Class 9Computer ScienceFull chapter

Cyber Safety

Every mark in this chapter comes from definitions and distinctions — virus versus worm, antivirus versus firewall, what a padlock does and does not prove. Learn the terms precisely and the answers write themselves.

Safe Browsing, Secure Sites and Cookies

Quick answer What cyber safety means, how to check that a website is genuinely secure, and how cookies help you but also track you.

Cyber safety (also called online safety) means using the Internet in a way that keeps your device, your data and your identity safe from theft, damage and misuse. It is not one setting you switch on; it is a set of daily habits. The first of those habits is safe browsing — being careful about which websites you open, what you download and what you type into a page.

Every page you visit has an address called a URL (Uniform Resource Locator), for example https://www.irctc.co.in. Read a URL from the left: first the protocol, then the domain name, then the path. The protocol http stands for HyperText Transfer Protocol. Plain HTTP sends your data as ordinary readable text, so anyone monitoring the network in between can read what you type. https stands for HyperText Transfer Protocol Secure: the data is encrypted (converted into an unreadable form) before it travels, using a security certificate issued to that site. Most browsers show a small padlock beside such an address; some recent browser versions have replaced the padlock with a different site-information icon, so the dependable rule is that a secure page never carries a Not secure warning.

A common question asks for two or three checks that a site is safe. Give these: the address begins with https:// and the browser shows a padlock or site-information icon rather than a Not secure warning; the domain name is spelled exactly right, because fake sites use lookalike spellings such as 1rctc.co.in or irctc-tickets.example; the site carries a proper contact address, privacy policy and refund policy; and the browser shows no certificate warning. Then state the limit, which completes the answer: a padlock proves only that the connection is encrypted, it does not prove that the owner is honest. A criminal can also obtain a certificate for a fake site, so the domain name must still be read character by character.

Other safe-browsing habits are worth listing in a long answer. Download software only from the official website or an official app store. Never install pirated or cracked software, which is one of the commonest carriers of malware. Keep the browser and the OS (Operating System) updated, because updates close known security holes. Do not click pop-ups that claim your device is infected or that you have won a prize. Avoid banking or shopping on free public Wi-Fi. Log out of accounts on shared or school computers instead of simply closing the tab.

A cookie is a small text file that a website asks your browser to store on your computer, holding information such as a login token, your language choice or the items in your shopping cart. A session cookie is deleted the moment you close the browser; a persistent cookie stays on the disk for a fixed period. A first-party cookie belongs to the site you are actually visiting; a third-party cookie belongs to some other company — usually an advertising network — whose content is embedded inside that page.

Cookies are genuinely useful: they keep you signed in, remember your settings and let a shopping cart survive while you browse. The risk is tracking. Third-party cookies and similar techniques let advertisers build a profile of the sites you visit, which is why a product you looked at once follows you around as an advertisement for days. You can control this. Clear cookies from the browser's settings, block third-party cookies, refuse non-essential cookies on the consent banner, and use private browsing (incognito) mode when you must. Be accurate about incognito mode in an answer: it stops the browser on that device from saving history, cookies and form data; it does not hide your activity from the website itself, from your school or office network, or from your Internet Service Provider.

HTTP HyperText Transfer Protocol protocol · Data travels as plain text — unsafe for passwords or payments.
HTTPS HyperText Transfer Protocol Secure protocol · Encrypted using a site certificate; shown by the padlock icon.
URL protocol :// domain / path address · Uniform Resource Locator — judge the domain, not the pretty path.
Cookie types session or persistent; first-party or third-party text file · Third-party persistent cookies do the advertisement tracking.
Secure-site check https + padlock + exact domain + policy pages checklist · A complete answer to 'how do you identify a secure site'.
Remember
  • Cyber safety is the set of habits and tools that protect your device, data and identity online.
  • HTTPS encrypts data in transit; plain HTTP does not, so never type a password on an HTTP page.
  • A padlock proves encryption, not honesty — always read the domain name letter by letter.
  • A cookie is a small text file stored by the browser; session cookies vanish on close, persistent cookies remain.
  • Third-party cookies are the ones used for advertisement tracking; block or clear them regularly.
  • Incognito mode hides history from the device only, not from the website, the network or the ISP.

Strong Passwords and Two-Factor Authentication

Quick answer How to build a password that resists guessing, the attacks used against passwords, and why a second factor such as an OTP matters.

Authentication is the process of proving that you are the person you claim to be. On most websites the only proof offered is a password, so the strength of that one string decides the safety of everything inside the account — e-mail, marks, photographs and money.

