CompTIA Security+

    CITY & GUILDS LIMITED
    Vocational

    This unit covers CompTIA Security+ concepts, including general security, communication security, infrastructure security, cryptography, and operational security. Learners will understand foundational cybersecurity principles.

    1
    Learning Outcomes
    3
    Assessment Guidance
    3
    Key Skills
    1
    Key Terms
    4
    Assessment Criteria

    Assessment criteria

    City & Guilds Level 4 Diploma For ICT Professionals (Systems and Principles)

    Topic Overview

    The City & Guilds Level 4 Diploma For ICT Professionals (Systems and Principles) is a comprehensive vocational qualification designed to equip students with the advanced knowledge and practical skills required for a successful career in ICT. This diploma covers a wide range of topics, including systems analysis, database design, network infrastructure, cybersecurity, and project management. It is structured to bridge the gap between foundational ICT concepts and the complex, real-world demands of the industry, making it ideal for those aspiring to roles such as IT support specialist, network administrator, or systems analyst.

    The qualification is divided into mandatory and optional units, allowing students to tailor their learning to specific career paths. Mandatory units typically include principles of ICT systems, communication technologies, and professional practice, while optional units may cover areas like web development, software design, or IT security. Assessment is through a combination of written exams, practical assignments, and projects, ensuring that students can demonstrate both theoretical understanding and hands-on competence. This diploma is recognised by employers and higher education institutions, providing a solid foundation for further study or direct entry into the workforce.

    In the wider context of ICT, this diploma addresses the growing need for professionals who can manage complex systems, ensure data security, and implement effective solutions. It emphasises critical thinking, problem-solving, and ethical considerations, preparing students to adapt to rapidly evolving technologies. By completing this qualification, students gain a competitive edge in the job market and a deep appreciation for how ICT systems underpin modern business and society.

    Key Concepts

    Core ideas you must understand for this topic

    • Systems Development Life Cycle (SDLC): Understand the phases—planning, analysis, design, implementation, testing, and maintenance—and how they apply to real-world projects.
    • Network Topologies and Protocols: Master the differences between star, mesh, and bus topologies, and key protocols like TCP/IP, HTTP, and DNS.
    • Database Normalisation: Learn the principles of normalisation (1NF, 2NF, 3NF) to reduce data redundancy and improve integrity.
    • Cybersecurity Principles: Grasp concepts like confidentiality, integrity, availability (CIA triad), and common threats such as malware and phishing.
    • Project Management Methodologies: Compare Waterfall and Agile approaches, and understand how to plan, execute, and monitor ICT projects.

    Learning Objectives

    What you need to know and understand

    • Understand general security concepts, Recognise and understand communication security, Understand and differentiate infrastructure security, Understand and apply the basics of cryptography, Understand and apply the basics of cryptography, Understand operational & organisational security

    Assessment Criteria

    Key criteria assessors look for in your portfolio

    • Identify common security threats and vulnerabilities.
    • Explain network security components and protocols.
    • Differentiate between types of cryptography and their uses.
    • Apply operational security measures such as policies and procedures.

    Assessment Guidance

    Guidance for achieving higher grades

    • 💡Memorise common port numbers and their associated services.
    • 💡Understand the CIA triad (Confidentiality, Integrity, Availability).
    • 💡Practice with sample questions to familiarise with exam format.
    • 💡When answering questions on the SDLC, always relate each phase to a specific example (e.g., a booking system) to demonstrate practical understanding.
    • 💡For network questions, draw diagrams to illustrate topologies or data flow—this can earn you marks for clarity and accuracy.
    • 💡In project management questions, explicitly compare methodologies (e.g., Waterfall vs. Agile) and justify which is better for a given scenario.

    Common Mistakes

    Common errors to avoid in your coursework

    • Confusing symmetric and asymmetric encryption.
    • Overlooking physical security controls.
    • Misunderstanding the difference between identification and authentication.
    • Misconception: The SDLC must always be followed sequentially. Correction: While the SDLC is often presented as linear, in practice, iterative models like Agile allow for revisiting phases based on feedback.
    • Misconception: Normalisation always improves database performance. Correction: Over-normalisation can lead to complex queries and slower performance; sometimes denormalisation is used for read-heavy systems.
    • Misconception: Cybersecurity is solely the IT department's responsibility. Correction: Effective security requires a culture of awareness across the entire organisation, including user training and policies.

    Frequently Asked Questions

    Common questions students ask about this topic

    Pass / Merit / Distinction Evidence Checklist

    How your portfolio evidence is graded for CITY & GUILDS LIMITED CompTIA Security+

    Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.

    Pass (P)

    Demonstrate baseline knowledge, accurate terminology, and core practical application.

    Merit (M)

    Provide detailed analysis, structured explanations, and clear workplace reasoning.

    Distinction (D)

    Deliver thorough evaluation, original problem solving, and fully justified recommendations.

    Before You Start

    Prior knowledge that will help with this topic

    • Basic understanding of computer hardware and software components.
    • Familiarity with fundamental networking concepts (e.g., IP addresses, routers).
    • Introductory knowledge of databases and SQL.

    Coursework AI Review

    Paste your assignment brief and check your draft against its P/M/D criteria

    Key Terminology

    Essential terms to know

    • Understand general security concepts, Recognise and understand communication security, Understand and differentiate infrastructure security, Understand and apply the basics of cryptography, Understand and apply the basics of cryptography, Understand operational & organisational security

    Ready to learn?

    AI-powered learning tailored to this unit