Ethical Hacking
Ethical hacking involves understanding the role, tools, and techniques used to test system security with permission. Learners plan, execute, and report on ethical hacking processes to identify vulnerabilities.
Assessment criteria
Topic Overview
The Gateway Qualifications Level 3 Certificate in Networking and Cybersecurity provides a comprehensive foundation in designing, implementing, and securing computer networks. This qualification covers essential networking concepts such as the OSI and TCP/IP models, IP addressing, routing, and switching, alongside cybersecurity principles including threat analysis, encryption, and risk management. Students gain practical skills in configuring network devices, setting up secure connections, and responding to security incidents, preparing them for roles like network technician or cybersecurity analyst.
This topic is critical in today's digital world where networks underpin all online services and cyber threats are ever-present. Understanding how data travels across networks and how to protect it is fundamental for any IT professional. The qualification aligns with industry standards, such as CompTIA Network+ and Security+, and equips students with the knowledge to troubleshoot network issues and implement security measures in real-world environments.
Within the wider subject of Computer Science, networking and cybersecurity bridge the gap between theoretical concepts and practical application. Students learn how protocols enable communication, how addressing schemes work, and how to defend against attacks like phishing, DDoS, and malware. This knowledge is essential for further study in areas like cloud computing, ethical hacking, or network architecture, and directly supports the UK's growing demand for skilled cybersecurity professionals.
Key Concepts
Core ideas you must understand for this topic
- →OSI and TCP/IP Models: Understand the seven layers of the OSI model and the four layers of the TCP/IP model, including the function of each layer and how data encapsulation works.
- →IP Addressing and Subnetting: Master IPv4 and IPv6 addressing, subnet masks, CIDR notation, and how to calculate network addresses, broadcast addresses, and usable host ranges.
- →Routing and Switching: Learn how routers forward packets between networks using routing tables and protocols like OSPF, and how switches use MAC addresses to forward frames within a LAN.
- →Cybersecurity Threats and Countermeasures: Identify common threats (e.g., malware, social engineering, man-in-the-middle attacks) and apply countermeasures such as firewalls, encryption (symmetric/asymmetric), and access control lists.
- →Network Security Devices and Protocols: Understand the role of firewalls, IDS/IPS, VPNs, and protocols like HTTPS, SSL/TLS, and IPsec in securing network communications.
Learning Objectives
What you need to know and understand
- 1. Understand the role of ethical hacking.2. Understand a range of ethical hacking tools and techniques.3. Be able to plan, execute and report on the process of ethical hacking.
- 1. Understand the role of ethical hacking.2. Understand a range of ethical hacking tools and techniques.3. Be able to plan, execute and report on the process of ethical hacking.
Assessment Criteria
Key criteria assessors look for in your portfolio
- Explains the role and legal boundaries of ethical hacking.
- Identifies and describes a range of ethical hacking tools and techniques.
- Plans an ethical hacking test with scope and rules of engagement.
- Executes the test safely and records findings.
- Produces a clear report with vulnerabilities and recommendations.
- Understands the legal and ethical boundaries of ethical hacking.
- Selects appropriate tools for penetration testing.
- Plans and executes a hacking process methodically.
- Reports findings clearly with recommendations.
Assessment Guidance
Guidance for achieving higher grades
- 💡Learn common tools like Nmap, Wireshark, Metasploit.
- 💡Understand the phases: reconnaissance, scanning, exploitation.
- 💡Practice writing professional reports.
- 💡Practise using tools like Nmap and Metasploit in a lab.
- 💡Understand the phases of ethical hacking: reconnaissance, scanning, exploitation, etc.
- 💡Always obtain written permission before testing.
- 💡When answering questions on the OSI model, always specify the layer number and name (e.g., Layer 3 – Network) and describe its function with a real-world example, such as IP routing.
- 💡For subnetting questions, show your working step-by-step: convert IP and subnet mask to binary, identify the network and broadcast addresses, and calculate the number of usable hosts. This demonstrates methodical thinking.
- 💡In cybersecurity questions, use specific terminology like 'confidentiality, integrity, availability' (CIA triad) and link countermeasures to the threat they mitigate. For example, 'Encryption ensures confidentiality by scrambling data so only authorised parties can read it.'
Common Mistakes
Common errors to avoid in your coursework
- Exceeding scope or causing system damage.
- Failing to obtain proper authorisation.
- Reporting findings without prioritising risks.
- Exceeding scope of authorisation.
- Failing to document steps properly.
- Misinterpreting scan results.
- Misconception: The OSI model is just theoretical and not used in practice. Correction: While TCP/IP is the dominant model, the OSI model is crucial for understanding how different protocols interact and for troubleshooting network issues layer by layer.
- Misconception: A firewall alone makes a network secure. Correction: Firewalls are essential but must be part of a defence-in-depth strategy that includes encryption, regular updates, user training, and intrusion detection systems.
- Misconception: Subnetting is only for large networks. Correction: Subnetting improves network efficiency and security in any size network by reducing broadcast traffic and isolating segments.
Frequently Asked Questions
Common questions students ask about this topic
Pass / Merit / Distinction Evidence Checklist
How your portfolio evidence is graded for GATEWAY QUALIFICATIONS LIMITED Ethical Hacking
Demonstrate baseline knowledge, accurate terminology, and core practical application.
Provide detailed analysis, structured explanations, and clear workplace reasoning.
Deliver thorough evaluation, original problem solving, and fully justified recommendations.
Before You Start
Prior knowledge that will help with this topic
- •Basic understanding of computer hardware and software, including how devices communicate over a network.
- •Familiarity with binary and hexadecimal numbering systems, as these are used in IP addressing and MAC addresses.
- •Foundational knowledge of operating systems (e.g., Windows, Linux) and command-line interfaces for network configuration.
Coursework AI Review
Self-check your coursework evidence against P/M/D criteria
Key Terminology
Essential terms to know
- 1. Understand the role of ethical hacking.2. Understand a range of ethical hacking tools and techniques.3. Be able to plan, execute and report on the process of ethical hacking.
- 1. Understand the role of ethical hacking.2. Understand a range of ethical hacking tools and techniques.3. Be able to plan, execute and report on the process of ethical hacking.
Ready to learn?
AI-powered learning tailored to this unit