A strong password is long, mixed, meaningless and unique. Long: at least 8 characters for a school answer, and 12 or more in practice, because every extra character multiplies the number of combinations an attacker must try. Mixed: it should combine uppercase letters, lowercase letters, digits and special characters such as @ # $ %. Meaningless: it must not be a dictionary word or a personal detail — not your name, your school name, your date of birth, your admission or roll number, your mobile number, and certainly not 123456 or password. Unique: a different password for every important account, so that one leaked site does not open all the others.

A convenient method is a passphrase. Take a sentence only you would remember — My uncle bought 3 mangoes in Delhi! — and keep the first letters with the digits and punctuation, giving Mub3miD!. It is easy for you to rebuild and hard for a machine to guess. Learn the method, not this example — a password printed in a book, in notes or on a website has already been published, so always build your own sentence. A password manager is an application that generates and stores a different strong password for every site, all locked behind one master password.

Name these attacks when a question asks why weak passwords are dangerous:

  • Brute-force attack — software tries every possible combination of characters until one works; length is the best defence.
  • Dictionary attack — the software first tries lists of common words, names and previously leaked passwords.
  • Shoulder surfing — someone simply watches you type, in a lab, a cyber cafe or a bus.
  • Keylogger — spyware that silently records every key you press and sends it to an attacker.
  • Social engineering — the attacker talks you into revealing the password, for example by claiming to call from the school IT department.

Because passwords do leak, serious sites add two-factor authentication (2FA), also called two-step verification. Logging in then needs two different kinds of proof drawn from three categories: something you know (password, PIN), something you have (a mobile phone that receives a code, an authenticator app, a hardware security key) and something you are (fingerprint, face or iris — collectively called biometrics). The familiar Indian example is the OTP (One-Time Password) sent to the registered mobile number after you enter your password, valid only for a few minutes and only once.

State the benefit precisely: even if a thief steals or correctly guesses your password, he still cannot log in, because he does not have your phone or your fingerprint. Codes from an authenticator app or a hardware key are considered stronger than SMS OTPs, since a SIM can be cloned or a number fraudulently transferred.

Everyday password discipline: never write passwords at the back of a notebook or on a slip near the computer; never share them with friends, not even for a minute; do not tick Remember password on a shared or school machine; log out fully; lock your phone with a PIN, pattern or biometric and set a short auto-lock time; and change a password at once if a site announces a data breach or if you have typed it on a page you now suspect. Above all, remember the rule that prevents most frauds in India: no bank, wallet, UPI app, telecom company or government office ever asks for your password, PIN, CVV or OTP — not by call, not by SMS, not by message. Anyone who asks is a fraudster.

2FA factors know + have + are (any two) factors · Password + OTP is the standard school example.
OTP One-Time Password code · Single use, short validity, sent to the registered mobile or app.
Strong password 8+ chars, upper + lower + digit + symbol, not personal characters · A safe school-level definition; say 'unique per account' as well.
Biometrics fingerprint / face / iris something you are · Cannot be forgotten, but cannot be changed once copied.
Brute force vs dictionary all combinations vs common word list attack type · A frequently asked distinction — learn both halves.
Remember
  • A strong password is long, mixes four character types, avoids personal or dictionary words and is unique per account.
  • A passphrase built from a sentence gives strength without being hard to remember.
  • Brute force tries every combination; a dictionary attack tries common words and leaked passwords first.
  • 2FA needs two of: something you know, something you have, something you are.
  • An OTP is single-use and short-lived, and must never be shared with anyone, including callers claiming to be from a bank.
  • Never save passwords on shared computers, and change a password immediately after any suspected breach.

Identity Protection and Privacy Settings

Quick answer What counts as personal information, how identity theft happens, and the privacy and permission settings a student should change.

Personal information is any data that can identify you: your full name, photograph, home address, school name, mobile number, e-mail address, date of birth, and identity numbers such as an Aadhaar number, a PAN or a bank account number. A part of it is treated as sensitive personal information — passwords, financial details, health records and biometrics — and needs the strongest protection of all.

Identity theft is the crime of stealing someone's personal information and using it to pretend to be that person. In India the usual patterns are easy to describe in an answer: a photograph or photocopy of an identity document being misused to obtain a SIM card or a loan; card and bank details used to make purchases; or a fake social-media profile created in a student's name and used to insult classmates. The victim often does not find out for months, and undoing the damage takes far longer than preventing it would have.

A related term is digital footprint — the trail of data you leave behind online. It is active when you deliberately post something (a comment, a photograph, a review) and passive when it is collected without any action by you (your IP address, the pages you visit, your location). The footprint is close to permanent: a post you delete may already have been screenshotted, downloaded or archived by someone else. Before posting, apply a simple test — would you be comfortable if this were read by your parents, your principal and a future employer?

