firewall stops hackers'.
- Phishing = fake email/message with a link; pharming = redirection by malicious code even with the correct URL — keep them apart.
- Asymmetric: encrypt with the RECEIVER's public key, decrypt with the receiver's private key.
- Match the principle to the threat in scenario questions (DDoS threatens availability; interception threatens confidentiality).
Mistakes that lose marks
- Saying encryption stops data being intercepted.
- Saying a virus spreads by itself across networks — that is a worm.
- Writing that the public key decrypts the message in asymmetric encryption.
- Calling a proxy server a firewall, or saying a VPN makes a user completely anonymous.
- Saying TLS is a piece of hardware — it is a protocol.
Infographics5download any diagram as PNG or SVG
Error detection methods
Cyber threats vs defences
Asymmetric encryption & digital signatures
Digital certificates & the TLS handshake
Five core principles of cybersecurity
Python for this topic1Python 3.10+, the only language on Paper 2 — runs in your browser
Key terms17use these exact words in the exam
Test yourself
Check you know the 2029–2031 content
Written for the new syllabus only: every card and question traces to a learning objective above. Rounds are random, and marks earn XP on your dashboard.
3 decks · 49 cards · 18 quiz questions.
From the current course
Most of this topic is taught in the 2026–2028 course today. Its notes and past-paper questions still help — skip anything the 2029–2031 syllabus removed (see the notes above).
- 2. Data Transmission2026–2028 topic · 110 past-paper questions
- 5. The Internet and Its Uses2026–2028 topic · 138 past-paper questions