What should never be shared online, especially with people you have not met in person:

  • Passwords, PINs, OTPs, card CVV numbers and UPI PINs — with anyone at all, including friends.
  • Photographs of identity cards, mark sheets, bank passbooks, cheques, tickets or boarding passes, which carry numbers and barcodes.
  • Your home address, your school name with class and section, and your daily timings together — combined, they tell a stranger exactly where to find you.
  • Your live location, or holiday plans that announce the house is empty.
  • Photographs of other people, especially classmates, without asking them first.

Privacy settings are the controls a platform gives you to decide who sees what. A complete answer lists them: set the account to private so that only approved contacts see your posts; restrict who may send friend or follow requests; restrict who can comment on or tag you, and switch on tag review; turn off location tagging in photographs; hide your date of birth, phone number and e-mail from the public profile; and review the list of connected apps and logged-in devices, removing anything you no longer use. Add this important point: default settings differ from platform to platform and are often more open than a student expects (a few platforms now make new teenage accounts private by default), so privacy must never be assumed — it has to be checked and set deliberately by the user.

App permissions deserve the same care. When an application asks for access to the camera, microphone, contacts, photographs, SMS or location, grant only what it genuinely needs to work — a torch app has no reason to read your contacts, and a game has no reason to read your messages. Prefer only while using the app over always, check permissions again after updates, install only from the official store, and read the ratings and the permission list before installing.

Two legal points are worth a line in a long answer. India's Information Technology Act, 2000 makes offences such as identity theft, cheating by impersonation and violation of privacy punishable by law. The Digital Personal Data Protection Act, 2023 requires organisations to take your consent before collecting and using your personal data and gives you the right to know what is held about you and to have it corrected or erased; for a child, that consent must come from a parent or guardian.

Personal vs sensitive name, address, DOB vs password, bank, health, biometric data class · Sensitive personal data attracts the highest protection.
Digital footprint active (posted) + passive (collected) data trail · IP address and browsing history are passive examples.
Identity theft stolen personal data + impersonation offence · Punishable under the Information Technology Act, 2000.
Permission rule grant the least access an app needs principle · Prefer 'only while using the app' to 'always'.
Consent law Digital Personal Data Protection Act, 2023 law · A child's data needs verifiable parental consent.
Remember
  • Personal information identifies you; sensitive personal information (passwords, financial, health, biometric) needs the most protection.
  • Identity theft is using someone else's personal data to impersonate them — for a SIM, a loan, a purchase or a fake profile.
  • A digital footprint is active (what you post) plus passive (what is collected silently), and it is effectively permanent.
  • Never post images of ID cards, tickets or passbooks, and never combine address, school and timings publicly.
  • Never assume privacy defaults are safe — check them, set the account to private and restrict tags, comments and location tagging yourself.
  • Grant apps only the permissions they truly need, and review them after every update.

Malware, Antivirus Software and Firewalls

Quick answer The six malware types CBSE asks about, exactly how each one spreads, and the difference between an antivirus and a firewall.

Malware — short for malicious software — is any program written to damage a computer, steal data or take control of a system without the owner's permission. Questions almost always ask you to name the types and say how each behaves or spreads, so learn them as a table in your head.

Virus: a piece of code that attaches itself to a file or program (its host) and runs only when that file is opened, then copies itself into other files. It cannot spread on its own — a user must open the infected file. Viruses travel through infected e-mail attachments, pen drives and downloaded software, and can corrupt or delete data.

Worm: a standalone program that copies itself and spreads by itself across a network, without needing a host file and without any action by the user. Worms exploit weaknesses in software and can slow an entire network by consuming bandwidth and memory. The virus-versus-worm distinction — host needed and user action needed, or not — is a very common short-answer question.

Trojan horse: a program that pretends to be something useful — a free game, a cracked application, a PDF converter — but performs a harmful action once installed. A Trojan does not replicate itself; it relies entirely on the user being tricked into installing it, and it often opens a backdoor that lets an attacker control the machine remotely.

Ransomware: malware that encrypts the victim's files, or locks the whole system, and then displays a message demanding a ransom in exchange for the key. It usually arrives through a phishing attachment or link, or through software that has not been updated. Paying does not guarantee that the files come back, so the real defence is regular backups kept on a separate drive or in cloud storage that is not permanently connected.

Spyware: software that hides on the system and secretly collects information — browsing history, files, screenshots — and sends it to an attacker. A keylogger is a type of spyware that records every keystroke, which is how passwords and card numbers are stolen. Spyware is frequently bundled with free downloads.

Adware: software that displays unwanted advertisements, opens pop-up windows or changes the browser home page and default search engine. It is usually more irritating than destructive, but it slows the machine and some adware also tracks the user.

Signs of infection worth listing: the computer becomes unusually slow; programs crash or start on their own; unknown files or icons appear; files go missing or refuse to open; the browser home page changes by itself; advertisement windows keep opening; or the hard disk stays busy when nothing is running.

Antivirus software is a program that detects, prevents and removes malware. It compares files against a database of known malware patterns called virus definitions (signature-based detection) and also watches for suspicious behaviour. It offers on-demand scans (quick or full), real-time or on-access scanning as files are opened, and it moves suspected files to quarantine — an isolated area — before repairing or deleting them. State the rule the examiner wants: antivirus software is of little use unless its definitions are updated regularly, because new malware appears every day.

A firewall is hardware, software, or a combination of both, placed between a computer or network and the outside world, which filters incoming and outgoing traffic according to a set of rules and blocks unauthorised access. Keep the difference sharp: a firewall controls traffic and stops intruders and unauthorised programs from communicating; antivirus software detects and removes malicious files that are already on the system. Neither one replaces the other.

Complete protection therefore means installing antivirus software and keeping it updated, leaving the firewall switched on, installing operating-system and application updates promptly, scanning pen drives before opening them and disabling autorun, refusing pirated software, never opening unexpected attachments, and taking regular backups.

Virus vs worm host + user action vs standalone + self-spreading malware · Keep both halves of this contrast ready — it is asked very often.
Trojan disguised program, no self-replication malware · Often installs a backdoor for remote control.
Ransomware encrypt files then demand ransom malware · Defence = regular backups on a disconnected drive.
Antivirus detect + quarantine + remove malware software · Needs updated virus definitions to be effective.
Firewall filter incoming and outgoing traffic by rules hardware/software · Blocks unauthorised access; does not clean infected files.
Remember
  • Malware is any software written to damage, steal or take control without the owner's permission.
  • Virus needs a host file and user action; a worm is standalone and spreads across a network by itself.
  • A Trojan disguises itself as useful software, does not self-replicate, and often opens a backdoor.
  • Ransomware encrypts files and demands payment — regular offline backups are the real defence.
  • Spyware secretly collects data (a keylogger records keystrokes); adware forces unwanted advertisements.
  • Antivirus removes malicious files; a firewall filters network traffic — state both when asked to differentiate.

Phishing, Scams and Safe Online Transactions

Quick answer How to recognise a phishing message on sight, what to do about it, and the rules that keep an online payment safe.

Phishing is an attempt to obtain personal information — usernames, passwords, OTPs, card or account details — by sending a message that pretends to come from a trustworthy organisation such as a bank, a delivery company, a school or a government department. The name comes from fishing: the attacker puts out bait and waits for someone to bite. Phishing carried out by telephone call is called vishing (voice phishing) and by SMS it is called smishing. When a message is customised for one particular person using details picked up from social media, it is called spear phishing.

Learn the warning signs as a list, because How will you recognise a phishing message? is a standard long-answer question:

  • Urgency or threat — your account will be blocked within 24 hours, immediate KYC update required, your parcel could not be delivered.
  • A reward that is too good to be true — a lottery you never entered, a free recharge, a job offer that first asks for a registration fee.
  • Generic greetingDear Customer or Dear User instead of your name.
  • Wrong sender address or lookalike link — a bank message sent from a free e-mail address, or a link whose real destination (seen by hovering over it on a computer, or long-pressing on a phone) does not match the text displayed.
  • Spelling and grammar mistakes, poor formatting, or a stretched and outdated logo.
  • It asks for secrets — password, PIN, CVV or OTP — or asks you to install a screen-sharing or remote-support application.
  • An unexpected attachment or a shortened link that hides the real address.

What to do: do not click, do not reply, and do not download the attachment. If you think the message might be genuine, verify it independently — type the official website address yourself, or open the official app, or ring the number printed on your passbook or on the back of your card, never the number given in the message itself. Then mark the message as spam or phishing and delete it. If money has already gone, report immediately on the national cybercrime reporting portal cybercrime.gov.in or on the helpline number 1930 and inform the bank at once, because early reporting improves the chance of the transaction being held.

Safe online transactions. Buy from well-known sellers, and read the return, refund and delivery policies before paying. Confirm that the payment page uses https and that the domain is spelled correctly. Pay through a trusted route — a UPI (Unified Payments Interface) application, net banking or a card — and enter your UPI PIN only inside the UPI application itself, never on a web page and never to a person on a call.

One rule prevents most UPI frauds in India, and it is worth stating in bold in an answer: a UPI PIN is needed only to send money, never to receive it. If a so-called buyer sends you a collect request or a QR code and tells you to enter your PIN in order to receive payment, it is a fraud — scanning that code and entering the PIN takes money out of your account. In the same way, never share an OTP that arrives for a payment you did not start; the OTP is the bank asking you to confirm, not a code to be read out to anyone.

Other sensible habits: do not save card details on unfamiliar sites; for a first purchase from a new site prefer cash on delivery, or a card with a low limit; avoid making payments on public Wi-Fi; switch on SMS and e-mail alerts for your account and actually read them; keep the order confirmation and the transaction reference number until the item arrives; log out after paying; and check your bank statement regularly. A public or shared computer should not be used for banking at all — and if it must be, log out completely and clear the browsing data afterwards.

Phishing fake trusted message → steals credentials attack · Vishing = by phone call; smishing = by SMS; spear phishing = targeted.
Recognition signs urgency + generic greeting + odd link + asks for OTP checklist · Any four of these together make a complete answer.
UPI PIN rule PIN to send, never to receive rule · Explains QR-code and collect-request frauds.
Report cyber fraud cybercrime.gov.in or helpline 1930 channel · Report the same day and inform the bank.
Safe payment page https + padlock + correct domain + known seller checklist · Check before entering any card or UPI detail.
Remember
  • Phishing tricks a user into revealing secrets through a message that imitates a trusted organisation; by call it is vishing, by SMS smishing.
  • Typical signs: urgency, generic greeting, lookalike link, spelling mistakes, unexpected attachment, and any request for OTP, PIN or CVV.
  • Never verify through the message — type the official address yourself or call the number on your passbook or card.
  • Report cyber fraud on cybercrime.gov.in or helpline 1930 and inform the bank immediately.
  • A UPI PIN is required only to send money, never to receive it — a PIN request to 'receive' payment is always fraud.
  • For safe payments: https page, known seller, no saved cards on new sites, alerts on, log out, check statements.

Social Media Safety, Cyberbullying and Netiquette

Quick answer Rules for communicating safely on social media, the forms cyberbullying takes, and the exact steps a victim or a witness should follow.

Social media is where most students meet the risks of the Internet, so the safe-use rules are worth memorising. Keep the account private. Accept requests only from people you actually know, because a friendly stranger may be an adult using a borrowed photograph. Keep personal details out of your bio and out of your username. Do not post your school timetable, your live location or your travel plans. Ask a friend before posting a photograph of them. Never agree to meet an online-only contact alone — tell a parent, and meet in a public place if at all. Be equally careful about forwarding: an unverified message on a messaging app spreads misinformation, and forwarding it makes you part of the problem, so check a claim on a reliable news site before passing it on.

Cyberbullying is the use of digital technology — messages, calls, social media, gaming platforms — to repeatedly harass, threaten, humiliate or target another person. Unlike bullying in a school corridor, it follows the victim home, it can be anonymous, and the material can be copied endlessly. Its common forms are:

  • Harassment — repeated abusive or threatening messages.
  • Trolling and flaming — deliberately insulting comments meant to provoke an angry public argument.
  • Impersonation — creating a fake profile in someone's name and posting as that person.
  • Outing and doxxing — publishing someone's private information, photographs or address without consent.
  • Exclusion — deliberately leaving a person out of a group chat or an online game to make them feel isolated.
  • Cyberstalking — persistent monitoring and contact that makes the victim fear for their safety.
  • Morphing — editing someone's photograph and circulating it to embarrass them.

The effects are real and should be mentioned in a long answer: fear, anxiety, loss of sleep and appetite, falling marks, avoiding school, and withdrawal from friends. A student who suddenly stops using a phone, or who becomes upset after using it, may well be a victim.

What to do if you are cyberbullied — learn it as five clear steps. Do not reply and do not retaliate, because a reaction is exactly what the bully wants and an angry reply can make you look equally guilty. Save the evidence: take screenshots showing the message, the profile name, the date and the time, and note the link. Block and report the account using the platform's own report option. Tell a trusted adult — a parent, your class teacher or the school counsellor; schools are expected to act on such complaints. Report to the authorities when it involves threats, obscene content, morphed images or a fake profile: a complaint can be filed on cybercrime.gov.in or on helpline 1930, and the Information Technology Act, 2000 makes such offences punishable.

If you are a witness rather than a victim, do not be a silent bystander. Do not like, share or forward the content — forwarding multiplies the harm and may itself be an offence. Message the victim privately to support them, report the post, and tell a teacher.

Netiquette (network etiquette) is the set of good manners expected of everyone online: be respectful and use polite language; do not type in capital letters, which reads as shouting; do not spam groups with forwards; respect other people's privacy and their time; give credit and never copy someone's work, images or code without permission, because plagiarism is a serious academic and ethical wrong and copying protected material is a violation of copyright law; and re-read a message before sending it, since tone is easily misread in plain text. Together with a sensible limit on screen time and regular breaks, these habits are what make a responsible digital citizen — the term used for a person who uses technology safely, ethically and respectfully.

Cyberbullying digital technology + repeated harassment of a person offence · Anonymity and permanence make it worse than face-to-face bullying.
Victim's five steps don't reply → save evidence → block & report → tell an adult → report to authorities procedure · The standard sequence to write in an answer.
Report channel cybercrime.gov.in / helpline 1930 channel · Also inform the school and, for serious cases, the police.
Netiquette network etiquette term · No ALL CAPS, no spam, no plagiarism, respect privacy.
Digital citizen safe + ethical + respectful use of technology term · Includes managing screen time and verifying before forwarding.
Remember
  • Keep social accounts private, accept only known contacts, and never post timetable, live location or travel plans.
  • Cyberbullying is repeated harassment using digital technology; it is anonymous, permanent and follows the victim home.
  • Its forms include harassment, trolling, impersonation, doxxing, exclusion, cyberstalking and morphing.
  • Response: do not reply, save evidence with screenshots, block and report, tell a trusted adult, report on cybercrime.gov.in or 1930.
  • A witness must not forward or like the content — forwarding multiplies the harm and can itself be an offence.
  • Netiquette means polite language, no shouting in capitals, no spam, no plagiarism and respect for privacy.

Quick reference

Every term, tag and rule from this chapter in one place — screenshot it before your exam.

HyperText Transfer Protocol
HTTPprotocol
HyperText Transfer Protocol Secure
HTTPSprotocol
protocol :// domain / path
URLaddress
session or persistent; first-party or third-party
Cookie typestext file
https + padlock + exact domain + policy pages
Secure-site checkchecklist
know + have + are (any two)
2FA factorsfactors
One-Time Password
OTPcode
8+ chars, upper + lower + digit + symbol, not personal
Strong passwordcharacters
fingerprint / face / iris
Biometricssomething you are
all combinations vs common word list
Brute force vs dictionaryattack type
name, address, DOB vs password, bank, health, biometric
Personal vs sensitivedata class
active (posted) + passive (collected)
Digital footprintdata trail
stolen personal data + impersonation
Identity theftoffence
grant the least access an app needs
Permission ruleprinciple
Digital Personal Data Protection Act, 2023
Consent lawlaw
host + user action vs standalone + self-spreading
Virus vs wormmalware
disguised program, no self-replication
Trojanmalware
encrypt files then demand ransom
Ransomwaremalware
detect + quarantine + remove malware
Antivirussoftware
filter incoming and outgoing traffic by rules
Firewallhardware/software
fake trusted message → steals credentials
Phishingattack
urgency + generic greeting + odd link + asks for OTP
Recognition signschecklist
PIN to send, never to receive
UPI PIN rulerule
cybercrime.gov.in or helpline 1930
Report cyber fraudchannel
https + padlock + correct domain + known seller
Safe payment pagechecklist
digital technology + repeated harassment of a person
Cyberbullyingoffence
don't reply → save evidence → block & report → tell an adult → report to authorities
Victim's five stepsprocedure
cybercrime.gov.in / helpline 1930
Report channelchannel
network etiquette
Netiquetteterm
safe + ethical + respectful use of technology
Digital citizenterm

Test yourself

Tap an answer to check it instantly — you'll see why it's right, and what to revise if it isn't.

0 correct · 0/12 answered
Q1 Secure sites easy

Which of these best shows that your connection to a website is secure?

Q2 Cookies easy

A cookie is best defined as:

Q3 Malware medium

Which malware can copy itself and spread across a network without any action by the user?

Q4 Malware medium

A free game downloaded from an unknown site installs correctly but secretly gives an attacker remote control of the computer. This is an example of:

Q5 Ransomware medium

The most reliable protection against ransomware is:

Q6 Firewall vs antivirus hard

Which statement correctly distinguishes a firewall from antivirus software?

Q7 Two-factor authentication hard

Which pair is a genuine example of two-factor authentication?

Q8 Passwords easy

Which of the following is the strongest password?

Q9 Phishing easy

Which of these is a clear sign of a phishing message?

Q10 Safe transactions medium

When is a UPI PIN required?

Q11 Cyberbullying easy

A student receives repeated insulting messages from an unknown account. What should be done first?

Q12 Spyware hard

Software that secretly records every key you press and sends it to an attacker is called:

NCERT solutions & previous-year questions

Step-by-step model answers — tap a question to reveal the full solution.

NCERT questions 8

1 What is cyber safety? Why is it important for a school student?Introduction

Cyber safety is the practice of using the Internet and digital devices in a way that protects one's device, data and identity from theft, damage and misuse. It is a combination of safe habits (checking a website before typing a password, not sharing an OTP) and safety tools (antivirus software, firewalls, privacy settings).

It matters to a school student because a student's accounts hold personal photographs, marks, contact details and often a parent's payment methods. Careless use can lead to a stolen account, identity theft, loss of money, exposure to strangers, or cyberbullying. Because a digital footprint is close to permanent, a single careless post can affect admissions or employment years later.

2 Differentiate between a virus, a worm and a Trojan horse.Malware

Virus: a malicious code that attaches itself to a host file or program. It runs and spreads only when the user opens that file, and it corrupts or deletes data. It travels through infected attachments, pen drives and downloads.

Worm: a standalone malicious program that copies itself and spreads across a network on its own, without a host file and without any user action. It consumes bandwidth and memory and can slow an entire network.

Trojan horse: a program disguised as useful software, such as a free game or a cracked application. It does not replicate itself; it depends on the user installing it, and it usually opens a backdoor through which an attacker can control the computer remotely.

The key contrast: a virus needs a host and a user action, a worm needs neither, and a Trojan needs a user action but never replicates.

3 What is phishing? State four ways in which a phishing message can be recognised.Phishing

Phishing is an attempt to steal personal information such as passwords, OTPs and card details by sending a message that pretends to come from a trusted organisation like a bank or a government office. Done by telephone it is called vishing; done by SMS it is called smishing.

It can be recognised by:

  1. Urgency or a threat, such as a claim that the account will be blocked within 24 hours.
  2. A generic greeting like Dear Customer instead of your name, often with spelling and grammar mistakes.
  3. A wrong or lookalike sender address or link — the visible text and the real destination of the link do not match.
  4. A request for secrets — password, PIN, CVV or OTP — or an offer that is too good to be true, such as a lottery you never entered.

The correct response is not to click or reply, to verify by typing the official address or calling the number printed on the passbook or card, and then to report and delete the message.

4 What is a cookie? Give one advantage and one disadvantage of cookies.Cookies

A cookie is a small text file that a website asks the browser to store on the user's computer. It holds information such as a login token, a language preference or the contents of a shopping cart. A session cookie is deleted when the browser is closed, while a persistent cookie remains for a fixed period.

Advantage: cookies remember the user, so one need not log in or re-enter settings on every visit, and a shopping cart survives while the user browses other pages.

Disadvantage: third-party cookies allow advertisers to track which sites a user visits and to build a profile of their interests, which is a loss of privacy. Cookies stored on a shared computer can also let another person enter an account that was left logged in.

5 What is meant by a strong password? List the rules for creating and using one.Passwords

A strong password is one that cannot easily be guessed by a person or discovered by software. It is long, uses several types of character, carries no personal meaning and is not used anywhere else.

  • Use at least 8 characters, and preferably 12 or more.
  • Mix uppercase letters, lowercase letters, digits and special characters such as @ # $ %.
  • Avoid dictionary words and personal details — name, school, date of birth, roll number or mobile number.
  • Use a different password for every important account, so that one leak does not open the rest.
  • Never write it down near the computer or share it with a friend; do not tick Remember password on a shared machine.
  • Change it immediately if a website reports a data breach or if you suspect it has been seen.

A passphrase is a convenient method: take the first letters of a sentence you can remember, keeping its digits and punctuation.

6 Explain two-factor authentication with an example. Why is it safer than a password alone?Authentication

Two-factor authentication (2FA), or two-step verification, is a login method that requires two different kinds of proof of identity out of three categories: something you know (password or PIN), something you have (a mobile phone, an authenticator app or a hardware key) and something you are (fingerprint, face or iris, called biometrics).

Example: after entering the password on a banking website, the user receives a one-time password (OTP) on the registered mobile number and must enter it within a few minutes to complete the login.

It is safer because a password can be guessed, leaked in a data breach or captured by a keylogger. Even then the attacker cannot log in, because he does not possess the registered phone or the user's fingerprint. Codes from an authenticator app or a hardware key are considered stronger than SMS OTPs, since a SIM can be cloned or a number fraudulently transferred.

7 What is cyberbullying? What steps should a student take on being cyberbullied?Cyberbullying

Cyberbullying is the use of digital technology — messages, calls, social media or gaming platforms — to repeatedly harass, threaten, humiliate or target another person. Its forms include harassment, trolling and flaming, impersonation through a fake profile, doxxing (publishing private details), exclusion from groups, cyberstalking and morphing of photographs.

Steps to be taken:

  1. Do not reply and do not retaliate — a reaction is what the bully wants.
  2. Save the evidence — screenshots showing the message, the profile name, the date, the time and the link.
  3. Block and report the account using the platform's own reporting option.
  4. Tell a trusted adult — a parent, class teacher or school counsellor.
  5. Report to the authorities for threats, obscene or morphed content, or a fake profile, through cybercrime.gov.in or helpline 1930; such offences are punishable under the Information Technology Act, 2000.

A witness should never like, share or forward such content, should support the victim privately and should report the post.

8 Differentiate between antivirus software and a firewall.Protection tools

Antivirus software is a program that detects, prevents and removes malware already present on or entering a computer. It compares files with a database of known malware patterns called virus definitions, watches for suspicious behaviour, offers quick, full and real-time scans, and moves suspect files to quarantine before repairing or deleting them. It is effective only if its definitions are updated regularly.

A firewall is hardware, software or both, placed between a computer or network and the outside world. It examines incoming and outgoing traffic against a set of rules and blocks unauthorised access, stopping intruders and preventing unapproved programs from communicating outside.

In short: a firewall controls traffic at the boundary, whereas antivirus software deals with files inside the system. They perform different tasks, so both should be used together.

Previous-year board questions 6

Q1 Expand HTTPS. State what the padlock icon in the address bar proves and what it does not prove. 2 marks

HTTPS stands for HyperText Transfer Protocol Secure.

The padlock proves that the connection between the browser and the website is encrypted using a valid security certificate, so data typed on the page cannot be read by someone monitoring the network.

It does not prove that the owner of the website is honest or that the site is genuine. A fraudulent site can also obtain a certificate, so the domain name must still be checked carefully for lookalike spellings.

Q2 Ravi receives an SMS: 'Dear Customer, your bank account will be blocked today. Click this link and update your KYC immediately.' Identify the type of attack and state two actions Ravi should take. 2 marks

This is a phishing attack — specifically smishing, because it arrives by SMS. The generic greeting Dear Customer, the manufactured urgency and the demand to click a link are the identifying signs.

Actions Ravi should take (any two):

  • Do not click the link and do not reply or share any account detail, PIN or OTP.
  • Verify independently by opening the bank's official app or by calling the number printed on his passbook or debit card, never the number in the message.
  • Report the message as spam or fraud, delete it, and if any money has been lost report at once on cybercrime.gov.in or helpline 1930.
Q3 Explain any three types of malware and state how each one spreads. 3 marks

1. Virus: malicious code that attaches itself to a file or program and damages or deletes data. It spreads when a user opens the infected file — through e-mail attachments, pen drives or downloaded software. It cannot spread on its own.

2. Worm: a standalone program that copies itself and spreads by itself across a network by exploiting weaknesses in software, without needing a host file or any user action. It slows the network by consuming bandwidth and memory.

3. Ransomware: malware that encrypts the victim's files or locks the system and demands a ransom for the key. It spreads mainly through phishing attachments and links, and through software that has not been updated. Regular backups on a separate drive are the reliable defence.

(Spyware, which secretly collects information and is often bundled with free downloads, and adware, which forces unwanted advertisements, are equally acceptable choices.)

Q4 What is identity theft? Give one example and state two ways of preventing it. 3 marks

Identity theft is the crime of stealing a person's personal information and using it to impersonate that person for gain or to cause harm.

Example: a photograph of a student's identity document is misused to obtain a SIM card or a loan in their name; or a fake social-media profile is created using their name and photograph and used to send offensive messages to classmates.

Prevention (any two):

  • Never share or post images of identity cards, mark sheets, bank passbooks or tickets, and never disclose ID numbers, card details, PINs or OTPs.
  • Use strong, unique passwords with two-factor authentication on every important account.
  • Keep social-media accounts private, restrict who can see personal details, and grant applications only the permissions they genuinely need.
Q5 Meera wants to buy a book from an online shopping site she has not used before. List five precautions she should take for a safe online transaction. 5 marks
  1. Check the site. The payment page must use https with a padlock, and the domain name must be spelled exactly right; the site should carry a contact address and a clear return and refund policy.
  2. Check the seller. Read reviews and ratings, and prefer a well-known seller. Avoid offers that are unrealistically cheap.
  3. Pay safely. Use a trusted method such as a UPI application, net banking or a card, entering the UPI PIN only inside the UPI app. For a first purchase, cash on delivery or a low-limit card is safer.
  4. Guard secrets. Never share the OTP, PIN or CVV with anyone, do not save card details on an unfamiliar site, and remember that a UPI PIN is needed only to send money, never to receive it.
  5. After paying. Log out, avoid public Wi-Fi for the transaction, keep the order confirmation and transaction reference number, keep SMS and e-mail alerts switched on, and check the bank statement; report any unknown debit immediately to the bank and on cybercrime.gov.in or helpline 1930.
Q6 Differentiate between a session cookie and a persistent cookie. Also state one way a user can limit tracking. 2 marks

A session cookie is stored only while the browser is open and is deleted automatically when the browser is closed; it is used for temporary purposes such as keeping a user logged in during one visit.

A persistent cookie is written to the disk with an expiry date and stays there across sessions, so the site can recognise the user on later visits.

To limit tracking, a user can block third-party cookies in the browser settings, clear stored cookies regularly, refuse non-essential cookies on a consent banner, or use private browsing mode — remembering that private mode hides history only from the device, not from the website or the network.

Part of Priodemy for School

Interactive Maths & Science — free with every school on Priodemy EduSuite. Explore more chapters and labs on the Priodemy for School hub.

Ask AI